WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 951–1,000 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack
5.3 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 7.7.0 CVE-2024-6448 Wordfence
4.3 Medium Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Request Forgery No login needed ≤ 2.6.18 Fixed in 2.6.19 CVE-2024-39657 Patchstack
4.3 Medium Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43316 Patchstack
5.3 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 3.23 Fixed in 3.24 CVE-2024-43259 Patchstack
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings ≤ 5.6.2 CVE-2024-5583 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget ≤ 5.6.2 CVE-2024-5763 Wordfence
5.9 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.16 Fixed in 1.4.17 CVE-2024-43292 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 9.1.2 Fixed in 9.1.3 CVE-2024-39666 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.6.4 Fixed in 2.0.0 CVE-2024-43342 Patchstack
6.5 Medium Event Manager for WooCommerce Plugin mage-eventpress Local File Inclusion ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-43138 Patchstack
6.5 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.5.1 Fixed in 3.8.6 CVE-2024-43128 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter ≤ 5.9.27 CVE-2024-7092 Wordfence
6.5 Medium JetWidgets for Elementor and WooCommerce Plugin jetwoo-widgets-for-elementor Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-38772 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget ≤ 2.2.85 CVE-2024-6346 Wordfence
6.5 Medium WooCommerce Customers Manager Plugin Cross-Site Request Forgery User Deletion via CSRF No login needed < 30.1 Fixed in 30.1 CVE-2024-2843 WPScan
6.5 Medium WooCommerce Customers Manager Plugin Cross-Site Scripting Subscriber+ Stored XSS < 30.2 Fixed in 30.2 CVE-2024-1747 WPScan
5.3 Medium CTT Expresso para WooCommerce Plugin ctt-expresso-para-woocommerce Information Disclosure Information Exposure via Unprotected Directory No login needed ≤ 3.2.12 CVE-2024-6687 Wordfence
6.4 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control Missing Authorization to (Subscriber+) Stored Cross-Site Scripting ≤ 3.5.1 CVE-2024-6458 Wordfence
5.3 Medium Aramex Shipping WooCommerce Plugin aramex-shipping-woocommerce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.1.21 CVE-2024-6566 Wordfence
4.3 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update ≤ 3.4.6 CVE-2024-6836 Wordfence
5.9 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Cross-Site Scripting Admin+ Stored XSS < 2.4.1 Fixed in 2.4.1 CVE-2024-6231 WPScan
6.5 Medium Empty Cart Button for WooCommerce Plugin empty-cart-button-for-woocommerce Cross-Site Scripting ≤ 1.3.8 CVE-2024-37217 Patchstack
5.8 Medium XPlainer - WooCommerce Product FAQ Plugin faq-for-woocommerce Cross-Site Scripting WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin <= 1.6.3 - Cross Site Scripting (XSS) No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2024-37515 Patchstack
5.9 Medium CC & BCC for Woocommerce Order Emails Plugin cc-bcc-for-woocommerce-order-emails Cross-Site Scripting ≤ 1.4.1 CVE-2024-37522 Patchstack
5.8 Medium YITH WooCommerce Ajax Product Filter Plugin yith-woocommerce-ajax-navigation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.0 Fixed in 5.2.0 CVE-2024-37943 Patchstack
6.5 Medium REVIEWS.io Plugin reviewscouk-for-woocommerce Cross-Site Scripting ≤ 1.2.7 CVE-2024-38677 Patchstack
6.5 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Path Traversal Authenticated (Subscriber+) Arbitrary File Download 7.3.0 – 7.6.1 CVE-2024-3934 Wordfence
5.3 Medium Addonify – Quick View For WooCommerce Plugin addonify-quick-view Information Disclosure Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path Dislcosure No login needed ≤ 1.2.16 CVE-2024-6560 Wordfence
4.3 Medium YITH Essential Kit for WooCommerce #1 Plugin yith-essential-kit-for-woocommerce-1 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation ≤ 2.34.0 CVE-2024-6799 Wordfence
4.3 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification ≤ 1.4.5 CVE-2024-6579 Wordfence
6.4 Medium WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Plugin wp-event-manager Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode ≤ 3.1.43 CVE-2024-2691 Wordfence
5.9 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Admin+ Stored XSS < 3.1.8 Fixed in 3.1.8 CVE-2024-3964 WPScan
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack
4.3 Medium Get Better Reviews for WooCommerce Plugin more-better-reviews-for-woocommerce Broken Access Control ≤ 4.0.6 CVE-2024-37544 Patchstack
6.5 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Local File Inclusion Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-37520 Patchstack
5.4 Medium WooCommerce Social Login Plugin woo-social-login PHP Object Injection No login needed ≤ 2.6.3 Fixed in 2.7.0 CVE-2024-37502 Patchstack
6.4 Medium XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] Plugin faq-for-woocommerce Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.7.0 CVE-2024-5669 Wordfence
4.3 Medium XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] Plugin faq-for-woocommerce Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.7.0 CVE-2024-5704 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
4.7 Medium Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce Plugin enhanced-e-commerce-for-woocommerce-store Cross-Site Scripting All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting No login needed ≤ 7.1.0 CVE-2024-6288 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.0 CVE-2024-4983 Wordfence
6.4 Medium Flatsome | Multi-Purpose Responsive WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.18.7 CVE-2024-5346 Wordfence
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Information Disclosure Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure ≤ 3.0.6 CVE-2024-1639 Wordfence
6.5 Medium WooCommerce Ship to Multiple Addresses Plugin Broken Access Control ≤ 3.8.5 Fixed in 3.8.6 CVE-2023-37872 Patchstack
6.5 Medium WooCommerce Checkout Manager Plugin woocommerce-checkout-manager Broken Access Control No login needed ≤ 7.3.0 Fixed in 7.3.1 CVE-2023-47681 Patchstack
6.4 Medium WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce Plugin cartflows Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.7 CVE-2024-4632 Wordfence
6.4 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2024-5768 Wordfence
6.5 Medium WooCommerce - Social Login Plugin Other Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness No login needed ≤ 2.6.2 CVE-2024-5868 Wordfence
6.5 Medium WooCommerce Warranty Requests Plugin Broken Access Control No login needed ≤ 2.2.7 Fixed in 2.3.0 CVE-2023-51495 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only