WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,001–1,050 of 2,136 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack
4.3 Medium Trust Payments Gateway for WooCommerce (JavaScript Library) Plugin trust-payments-gateway-3ds2 Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-53569 Patchstack
6.4 Medium PayMaster for WooCommerce Plugin woocommerce-paymaster-gateway-019 Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 0.4.31 CVE-2025-6729 Wordfence
6.5 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 8.0.2 Fixed in 8.0.3 CVE-2025-39362 Patchstack
7.2 High Amazon Products to WooCommerce Plugin import-products-to-wc Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 1.2.7 CVE-2025-5817 Wordfence
9.8 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin Arbitrary File Upload WooCommerce <= 1.7.1 and 5.0 - 5.0.5 - Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.1, 5.0 – 5.0.5 CVE-2025-5746 Wordfence
7.5 High WPB Category Slider for WooCommerce Plugin wpb-woocommerce-category-slider Local File Inclusion ≤ 1.71 CVE-2025-53281 Patchstack
7.1 High Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.22 Fixed in 1.23 CVE-2025-53271 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
7.1 High WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 CVE-2025-24774 Patchstack
8.1 High MBStore - Digital WooCommerce Plugin mbstore Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed ≤ 2.3 CVE-2025-28947 Patchstack
7.1 High Woocommerce Line Notify Plugin woo-line-notify Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-30972 Patchstack
10.0 Critical Drag and Drop Multiple File Upload (Pro) - WooCommerce Plugin drag-and-drop-file-upload-wc-pro Arbitrary File Upload WooCommerce plugin <= 5.0.6 - Arbitrary File Upload No login needed ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-49885 Patchstack
8.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed ≤ 2.6 CVE-2023-25998 Patchstack
7.1 High SpecFit-Virtual Try On Woocommerce Plugin try-on-for-woocommerce Cross-Site Scripting No login needed ≤ 8.0.3 CVE-2025-23973 Patchstack
9.3 Critical GG Bought Together for WooCommerce Plugin gg-bought-together SQL Injection No login needed ≤ 1.0.2 CVE-2025-23967 Patchstack
5.3 Medium Amazon Products to WooCommerce Plugin import-products-to-wc Broken Access Control Missing Authorization to Unauthenticated Arbitrary Product Creation No login needed ≤ 1.2.7 CVE-2025-5813 Wordfence
5.4 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Broken Access Control ≤ 4.5.5 Fixed in 4.5.6 CVE-2025-49998 Patchstack
5.4 Medium WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily Plugin innovs-woo-manager Broken Access Control Customize and Control Cart page, Add to Cart button, Checkout fields easily plugin <= 1.2.4.5 - Broken Access Control ≤ 1.2.4.5 CVE-2025-50008 Patchstack
5.9 Medium Login/Signup Popup Plugin easy-login-woocommerce Cross-Site Scripting ≤ 2.9.4 Fixed in 2.9.5 CVE-2025-50027 Patchstack
6.5 Medium Related Products Manager for WooCommerce Plugin related-products-manager-woocommerce Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-50045 Patchstack
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.7 Fixed in 1.3.7.1 CVE-2025-52708 Patchstack
6.4 Medium Pixel Manager for WooCommerce (PRO) Plugin woocommerce-google-adwords-conversion-tracking-tag Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Shortcode ≤ 1.49.0 CVE-2025-6201 Wordfence
9.8 Critical Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 3.5.3 CVE-2025-1562 Wordfence
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
9.3 Critical WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm SQL Injection CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - SQL Injection No login needed ≤ 3.2.0 CVE-2025-24773 Patchstack
9.8 Critical Rapyd Payment Extension for WooCommerce Plugin rapyd-payments PHP Object Injection No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-30618 Patchstack
8.5 High Woocommerce Partial Shipment Plugin wc-partial-shipment SQL Injection ≤ 3.2 Fixed in 3.3 CVE-2025-48118 Patchstack
6.4 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 4.5.0 CVE-2025-5238 Wordfence
8.1 High Zagg - Electronics & Accessories WooCommerce Theme Local File Inclusion Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.1 CVE-2025-4200 Wordfence
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
8.1 High BodyCenter - Gym, Fitness WooCommerce Theme bodycenter Local File Inclusion Gym, Fitness WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2023-25999 Patchstack
9.3 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai SQL Injection No login needed ≤ 3.19 Fixed in 3.21 CVE-2025-24767 Patchstack
8.1 High Valen - Sport, Fashion WooCommerce Plugin valen Local File Inclusion Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2025-28945 Patchstack
7.1 High Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-47463 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47487 Patchstack
9.3 Critical Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart SQL Injection No login needed ≤ 2.5 CVE-2025-47608 Patchstack
9.3 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light SQL Injection Light plugin <= 2.4.37 - SQL Injection No login needed ≤ 2.4.37 CVE-2025-48122 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Path Traversal Light plugin <= 2.4.37 - Arbitrary File Download No login needed ≤ 2.4.37 CVE-2025-48124 Patchstack
10.0 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Remote Code Execution Light plugin <= 2.4.37 - Remote Code Execution (RCE) No login needed ≤ 2.4.37 CVE-2025-48123 Patchstack
9.8 Critical Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Privilege Escalation Light plugin <= 2.4.37 - Privilege Escalation No login needed ≤ 2.4.37 CVE-2025-48129 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.8.1 Fixed in 2.8.2 CVE-2025-49265 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 6.1.12 CVE-2024-9993 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 6.1.12 - Authenticated(Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 6.1.12 CVE-2024-9994 Wordfence
5.4 Medium TicketBAI Facturas para WooCommerce Plugin wp-ticketbai Broken Access Control ≤ 3.45 CVE-2025-24762 Patchstack
4.3 Medium Subscription Renewal Reminders for WooCommerce Plugin subscriptions-renewal-reminders Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2025-28984 Patchstack
5.3 Medium Direct Checkout for WooCommerce Lite Plugin woo-direct-checkout-lite Broken Access Control No login needed ≤ 1.0.3 CVE-2025-29006 Patchstack
6.5 Medium All Currencies for WooCommerce Plugin woocommerce-all-currencies Cross-Site Scripting ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-30950 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only