WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,001–1,050 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WooCommerce Warranty Requests Plugin Broken Access Control No login needed ≤ 2.2.7 Fixed in 2.3.0 CVE-2023-51496 Patchstack
5.4 Medium WooCommerce Ship to Multiple Addresses Plugin Broken Access Control ≤ 3.8.9 Fixed in 3.8.10 CVE-2023-51497 Patchstack
4.3 Medium WooCommerce Easy Duplicate Product Plugin woo-easy-duplicate-product Broken Access Control ≤ 0.3.0.7 Fixed in 0.3.0.8 CVE-2023-51523 Patchstack
6.5 Medium SKU Label Changer For WooCommerce Plugin woo-sku-label-changer Broken Access Control No login needed ≤ 3.0 Fixed in 3.0.1 CVE-2023-29174 Patchstack
5.3 Medium Pricing Deals for WooCommerce Plugin pricing-deals-for-woocommerce Broken Access Control No login needed ≤ 2.0.3.2 CVE-2023-41240 Patchstack
5.4 Medium BulkGate SMS Plugin for WooCommerce Plugin woosms-sms-module-for-woocommerce Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2023-51679 Patchstack
4.3 Medium Quotes for WooCommerce Plugin quotes-for-woocommerce Broken Access Control ≤ 2.0.1 Fixed in 2.0.2 CVE-2023-51680 Patchstack
6.4 Medium CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin woolementor Cross-Site Scripting Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 4.4.1 CVE-2024-4564 Wordfence
5.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Broken Access Control ReviewShort plugin <= 1.01.5 - Broken Access Control No login needed ≤ 1.01.5 Fixed in 1.01.6 CVE-2024-34763 Patchstack
4.3 Medium MailerLite – WooCommerce integration Plugin woo-mailerlite Broken Access Control WooCommerce integration plugin <= 2.0.8 - Broken Access Control ≤ 2.0.8 Fixed in 2.0.9 CVE-2023-52227 Patchstack
4.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control ≤ 4.9.7 Fixed in 4.9.8 CVE-2023-52224 Patchstack
5.3 Medium MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Broken Access Control No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-34819 Patchstack
5.3 Medium WooCommerce Canada Post Shipping Plugin Broken Access Control No login needed ≤ 2.8.3 Fixed in 2.8.4 CVE-2023-51498 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.23 CVE-2024-5189 Wordfence
5.4 Medium Product Expiry for WooCommerce Plugin product-expiry-for-woocommerce Broken Access Control ≤ 2.5 Fixed in 2.6 CVE-2023-52179 Patchstack
5.3 Medium MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Broken Access Control No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2024-34813 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2023-52217 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-52186 Patchstack
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget ≤ 2.9.0 CVE-2024-5530 Wordfence
5.3 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Content Injection No login needed ≤ 32.0.20 Fixed in 32.0.21 CVE-2024-35728 Patchstack
5.3 Medium YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Content Injection No login needed ≤ 4.9.2 Fixed in 4.9.3 CVE-2024-35680 Patchstack
4.3 Medium Bosa Elementor Addons and Templates for WooCommerce Plugin bosa-elementor-for-woocommerce Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2024-35724 Patchstack
4.3 Medium Extra Product Options for WooCommerce Plugin extra-product-options-for-woocommerce Broken Access Control ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-35727 Patchstack
5.3 Medium WooCommerce Dropshipping Plugin Broken Access Control Unauthenticated Arbitrary Email Sending No login needed ≤ 5.0.4 CVE-2024-35748 Patchstack
5.4 Medium Simple COD Fees for WooCommerce Plugin simple-cod-fee-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-35662 Patchstack
5.3 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Broken Access Control No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-31276 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
5.3 Medium USPS Shipping for WooCommerce – Live Rates Plugin flexible-shipping-usps Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed ≤ 1.9.4 Fixed in 1.10.0 CVE-2024-32811 Patchstack
5.3 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32814 Patchstack
4.3 Medium Flexible Checkout Fields for WooCommerce Plugin flexible-checkout-fields Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-31267 Patchstack
6.5 Medium YITH WooCommerce Account Funds Premium Plugin Broken Access Control ≤ 1.33.0 Fixed in 1.34.0 CVE-2024-30470 Patchstack
5.4 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.4 Fixed in 5.3.5 CVE-2024-30466 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2024-25929 Patchstack
6.5 Medium WooCommerce Box Office Plugin Broken Access Control Unauthenticated Save Ticket Barcode No login needed ≤ 1.1.51 Fixed in 1.1.52 CVE-2023-34003 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2023-51494 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Information Disclosure Authenticated Arbitrary WordPress Option Disclosure < 7.1.3 Fixed in 7.1.3 CVE-2023-52230 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Broken Access Control Authenticated Arbitrary Post/Page Deletion < 7.1.2 Fixed in 7.1.2 CVE-2023-52232 Patchstack
4.3 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Broken Access Control ≤ 2.4.0 Fixed in 2.4.1 CVE-2024-30537 Patchstack
5.9 Medium YITH WooCommerce Tab Manager Plugin yith-woocommerce-tab-manager Cross-Site Scripting ≤ 1.35.0 Fixed in 1.35.1 CVE-2024-35698 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute ≤ 2.2.80 CVE-2024-4042 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget ≤ 5.8.15 CVE-2024-5612 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-1988 Wordfence
4.3 Medium WooCommerce Tools Plugin woo-tools Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Module Deactivation ≤ 1.2.9 CVE-2024-1689 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.22 CVE-2024-5188 Wordfence
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
4.3 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Exposure 2.7.1 – 2.7.2 CVE-2024-5665 Wordfence
6.4 Medium SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster Plugin sellkit Cross-Site Scripting Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9.8 CVE-2024-4608 Wordfence
4.9 Medium Woocommerce – Recent Purchases Plugin woo-recent-purchases Local File Inclusion Recent Purchases plugin <= 1.0.1 - File Inclusion ≤ 1.0.1 CVE-2024-35634 Patchstack
6.5 Medium Booster Elite for WooCommerce Plugin Authentication Bypass Authenticated Production Creation/Modification < 7.1.3 Fixed in 7.1.3 CVE-2023-51511 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Authentication Bypass Authenticated Production Creation/Modification ≤ 7.1.2 Fixed in 7.1.3 CVE-2023-48747 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only