WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,051–1,100 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
5.3 Medium Claudio Sanches – Checkout Cielo for WooCommerce Plugin woocommerce-checkout-cielo Broken Access Control Checkout Cielo for WooCommerce <= 1.1.0 - Insufficient Verification of Data Authenticity to Order Payment Status Update No login needed ≤ 1.1.0 CVE-2024-1718 Wordfence
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.4 Medium WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce Plugin wp-cafe Cross-Site Scripting Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode ≤ 2.2.24 CVE-2024-5427 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget ≤ 5.5.4 CVE-2024-5341 Wordfence
6.4 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.5.3 CVE-2024-5039 Wordfence
6.4 Medium Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Carousel Widget ≤ 5.8.14 CVE-2024-5086 Wordfence
5.3 Medium WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly Plugin tour-booking-manager Broken Access Control WpTravelly <= 1.7.1 - Missing Authorization via ttbm_new_place_save No login needed ≤ 1.7.1 CVE-2024-0434 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.5.1 CVE-2024-4484 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.5.2 CVE-2024-4485 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization ≤ 5.7.17 CVE-2024-3626 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-3155 Wordfence
5.3 Medium Conditional Checkout Fields for WooCommerce Plugin Authentication Bypass Broken Authentication No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2022-45070 Patchstack
4.3 Medium ReviewX – Multi-criteria Rating & Reviews for WooCommerce Plugin Broken Access Control Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization ≤ 1.6.27 CVE-2024-3609 Wordfence
4.4 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection ≤ 2.4.9 Fixed in 2.5.0 CVE-2024-34751 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.20 CVE-2024-4624 Wordfence
5.3 Medium YITH WooCommerce Gift Cards Plugin yith-woocommerce-gift-cards Broken Access Control Missing Authorization to Unauthenticated WooCommerce Settings Update No login needed ≤ 4.12.0 CVE-2024-0870 Wordfence
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.8 Fixed in 1.4.9 CVE-2024-35167 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-34812 Patchstack
6.5 Medium Orders Tracking for WooCommerce Plugin woo-orders-tracking Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.10 CVE-2024-4039 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' ≤ 5.9.19 CVE-2024-4275 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' ≤ 5.9.19 CVE-2024-4448 Wordfence
6.5 Medium Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro Plugin back-in-stock-notifier-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.3.1 CVE-2024-4038 Wordfence
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares ≤ 4.8.1, ≤ 2.1.10, ≤ 1.9.3 Fixed in 4.9.0 CVE-2024-4233 Patchstack
5.5 Medium Where Did You Hear About Us Checkout Field for WooCommerce Plugin wc-customer-source Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-2752 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
5.3 Medium 2Checkout Payment Gateway for WooCommerce Plugin woocommerce-2checkout-payment Broken Access Control Missing Authorization via sniff_ins No login needed ≤ 6.2 CVE-2024-0629 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id ≤ 2.8.7 CVE-2024-3991 Wordfence
6.5 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.1.8 CVE-2024-3734 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.17 CVE-2024-4156 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.15 CVE-2024-4003 Wordfence
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.8 CVE-2024-3957 Wordfence
6.5 Medium Min and Max Purchase for WooCommerce Plugin min-and-max-purchase-for-woocommerce Cross-Site Scripting ≤ 2.0.0 CVE-2024-33949 Patchstack
6.5 Medium WooCommerce AWeber Newsletter Subscription Plugin Broken Access Control Unauthenticated Access Token Change/Reset No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2024-33944 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Broken Access Control ≤ 1.3.0 Fixed in 1.3.2 CVE-2024-33956 Patchstack
4.3 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-33585 Patchstack
6.4 Medium WPC Composite Products for WooCommerce Plugin wpc-composite-products Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 7.2.7 CVE-2024-2838 Wordfence
4.3 Medium Flexible Shipping Plugin flexible-shipping Broken Access Control ≤ 4.24.15 Fixed in 4.24.16 CVE-2024-32828 Patchstack
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure No login needed ≤ 5.9.15 CVE-2024-3733 Wordfence
6.5 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-32675 Patchstack
5.3 Medium TrackShip for WooCommerce Plugin trackship-for-woocommerce Broken Access Control No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-32678 Patchstack
4.3 Medium YITH WooCommerce Compare Plugin yith-woocommerce-compare Cross-Site Request Forgery No login needed ≤ 2.37.0 Fixed in 2.38.0 CVE-2024-32699 Patchstack
5.9 Medium WooCommerce Shipping Label Plugin shipping-labels-for-woo Cross-Site Scripting ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-32834 Patchstack
5.4 Medium Import Export WordPress Users Plugin users-customers-import-export-for-wp-woocommerce PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-32835 Patchstack
6.4 Medium SuperFaktura WooCommerce Plugin woocommerce-superfaktura Server-Side Request Forgery ≤ 1.40.3 Fixed in 1.40.4 CVE-2024-32803 Patchstack
6.5 Medium WooCommerce Customers Manager Plugin Information Disclosure Subscriber+ Email Disclosure < 29.8 Fixed in 29.8 CVE-2024-1756 WPScan
5.9 Medium WooCommerce Customers Manager Plugin Cross-Site Scripting Reflected XSS No login needed < 29.8 Fixed in 29.8 CVE-2024-1743 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only