WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,101–1,150 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 23 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.2.11 Fixed in 5.3.3 CVE-2025-47661 Patchstack
8.8 High Open Close WooCommerce Store Plugin woc-open-close Local File Inclusion ≤ 4.9.9 CVE-2025-47649 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.6 High ELEX Product Feed for WooCommerce Plugin elex-product-feed SQL Injection ≤ 3.1.2 CVE-2025-47643 Patchstack
4.3 Medium Awin – Advertiser Tracking for WooCommerce Plugin awin-advertiser-tracking Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-47633 Patchstack
5.4 Medium Calculate Prices based on Distance For WooCommerce Plugin calculate-prices-based-on-distance-for-woocommerce Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-47602 Patchstack
5.9 Medium Terms Popup On User Login Plugin terms-popup-on-user-login Cross-Site Scripting TPUL plugin <= 2.0.8 - Cross Site Scripting (XSS) ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-47592 Patchstack
7.6 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing SQL Injection ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-47544 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
5.4 Medium GS Variation Swatches for WooCommerce Plugin gs-woo-variation-swatches Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47526 Patchstack
6.5 Medium Product Time Countdown for WooCommerce Plugin product-countdown-for-woocommerce Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-47505 Patchstack
6.5 Medium Custom Checkout Fields for WooCommerce Plugin custom-checkout-fields-for-woocommerce Cross-Site Scripting ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-47504 Patchstack
5.4 Medium PW WooCommerce Bulk Edit Plugin pw-bulk-edit Cross-Site Request Forgery No login needed ≤ 2.134 Fixed in 2.135 CVE-2025-47473 Patchstack
5.4 Medium Music Player for WooCommerce Plugin music-player-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-47472 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
7.6 High TrackShip for WooCommerce Plugin trackship-for-woocommerce SQL Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47460 Patchstack
4.7 Medium Integration for WooCommerce and Salesforce Plugin woo-salesforce-plugin-crm-perks Open Redirect No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2025-47455 Patchstack
4.3 Medium Product Quantity Dropdown For Woocommerce Plugin product-quantity-dropdown-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 Fixed in 1.3 CVE-2025-47451 Patchstack
8.8 High Woocommerce Multiple Addresses Plugin woocommerce-multiple-addresses Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.7.1 CVE-2025-4335 Wordfence
7.5 High Advance Seat Reservation Management for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.3 CVE-2024-13344 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
9.8 Critical Order Delivery Date Pro for WooCommerce Plugin Cross-Site Request Forgery Unauthenticated Arbitrary Option Update No login needed 2.0 – < 12.3.1 Fixed in 12.3.1 CVE-2025-2907 WPScan
8.8 High Integração entre Eduzz e Woocommerce Plugin integracao-entre-eduzz-e-wc-powers Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.7.5 CVE-2025-3906 Wordfence
5.3 Medium Upsell Funnel Builder for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Other Unauthenticated Order Manipulation No login needed ≤ 3.0.0 CVE-2025-3743 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
5.3 Medium Bulk Assign Linked Products For WooCommerce Plugin wc-bulk-assign-linked-products Broken Access Control No login needed ≤ 2.1 CVE-2025-46489 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Local File Inclusion Light plugin <= 2.4.37 - Local File Inclusion No login needed ≤ 2.4.37 CVE-2025-39378 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2025-39390 Patchstack
7.5 High Checkout Field Visibility for WooCommerce Plugin checkout-field-visibility-for-woocommerce Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.4.0 CVE-2025-39391 Patchstack
6.5 Medium ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.4.9 CVE-2025-3280 Wordfence
4.3 Medium Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure ≤ 4.1 CVE-2025-1284 Wordfence
5.3 Medium Advanced Linked Variations for Woocommerce Plugin linked-variation Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-46244 Patchstack
4.3 Medium Recover abandoned cart for WooCommerce Plugin recover-wc-abandoned-cart Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2025-46243 Patchstack
6.4 Medium Tax Switch for WooCommerce Plugin tax-switch-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class-name Parameter ≤ 1.4.2 CVE-2025-3814 Wordfence
6.1 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Cross-Site Scripting Affiliate Plugin for WooCommerce <= 6.3.0 - Reflected Cross-Site Scripting via 'commission_summary' Parameter No login needed ≤ 6.3.0 CVE-2025-3598 Wordfence
7.1 High Shipping with Venipak for WooCommerce Plugin wc-venipak-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.3 Fixed in 1.22.5 CVE-2025-24553 Patchstack
7.1 High Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.23 Fixed in 1.4.23.1 CVE-2025-24586 Patchstack
7.1 High QR Code for WooCommerce Plugin wc-qr-codes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-27322 Patchstack
7.1 High 17TRACK for WooCommerce Plugin 17track Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 CVE-2025-27324 Patchstack
7.1 High WooCommerce HTML5 Video Plugin woocommerce-html5-video Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.10 CVE-2025-27343 Patchstack
7.1 High Revamp CRM for WooCommerce Plugin revampcrm-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-32512 Patchstack
7.1 High Make Email Customizer for WooCommerce Plugin make-email-customizer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 CVE-2025-32511 Patchstack
7.1 High WooCommerce Estimate and Quote Plugin wc-estimate-and-quote Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2.5 CVE-2025-32514 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-32522 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2025-32530 Patchstack
7.1 High DN Shipping by Weight for WooCommerce Plugin dn-shipping-by-weight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-32535 Patchstack
7.1 High Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.7 Fixed in 2.2.0 CVE-2025-32533 Patchstack
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only