WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,151–1,200 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WooCommerce Loyal Customers Plugin woocommerce-loyal-customer Broken Access Control No login needed ≤ 2.6 CVE-2025-32544 Patchstack
7.1 High MSRP (RRP) Pricing for WooCommerce Plugin msrp-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 Fixed in 2.0.0 CVE-2025-32552 Patchstack
8.2 High Add Product Frontend for WooCommerce Plugin add-product-frontend-for-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.8 CVE-2025-32593 Patchstack
7.1 High WooCommerce TBC Credit Card Payment Gateway (Free) Plugin woo-tbc-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-32611 Patchstack
7.1 High Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.12 Fixed in 3.1.13 CVE-2025-32628 Patchstack
7.1 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Cross-Site Scripting No login needed ≤ 0.4.61 CVE-2025-32638 Patchstack
7.1 High Product Excel Import Export & Bulk Edit for WooCommerce Plugin webd-woocommerce-product-excel-importer-bulk-edit Cross-Site Scripting No login needed ≤ 4.7 CVE-2025-32674 Patchstack
6.5 Medium Bring Fraktguiden for WooCommerce Plugin bring-fraktguiden-for-woocommerce Broken Access Control ≤ 1.11.4 Fixed in 1.11.5 CVE-2025-39559 Patchstack
7.5 High StoreContrl Woocommerce Plugin storecontrl-wp-connection Path Traversal Arbitrary File Download No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-39568 Patchstack
4.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.9.3 Fixed in 4.9.5 CVE-2025-39453 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-39457 Patchstack
5.3 Medium Password Protected – Password Protect your WordPress Site, Pages, & WooCommerce Products Plugin password-protected Information Disclosure Password Protect your WordPress Site, Pages, & WooCommerce Products <= 2.7.7 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.7.7 CVE-2025-3453 Wordfence
7.5 High Klarna Checkout for WooCommerce Plugin Denial of Service DoS via Excessive Logging No login needed < 2.13.5 Fixed in 2.13.5 CVE-2024-13925 WPScan
4.3 Medium WooCommerce Social Login Plugin woo-social-login Cross-Site Request Forgery No login needed ≤ 2.8.3 Fixed in 2.8.3 CVE-2025-39472 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2025-39520 Patchstack
9.1 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Arbitrary File Upload ≤ 1.5.14 Fixed in 1.5.15 CVE-2025-39557 Patchstack
6.5 Medium Conditional Payments for WooCommerce Plugin conditional-payments-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-39563 Patchstack
6.5 Medium Conditional Shipping for WooCommerce Plugin conditional-shipping-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-39564 Patchstack
6.5 Medium Membership For WooCommerce Plugin membership-for-woocommerce Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2025-39579 Patchstack
4.3 Medium Integration for WooCommerce and QuickBooks Plugin wp-woocommerce-quickbooks Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-39600 Patchstack
4.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control ≤ 3.9.5 Fixed in 3.9.6 CVE-2025-39602 Patchstack
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-27011 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-26749 Patchstack
7.5 High Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-32929 Patchstack
8.6 High Oxygen MyData for WooCommerce Plugin oxygen-mydata Arbitrary File Deletion No login needed ≤ 1.0.64 Fixed in 1.0.65 CVE-2025-32631 Patchstack
8.1 High WooCommerce Pickupp Plugin wc-pickupp Local File Inclusion No login needed ≤ 2.4.3 CVE-2025-32587 Patchstack
7.1 High ABA PayWay Payment Gateway for WooCommerce Plugin aba-payway-woocommerce-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-32586 Patchstack
9.8 Critical EmpikPlace for Woocommerce Plugin empik-for-woocommerce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32568 Patchstack
9.3 Critical Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.0 CVE-2025-32565 Patchstack
7.1 High WooCommerce Sales MIS Report Plugin woocommerce-mis-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 CVE-2025-32541 Patchstack
7.1 High Store Exporter Plugin woocommerce-exporter Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-32539 Patchstack
7.1 High MyWorks WooCommerce Sync for QuickBooks Online Plugin myworks-woo-sync-for-quickbooks-online Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-32524 Patchstack
7.1 High WooCommerce – Payphone Gateway Plugin wc-payphone-gateway Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32523 Patchstack
5.9 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Path Traversal Arbitrary File Read/Deletion ≤ 3.5.12 Fixed in 3.6.0 CVE-2025-31411 Patchstack
4.3 Medium Woocommerce Products Reorder Drag Drop Multiple Sort – Sortable, Rearrange Products Vagonic Plugin vagonic-sortable Broken Access Control ≤ 1.9 CVE-2025-32236 Patchstack
6.5 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.5 Fixed in 7.1.6 CVE-2025-32209 Patchstack
8.2 High CardGate Payments for WooCommerce Plugin cardgate SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-32119 Patchstack
8.5 High Review Stars Count For WooCommerce Plugin review-stars-count-for-woocommerce SQL Injection ≤ 2.0 CVE-2025-32687 Patchstack
6.5 Medium Swatchly – WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) Plugin swatchly Broken Access Control WooCommerce Variation Swatches for Products (product attributes: Image swatch, Color swatches, Label swatches) 1.2.8 - 1.4.0 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update 1.2.8 – 1.4.0 CVE-2025-2719 Wordfence
5.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2025-26888 Patchstack
7.1 High Pagopar – WooCommerce Gateway Plugin pagopar-woocommerce-gateway Cross-Site Request Forgery WooCommerce Gateway plugin <= 2.7.1 - CSRF to Stored XSS No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2025-31032 Patchstack
7.5 High Woo Product Feed For Marketing Channels Plugin woocommerce-to-google-merchant-center Broken Access Control No login needed ≤ 1.9.0 CVE-2025-31377 Patchstack
7.1 High ChillPay WooCommerce Plugin chillpay-payment-gateway Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-32570 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence
9.8 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Move No login needed ≤ 1.1.4 CVE-2025-2941 Wordfence
5.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.19 - Missing Authorization to Unauthenticated Table Rates Deletion No login needed ≤ 4.2.19 CVE-2025-2789 Wordfence
4.3 Medium Woocommerce Role Pricing Plugin woocommerce-role-pricing Cross-Site Request Forgery No login needed ≤ 3.5.6 CVE-2025-32271 Patchstack
4.3 Medium Sequential Order Numbers for WooCommerce Plugin sequential-order-numbers-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-32263 Patchstack
6.5 Medium Official CleverReach Plugin for WooCommerce Plugin cleverreach-wc Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2025-32241 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only