WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,201–1,250 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium AdMail – Multilingual Back in-Stock Notifier for WooCommerce Plugin admail Broken Access Control ≤ 1.7.0 CVE-2025-32234 Patchstack
6.5 Medium Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods Cross-Site Scripting ≤ 3.2.8 Fixed in 3.2.9 CVE-2025-32207 Patchstack
6.5 Medium Search, Filters & Merchandising for WooCommerce Plugin instantsearch-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.58 Fixed in 3.0.59 CVE-2025-32181 Patchstack
6.5 Medium Pallet Packaging for WooCommerce Plugin pallet-packaging-for-woocommerce Broken Access Control No login needed ≤ 1.1.15 Fixed in 1.1.16 CVE-2025-22285 Patchstack
7.5 High Fami WooCommerce Compare Plugin fami-woocommerce-compare Local File Inclusion No login needed ≤ 1.0.5 CVE-2025-31405 Patchstack
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed 4.0.1 – 7.2.4 CVE-2024-13708 Wordfence
8.1 High Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 4.0.1 – 7.2.4 CVE-2024-13744 Wordfence
6.5 Medium Shopify to WooCommerce Migration Plugin migrate-shopify-to-woocommerce Broken Access Control Settings Change No login needed ≤ 1.3.0 CVE-2025-31795 Patchstack
5.4 Medium WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.0.8 CVE-2025-31794 Patchstack
6.5 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.78 CVE-2025-31758 Patchstack
7.5 High Ni WooCommerce Product Enquiry Plugin ni-woocommerce-product-enquiry Broken Access Control No login needed ≤ 4.1.8 CVE-2025-31580 Patchstack
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-31553 Patchstack
8.5 High Order Splitter for WooCommerce Plugin woo-order-splitter SQL Injection ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-31089 Patchstack
7.1 High Plugin Oficial – Getnet para WooCommerce Plugin wc-checkout-getnet Cross-Site Scripting Getnet para WooCommerce plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.8.0 CVE-2025-30906 Patchstack
8.8 High WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce Plugin wpc-smart-linked-products Privilege Escalation ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-30825 Patchstack
9.3 Critical Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-30807 Patchstack
5.4 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Broken Access Control Settings Change ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-31879 Patchstack
4.3 Medium ShipDepot for WooCommerce Plugin ship-depot Broken Access Control ≤ 1.2.19 CVE-2025-31866 Patchstack
4.3 Medium Simple Sticky Add To Cart For WooCommerce Plugin sticky-add-to-cart-woo Broken Access Control ≤ 1.4.9 CVE-2025-31854 Patchstack
4.3 Medium OpenAI Tools for WordPress & WooCommerce Plugin openai-tools-for-wp-wc Broken Access Control ≤ 2.2.1 CVE-2025-31843 Patchstack
4.3 Medium Printus Plugin printus-cloud-printing-for-woocommerce Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-31830 Patchstack
5.4 Medium Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods Broken Access Control ≤ 3.2.8 Fixed in 3.2.9 CVE-2025-31826 Patchstack
4.3 Medium Product Notices for WooCommerce Plugin product-notices-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-31807 Patchstack
5.4 Medium Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Broken Access Control Settings Change ≤ 3.1.86 CVE-2025-31802 Patchstack
4.3 Medium Gift Cards for WooCommerce Plugin woo-giftcards Broken Access Control ≤ 1.5.8 CVE-2025-31781 Patchstack
5.4 Medium Free Woocommerce Product Table View Plugin free-product-table-for-woocommerce Broken Access Control ≤ 1.78 CVE-2025-31757 Patchstack
9.8 Critical SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation No login needed ≤ 3.7.9 CVE-2024-13553 Wordfence
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 7.2.4 CVE-2024-12278 Wordfence
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.4 Fixed in 4.2.4 CVE-2025-30924 Patchstack
7.1 High SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30917 Patchstack
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.1 High Pesapal Gateway for Woocommerce Plugin pesapal-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-30579 Patchstack
6.5 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-31598 Patchstack
4.3 Medium ELEX WooCommerce Request a Quote Plugin elex-request-a-quote Broken Access Control ≤ 2.3.9 CVE-2025-31406 Patchstack
7.5 High Accounting for WooCommerce Plugin accounting-for-woocommerce Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-30835 Patchstack
9.8 Critical Checkout Mestres do WP for WooCommerce Plugin checkout-mestres-wp Broken Access Control Unauthenticated Arbitrary Options Update No login needed 8.6.5 – 8.7.5 CVE-2025-2266 Wordfence
7.1 High GlobalPayments WooCommerce Plugin global-payments-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2025-22767 Patchstack
7.1 High Já-Já Pagamentos for WooCommerce Plugin wc-ja-ja-pagamentos-multicaixa-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51624 Patchstack
6.5 Medium Shipmondo – A complete shipping solution for WooCommerce Plugin pakkelabels-for-woocommerce Information Disclosure A complete shipping solution for WooCommerce plugin <= 5.0.3 - Authenticated Arbitrary WordPress Option Disclosure ≤ 5.0.3 Fixed in 5.0.4 CVE-2025-27001 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.6.4 Fixed in 1.3.6.5 CVE-2025-26890 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 9.7.0 Fixed in 9.7.1 CVE-2025-26762 Patchstack
6.5 Medium Product Table For WooCommerce Plugin product-table-for-woocommerce Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-22638 Patchstack
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
4.3 Medium Export Order, Product, Customer & Coupon for WooCommerce to Google Sheets Plugin wpsyncsheets-woocommerce Broken Access Control ≤ 1.8.2 Fixed in 1.9 CVE-2025-22667 Patchstack
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control ≤ 5.3.5 Fixed in 5.4.0 CVE-2025-22673 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
4.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control ≤ 7.2.3 Fixed in 7.2.4 CVE-2025-30909 Patchstack
6.5 Medium افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) Plugin persian-woocommerce-shipping Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-30898 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only