WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,201–1,250 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Gestpay for WooCommerce Plugin Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_set_default_card No login needed ≤ 20221130 CVE-2024-0431 Wordfence
4.3 Medium Gestpay for WooCommerce Plugin wppdf Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_delete_card No login needed ≤ 20221130 CVE-2024-0432 Wordfence
4.3 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery via ajax_theme_activation No login needed ≤ 1.4.4 CVE-2024-0768 Wordfence
4.3 Medium Gestpay for WooCommerce Plugin wppdf Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_unset_default_card No login needed ≤ 20221130 CVE-2024-0433 Wordfence
5.4 Medium Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.1.2 CVE-2024-1687 Wordfence
4.3 Medium Thank You Page Customizer for WooCommerce – Increase Your Sales Plugin woo-thank-you-page-customizer Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export ≤ 1.1.2 CVE-2024-1686 Wordfence
5.3 Medium WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin myshopkit-popup-smartbar-slidein Information Disclosure WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.0.9 CVE-2024-1436 Patchstack
5.4 Medium SuperFaktura WooCommerce Plugin woocommerce-superfaktura Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery ≤ 1.40.3 CVE-2024-1758 Wordfence
4.3 Medium FG PrestaShop to WooCommerce Plugin fg-prestashop-to-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed ≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 CVE-2024-24837 Patchstack
5.3 Medium WooCommerce Google Sheet Connector Plugin Broken Access Control Missing Authorization No login needed ≤ 1.3.11 CVE-2024-1562 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery ≤ 5.9.8 CVE-2024-1171 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion ≤ 5.9.8 CVE-2024-1172 Wordfence
6.1 Medium Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.8 CVE-2024-0821 Wordfence
6.4 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.1.6 CVE-2024-1054 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1276 Wordfence
5.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Improper Authorization via submit_review No login needed ≤ 5.38.12 CVE-2024-1044 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1236 Wordfence
6.5 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Scripting WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0.6 Fixed in 1.0.6.1 CVE-2023-51480 Patchstack
6.5 Medium Pay with Vipps and MobilePay for WooCommerce Plugin woo-vipps Cross-Site Scripting WordPress Pay with Vipps for WooCommerce Plugin <= 1.14.13 is vulnerable to Cross Site Scripting (XSS) ≤ 1.14.13 Fixed in 1.14.14 CVE-2023-51485 Patchstack
5.3 Medium Event Manager, Events Calendar, Events Tickets for WooCommerce – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 3.3.50 - Missing Authorization to Unauthenticated Events Export No login needed ≤ 3.3.50 CVE-2024-1122 Wordfence
5.9 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Scripting WordPress BEAR Plugin <= 1.1.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24834 Patchstack
5.9 Medium Woocommerce Vietnam Checkout Plugin woo-vietnam-checkout Cross-Site Scripting WordPress Woocommerce Vietnam Checkout Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-24885 Patchstack
5.9 Medium Product Labels For Woocommerce (Sale Badges) Plugin aco-product-labels-for-woocommerce Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-24886 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping ≤ 5.9.4 CVE-2024-0586 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.7 CVE-2024-0954 Wordfence
4.3 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.6.1 CVE-2024-0796 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl ≤ 5.9.4 CVE-2024-0585 Wordfence
4.3 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Broken Access Control Missing Authorization ≤ 1.0.6.1 CVE-2024-0797 Wordfence
5.9 Medium Add Customer for WooCommerce Plugin add-customer-for-woocommerce Cross-Site Scripting WordPress Add Customer for WooCommerce Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7 Fixed in 1.7.1 CVE-2024-24841 Patchstack
6.5 Medium Product Code for WooCommerce Plugin product-code-for-woocommerce Cross-Site Scripting WordPress Product Code for WooCommerce Plugin <= 1.4.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.4 Fixed in 1.4.5 CVE-2023-51669 Patchstack
5.9 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Cross-Site Scripting WordPress Stock Locations for WooCommerce Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) ≤ 2.5.9 Fixed in 2.6.0 CVE-2024-22153 Patchstack
6.1 Medium Biteship for WooCommerce Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 2.2.25 Fixed in 2.2.25 CVE-2023-6278 WPScan
5.3 Medium Category Discount Woocommerce Plugin woo-product-category-discount Broken Access Control Missing Authorization via wpcd_save_discount() No login needed ≤ 4.12 CVE-2024-0617 Wordfence
4.8 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Admin+ Stored XSS < 3.1 Fixed in 3.1 CVE-2023-6626 WPScan
4.3 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Request Forgery Arbitrary Enquiry Deletion via CSRF No login needed < 3.1 Fixed in 3.1 CVE-2023-6625 WPScan
5.4 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2022-40702 Patchstack
5.4 Medium Cart2Cart: Magento to WooCommerce Migration Plugin cart2cart-magento-to-woocommerce-migration Broken Access Control WordPress Cart2Cart: Magento to WooCommerce Migration Plugin <= 2.0.0 is vulnerable to Broken Access Control ≤ 2.0.0 CVE-2023-34379 Patchstack
6.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Broken Access Control WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control ≤ 4.1.5 Fixed in 4.1.6 CVE-2022-40203 Patchstack
4.3 Medium Sales Report Email for WooCommerce Plugin woo-advanced-sales-report-email Broken Access Control WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control ≤ 2.8 Fixed in 2.9 CVE-2022-38141 Patchstack
6.1 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Reflected XSS No login needed < 3.2 Fixed in 3.2 CVE-2023-7151 WPScan
6.1 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Scripting Reflected XSS No login needed < 4.7.2 Fixed in 4.7.2 CVE-2023-0479 WPScan
5.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Contributor+ Stored XSS < 5.17.0 Fixed in 5.17.0 CVE-2023-0079 WPScan
4.3 Medium WooCommerce Plugin woocommerce Broken Access Control Subscriber+ Arbitrary Comment Deletion < 6.2.1 Fixed in 6.2.1 CVE-2022-0775 WPScan
5.3 Medium WPGraphQL WooCommerce Plugin Information Disclosure Unauthenticated Coupon Codes Disclosure No login needed < 0.12.4 Fixed in 0.12.4 CVE-2022-1563 WPScan
6.1 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting Unauthenticated Reflected Cross-Site Scripting (XSS) No login needed < 1.5.4.7 Fixed in 1.5.4.7 CVE-2021-24432 WPScan
5.4 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.4.1.6 CVE-2023-6556 Wordfence
5.4 Medium Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More Plugin woocommerce-wholesale-prices Broken Access Control WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control ≤ 2.1.5 Fixed in 2.1.5.1 CVE-2022-34344 Patchstack
5.3 Medium WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Plugin wp-optin-wheel Information Disclosure WordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-51408 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.2.2 Fixed in 8.3.0 CVE-2023-52222 Patchstack
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only