WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,251–1,300 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.8.9 Fixed in 1.9.0 CVE-2025-30879 Patchstack
4.3 Medium Product Author for WooCommerce Plugin wc-product-author Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-30872 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
4.3 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-30854 Patchstack
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-30839 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
4.7 Medium Scheduled & Automatic Order Status Controller for WooCommerce Plugin order-status-rules-for-woocommerce Open Redirect No login needed ≤ 3.7.1 Fixed in 3.7.2 CVE-2025-30781 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
5.9 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-26929 Patchstack
9.3 Critical Trust Payments Gateway for WooCommerce Plugin trust-payments-hosted-payment-pages-integration SQL Injection No login needed ≤ 1.1.4 Fixed in 2.0.0 CVE-2025-28942 Patchstack
7.1 High Custom Product Stickers for Woocommerce Plugin custom-product-stickers-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 CVE-2025-28889 Patchstack
7.1 High In Stock Mailer for WooCommerce Plugin in-stock-mailer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-26566 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack
7.2 High Product Import Export for WooCommerce Plugin product-import-export-for-woo PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.5.0 CVE-2025-1913 Wordfence
2.7 Low Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.5.0 CVE-2025-1911 Wordfence
7.6 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.5.0 CVE-2025-1912 Wordfence
4.9 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.5.0 CVE-2025-1769 Wordfence
7.3 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Broken Access Control Unauthenticated Arbitrary Filter Call No login needed ≤ 1.0.6.7 CVE-2025-1514 Wordfence
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.9 Fixed in 1.5.9 CVE-2024-12109 WPScan
4.1 Medium Product Labels For Woocommerce Plugin SQL Injection Admin+ SQLi < 1.5.11 Fixed in 1.5.11 CVE-2024-10638 WPScan
7.5 High Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations SQL Injection Unauthenticated SQL Injection via 'automationId' No login needed ≤ 3.5.1 CVE-2025-2186 Wordfence
4.9 Medium Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.6.2 CVE-2025-1973 Wordfence
7.6 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.2 CVE-2025-1970 Wordfence
2.7 Low Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.2 CVE-2025-1972 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.2 CVE-2025-1971 Wordfence
6.5 Medium WooCommerce Multivendor Marketplace – REST API Plugin wcfm-marketplace-rest-api SQL Injection REST API <= 1.6.2 - Authenticated (Subscriber+) SQL Injection ≤ 1.6.2 CVE-2025-1311 Wordfence
4.9 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function ≤ 2.6.0 CVE-2024-13920 Wordfence
7.2 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.0 CVE-2024-13921 Wordfence
2.7 Low Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Path Traversal Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Deletion via admin_log_page Function ≤ 2.6.0 CVE-2024-13922 Wordfence
7.5 High NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.9.179 CVE-2024-13558 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
7.1 High Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26553 Patchstack
6.5 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Broken Access Control A Complete WooCommerce Affiliate Plugin <= 2.5.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via wf-export-all ≤ 2.5.3 CVE-2024-12336 Wordfence
9.8 Critical CiyaShop - Multipurpose WooCommerce Theme PHP Object Injection Multipurpose WooCommerce Theme <= 4.19.0 - Unauthenticated PHP Object Injection No login needed ≤ 4.19.0 CVE-2024-13824 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
6.4 Medium Finale Lite – Sales Countdown Timer & Discount for WooCommerce Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting Sales Countdown Timer & Discount for WooCommerce <= 2.19.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Countdown Timer ≤ 2.19.0 CVE-2024-12589 Wordfence
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
9.8 Critical HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.6.5 CVE-2025-1661 Wordfence
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
8.1 High Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.12.0 CVE-2024-13359 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
5.9 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 5.4.1 CVE-2024-13640 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer Plugin wish-list-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scriping via Wishlist Name No login needed ≤ 3.1.7 CVE-2024-13774 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only