WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,301–1,350 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | CURCY - WooCommerce Multi Currency - Currency Switcher | SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed |
≤ 2.3.6 |
CVE-2024-13320 |
Wordfence | |
| 4.3 Medium | WooMail - WooCommerce Email Customizer | Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection |
≤ 3.0.34 |
CVE-2024-13747 |
Wordfence | |
| 4.3 Medium | Zass - WooCommerce Theme for Handmade Artists and Artisans | Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 3.9.9.10 |
CVE-2024-13810 |
Wordfence | |
| 4.3 Medium | Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce | Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 4.5.7 |
CVE-2024-13811 |
Wordfence | |
| 8.1 High | WooCommerce Recover Abandoned Cart | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 24.4.0 |
CVE-2025-0956 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization |
≤ 2.6.2 |
CVE-2024-13724 |
Wordfence | |
| 4.3 Medium | Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction | Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed |
≤ 2.6.2 |
CVE-2024-13682 |
Wordfence | |
| 9.3 Critical | SMS Alert Order Notifications | SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed |
≤ 3.7.8 Fixed in 3.7.9 |
CVE-2025-26988 |
Patchstack | |
| 7.1 High | SMS Alert Order Notifications | Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.7.8 Fixed in 3.7.9 |
CVE-2025-26984 |
Patchstack | |
| 9.3 Critical | Bitcoin / AltCoin Payment Gateway for WooCommerce | SQL Injection No login needed |
≤ 1.7.6 |
CVE-2025-26535 |
Patchstack | |
| 7.1 High | Woocommerce osCommerce Sync | Cross-Site Scripting No login needed |
≤ 2.0.20 |
CVE-2025-25119 |
Patchstack | |
| 7.1 High | Local Shipping Labels for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2025-23903 |
Patchstack | |
| 7.1 High | Tax Report for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2 |
CVE-2025-23731 |
Patchstack | |
| 7.1 High | ChatGPT Open AI Images & Content for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.0 |
CVE-2025-23668 |
Patchstack | |
| 7.1 High | Ni WooCommerce Sales Report Email | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.1.4 |
CVE-2025-23481 |
Patchstack | |
| 7.1 High | AW WooCommerce Kode Pembayaran | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.4 |
CVE-2025-23450 |
Patchstack | |
| 6.1 Medium | SKU Generator for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.2 |
CVE-2024-9212 |
Wordfence | |
| 6.5 Medium | Multilevel Referral Affiliate Plugin for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.28 |
CVE-2024-13750 |
Wordfence | |
| 6.1 Medium | Currency Switcher for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.16.2 |
CVE-2024-9217 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update |
≤ 3.4.25 |
CVE-2025-1780 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update |
≤ 3.4.24 |
CVE-2024-13358 |
Wordfence | |
| 4.3 Medium | NextMove Lite – Thank You Page for WooCommerce | Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission |
≤ 2.19.0 |
CVE-2024-10860 |
Wordfence | |
| 7.2 High | Tabs for WooCommerce | PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs |
≤ 1.0.0 |
CVE-2024-13831 |
Wordfence | |
| 5.9 Medium | Order Attachments for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 2.5.1 |
CVE-2024-13638 |
Wordfence | |
| 9.8 Critical | WooCommerce Ultimate Gift Card | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.9.2 |
CVE-2024-8425 |
Wordfence | |
| 6.1 Medium | Advanced AJAX Product Filters | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.8.1 |
CVE-2025-1505 |
Wordfence | |
| 5.4 Medium | WooCommerce Cart Count Shortcode | Cross-Site Scripting Contributor+ XSS |
< 1.1.0 Fixed in 1.1.0 |
CVE-2024-10563 |
WPScan | |
| 4.3 Medium | Order Limit for WooCommerce | Broken Access Control |
≤ 3.0.2 Fixed in 3.0.3 |
CVE-2025-26928 |
Patchstack | |
| 6.5 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting |
≤ 2.8.0.1 Fixed in 2.8.1 |
CVE-2025-26878 |
Patchstack | |
| 7.1 High | Woocommerce – Loi Hamon | Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed |
≤ 1.1.0 |
CVE-2025-27355 |
Patchstack | |
| 6.5 Medium | Direct Checkout Button for WooCommerce | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-27347 |
Patchstack | |
| 4.3 Medium | WooCommerce Recargo de Equivalencia | Cross-Site Request Forgery No login needed |
≤ 1.6.24 |
CVE-2025-27342 |
Patchstack | |
| 6.5 Medium | WooCommerce Display Products by Tags | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-27331 |
Patchstack | |
| 7.1 High | WooCommerce Pricing – Product Pricing | Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed |
≤ 1.0.9 Fixed in 1.1.0 |
CVE-2025-22632 |
Patchstack | |
| 8.8 High | A1POST.BG Shipping for Woo | Cross-Site Request Forgery CSRF to Privilege Escalation No login needed |
≤ 1.5 Fixed in 1.5.1 |
CVE-2025-27012 |
Patchstack | |
| 6.4 Medium | Autoship Cloud for WooCommerce Subscription Products | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.0 |
CVE-2024-13461 |
Wordfence | |
| 7.3 High | WooCommerce Food - Restaurant Menu & Food ordering | Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed |
≤ 3.3.2 |
CVE-2024-13792 |
Wordfence | |
| 5.3 Medium | Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) | Broken Access Control Missing Authorization to Unauthenticated Price, Date, and Note Updates No login needed |
≤ 4.4.9 |
CVE-2024-13520 |
Wordfence | |
| 6.4 Medium | Login/Signup Popup ( Inline Form + Woocommerce ) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode |
≤ 2.8.5 |
CVE-2025-1064 |
Wordfence | |
| 8.5 High | Distance Rate Shipping for WooCommerce | SQL Injection |
≤ 1.3.4 |
CVE-2025-22639 |
Patchstack | |
| 7.3 High | PressMart - Modern Elementor WooCommerce | Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.16 |
CVE-2024-13797 |
Wordfence | |
| 4.3 Medium | Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later | Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed |
≤ 1.2.26 |
CVE-2024-13718 |
Wordfence | |
| 6.1 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6.6 |
CVE-2025-0864 |
Wordfence | |
| 8.8 High | Shopwarden – Automated WooCommerce monitoring & testing | Cross-Site Request Forgery Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update No login needed |
≤ 1.0.11 |
CVE-2024-13315 |
Wordfence | |
| 7.5 High | File Uploads Addon for WooCommerce | Arbitrary File Upload Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed |
≤ 1.7.1 |
CVE-2024-13622 |
Wordfence | |
| 5.3 Medium | WooODT Lite – Delivery & pickup date time location for WooCommerce | Information Disclosure Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure No login needed |
≤ 2.5.1 |
CVE-2024-13540 |
Wordfence | |
| 5.3 Medium | BigBuy Dropshipping Connector for WooCommerce | Information Disclosure Unauthenticated Full Path Disclosute No login needed |
≤ 2.0.0 |
CVE-2024-13538 |
Wordfence | |
| 6.5 Medium | Customer Email Verification for WooCommerce | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure |
≤ 2.9.4 |
CVE-2024-13525 |
Wordfence | |
| 9.8 Critical | Oliver POS – A WooCommerce Point of Sale (POS) | Information Disclosure A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation No login needed |
≤ 2.4.2.3 |
CVE-2024-13513 |
Wordfence | |
| 7.1 High | Customize My Account for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.8.22 Fixed in 2.9.0 |
CVE-2025-24592 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.