WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,301–1,350 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High CURCY - WooCommerce Multi Currency - Currency Switcher Plugin SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed ≤ 2.3.6 CVE-2024-13320 Wordfence
4.3 Medium WooMail - WooCommerce Email Customizer Plugin Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection ≤ 3.0.34 CVE-2024-13747 Wordfence
4.3 Medium Zass - WooCommerce Theme for Handmade Artists and Artisans Theme Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 3.9.9.10 CVE-2024-13810 Wordfence
4.3 Medium Lafka - Multi Store Burger - Pizza & Food Delivery WooCommerce Theme Broken Access Control Multi Store Burger - Pizza & Food Delivery WooCommerce Theme <= 4.5.7 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 4.5.7 CVE-2024-13811 Wordfence
8.1 High WooCommerce Recover Abandoned Cart Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 24.4.0 CVE-2025-0956 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Broken Access Control Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization ≤ 2.6.2 CVE-2024-13724 Wordfence
4.3 Medium Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction Plugin Cross-Site Request Forgery Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery No login needed ≤ 2.6.2 CVE-2024-13682 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
9.3 Critical Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway SQL Injection No login needed ≤ 1.7.6 CVE-2025-26535 Patchstack
7.1 High Woocommerce osCommerce Sync Plugin woo-oscommerce-sync Cross-Site Scripting No login needed ≤ 2.0.20 CVE-2025-25119 Patchstack
7.1 High Local Shipping Labels for WooCommerce Plugin local-shipping-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23903 Patchstack
7.1 High Tax Report for WooCommerce Plugin tax-report-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-23731 Patchstack
7.1 High ChatGPT Open AI Images & Content for WooCommerce Plugin glasses-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2025-23668 Patchstack
7.1 High Ni WooCommerce Sales Report Email Plugin ni-woocommerce-sales-report-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.4 CVE-2025-23481 Patchstack
7.1 High AW WooCommerce Kode Pembayaran Plugin aw-woocommerce-kode-pembayaran Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-23450 Patchstack
6.1 Medium SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.2 CVE-2024-9212 Wordfence
6.5 Medium Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.28 CVE-2024-13750 Wordfence
6.1 Medium Currency Switcher for WooCommerce Plugin currency-switcher-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.16.2 CVE-2024-9217 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 3.4.24 CVE-2024-13358 Wordfence
4.3 Medium NextMove Lite – Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission ≤ 2.19.0 CVE-2024-10860 Wordfence
7.2 High Tabs for WooCommerce Plugin wc-tabs PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs ≤ 1.0.0 CVE-2024-13831 Wordfence
5.9 Medium Order Attachments for WooCommerce Plugin order-attachments-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.5.1 CVE-2024-13638 Wordfence
9.8 Critical WooCommerce Ultimate Gift Card Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.9.2 CVE-2024-8425 Wordfence
6.1 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.1 CVE-2025-1505 Wordfence
5.4 Medium WooCommerce Cart Count Shortcode Plugin Cross-Site Scripting Contributor+ XSS < 1.1.0 Fixed in 1.1.0 CVE-2024-10563 WPScan
4.3 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2025-26928 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
7.1 High Woocommerce – Loi Hamon Plugin loi-hamon Cross-Site Request Forgery Loi Hamon Plugin <= 1.1.0 - CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-27355 Patchstack
6.5 Medium Direct Checkout Button for WooCommerce Plugin woo-direct-checkout-button Cross-Site Scripting ≤ 1.0 CVE-2025-27347 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
6.5 Medium WooCommerce Display Products by Tags Plugin woocommerce-display-products-by-tags Cross-Site Scripting ≤ 1.0.0 CVE-2025-27331 Patchstack
7.1 High WooCommerce Pricing – Product Pricing Plugin woo-pricing-table Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-22632 Patchstack
8.8 High A1POST.BG Shipping for Woo Plugin a1post-bg-shipping-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5 Fixed in 1.5.1 CVE-2025-27012 Patchstack
6.4 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2024-13461 Wordfence
7.3 High WooCommerce Food - Restaurant Menu & Food ordering Plugin Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed ≤ 3.3.2 CVE-2024-13792 Wordfence
5.3 Medium Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Plugin gift-voucher Broken Access Control Missing Authorization to Unauthenticated Price, Date, and Note Updates No login needed ≤ 4.4.9 CVE-2024-13520 Wordfence
6.4 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode ≤ 2.8.5 CVE-2025-1064 Wordfence
8.5 High Distance Rate Shipping for WooCommerce Plugin distance-rate-shipping-for-woocommerce-pro SQL Injection ≤ 1.3.4 CVE-2025-22639 Patchstack
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
4.3 Medium Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later Plugin flexible-wishlist Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed ≤ 1.2.26 CVE-2024-13718 Wordfence
6.1 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6.6 CVE-2025-0864 Wordfence
8.8 High Shopwarden – Automated WooCommerce monitoring & testing Plugin shopwarden Cross-Site Request Forgery Automated WooCommerce monitoring & testing <= 1.0.11 - Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.0.11 CVE-2024-13315 Wordfence
7.5 High File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 1.7.1 CVE-2024-13622 Wordfence
5.3 Medium WooODT Lite – Delivery & pickup date time location for WooCommerce Plugin byconsole-woo-order-delivery-time Information Disclosure Delivery & pickup date time location for WooCommerce <= 2.5.1 - Unauthenticated Full Path Dsiclosure No login needed ≤ 2.5.1 CVE-2024-13540 Wordfence
5.3 Medium BigBuy Dropshipping Connector for WooCommerce Plugin bigbuy-wc-dropshipping-connector Information Disclosure Unauthenticated Full Path Disclosute No login needed ≤ 2.0.0 CVE-2024-13538 Wordfence
6.5 Medium Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.9.4 CVE-2024-13525 Wordfence
9.8 Critical Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Information Disclosure A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation No login needed ≤ 2.4.2.3 CVE-2024-13513 Wordfence
7.1 High Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.22 Fixed in 2.9.0 CVE-2025-24592 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only