WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High URL Shortener | Conversion Tracking | AB Testing | WooCommerce Plugin easy-broken-link-checker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.0.2 CVE-2025-23789 Patchstack
5.4 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 4.4.5 CVE-2024-13692 Wordfence
5.9 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 4.4.5 CVE-2024-13641 Wordfence
7.5 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Authentication Bypass via Shortcode ≤ 2.9.5 CVE-2024-13528 Wordfence
6.4 Medium Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin gs-woo-brands Cross-Site Scripting Woocommerce Brands Plugin <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.2 CVE-2024-11746 Wordfence
7.3 High CURCY – Multi Currency for WooCommerce Plugin woo-multi-currency Arbitrary Shortcode Execution Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price Function No login needed ≤ 2.2.5 CVE-2024-13487 Wordfence
6.5 Medium Product Blocks for WooCommerce Plugin product-blocks-for-woocommerce Cross-Site Scripting ≤ 1.9.1 Fixed in 2.0 CVE-2025-22674 Patchstack
8.8 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager PHP Object Injection ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-24661 Patchstack
4.3 Medium Hide Shipping Method For WooCommerce Plugin hide-shipping-method-for-woocommerce Broken Access Control ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-22694 Patchstack
6.5 Medium Korea for WooCommerce Plugin korea-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.1.11 Fixed in 1.1.12 CVE-2025-24639 Patchstack
7.1 High PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-24574 Patchstack
5.4 Medium WooCommerce Support Ticket System Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure ≤ 17.8 CVE-2024-13775 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
6.5 Medium MultiLoca - WooCommerce Multi Locations Inventory Management Plugin SQL Injection WooCommerce Multi Locations Inventory Management <= 4.1.11 - Authenticated (Subscriber+) SQL Injection ≤ 4.1.11 CVE-2024-13341 Wordfence
8.8 High WooCommerce Customers Manager Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 31.3 CVE-2024-13343 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.9.4 CVE-2024-13472 Wordfence
7.1 High Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Cross-Site Scripting WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.9.0 -Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.0 Fixed in 4.9.1 CVE-2025-24632 Patchstack
7.1 High PORTONE 우커머스 결제 Plugin iamport-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.4 Fixed in 3.2.6 CVE-2025-24609 Patchstack
6.5 Medium Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Information Disclosure Sensitive Data Exposure ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-24597 Patchstack
7.1 High Radio Buttons and Swatches for WooCommerce Plugin variations-radio-buttons-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-24551 Patchstack
5.8 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-22720 Patchstack
5.9 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 3.24 CVE-2024-13623 Wordfence
4.3 Medium Ni Sales Commission For WooCommerce Plugin ni-woo-sales-commission Broken Access Control Missing Authorization to Authenticated (Subscriber+) Commission Update ≤ 1.2.4 CVE-2024-13424 Wordfence
4.3 Medium Food Menu – Restaurant Menu & Online Ordering for WooCommerce Plugin tlp-food-menu Broken Access Control Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 5.1.4 CVE-2024-13415 Wordfence
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Local File Inclusion The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion No login needed ≤ 4.2.14 CVE-2025-0493 Wordfence
8.8 High MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics Plugin makewebbetter-hubspot-for-woocommerce Broken Access Control CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics <= 1.5.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Options Update ≤ 1.5.9 CVE-2024-10591 Wordfence
6.5 Medium W2S – Migrate WooCommerce to Shopify Plugin w2s-migrate-woo-to-shopify Broken Access Control Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read ≤ 1.2.1 CVE-2024-12861 Wordfence
4.3 Medium ECPay Ecommerce for WooCommerce Plugin ecpay-ecommerce-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 1.1.2411060 CVE-2024-13652 Wordfence
7.5 High WooCommerce Wishlist Plugin smart-wishlist-for-more-convert Information Disclosure Unauthenticated Wishlist Disclosure via download_pdf_file Function No login needed ≤ 1.8.7 CVE-2024-13694 Wordfence
7.2 High Flexible Wishlist for WooCommerce Plugin flexible-wishlist Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wishlist_name Parameter No login needed ≤ 1.2.25 CVE-2024-13696 Wordfence
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
6.1 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Cross-Site Scripting A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2024-12334 Wordfence
4.3 Medium GoHero Store Customizer for WooCommerce Plugin personalize-woocommerce-cart-page Broken Access Control Missing Authorization to Unuthenticated Settings Update ≤ 3.5 CVE-2024-12826 Wordfence
7.2 High Custom Product Tabs Lite for WooCommerce Plugin woocommerce-custom-product-tabs-lite PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.9.0 CVE-2024-12600 Wordfence
6.5 Medium PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce Cross-Site Scripting ≤ 4.6.0 Fixed in 4.7.0 CVE-2025-24755 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.13 Fixed in 4.2.14 CVE-2025-24706 Patchstack
5.3 Medium WooCommerce Quick View Plugin woo-quick-view Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.1 Fixed in 1.1.3 CVE-2025-24705 Patchstack
5.9 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Cross-Site Scripting ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-24681 Patchstack
5.9 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Cross-Site Scripting ≤ 33.0.8 Fixed in 33.0.9 CVE-2025-24668 Patchstack
5.9 Medium Wishlist for WooCommerce Plugin wt-woocommerce-wishlist Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-24657 Patchstack
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
5.4 Medium WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Cross-Site Request Forgery No login needed ≤ 1.0.35 Fixed in 1.0.36 CVE-2025-24647 Patchstack
4.3 Medium Taxonomy/Term and Role based Discounts for WooCommerce Plugin taxonomy-discounts-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.1 Fixed in 5.2 CVE-2025-24625 Patchstack
5.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24633 Patchstack
5.3 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control No login needed ≤ 3.8.7 Fixed in 3.9.0 CVE-2025-24596 Patchstack
6.5 Medium Linet ERP-Woocommerce Integration Plugin linet-erp-woocommerce-integration Cross-Site Request Forgery CSRF to Broken Access Control No login needed ≤ 3.5.7 Fixed in 3.5.8 CVE-2025-24594 Patchstack
4.3 Medium Product Size Charts Plugin for WooCommerce Plugin woo-advanced-product-size-chart Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-23991 Patchstack
4.3 Medium Variation Swatches for WooCommerce Plugin th-variation-swatches Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Reset No login needed 1.0.8 – 1.3.2 CVE-2024-13511 Wordfence
7.1 High a Gateway for Pasargad Bank on WooCommerce Plugin a-gateway-for-pasargad-bank-on-woocommerce Cross-Site Scripting No login needed ≤ 2.5.2 CVE-2025-23966 Patchstack
7.1 High WooCommerce Order Search Plugin woocommerce-order-searching Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-23495 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only