WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,401–1,450 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 29 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Standard Box Sizes – for WooCommerce Plugin standard-box-sizes Broken Access Control No login needed ≤ 1.6.13 Fixed in 1.6.14 CVE-2025-22318 Patchstack
4.4 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.9.80 CVE-2024-13519 Wordfence
4.3 Medium ShipWorks Connector for Woocommerce Plugin shipworks-e-commerce-bridge Cross-Site Request Forgery Cross-Site Request Forgery to Service Password/Username Update No login needed ≤ 5.2.5 CVE-2024-13317 Wordfence
7.1 High EditionGuard for WooCommerce – eBook Sales with DRM Plugin editionguard-for-woocommerce-ebook-sales-with-drm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 CVE-2025-23452 Patchstack
7.1 High Altima Lookbook Free for WooCommerce Plugin altima-lookbook-free-for-woocommerce Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-23429 Patchstack
5.4 Medium Admin and Customer Messages After Order for WooCommerce Plugin Arbitrary File Upload Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting ≤ 13.2 CVE-2024-13355 Wordfence
6.5 Medium Product Carousel For WooCommerce – WoorouSell Plugin woorousell Cross-Site Scripting WoorouSell plugin <= 1.1.0 - Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2025-22724 Patchstack
4.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-22731 Patchstack
9.9 Critical WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Remote Code Execution ≤ 1.0.8 CVE-2025-22782 Patchstack
8.5 High Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection ≤ 2.2.0 CVE-2025-22799 Patchstack
7.1 High Order Audit Log for WooCommerce Plugin order-audit-log-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-22337 Patchstack
7.1 High Scanventory Plugin woocommerce-inventory-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-22588 Patchstack
6.1 Medium Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting WpRently | WordPress plugin <= 2.2.1 - Reflected Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2024-12412 Wordfence
4.3 Medium Unlimited Theme Addon For Elementor and WooCommerce Plugin unlimited-theme-addons Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.2 CVE-2024-12116 Wordfence
5.4 Medium Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization ≤ 1.3.5 CVE-2024-12204 Wordfence
7.5 High Coupon X: Discount Pop Up, Promo Code Pop Ups, Announcement Pop Up, WooCommerce Popups Plugin coupon-x-discount-pop-up Broken Access Control Missing Authorization to Authenticated (Contributor+) PHP Object Injection ≤ 1.3.5 CVE-2024-12627 Wordfence
7.1 High Product Table for WooCommerce Plugin woo-product-table Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 Fixed in 5.0.0 CVE-2025-22307 Patchstack
8.5 High NC Wishlist for Woocommerce Plugin nc-wishlist-for-woocommerce SQL Injection ≤ 1.0.1 CVE-2025-22505 Patchstack
6.5 Medium Free WooCommerce Theme 99fy Extension Plugin 99fy-core Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-22801 Patchstack
6.5 Medium Advanced Product Information for WooCommerce Plugin woo-advanced-product-information Cross-Site Scripting ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-22803 Patchstack
6.5 Medium PDF Catalog Woocommerce Plugin pdf-catalog-woocommerce Cross-Site Scripting ≤ 2.0 Fixed in 3.0 CVE-2025-22809 Patchstack
6.5 Medium S3Player – WooCommerce & Elementor Integration Plugin drm-protected-video-streaming Cross-Site Scripting ≤ 4.2.1 CVE-2025-22818 Patchstack
6.1 Medium Pósturinn\'s Shipping with WooCommerce Plugin posturinn Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3.1 CVE-2024-11815 Wordfence
6.1 Medium Woocommerce check pincode/zipcode for shipping Plugin woocommerce-check-pincode-zipcode-for-shipping Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2024-12218 Wordfence
4.3 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Limited Settings Update ≤ 1.0.2 CVE-2024-5769 Wordfence
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
6.1 Medium Shipping via Planzer for WooCommerce Plugin wc-planzer-shipping Cross-Site Scripting Reflected Cross-Site Scripting via processed-ids No login needed ≤ 1.0.25 CVE-2024-12337 Wordfence
7.5 High Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Missing Authorization to Infinite Money Glitch No login needed ≤ 2.9.1, ≤ 3.0.6 CVE-2024-11423 Wordfence
5.3 Medium Allada T-shirt Designer for Woocommerce Plugin allada-tshirt-designer-for-woocommerce Broken Access Control No login needed ≤ 1.1 CVE-2025-22363 Patchstack
4.3 Medium Hide Category by User Role for WooCommerce Plugin hide-category-by-user-role-for-woocommerce Broken Access Control ≤ 2.1.1 Fixed in 2.2 CVE-2024-56272 Patchstack
7.5 High 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce Local File Inclusion 우커머스 결제 플러그인 plugin <= 5.2.0 - Local File Inclusion ≤ 5.2.0 Fixed in 5.2.2 CVE-2024-56281 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2 Fixed in 1.3 CVE-2024-56290 Patchstack
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
4.3 Medium Aurum - WordPress & WooCommerce Shopping Theme Broken Access Control WordPress & WooCommerce Shopping Theme <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Demo Content Import ≤ 4.0.2 CVE-2024-12781 Wordfence
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Broken Access Control WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.7.6 CVE-2024-11725 Wordfence
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed ≤ 2.0 CVE-2024-12384 Wordfence
6.1 Medium WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket Plugin woocommerce-digital-content-delivery-with-drm-flickrocket Cross-Site Scripting FlickRocket <= 4.75 - Reflected Cross-Site Scripting No login needed ≤ 4.75 CVE-2024-12438 Wordfence
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-12383 Wordfence
6.1 Medium Store credit / Gift cards for woocommerce Plugin store-credit-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.49.46 CVE-2024-11369 Wordfence
6.1 Medium Compare Products for WooCommerce Plugin woocommerce-compare-products Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12435 Wordfence
8.1 High Compare Products for WooCommerce Plugin woocommerce-compare-products PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.2.1 CVE-2024-12313 Wordfence
6.1 Medium Bizapp for WooCommerce Plugin bizapp-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2024-11378 Wordfence
6.1 Medium WooCommerce HSS Extension for Streaming Video Plugin woocommerce-hss-extension-for-streaming-video Cross-Site Scripting Reflected Cross-Site Scripting via videolink Parameter No login needed ≤ 3.31 CVE-2024-12214 Wordfence
7.2 High Custom Product Tabs for WooCommerce Plugin yikes-inc-easy-custom-woocommerce-product-tabs PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.8.5 CVE-2024-11465 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
4.3 Medium Metorik – Reports & Email Automation for WooCommerce Plugin metorik-helper Cross-Site Request Forgery No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-38691 Patchstack
5.3 Medium CoCart – Headless ecommerce Plugin cart-rest-api-for-woocommerce Broken Access Control Headless ecommerce plugin <= 3.11.2 - Broken Access Control No login needed ≤ 3.11.2 Fixed in 3.12.0 CVE-2023-47241 Patchstack
6.5 Medium Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Sales Countdown Timer & Discount for WooCommerce plugin <= 2.16.0 - Arbitrary Content Deletion No login needed ≤ 2.16.0 Fixed in 2.17.0 CVE-2023-47180 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only