WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 245 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium OpenPix Plugin openpix-for-woocommerce Broken Access Control Subscriber+ Payment Gateway Settings Reset ≤ 2.13.3 CVE-2025-15400 WPScan
5.3 Medium Chapa Payment Gateway Plugin for WooCommerce Plugin chapa-payment-gateway-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.3 CVE-2025-15482 Wordfence
5.3 Medium Wizit Gateway for WooCommerce Plugin wizit-gateway-for-woocommerce Broken Access Control Missing Authentication to Unauthenticated Arbitrary Order Cancellation No login needed ≤ 1.3.1 CVE-2025-14843 Wordfence
5.3 Medium SumUp Payment Gateway For WooCommerce Plugin sumup-payment-gateway-for-woocommerce Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2026-24583 Patchstack
6.4 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via wp-rss-aggregator Shortcode ≤ 5.0.10 CVE-2025-14745 Wordfence
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
6.5 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control No login needed ≤ 3.3.6 Fixed in 3.3.7 CVE-2025-67942 Patchstack
5.3 Medium Payment Gateway bKash for WC Plugin woo-payment-bkash Broken Access Control No login needed ≤ 3.1.0 CVE-2025-62754 Patchstack
6.1 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Cross-Site Scripting RSS Import, News Feeds, Feed to Post, and Autoblogging <= 5.0.10 - Reflected Cross-Site Scripting via className No login needed ≤ 5.0.10 CVE-2025-14375 Wordfence
5.3 Medium PayHere Payment Gateway Plugin for WooCommerce Plugin payhere-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.3.9 CVE-2025-15475 Wordfence
5.3 Medium Float Payment Gateway Plugin float-gateway Broken Access Control Improper Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.1.9 CVE-2025-15513 Wordfence
5.3 Medium Aplazo Payment Gateway Plugin aplazo-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation No login needed ≤ 1.4.3 CVE-2025-15512 Wordfence
5.3 Medium Netcash WooCommerce Payment Gateway Plugin netcash-pay-now-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 4.1.3 CVE-2025-14880 Wordfence
5.3 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Change No login needed ≤ 3.1.4 CVE-2025-14460 Wordfence
7.5 High Yoco Payments Plugin yoco-payment-gateway Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 3.9.0 CVE-2025-13801 Wordfence
8.2 High iPaymu Payment Gateway for WooCommerce Plugin ipaymu-for-woocommerce Price Manipulation Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure No login needed ≤ 2.0.2 CVE-2026-0656 Wordfence
6.1 Medium HBLPAY Payment Gateway for WooCommerce Plugin hblpay-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'cusdata' Parameter No login needed ≤ 5.0.0 CVE-2025-14875 Wordfence
4.3 Medium Quran Gateway Plugin quran-gateway Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.5 CVE-2025-14164 Wordfence
5.3 Medium Yaad Sarig Payment Gateway For WC Plugin yaad-sarig-payment-gateway-for-wc Broken Access Control No login needed ≤ 2.2.11 CVE-2025-66131 Patchstack
5.3 Medium Campay Woocommerce Payment Gateway Plugin campay-api Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.2.2 CVE-2025-12883 Wordfence
5.8 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 5.1.1 CVE-2025-11467 Wordfence
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Broken Access Control No login needed ≤ 9.0.53 Fixed in 9.0.54 CVE-2025-63023 Patchstack
4.3 Medium WooCommerce Payment Gateway - Paysera Plugin woo-payment-gateway-paysera Broken Access Control Paysera plugin <= 3.10.0 - Broken Access Control ≤ 3.10.0 Fixed in 3.11.0 CVE-2025-63015 Patchstack
5.3 Medium Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control No login needed ≤ 4.7.1 CVE-2025-62870 Patchstack
4.3 Medium Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents Plugin bread-butter Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 7.11.1374 CVE-2025-12189 Wordfence
5.3 Medium Cryptocurrency Payment Gateway for WooCommerce Plugin triplea-cryptocurrency-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 2.0.25 CVE-2025-12392 Wordfence
7.5 High Payment Plugins Braintree For WooCommerce Plugin woo-payment-gateway Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed ≤ 3.2.78 CVE-2025-12903 Wordfence
5.4 Medium Slippy Slider – Responsive Touch Navigation Slider Plugin slippy-slider-responsive-touch-navigation-slider Cross-Site Scripting Responsive Touch Navigation Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-11874 Wordfence
9.3 Critical HieCOR Payment Gateway Plugin hcv4-payment-gateway SQL Injection No login needed ≤ 1.5.11 Fixed in 2.0.0 CVE-2025-52773 Patchstack
7.5 High Crypto Payment Gateway with Payeer for WooCommerce Plugin crypto-payment-gateway-with-payeer-for-woocommerce Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.0.3 CVE-2025-11890 Wordfence
4.3 Medium Posts Navigation Links for Sections and Headings - Free by WP Masters Plugin posts-navigation-links-for-sections-and-headings-free-by-wp-masters Cross-Site Request Forgery Free by WP Masters <= 1.0.1 - Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.1 CVE-2025-12188 Wordfence
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting No login needed ≤ 1.8.6 CVE-2025-49958 Patchstack
5.3 Medium Oceanpayment CreditCard Gateway Plugin oceanpayment-creditcard-gateway Broken Access Control Missing Authentication to Unauthenticated Order Status Update No login needed ≤ 6.0 CVE-2025-11728 Wordfence
4.3 Medium Payrexx Payment Gateway for WooCommerce Plugin woo-payrexx-gateway Broken Access Control ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-59559 Patchstack
5.3 Medium CardCom Payment Gateway Plugin woo-cardcom-payment-gateway Broken Access Control No login needed ≤ 3.5.0.7 CVE-2025-57976 Patchstack
5.9 Medium GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership Plugin gourl-bitcoin-payment-gateway-paid-downloads-membership Cross-Site Scripting ≤ 1.6.6 CVE-2025-48102 Patchstack
7.5 High WooCommerce Payment Gateway for Saferpay Plugin woocommerce-payment-gateway-for-saferpay Path Traversal No login needed ≤ 0.4.9 CVE-2025-48317 Patchstack
6.5 Medium Frisbii Pay Plugin reepay-checkout-gateway Broken Access Control ≤ 1.8.2.1 Fixed in 1.8.3 CVE-2025-58616 Patchstack
7.5 High Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts No login needed ≤ 1.5.4 CVE-2025-6025 Wordfence
4.3 Medium Trust Payments Gateway for WooCommerce (JavaScript Library) Plugin trust-payments-gateway-3ds2 Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-53569 Patchstack
6.4 Medium PayMaster for WooCommerce Plugin woocommerce-paymaster-gateway-019 Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 0.4.31 CVE-2025-6729 Wordfence
5.3 Medium iCount Payment Gateway Plugin icount Broken Access Control No login needed ≤ 2.0.7 CVE-2025-53295 Patchstack
8.5 High Navigation Tree Elementor Plugin navigation-tree-elementor SQL Injection ≤ 1.0.1 CVE-2025-30562 Patchstack
6.5 Medium CryptoCloud - Crypto Payment Gateway Plugin cryptocloud-crypto-payment-gateway Broken Access Control Crypto Payment Gateway plugin <= 2.1.2 - Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.3.2 CVE-2025-48147 Patchstack
4.9 Medium Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Path Traversal Arbitrary File Download ≤ 7.1.7 Fixed in 7.1.8 CVE-2025-46486 Patchstack
9.8 Critical CoinPayments.net Payment Gateway for WooCommerce Plugin coinpayments-payment-gateway-for-woocommerce PHP Object Injection No login needed ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47532 Patchstack
6.1 Medium Payment Gateway for Telcell Plugin payment-gateway-for-telcell Open Redirect Unauthenticated Open Redirect No login needed ≤ 2.0.1 CVE-2023-6786 WPScan
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only