WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 176 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Arbitrary File Upload No login needed ≤ 2.9.2 Fixed in 2.10.0 CVE-2025-47577 Patchstack
9.8 Critical TicketBAI Facturas para WooCommerce Plugin wp-ticketbai Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.18 CVE-2025-4564 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.8.1 - SQL Injection No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-47682 Patchstack
9.8 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload via upload Function No login needed ≤ 1.1.6 CVE-2025-4403 Wordfence
9.8 Critical Order Delivery Date Pro for WooCommerce Plugin Cross-Site Request Forgery Unauthenticated Arbitrary Option Update No login needed 2.0 – < 12.3.1 Fixed in 12.3.1 CVE-2025-2907 WPScan
9.1 Critical Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Arbitrary File Upload ≤ 1.5.14 Fixed in 1.5.15 CVE-2025-39557 Patchstack
9.8 Critical EmpikPlace for Woocommerce Plugin empik-for-woocommerce PHP Object Injection No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-32568 Patchstack
9.3 Critical Neon Product Designer Plugin neon-product-designer-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.0 CVE-2025-32565 Patchstack
9.8 Critical Drag and Drop Multiple File Upload for WooCommerce Plugin drag-and-drop-multiple-file-upload-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Move No login needed ≤ 1.1.4 CVE-2025-2941 Wordfence
9.3 Critical Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics SQL Injection No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-31553 Patchstack
9.3 Critical Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration SQL Injection No login needed ≤ 3.9.4 Fixed in 3.9.5 CVE-2025-30807 Patchstack
9.8 Critical SMS Alert Order Notifications – WooCommerce Plugin Privilege Escalation WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation No login needed ≤ 3.7.9 CVE-2024-13553 Wordfence
9.8 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce PHP Object Injection No login needed ≤ 1.5 Fixed in 1.6 CVE-2025-31087 Patchstack
9.8 Critical Checkout Mestres do WP for WooCommerce Plugin checkout-mestres-wp Broken Access Control Unauthenticated Arbitrary Options Update No login needed 8.6.5 – 8.7.5 CVE-2025-2266 Wordfence
9.3 Critical Trust Payments Gateway for WooCommerce Plugin trust-payments-hosted-payment-pages-integration SQL Injection No login needed ≤ 1.1.4 Fixed in 2.0.0 CVE-2025-28942 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection No login needed ≤ 1.3 Fixed in 1.5 CVE-2025-26875 Patchstack
9.8 Critical CiyaShop - Multipurpose WooCommerce Theme PHP Object Injection Multipurpose WooCommerce Theme <= 4.19.0 - Unauthenticated PHP Object Injection No login needed ≤ 4.19.0 CVE-2024-13824 Wordfence
9.8 Critical HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.6.5 CVE-2025-1661 Wordfence
9.3 Critical SMS Alert Order Notifications Plugin sms-alert SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26988 Patchstack
9.3 Critical Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway SQL Injection No login needed ≤ 1.7.6 CVE-2025-26535 Patchstack
9.8 Critical WooCommerce Ultimate Gift Card Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.9.2 CVE-2024-8425 Wordfence
9.8 Critical Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Information Disclosure A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation No login needed ≤ 2.4.2.3 CVE-2024-13513 Wordfence
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Local File Inclusion The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion No login needed ≤ 4.2.14 CVE-2025-0493 Wordfence
9.9 Critical WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Remote Code Execution ≤ 1.0.8 CVE-2025-22782 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2 Fixed in 1.3 CVE-2024-56290 Patchstack
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
9.8 Critical WooCommerce Point of Sale Plugin Broken Access Control Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change No login needed ≤ 6.1.0 CVE-2024-11281 Wordfence
9.8 Critical WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Authentication Bypass PDF Vouchers plugin < 4.9.9 - Broken Authentication No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-54383 Patchstack
9.9 Critical Import Export For WooCommerce Plugin import-export-for-woocommerce Arbitrary File Upload ≤ 1.6.2 CVE-2024-54262 Patchstack
9.8 Critical Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.1.1 CVE-2024-10124 Wordfence
9.8 Critical Xpresslane Fast Checkout Plugin xpresslane-integration-for-woocommerce PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-52440 Patchstack
9.1 Critical CDI Plugin collect-and-deliver-interface-for-woocommerce Arbitrary File Upload ≤ 5.5.3 Fixed in 5.5.6 CVE-2024-52398 Patchstack
10.0 Critical kineticPay for WooCommerce Plugin kineticpay-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.8 Fixed in 3.0 CVE-2024-52379 Patchstack
9.8 Critical WooCommerce Upload Files Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 84.3 CVE-2024-10820 Wordfence
9.8 Critical WooCommerce Support Ticket System Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 17.7 CVE-2024-10627 Wordfence
9.8 Critical WooCommerce Support Ticket System Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 17.6 CVE-2024-10625 Wordfence
10.0 Critical AR For Woocommerce Plugin ar-for-woocommerce Arbitrary File Upload No login needed ≤ 6.3 Fixed in 7.0 CVE-2024-50510 Patchstack
10.0 Critical Woocommerce Product Design Plugin woo-product-design Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-50482 Patchstack
10.0 Critical Sudan Payment Gateway for WooCommerce Plugin wc-sudan-payment-gateway Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-50494 Patchstack
9.3 Critical Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection No login needed ≤ 1.1 CVE-2024-50479 Patchstack
9.9 Critical Woocommerce Custom Profile Picture Plugin woo-custom-profile-picture Arbitrary File Upload ≤ 1.0 CVE-2024-49658 Patchstack
9.3 Critical Email Verification for WooCommerce Plugin emails-verification-for-woocommerce SQL Injection No login needed ≤ 2.8.10 Fixed in 2.9.0 CVE-2024-49305 Patchstack
9.8 Critical Recently Plugin recently-viewed-most-viewed-and-sold-products-for-woocommerce PHP Object Injection No login needed ≤ 1.1 CVE-2024-49218 Patchstack
9.3 Critical YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search SQL Injection No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-47350 Patchstack
9.8 Critical WordPress & WooCommerce Affiliate Program Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 8.4.1 CVE-2024-9289 Wordfence
9.8 Critical WooCommerce Photo Reviews Premium Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 1.3.13.2 CVE-2024-8277 Wordfence
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed ≤ 4.2.0 CVE-2024-8289 Wordfence
9.3 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection No login needed ≤ 2.8.2 CVE-2024-43917 Patchstack
9.3 Critical Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin SQL Injection Unauthenticated SQL Injection No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43132 Patchstack
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only