WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 176 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 10.0 Critical | TI WooCommerce Wishlist | Arbitrary File Upload No login needed |
≤ 2.9.2 Fixed in 2.10.0 |
CVE-2025-47577 |
Patchstack | |
| 9.8 Critical | TicketBAI Facturas para WooCommerce | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 3.18 |
CVE-2025-4564 |
Wordfence | |
| 9.3 Critical | SMS Alert Order Notifications | SQL Injection WooCommerce plugin <= 3.8.1 - SQL Injection No login needed |
≤ 3.8.1 Fixed in 3.8.2 |
CVE-2025-47682 |
Patchstack | |
| 9.8 Critical | Drag and Drop Multiple File Upload for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload via upload Function No login needed |
≤ 1.1.6 |
CVE-2025-4403 |
Wordfence | |
| 9.8 Critical | Order Delivery Date Pro for WooCommerce | Cross-Site Request Forgery Unauthenticated Arbitrary Option Update No login needed |
2.0 – < 12.3.1 Fixed in 12.3.1 |
CVE-2025-2907 |
WPScan | |
| 9.1 Critical | Kadence WooCommerce Email Designer | Arbitrary File Upload |
≤ 1.5.14 Fixed in 1.5.15 |
CVE-2025-39557 |
Patchstack | |
| 9.8 Critical | EmpikPlace for Woocommerce | PHP Object Injection No login needed |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2025-32568 |
Patchstack | |
| 9.3 Critical | Neon Product Designer | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.2.0 |
CVE-2025-32565 |
Patchstack | |
| 9.8 Critical | Drag and Drop Multiple File Upload for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Move No login needed |
≤ 1.1.4 |
CVE-2025-2941 |
Wordfence | |
| 9.3 Critical | Advanced WooCommerce Product Sales Reporting | SQL Injection No login needed |
≤ 4.1.1 Fixed in 4.1.2 |
CVE-2025-31553 |
Patchstack | |
| 9.3 Critical | Next-Cart Store to WooCommerce Migration | SQL Injection No login needed |
≤ 3.9.4 Fixed in 3.9.5 |
CVE-2025-30807 |
Patchstack | |
| 9.8 Critical | SMS Alert Order Notifications – WooCommerce | Privilege Escalation WooCommerce <= 3.7.9 - Unauthenticated Account Takeover/Privilege Escalation No login needed |
≤ 3.7.9 |
CVE-2024-13553 |
Wordfence | |
| 9.8 Critical | Multiple Shipping And Billing Address For Woocommerce | PHP Object Injection No login needed |
≤ 1.5 Fixed in 1.6 |
CVE-2025-31087 |
Patchstack | |
| 9.8 Critical | Checkout Mestres do WP for WooCommerce | Broken Access Control Unauthenticated Arbitrary Options Update No login needed |
8.6.5 – 8.7.5 |
CVE-2025-2266 |
Wordfence | |
| 9.3 Critical | Trust Payments Gateway for WooCommerce | SQL Injection No login needed |
≤ 1.1.4 Fixed in 2.0.0 |
CVE-2025-28942 |
Patchstack | |
| 9.3 Critical | Multiple Shipping And Billing Address For Woocommerce | SQL Injection No login needed |
≤ 1.3 Fixed in 1.5 |
CVE-2025-26875 |
Patchstack | |
| 9.8 Critical | CiyaShop - Multipurpose WooCommerce | PHP Object Injection Multipurpose WooCommerce Theme <= 4.19.0 - Unauthenticated PHP Object Injection No login needed |
≤ 4.19.0 |
CVE-2024-13824 |
Wordfence | |
| 9.8 Critical | HUSKY – Products Filter Professional for WooCommerce | Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion No login needed |
≤ 1.3.6.5 |
CVE-2025-1661 |
Wordfence | |
| 9.3 Critical | SMS Alert Order Notifications | SQL Injection WooCommerce plugin <= 3.7.8 - SQL Injection No login needed |
≤ 3.7.8 Fixed in 3.7.9 |
CVE-2025-26988 |
Patchstack | |
| 9.3 Critical | Bitcoin / AltCoin Payment Gateway for WooCommerce | SQL Injection No login needed |
≤ 1.7.6 |
CVE-2025-26535 |
Patchstack | |
| 9.8 Critical | WooCommerce Ultimate Gift Card | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.9.2 |
CVE-2024-8425 |
Wordfence | |
| 9.8 Critical | Oliver POS – A WooCommerce Point of Sale (POS) | Information Disclosure A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation No login needed |
≤ 2.4.2.3 |
CVE-2024-13513 |
Wordfence | |
| 9.8 Critical | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | Local File Inclusion The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion No login needed |
≤ 4.2.14 |
CVE-2025-0493 |
Wordfence | |
| 9.9 Critical | WR Price List Manager For Woocommerce | Remote Code Execution |
≤ 1.0.8 |
CVE-2025-22782 |
Patchstack | |
| 9.3 Critical | Multiple Shipping And Billing Address For Woocommerce | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.2 Fixed in 1.3 |
CVE-2024-56290 |
Patchstack | |
| 9.8 Critical | Themes Coder – Create Android & iOS Apps For Your Woocommerce Site | Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed |
≤ 1.3.4 |
CVE-2024-12402 |
Wordfence | |
| 9.8 Critical | WooCommerce Point of Sale | Broken Access Control Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change No login needed |
≤ 6.1.0 |
CVE-2024-11281 |
Wordfence | |
| 9.8 Critical | WooCommerce PDF Vouchers | Authentication Bypass PDF Vouchers plugin < 4.9.9 - Broken Authentication No login needed |
≤ 4.9.9 Fixed in 4.9.9 |
CVE-2024-54383 |
Patchstack | |
| 9.9 Critical | Import Export For WooCommerce | Arbitrary File Upload |
≤ 1.6.2 |
CVE-2024-54262 |
Patchstack | |
| 9.8 Critical | Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce | Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed |
≤ 1.1.1 |
CVE-2024-10124 |
Wordfence | |
| 9.8 Critical | Xpresslane Fast Checkout | PHP Object Injection No login needed |
≤ 1.0.0 |
CVE-2024-52440 |
Patchstack | |
| 9.1 Critical | CDI | Arbitrary File Upload |
≤ 5.5.3 Fixed in 5.5.6 |
CVE-2024-52398 |
Patchstack | |
| 10.0 Critical | kineticPay for WooCommerce | Arbitrary File Upload No login needed |
≤ 2.0.8 Fixed in 3.0 |
CVE-2024-52379 |
Patchstack | |
| 9.8 Critical | WooCommerce Upload Files | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 84.3 |
CVE-2024-10820 |
Wordfence | |
| 9.8 Critical | WooCommerce Support Ticket System | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 17.7 |
CVE-2024-10627 |
Wordfence | |
| 9.8 Critical | WooCommerce Support Ticket System | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 17.6 |
CVE-2024-10625 |
Wordfence | |
| 10.0 Critical | AR For Woocommerce | Arbitrary File Upload No login needed |
≤ 6.3 Fixed in 7.0 |
CVE-2024-50510 |
Patchstack | |
| 10.0 Critical | Woocommerce Product Design | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-50482 |
Patchstack | |
| 10.0 Critical | Sudan Payment Gateway for WooCommerce | Arbitrary File Upload No login needed |
≤ 1.2.2 |
CVE-2024-50494 |
Patchstack | |
| 9.3 Critical | Woocommerce Quote Calculator | SQL Injection No login needed |
≤ 1.1 |
CVE-2024-50479 |
Patchstack | |
| 9.9 Critical | Woocommerce Custom Profile Picture | Arbitrary File Upload |
≤ 1.0 |
CVE-2024-49658 |
Patchstack | |
| 9.3 Critical | Email Verification for WooCommerce | SQL Injection No login needed |
≤ 2.8.10 Fixed in 2.9.0 |
CVE-2024-49305 |
Patchstack | |
| 9.8 Critical | Recently | PHP Object Injection No login needed |
≤ 1.1 |
CVE-2024-49218 |
Patchstack | |
| 9.3 Critical | YITH WooCommerce Ajax Search | SQL Injection No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2024-47350 |
Patchstack | |
| 9.8 Critical | WordPress & WooCommerce Affiliate Program | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 8.4.1 |
CVE-2024-9289 |
Wordfence | |
| 9.8 Critical | WooCommerce Photo Reviews Premium | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 1.3.13.2 |
CVE-2024-8277 |
Wordfence | |
| 9.8 Critical | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed |
≤ 4.2.0 |
CVE-2024-8289 |
Wordfence | |
| 9.3 Critical | TI WooCommerce Wishlist | SQL Injection No login needed |
≤ 2.8.2 |
CVE-2024-43917 |
Patchstack | |
| 9.3 Critical | Docket (WooCommerce Collections / Wishlist / Watchlist) | SQL Injection Unauthenticated SQL Injection No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-43132 |
Patchstack | |
| 9.8 Critical | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 2.0.3 |
CVE-2024-8030 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.