WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,451–1,500 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Broken Access Control No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-46635 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control No login needed ≤ 2.7.8 Fixed in 3.0.0 CVE-2023-45271 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control ≤ 5.36.0 Fixed in 5.36.1 CVE-2023-45101 Patchstack
8.8 High EditionGuard for WooCommerce – eBook Sales with DRM Plugin editionguard-for-woocommerce-ebook-sales-with-drm Cross-Site Request Forgery eBook Sales with DRM plugin <= 3.4.2 - CSRF to Privilege Escalation No login needed ≤ 3.4.2 CVE-2024-56207 Patchstack
4.3 Medium WooCommerce Subscriptions Plugin woocommerce-subscriptions Broken Access Control < 5.8.0 Fixed in 5.8.0 CVE-2023-50850 Patchstack
7.1 High Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-56228 Patchstack
7.1 High WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Cross-Site Scripting PDF Vouchers plugin < 4.9.9 - Cross Site Scripting (XSS) No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-56265 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
4.3 Medium DN Shipping by Weight for WooCommerce Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.2 Fixed in 1.2 CVE-2024-11842 WPScan
9.8 Critical WooCommerce Point of Sale Plugin Broken Access Control Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change No login needed ≤ 6.1.0 CVE-2024-11281 Wordfence
5.3 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.0.00 CVE-2024-12413 Wordfence
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Logo Deletion ≤ 5.4.0 CVE-2024-12210 Wordfence
6.5 Medium ELEX WooCommerce Dynamic Pricing and Discounts Plugin elex-woocommerce-dynamic-pricing-and-discounts Broken Access Control Missing Authorization No login needed ≤ 2.1.7 CVE-2024-12266 Wordfence
6.4 Medium One Click Upsell Funnel for WooCommerce Plugin woo-one-click-upsell-funnel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wps_wocuf_pro_yes Shortcode ≤ 3.4.9 CVE-2024-11938 Wordfence
7.2 High Custom Product Tabs For WooCommerce Plugin wb-custom-product-tabs-for-woocommerce PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.2.4 CVE-2024-12721 Wordfence
6.4 Medium Spoki – Chat Buttons and WooCommerce Notifications Plugin spoki Cross-Site Scripting Chat Buttons and WooCommerce Notifications <= 2.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.15.15 CVE-2024-11893 Wordfence
9.8 Critical WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Authentication Bypass PDF Vouchers plugin < 4.9.9 - Broken Authentication No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-54383 Patchstack
7.5 High Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56008 Patchstack
8.1 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Authentication Bypass Authentication Bypass Due to Insufficiently Unique Key No login needed ≤ 1.2.8 CVE-2024-12432 Wordfence
6.1 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via 'number' No login needed ≤ 1.4.7 CVE-2024-12395 Wordfence
6.1 Medium SMS for WooCommerce Plugin wc-sms Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.8.1 CVE-2024-12220 Wordfence
6.1 Medium Dreamfox Media Payment gateway per Product for Woocommerce Plugin woocommerce-product-payments Broken Access Control No login needed ≤ 3.5.6 Fixed in 3.5.9 CVE-2024-55996 Patchstack
5.4 Medium WooCommerce Basic Ordernumbers Plugin woocommerce-basic-ordernumbers Broken Access Control ≤ 1.4.4 CVE-2024-55992 Patchstack
5.3 Medium Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56009 Patchstack
7.1 High Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart Plugin push-monkey-desktop-push-notifications Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.9 CVE-2024-54386 Patchstack
6.4 Medium Posts and Products Views for WooCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-12448 Wordfence
6.4 Medium WooCommerce Cart Count Shortcode Plugin woo-cart-count-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-12517 Wordfence
7.1 High Check Pincode For Woocommerce Plugin check-pincode-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2024-54333 Patchstack
7.1 High Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 2.0.0 CVE-2024-54328 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2024-54312 Patchstack
9.9 Critical Import Export For WooCommerce Plugin import-export-for-woocommerce Arbitrary File Upload ≤ 1.6.2 CVE-2024-54262 Patchstack
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
7.1 High Blaze Online eParcel for WooCommerce Plugin blaze-online-eparcel-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2024-54240 Patchstack
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack
7.1 High Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.86 CVE-2024-54235 Patchstack
7.1 High Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 CVE-2024-54231 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium BitPay Checkout for WooCommerce Plugin bitpay-checkout-for-woocommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 5.0.0 CVE-2023-41803 Patchstack
6.5 Medium Woocommerce Support System Plugin wc-support-system Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-41686 Patchstack
5.4 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery ≤ 5.16.1 Fixed in 5.16.2 CVE-2023-41671 Patchstack
4.3 Medium Category Slider for WooCommerce Plugin woo-category-slider-grid Broken Access Control ≤ 1.4.15 Fixed in 1.4.16 CVE-2023-41132 Patchstack
4.3 Medium HUSKY Plugin woocommerce-products-filter Broken Access Control ≤ 1.3.4.2 Fixed in 1.3.4.3 CVE-2023-40334 Patchstack
5.4 Medium Easyship WooCommerce Shipping Rates Plugin easyship-woocommerce-shipping-rates Broken Access Control ≤ 0.9.0 Fixed in 0.9.1 CVE-2023-37989 Patchstack
6.5 Medium WooCommerce Product Stock Alert Plugin woocommerce-product-stock-alert Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2023-37971 Patchstack
5.3 Medium Checkout with Zelle on Woocommerce Plugin wc-zelle Broken Access Control No login needed ≤ 3.1 Fixed in 3.1.1 CVE-2023-37969 Patchstack
5.3 Medium YITH WooCommerce Waiting List Plugin yith-woocommerce-waiting-list Broken Access Control No login needed ≤ 2.13.0 Fixed in 2.13.1 CVE-2023-36506 Patchstack
5.4 Medium Change WooCommerce Add To Cart Button Text Plugin change-woocommerce-add-to-cart-button-text Broken Access Control ≤ 1.3 CVE-2023-34376 Patchstack
5.3 Medium WooCommerce Predictive Search Plugin woocommerce-predictive-search Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.8.1 CVE-2023-32963 Patchstack
5.3 Medium APIExperts Square for WooCommerce Plugin woosquare Broken Access Control No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2022-47182 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only