WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,501–1,550 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Cross-Site Request Forgery ≤ 2.2.3 Fixed in 2.2.4 CVE-2022-47168 Patchstack
4.3 Medium ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Plugin woo-alidropship Broken Access Control Broken Access Control + CSRF ≤ 1.0.21 Fixed in 1.0.22 CVE-2022-46811 Patchstack
4.3 Medium Stock Sync for WooCommerce Plugin stock-sync-for-woocommerce Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2022-46807 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery CSRF Plugin Settings Reset No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2022-46795 Patchstack
6.1 Medium MyParcel Plugin woocommerce-myparcel Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.24.1 CVE-2024-9608 Wordfence
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation ≤ 2.1.12 CVE-2024-11911 Wordfence
6.5 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Arbitrary Shortcode Execution Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 5.16.7.1 CVE-2024-12421 Wordfence
6.1 Medium Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.1 CVE-2024-11809 Wordfence
6.1 Medium Seraphinite Bulk Discounts for WooCommerce Plugin seraphinite-discount-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-12160 Wordfence
4.4 Medium NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Plugin notificationx Cross-Site Scripting Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.9.3 CVE-2024-11727 Wordfence
5.3 Medium Web3 Cryptocurrency Payments by DePay for WooCommerce Plugin Broken Access Control Missing Authorization to Information Exposure No login needed ≤ 2.12.17 CVE-2024-12265 Wordfence
9.8 Critical Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.1.1 CVE-2024-10124 Wordfence
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
6.1 Medium WPC Order Notes for WooCommerce Plugin woo-order-notes Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.5.2 CVE-2024-12004 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
4.3 Medium Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54227 Patchstack
5.4 Medium Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2023-23868 Patchstack
4.3 Medium PayPal Brasil para WooCommerce Plugin paypal-brasil-para-woocommerce Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2023-25026 Patchstack
5.3 Medium Stamped.io Product Reviews & UGC for WooCommerce Plugin stampedio-product-reviews Broken Access Control No login needed ≤ 2.3.2 Fixed in 2.3.3 CVE-2023-30479 Patchstack
4.3 Medium Smart WooCommerce Search Plugin smart-woocommerce-search Broken Access Control ≤ 2.5.0 Fixed in 2.5.1 CVE-2023-30783 Patchstack
6.5 Medium Ni WooCommerce Sales Report Plugin ni-woocommerce-sales-report Broken Access Control ≤ 3.7.3 Fixed in 3.7.4 CVE-2023-32299 Patchstack
5.4 Medium Mini Cart Drawer For WooCommerce Plugin woo-mini-cart-drawer Broken Access Control No login needed ≤ 4.0.0 Fixed in 4.0.1 CVE-2023-47694 Patchstack
8.6 High Japanized For WooCommerce Plugin woocommerce-for-japan Broken Access Control Multiple Broken Access Control No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2023-47698 Patchstack
5.3 Medium PayTR Taksit Tablosu Plugin paytr-taksit-tablosu-woocommerce Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-47847 Patchstack
5.3 Medium Importify (Dropshipping WooCommerce) Plugin importify Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2023-49194 Patchstack
8.2 High Flexible Woocommerce Checkout Field Editor Plugin flexible-woocommerce-checkout-field-editor Broken Access Control No login needed ≤ 2.0.1 CVE-2023-49817 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
5.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control No login needed ≤ 6.5.0 Fixed in 6.5.1 CVE-2023-51357 Patchstack
6.1 Medium CardGate Payments for WooCommerce Plugin cardgate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12257 Wordfence
6.1 Medium 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 Plugin pgall-for-woocommerce Cross-Site Scripting 우커머스 결제 플러그인 <= 5.2.2 - Reflected Cross-Site Scripting via add_query_arg Function No login needed ≤ 5.2.2 CVE-2024-11943 Wordfence
6.1 Medium افزونه پیامک ووکامرس Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.5 CVE-2024-10046 Wordfence
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
6.1 Medium Next-Cart Store to WooCommerce Migration Plugin nextcart-woocommerce-migration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.9.2 CVE-2024-11687 Wordfence
6.1 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.136 CVE-2024-11276 Wordfence
6.1 Medium Accounting for WooCommerce Plugin accounting-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.6 CVE-2024-11324 Wordfence
6.1 Medium Additional Custom Order Status for WooCommerce Plugin order-status-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-11814 Wordfence
7.5 High TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control Missing Authorization to Unauthenticated Plugin Setup Wizard Access No login needed ≤ 2.9.1 CVE-2024-10567 Wordfence
6.1 Medium Quick License Manager – WooCommerce Plugin quick-license-manager Cross-Site Scripting WooCommerce Plugin <= 2.4.17 - Reflected Cross-Site Scripting No login needed ≤ 2.4.17 CVE-2024-11805 Wordfence
7.1 High AtaraPay WooCommerce Payment Gateway Plugin atarapay-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-52460 Patchstack
7.1 High WooCommerce Price Alert Plugin price-alert-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-52469 Patchstack
7.1 High WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2024-53740 Patchstack
7.1 High Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.27 Fixed in 2.28 CVE-2024-53742 Patchstack
7.6 High Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods SQL Injection ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-53783 Patchstack
6.5 Medium Wallet for WooCommerce Plugin woo-wallet Other Authenticated (Subscriber+) Incorrect Conversion between Numeric Types ≤ 1.5.6 CVE-2024-7747 Wordfence
5.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode ≤ 7.2.3 CVE-2024-9170 Wordfence
6.5 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.9 CVE-2024-10857 Wordfence
6.1 Medium Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.21 CVE-2024-11418 Wordfence
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
6.4 Medium 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 Plugin pgall-for-woocommerce Cross-Site Scripting 우커머스 결제 플러그인 <= 5.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting pafw_instant_payment Shortcode ≤ 5.1.4 CVE-2024-11228 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only