WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,551–1,600 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 32 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
6.1 Medium Wishlist for WooCommerce: Multi Wishlists Per Customer PRO Plugin wish-list-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via wtab Parameter No login needed 3.0.8, 3.0.9, 3.1.0, … CVE-2024-10519 Wordfence
6.1 Medium Checkout with Cash App on WooCommerce Plugin wc-cashapp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.0.2 CVE-2024-9635 Wordfence
6.1 Medium PDF Invoices & Packing Slips Generator for WooCommerce Plugin pdf-invoicing-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2024-11361 Wordfence
5.3 Medium Product Table for WooCommerce by CodeAstrology (wooproducttable.com) Plugin woo-product-table Information Disclosure Information Exposure No login needed ≤ 3.5.1 CVE-2024-10813 Wordfence
6.1 Medium Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net Plugin peachpay-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.112.0 CVE-2024-11362 Wordfence
6.1 Medium Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels Plugin wpfunnels Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.5 CVE-2024-10792 Wordfence
6.1 Medium Subaccounts for WooCommerce Plugin subaccounts-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-11370 Wordfence
9.8 Critical Xpresslane Fast Checkout Plugin xpresslane-integration-for-woocommerce PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-52440 Patchstack
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.0.3 CVE-2024-10365 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.8.6 CVE-2024-10899 Wordfence
6.1 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.2.3 CVE-2024-9239 Wordfence
6.1 Medium HUSKY – Products Filter for WooCommerce Plugin Cross-Site Scripting Products Filter for WooCommerce <= 1.3.6.3 - Reflected Cross-Site Scripting via really_curr_tax Parameter No login needed ≤ 1.3.6.3 CVE-2024-11400 Wordfence
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
5.3 Medium Google for WooCommerce Plugin google-listings-and-ads Information Disclosure Information Disclosure via Publicly Accessible PHP Info File No login needed ≤ 2.8.6 CVE-2024-10486 Wordfence
9.1 Critical CDI Plugin collect-and-deliver-interface-for-woocommerce Arbitrary File Upload ≤ 5.5.3 Fixed in 5.5.6 CVE-2024-52398 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Import Cancellation ≤ 5.61.0 CVE-2024-10614 Wordfence
6.1 Medium PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.6.9 CVE-2024-8873 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
5.7 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 6.0.9 CVE-2024-8978 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.7 CVE-2024-8961 Wordfence
6.1 Medium Yotpo: Product & Photo Reviews for WooCommerce Plugin yotpo-social-reviews-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.9 CVE-2024-9356 Wordfence
10.0 Critical kineticPay for WooCommerce Plugin kineticpay-for-woocommerce Arbitrary File Upload No login needed ≤ 2.0.8 Fixed in 3.0 CVE-2024-52379 Patchstack
9.8 Critical WooCommerce Upload Files Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 84.3 CVE-2024-10820 Wordfence
8.1 High Advanced Order Export For WooCommerce Plugin woo-order-export-lite PHP Object Injection Unauthenticated PHP Object Injection via Order Details No login needed ≤ 3.5.5 CVE-2024-10828 Wordfence
6.1 Medium Product Delivery Date for WooCommerce - Lite Plugin product-delivery-date-for-woocommerce-lite Cross-Site Scripting Lite <= 2.8.0 - Reflected Cross-Site Scripting No login needed ≤ 2.8.0 CVE-2024-10882 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Import ≤ 2.2.9 CVE-2024-10854 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Deletion ≤ 2.2.9 CVE-2024-10853 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Export ≤ 2.2.9 CVE-2024-10852 Wordfence
7.1 High Search order by product SKU for WooCommerce Plugin search-order-by-product-sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2024-51693 Patchstack
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via tab Parameter No login needed ≤ 2.7.29 CVE-2024-10837 Wordfence
7.3 High The FOX – Currency Switcher Professional for WooCommerce Plugin Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.2 CVE-2024-10640 Wordfence
7.1 High FriendStore for WooCommerce Plugin friendstore-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.2 CVE-2024-51784 Patchstack
9.8 Critical WooCommerce Support Ticket System Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 17.7 CVE-2024-10627 Wordfence
8.8 High WooCommerce Support Ticket System Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.7 CVE-2024-10626 Wordfence
9.8 Critical WooCommerce Support Ticket System Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 17.6 CVE-2024-10625 Wordfence
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
5.3 Medium Video Gallery for WooCommerce Plugin video-wc-gallery Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed ≤ 1.31 CVE-2024-10535 Wordfence
6.4 Medium XT Floating Cart for WooCommerce Plugin woo-floating-cart-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.8.2 CVE-2024-9178 Wordfence
8.8 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.1 CVE-2024-10711 Wordfence
8.1 High Social Login - WordPress / WooCommerce Plugin Authentication Bypass WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 2.7.7 CVE-2024-10114 Wordfence
8.5 High Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection ≤ 1.1 CVE-2024-51626 Patchstack
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.2 - Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-38702 Patchstack
5.3 Medium Wholesale Suite Plugin woocommerce-wholesale-prices Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.2.0 CVE-2024-38745 Patchstack
7.3 High WooCommerce PDF Vouchers Plugin Broken Access Control Unauthenticated Multiple Vulnerabilities No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2024-39650 Patchstack
4.3 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Broken Access Control ≤ 2.6 Fixed in 2.6.1 CVE-2024-43134 Patchstack
5.3 Medium Persian WooCommerce Plugin persian-woocommerce Broken Access Control No login needed ≤ 7.1.6 Fixed in 9.0.0 CVE-2024-43219 Patchstack
5.4 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.1.9 Fixed in 7.2.0 CVE-2024-43312 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only