WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,601–1,650 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 33 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
4.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.6 Fixed in 5.3.7 CVE-2024-44006 Patchstack
6.5 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.3 CVE-2024-6479 Wordfence
6.4 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 1.2.3 CVE-2024-6480 Wordfence
5.3 Medium Get Quote For Woocommerce – Request A Quote For Woocommerce Plugin get-a-quote-for-woocommerce Broken Access Control Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download No login needed ≤ 1.0.0 CVE-2024-9430 Wordfence
6.4 Medium Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Plugin gift-voucher Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.4.4 CVE-2024-9165 Wordfence
7.5 High Woocommerce Product Design Plugin woo-product-design Path Traversal Arbitrary File Download No login needed ≤ 1.0.0 CVE-2024-50508 Patchstack
10.0 Critical AR For Woocommerce Plugin ar-for-woocommerce Arbitrary File Upload No login needed ≤ 6.3 Fixed in 7.0 CVE-2024-50510 Patchstack
8.6 High Woocommerce Product Design Plugin woo-product-design Arbitrary File Deletion No login needed ≤ 1.0.0 CVE-2024-50509 Patchstack
5.3 Medium WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control No login needed ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-50421 Patchstack
7.1 High ACL Floating Cart for WooCommerce Plugin acl-floating-cart-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9 CVE-2024-49640 Patchstack
7.1 High WooCommerce Maintenance Mode Plugin woocommerce-maintenance-mode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-49651 Patchstack
6.4 Medium SMSAlert - WooCommerce Plugin sms-alert Cross-Site Scripting WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode ≤ 3.7.5 CVE-2024-10233 Wordfence
4.3 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Broken Access Control Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation ≤ 4.2.1 CVE-2024-10437 Wordfence
8.8 High WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 4.2.1 CVE-2024-10436 Wordfence
10.0 Critical Woocommerce Product Design Plugin woo-product-design Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-50482 Patchstack
10.0 Critical Sudan Payment Gateway for WooCommerce Plugin wc-sudan-payment-gateway Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-50494 Patchstack
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.19 Fixed in 1.4.20 CVE-2024-50447 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.14.1 Fixed in 4.14.2 CVE-2024-50448 Patchstack
9.3 Critical Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection No login needed ≤ 1.1 CVE-2024-50479 Patchstack
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer PHP Object Injection ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-50416 Patchstack
6.1 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.133 CVE-2024-9214 Wordfence
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce Plugin hurrytimer Broken Access Control An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication ≤ 2.10.0 CVE-2024-8667 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
9.9 Critical Woocommerce Custom Profile Picture Plugin woo-custom-profile-picture Arbitrary File Upload ≤ 1.0 CVE-2024-49658 Patchstack
7.2 High WooCommerce Order Proposal Plugin Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation via Order Proposal ≤ 2.0.5 CVE-2024-9927 Wordfence
7.6 High FunnelKit Automations Plugin wp-marketing-automations SQL Injection ≤ 3.1.2 Fixed in 3.2.0 CVE-2024-47328 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
7.1 High EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.12.14 Fixed in 3.0.0 CVE-2024-44061 Patchstack
6.1 Medium Edit WooCommerce Templates Plugin woo-edit-templates Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed ≤ 1.1.2 CVE-2024-10049 Wordfence
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.9.1 Fixed in 1.2.9.2 CVE-2024-49288 Patchstack
8.5 High CSV Product Import Export for WooCommerce Plugin csv-wc-product-import-export SQL Injection ≤ 1.0.0 CVE-2024-49244 Patchstack
9.3 Critical Email Verification for WooCommerce Plugin emails-verification-for-woocommerce SQL Injection No login needed ≤ 2.8.10 Fixed in 2.9.0 CVE-2024-49305 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
6.1 Medium Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.2 CVE-2024-9213 Wordfence
9.8 Critical Recently Plugin recently-viewed-most-viewed-and-sold-products-for-woocommerce PHP Object Injection No login needed ≤ 1.1 CVE-2024-49218 Patchstack
5.3 Medium WooCommerce Smart Coupons Plugin Broken Access Control Unauthenticated Coupon Creation No login needed < 4.6.5 Fixed in 4.6.5 CVE-2020-36841 Wordfence
6.3 Medium Discount Rules for WooCommerce Plugin woo-discount-rules Broken Access Control Missing Authorization ≤ 2.0.2 CVE-2020-36834 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
5.3 Medium WooCommerce Plugin woocommerce Content Injection Unauthenticated HTML Injection No login needed ≤ 9.0.2 CVE-2024-9944 Wordfence
4.3 Medium Order Attachments for WooCommerce Plugin order-attachments-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary File Upload 2.0 – 2.4.1 CVE-2024-9756 Wordfence
8.8 High Bot for Telegram on WooCommerce Plugin bot-for-telegram-on-woocommerce Information Disclosure Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass ≤ 1.2.7 CVE-2024-9821 Wordfence
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template ≤ 5.6.11 CVE-2024-8913 Wordfence
6.5 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal ≤ 2.3.7 CVE-2024-7514 Wordfence
5.9 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection Unauthenticated SQL Injection via lang parameters No login needed ≤ 2.8.2 CVE-2024-9156 WPScan
6.1 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.15 CVE-2024-9377 Wordfence
6.1 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.8 CVE-2024-9205 Wordfence
6.1 Medium WooCommerce Multilingual & Multicurrency with WPML Plugin woocommerce-multilingual Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.3.7 CVE-2024-8629 Wordfence
9.3 Critical YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search SQL Injection No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-47350 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only