WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,651–1,700 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.9 Medium | Themify – WooCommerce Product Filter | Cross-Site Scripting |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2024-44046 |
Patchstack | |
| 7.1 High | YITH WooCommerce Product Add-Ons | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.13.0 Fixed in 4.13.1 |
CVE-2024-47367 |
Patchstack | |
| 7.1 High | Robokassa payment gateway for Woocommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-47395 |
Patchstack | |
| 6.6 Medium | Cities Shipping Zones for WooCommerce | Local File Inclusion |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2024-47309 |
Patchstack | |
| 4.7 Medium | Checkout Field Editor (Checkout Manager) for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed |
≤ 2.0.3 |
CVE-2024-8499 |
Wordfence | |
| 6.1 Medium | Quantity Dynamic Pricing & Bulk Discounts for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.8.0 |
CVE-2024-9384 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce – Lite | Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-9345 |
Wordfence | |
| 5.4 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 5.7.34 |
CVE-2024-8254 |
Wordfence | |
| 9.8 Critical | WordPress & WooCommerce Affiliate Program | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 8.4.1 |
CVE-2024-9289 |
Wordfence | |
| 6.1 Medium | Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More | Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.2.1 |
CVE-2024-8793 |
Wordfence | |
| 5.3 Medium | EU/UK VAT Manager for WooCommerce | Broken Access Control Missing Authorization No login needed |
≤ 2.12.12 |
CVE-2024-9189 |
Wordfence | |
| 6.1 Medium | EU/UK VAT Manager for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.12.12 |
CVE-2024-8788 |
Wordfence | |
| 8.8 High | Product Enquiry for WooCommerce | PHP Object Injection Authenticated (Author+) PHP Object Injection in enquiry_detail.php |
≤ 2.2.33.33 |
CVE-2024-8922 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 5.7.34 |
CVE-2024-8771 |
Wordfence | |
| 6.1 Medium | Store Hours for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.3.20 |
CVE-2024-8872 |
Wordfence | |
| 8.8 High | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation |
≤ 6.7.12 |
CVE-2024-8290 |
Wordfence | |
| 5.3 Medium | Revolut Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed |
≤ 4.17.3 |
CVE-2024-8678 |
Wordfence | |
| 5.3 Medium | Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred | Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed |
≤ 2.7.3 |
CVE-2024-8658 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.9.7 |
CVE-2024-8668 |
Wordfence | |
| 5.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed |
≤ 1.3.6.1 |
CVE-2024-7491 |
Wordfence | |
| 6.3 Medium | WPGSI: Spreadsheet Integration | Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 3.8.0 |
CVE-2024-6590 |
Wordfence | |
| 6.1 Medium | XT Ajax Add To Cart for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.2 |
CVE-2024-8716 |
Wordfence | |
| 6.5 Medium | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated Local File Inclusion |
≤ 1.9.10 Fixed in 1.10.0 |
CVE-2024-44048 |
Patchstack | |
| 7.1 High | Product Slider for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.13.50 Fixed in 1.13.51 |
CVE-2024-45459 |
Patchstack | |
| 6.1 Medium | Waitlist Woocommerce ( Back in stock notifier ) | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.7.5 |
CVE-2024-8724 |
Wordfence | |
| 7.3 High | FOX – Currency Switcher Professional for WooCommerce | Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.4.2.1 |
CVE-2024-8271 |
Wordfence | |
| 5.3 Medium | WooCommerce Multiple Free Gift | Broken Access Control Insufficient Server-Side Validation to Arbitrary Gift Adding No login needed |
≤ 1.2.3 |
CVE-2022-3459 |
Wordfence | |
| 6.4 Medium | Betheme | Responsive Multipurpose WordPress & WooCommerce | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File |
≤ 27.5.5 |
CVE-2024-5567 |
Wordfence | |
| 9.8 Critical | WooCommerce Photo Reviews Premium | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 1.3.13.2 |
CVE-2024-8277 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
≤ 6.0.3 |
CVE-2024-8440 |
Wordfence | |
| 9.8 Critical | MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution | Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed |
≤ 4.2.0 |
CVE-2024-8289 |
Wordfence | |
| 6.4 Medium | Betheme | Responsive Multipurpose WordPress & WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 27.5.6 |
CVE-2024-3998 |
Wordfence | |
| 5.9 Medium | Web and WooCommerce Addons for WPBakery Builder | Cross-Site Scripting |
≤ 1.4.6 |
CVE-2024-43960 |
Patchstack | |
| 8.5 High | Greenshift Woocommerce Addon | SQL Injection Subscriber+ SQL Injection |
< 1.9.8 Fixed in 1.9.8 |
CVE-2024-43943 |
Patchstack | |
| 9.3 Critical | TI WooCommerce Wishlist | SQL Injection No login needed |
≤ 2.8.2 |
CVE-2024-43917 |
Patchstack | |
| 9.3 Critical | Docket (WooCommerce Collections / Wishlist / Watchlist) | SQL Injection Unauthenticated SQL Injection No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-43132 |
Patchstack | |
| 5.9 Medium | Taxi Booking Manager for WooCommerce | Cross-Site Scripting |
≤ 1.0.9 Fixed in 1.1.0 |
CVE-2024-43986 |
Patchstack | |
| 5.3 Medium | Mollie Payments for WooCommerce | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 7.7.0 |
CVE-2024-6448 |
Wordfence | |
| 9.8 Critical | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 2.0.3 |
CVE-2024-8030 |
Wordfence | |
| 4.3 Medium | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.6.18 Fixed in 2.6.19 |
CVE-2024-39657 |
Patchstack | |
| 4.3 Medium | Stripe Payments For WooCommerce by Checkout | Cross-Site Request Forgery No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2024-43316 |
Patchstack | |
| 5.3 Medium | Order Export for WooCommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.23 Fixed in 3.24 |
CVE-2024-43259 |
Patchstack | |
| 8.8 High | WooCommerce Google Feed Manager | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Deletion |
≤ 2.8.0 |
CVE-2024-7258 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings |
≤ 5.6.2 |
CVE-2024-5583 |
Wordfence | |
| 9.8 Critical | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 1.6.4 |
CVE-2024-5335 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget |
≤ 5.6.2 |
CVE-2024-5763 |
Wordfence | |
| 8.5 High | Woo Products Widgets For Elementor | Local File Inclusion |
≤ 2.0.0 |
CVE-2024-43271 |
Patchstack | |
| 7.5 High | Stripe Payments For WooCommerce by Checkout | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2024-43315 |
Patchstack | |
| 5.9 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Scripting |
≤ 1.4.16 Fixed in 1.4.17 |
CVE-2024-43292 |
Patchstack | |
| 5.9 Medium | WooCommerce | Cross-Site Scripting |
≤ 9.1.2 Fixed in 9.1.3 |
CVE-2024-39666 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.