WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,651–1,700 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 34 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Themify – WooCommerce Product Filter Plugin themify-wc-product-filter Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-44046 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.13.0 Fixed in 4.13.1 CVE-2024-47367 Patchstack
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-47395 Patchstack
6.6 Medium Cities Shipping Zones for WooCommerce Plugin cities-shipping-zones-for-woocommerce Local File Inclusion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-47309 Patchstack
4.7 Medium Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed ≤ 2.0.3 CVE-2024-8499 Wordfence
6.1 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-9384 Wordfence
6.1 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed ≤ 2.7.3 CVE-2024-9345 Wordfence
5.4 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 5.7.34 CVE-2024-8254 Wordfence
9.8 Critical WordPress & WooCommerce Affiliate Program Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 8.4.1 CVE-2024-9289 Wordfence
6.1 Medium Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More Plugin woocommerce-exporter Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed ≤ 2.7.2.1 CVE-2024-8793 Wordfence
5.3 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.12.12 CVE-2024-9189 Wordfence
6.1 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.12.12 CVE-2024-8788 Wordfence
8.8 High Product Enquiry for WooCommerce Plugin enquiry-quotation-for-woocommerce PHP Object Injection Authenticated (Author+) PHP Object Injection in enquiry_detail.php ≤ 2.2.33.33 CVE-2024-8922 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 5.7.34 CVE-2024-8771 Wordfence
6.1 Medium Store Hours for WooCommerce Plugin order-hours-scheduler-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.3.20 CVE-2024-8872 Wordfence
8.8 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation ≤ 6.7.12 CVE-2024-8290 Wordfence
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed ≤ 4.17.3 CVE-2024-8678 Wordfence
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
5.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed ≤ 1.3.6.1 CVE-2024-7491 Wordfence
6.3 Medium WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 3.8.0 CVE-2024-6590 Wordfence
6.1 Medium XT Ajax Add To Cart for WooCommerce Plugin xt-woo-ajax-add-to-cart Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-8716 Wordfence
6.5 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated Local File Inclusion ≤ 1.9.10 Fixed in 1.10.0 CVE-2024-44048 Patchstack
7.1 High Product Slider for WooCommerce Plugin woocommerce-products-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.50 Fixed in 1.13.51 CVE-2024-45459 Patchstack
6.1 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2024-8724 Wordfence
7.3 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.1 CVE-2024-8271 Wordfence
5.3 Medium WooCommerce Multiple Free Gift Plugin woocommerce-multiple-free-gift Broken Access Control Insufficient Server-Side Validation to Arbitrary Gift Adding No login needed ≤ 1.2.3 CVE-2022-3459 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
9.8 Critical WooCommerce Photo Reviews Premium Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 1.3.13.2 CVE-2024-8277 Wordfence
6.4 Medium Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget ≤ 6.0.3 CVE-2024-8440 Wordfence
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed ≤ 4.2.0 CVE-2024-8289 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence
5.9 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.4.6 CVE-2024-43960 Patchstack
8.5 High Greenshift Woocommerce Addon Plugin SQL Injection Subscriber+ SQL Injection < 1.9.8 Fixed in 1.9.8 CVE-2024-43943 Patchstack
9.3 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection No login needed ≤ 2.8.2 CVE-2024-43917 Patchstack
9.3 Critical Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin SQL Injection Unauthenticated SQL Injection No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43132 Patchstack
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack
5.3 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 7.7.0 CVE-2024-6448 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence
4.3 Medium Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Request Forgery No login needed ≤ 2.6.18 Fixed in 2.6.19 CVE-2024-39657 Patchstack
4.3 Medium Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43316 Patchstack
5.3 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 3.23 Fixed in 3.24 CVE-2024-43259 Patchstack
8.8 High WooCommerce Google Feed Manager Plugin wp-product-feed-manager Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Deletion ≤ 2.8.0 CVE-2024-7258 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings ≤ 5.6.2 CVE-2024-5583 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget ≤ 5.6.2 CVE-2024-5763 Wordfence
8.5 High Woo Products Widgets For Elementor Plugin woo-products-widgets-for-elementor Local File Inclusion ≤ 2.0.0 CVE-2024-43271 Patchstack
7.5 High Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43315 Patchstack
5.9 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.16 Fixed in 1.4.17 CVE-2024-43292 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 9.1.2 Fixed in 9.1.3 CVE-2024-39666 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only