WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,701–1,750 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.6.4 Fixed in 2.0.0 CVE-2024-43342 Patchstack
10.0 Critical InPost for WooCommerce Plugin woo-inpost Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Delete No login needed ≤ 1.4.0, ≤ 1.4.4 CVE-2024-6500 Wordfence
6.5 Medium Event Manager for WooCommerce Plugin mage-eventpress Local File Inclusion ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-43138 Patchstack
7.5 High Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43131 Patchstack
6.5 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.5.1 Fixed in 3.8.6 CVE-2024-43128 Patchstack
9.1 Critical HUSKY Plugin woocommerce-products-filter Privilege Escalation ≤ 1.3.6.1 Fixed in 1.3.6.2 CVE-2024-43121 Patchstack
8.6 High WooCommerce PDF Vouchers Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39651 Patchstack
7.5 High HitPay Payment Gateway for WooCommerce Plugin hitpay-payment-gateway Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-38747 Patchstack
7.5 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Information Disclosure Sensitive Data Exposure via Exported File No login needed ≤ 2.5.13 Fixed in 2.5.14 CVE-2024-38699 Patchstack
7.5 High Woocommerce OpenPos Plugin Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 6.4.4 CVE-2024-37935 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter ≤ 5.9.27 CVE-2024-7092 Wordfence
7.1 High Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Scripting Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.6.14 - Cross Site Scripting (XSS) No login needed ≤ 2.6.14 Fixed in 2.6.16 CVE-2024-43126 Patchstack
7.1 High Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-43127 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.17 CVE-2024-43213 Patchstack
9.8 Critical WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.7.5 - Authentication Bypass to Account Takeover No login needed ≤ 2.7.5 CVE-2024-7503 Wordfence
9.8 Critical YayExtra – WooCommerce Extra Product Options Plugin yayextra Arbitrary File Upload WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file Function No login needed ≤ 1.3.7 CVE-2024-7257 Wordfence
7.1 High WooCommerce PDF Vouchers Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39652 Patchstack
6.5 Medium JetWidgets for Elementor and WooCommerce Plugin jetwoo-widgets-for-elementor Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-38772 Patchstack
7.2 High CTX Feed Plugin webappick-product-feed-for-woocommerce Privilege Escalation Arbitrary Options Update ≤ 6.5.6 Fixed in 6.5.7 CVE-2024-38775 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget ≤ 2.2.85 CVE-2024-6346 Wordfence
8.1 High WooCommerce Customers Manager Plugin Cross-Site Request Forgery Bulk Action via CSRF No login needed < 30.1 Fixed in 30.1 CVE-2024-3983 WPScan
6.5 Medium WooCommerce Customers Manager Plugin Cross-Site Request Forgery User Deletion via CSRF No login needed < 30.1 Fixed in 30.1 CVE-2024-2843 WPScan
6.5 Medium WooCommerce Customers Manager Plugin Cross-Site Scripting Subscriber+ Stored XSS < 30.2 Fixed in 30.2 CVE-2024-1747 WPScan
5.3 Medium CTT Expresso para WooCommerce Plugin ctt-expresso-para-woocommerce Information Disclosure Information Exposure via Unprotected Directory No login needed ≤ 3.2.12 CVE-2024-6687 Wordfence
6.4 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Broken Access Control Missing Authorization to (Subscriber+) Stored Cross-Site Scripting ≤ 3.5.1 CVE-2024-6458 Wordfence
5.3 Medium Aramex Shipping WooCommerce Plugin aramex-shipping-woocommerce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.1.21 CVE-2024-6566 Wordfence
4.3 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update ≤ 3.4.6 CVE-2024-6836 Wordfence
7.3 High WooCommerce - PDF Vouchers Plugin Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed ≤ 4.9.3 CVE-2024-7027 Wordfence
5.9 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Cross-Site Scripting Admin+ Stored XSS < 2.4.1 Fixed in 2.4.1 CVE-2024-6231 WPScan
6.5 Medium Empty Cart Button for WooCommerce Plugin empty-cart-button-for-woocommerce Cross-Site Scripting ≤ 1.3.8 CVE-2024-37217 Patchstack
7.1 High MakeCommerce for WooCommerce Plugin makecommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2024-37509 Patchstack
5.8 Medium XPlainer - WooCommerce Product FAQ Plugin faq-for-woocommerce Cross-Site Scripting WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin <= 1.6.3 - Cross Site Scripting (XSS) No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2024-37515 Patchstack
5.9 Medium CC & BCC for Woocommerce Order Emails Plugin cc-bcc-for-woocommerce-order-emails Cross-Site Scripting ≤ 1.4.1 CVE-2024-37522 Patchstack
5.8 Medium YITH WooCommerce Ajax Product Filter Plugin yith-woocommerce-ajax-navigation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.0 Fixed in 5.2.0 CVE-2024-37943 Patchstack
7.1 High WooCommerce Predictive Search Plugin woocommerce-predictive-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.1 CVE-2024-38669 Patchstack
6.5 Medium REVIEWS.io Plugin reviewscouk-for-woocommerce Cross-Site Scripting ≤ 1.2.7 CVE-2024-38677 Patchstack
7.1 High Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps Plugin appmaker-woocommerce-mobile-app-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.36.12 CVE-2024-38680 Patchstack
7.1 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-38683 Patchstack
9.8 Critical WooCommerce - Social Login Plugin Broken Access Control Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation No login needed ≤ 2.7.3 CVE-2024-6636 Wordfence
7.3 High WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.7.3 - Unauthenticated Authentication Bypass No login needed ≤ 2.7.3 CVE-2024-6635 Wordfence
7.3 High WooCommerce - Social Login Plugin Privilege Escalation Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password No login needed ≤ 2.7.3 CVE-2024-6637 Wordfence
6.5 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Path Traversal Authenticated (Subscriber+) Arbitrary File Download 7.3.0 – 7.6.1 CVE-2024-3934 Wordfence
5.3 Medium Addonify – Quick View For WooCommerce Plugin addonify-quick-view Information Disclosure Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path Dislcosure No login needed ≤ 1.2.16 CVE-2024-6560 Wordfence
4.3 Medium YITH Essential Kit for WooCommerce #1 Plugin yith-essential-kit-for-woocommerce-1 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation ≤ 2.34.0 CVE-2024-6799 Wordfence
9.8 Critical HUSKY - Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection No login needed ≤ 1.3.6 CVE-2024-6457 Wordfence
4.3 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification ≤ 1.4.5 CVE-2024-6579 Wordfence
6.4 Medium WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Plugin wp-event-manager Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode ≤ 3.1.43 CVE-2024-2691 Wordfence
5.9 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Admin+ Stored XSS < 3.1.8 Fixed in 3.1.8 CVE-2024-3964 WPScan
8.6 High Woocommerce OpenPos Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.4.4 CVE-2024-37932 Patchstack
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only