WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,751–1,800 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Get Better Reviews for WooCommerce | Broken Access Control |
≤ 4.0.6 |
CVE-2024-37544 |
Patchstack | |
| 9.3 Critical | Woocommerce OpenPos | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.4.4 |
CVE-2024-37933 |
Patchstack | |
| 8.8 High | Wallet for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection via 'search[value]' |
≤ 1.5.4 |
CVE-2024-6353 |
Wordfence | |
| 6.5 Medium | ShopBuilder – Elementor WooCommerce Builder Addons | Local File Inclusion Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion |
≤ 2.1.12 Fixed in 2.1.13 |
CVE-2024-37520 |
Patchstack | |
| 3.5 Low | WooCommerce | Content Injection |
≤ 8.9.2 Fixed in 9.0.0 |
CVE-2024-35777 |
Patchstack | |
| 5.4 Medium | WooCommerce Social Login | PHP Object Injection No login needed |
≤ 2.6.3 Fixed in 2.7.0 |
CVE-2024-37502 |
Patchstack | |
| 6.4 Medium | XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] | Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 1.7.0 |
CVE-2024-5669 |
Wordfence | |
| 4.3 Medium | XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] | Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.7.0 |
CVE-2024-5704 |
Wordfence | |
| 9.8 Critical | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed |
≤ 5.7.25 |
CVE-2024-6172 |
Wordfence | |
| 6.4 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload |
≤ 3.3.1 |
CVE-2024-5192 |
Wordfence | |
| 4.7 Medium | Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce | Cross-Site Scripting All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting No login needed |
≤ 7.1.0 |
CVE-2024-6288 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.0 |
CVE-2024-4983 |
Wordfence | |
| 8.8 High | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | Local File Inclusion Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode |
≤ 2.2.25 |
CVE-2024-5431 |
Wordfence | |
| 6.4 Medium | Flatsome | Multi-Purpose Responsive WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 3.18.7 |
CVE-2024-5346 |
Wordfence | |
| 9.8 Critical | Themify - WooCommerce Product Filter | SQL Injection WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter No login needed |
≤ 1.4.9 |
CVE-2024-6027 |
Wordfence | |
| 8.8 High | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Local File Inclusion Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion |
≤ 5.5.6 |
CVE-2024-5455 |
Wordfence | |
| 6.5 Medium | License Manager for WooCommerce | Information Disclosure Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure |
≤ 3.0.6 |
CVE-2024-1639 |
Wordfence | |
| 6.5 Medium | WooCommerce Ship to Multiple Addresses | Broken Access Control |
≤ 3.8.5 Fixed in 3.8.6 |
CVE-2023-37872 |
Patchstack | |
| 8.1 High | WooCommerce Warranty Requests | Broken Access Control |
≤ 2.1.9 Fixed in 2.2.0 |
CVE-2023-37870 |
Patchstack | |
| 7.5 High | WooCommerce Stripe Payment Gateway | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 7.4.0 Fixed in 7.4.1 |
CVE-2023-35049 |
Patchstack | |
| 6.5 Medium | WooCommerce Checkout Manager | Broken Access Control No login needed |
≤ 7.3.0 Fixed in 7.3.1 |
CVE-2023-47681 |
Patchstack | |
| 6.4 Medium | WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce | Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.7 |
CVE-2024-4632 |
Wordfence | |
| 6.4 Medium | MIMO Woocommerce Order Tracking | Broken Access Control Missing Authorization to Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.2 |
CVE-2024-5768 |
Wordfence | |
| 9.8 Critical | WooCommerce - Social Login | PHP Object Injection Social Login <= 2.6.2 - Unauthenticated PHP Object Injection No login needed |
≤ 2.6.2 |
CVE-2024-5871 |
Wordfence | |
| 6.5 Medium | WooCommerce - Social Login | Other Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness No login needed |
≤ 2.6.2 |
CVE-2024-5868 |
Wordfence | |
| 7.1 High | FooEvents for WooCommerce | Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload |
≤ 1.19.20 |
CVE-2024-6000 |
Wordfence | |
| 6.5 Medium | WooCommerce Warranty Requests | Broken Access Control No login needed |
≤ 2.2.7 Fixed in 2.3.0 |
CVE-2023-51495 |
Patchstack | |
| 5.3 Medium | WooCommerce Warranty Requests | Broken Access Control No login needed |
≤ 2.2.7 Fixed in 2.3.0 |
CVE-2023-51496 |
Patchstack | |
| 5.4 Medium | WooCommerce Ship to Multiple Addresses | Broken Access Control |
≤ 3.8.9 Fixed in 3.8.10 |
CVE-2023-51497 |
Patchstack | |
| 4.3 Medium | WooCommerce Easy Duplicate Product | Broken Access Control |
≤ 0.3.0.7 Fixed in 0.3.0.8 |
CVE-2023-51523 |
Patchstack | |
| 6.5 Medium | SKU Label Changer For WooCommerce | Broken Access Control No login needed |
≤ 3.0 Fixed in 3.0.1 |
CVE-2023-29174 |
Patchstack | |
| 9.0 Critical | CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More | PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed |
≤ 4.4.1 |
CVE-2024-4371 |
Wordfence | |
| 5.3 Medium | Pricing Deals for WooCommerce | Broken Access Control No login needed |
≤ 2.0.3.2 |
CVE-2023-41240 |
Patchstack | |
| 5.4 Medium | BulkGate SMS Plugin for WooCommerce | Broken Access Control |
≤ 3.0.2 Fixed in 3.0.3 |
CVE-2023-51679 |
Patchstack | |
| 4.3 Medium | Quotes for WooCommerce | Broken Access Control |
≤ 2.0.1 Fixed in 2.0.2 |
CVE-2023-51680 |
Patchstack | |
| 6.4 Medium | CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More | Cross-Site Scripting Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 4.4.1 |
CVE-2024-4564 |
Wordfence | |
| 5.3 Medium | Builder for WooCommerce reviews shortcodes – ReviewShort | Broken Access Control ReviewShort plugin <= 1.01.5 - Broken Access Control No login needed |
≤ 1.01.5 Fixed in 1.01.6 |
CVE-2024-34763 |
Patchstack | |
| 4.3 Medium | MailerLite – WooCommerce integration | Broken Access Control WooCommerce integration plugin <= 2.0.8 - Broken Access Control |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2023-52227 |
Patchstack | |
| 4.3 Medium | Revolut Gateway for WooCommerce | Broken Access Control |
≤ 4.9.7 Fixed in 4.9.8 |
CVE-2023-52224 |
Patchstack | |
| 5.3 Medium | MC Woocommerce Wishlist | Broken Access Control No login needed |
≤ 1.7.2 Fixed in 1.7.3 |
CVE-2024-34819 |
Patchstack | |
| 8.6 High | WC Marketplace | Broken Access Control No login needed |
≤ 4.0.25 Fixed in 4.0.26 |
CVE-2024-24703 |
Patchstack | |
| 5.3 Medium | WooCommerce Canada Post Shipping | Broken Access Control No login needed |
≤ 2.8.3 Fixed in 2.8.4 |
CVE-2023-51498 |
Patchstack | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.9.23 |
CVE-2024-5189 |
Wordfence | |
| 5.4 Medium | Product Expiry for WooCommerce | Broken Access Control |
≤ 2.5 Fixed in 2.6 |
CVE-2023-52179 |
Patchstack | |
| 5.3 Medium | MC Woocommerce Wishlist | Broken Access Control No login needed |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2024-34813 |
Patchstack | |
| 4.3 Medium | WooCommerce Conversion Tracking | Broken Access Control |
≤ 2.0.11 Fixed in 2.0.12 |
CVE-2023-52217 |
Patchstack | |
| 5.3 Medium | WooCommerce Product Vendors | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2023-52186 |
Patchstack | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget |
≤ 2.9.0 |
CVE-2024-5530 |
Wordfence | |
| 5.3 Medium | PPOM for WooCommerce | Content Injection No login needed |
≤ 32.0.20 Fixed in 32.0.21 |
CVE-2024-35728 |
Patchstack | |
| 5.3 Medium | YITH WooCommerce Product Add-Ons | Content Injection No login needed |
≤ 4.9.2 Fixed in 4.9.3 |
CVE-2024-35680 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.