WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,801–1,850 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 37 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.6 High Checkout Field Editor for WooCommerce (Pro) Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2024-35658 Patchstack
4.3 Medium Bosa Elementor Addons and Templates for WooCommerce Plugin bosa-elementor-for-woocommerce Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2024-35724 Patchstack
4.3 Medium Extra Product Options for WooCommerce Plugin extra-product-options-for-woocommerce Broken Access Control ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-35727 Patchstack
5.3 Medium WooCommerce Dropshipping Plugin Broken Access Control Unauthenticated Arbitrary Email Sending No login needed ≤ 5.0.4 CVE-2024-35748 Patchstack
5.4 Medium Simple COD Fees for WooCommerce Plugin simple-cod-fee-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-35662 Patchstack
5.3 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Broken Access Control No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-31276 Patchstack
7.5 High Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-31283 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-31304 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
7.5 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control No login needed ≤ 4.3.39 Fixed in 4.5.4 CVE-2024-32777 Patchstack
5.3 Medium USPS Shipping for WooCommerce – Live Rates Plugin flexible-shipping-usps Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed ≤ 1.9.4 Fixed in 1.10.0 CVE-2024-32811 Patchstack
5.3 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32814 Patchstack
4.3 Medium Flexible Checkout Fields for WooCommerce Plugin flexible-checkout-fields Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-31267 Patchstack
8.8 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.18.0 Fixed in 2.18.1 CVE-2024-30485 Patchstack
6.5 Medium YITH WooCommerce Account Funds Premium Plugin Broken Access Control ≤ 1.33.0 Fixed in 1.34.0 CVE-2024-30470 Patchstack
5.4 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.4 Fixed in 5.3.5 CVE-2024-30466 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2024-25929 Patchstack
6.5 Medium WooCommerce Box Office Plugin Broken Access Control Unauthenticated Save Ticket Barcode No login needed ≤ 1.1.51 Fixed in 1.1.52 CVE-2023-34003 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2023-51494 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Information Disclosure Authenticated Arbitrary WordPress Option Disclosure < 7.1.3 Fixed in 7.1.3 CVE-2023-52230 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Broken Access Control Authenticated Arbitrary Post/Page Deletion < 7.1.2 Fixed in 7.1.2 CVE-2023-52232 Patchstack
4.3 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Broken Access Control ≤ 2.4.0 Fixed in 2.4.1 CVE-2024-30537 Patchstack
7.1 High New Order Notification for Woocommerce Plugin new-order-notification-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-31098 Patchstack
5.9 Medium YITH WooCommerce Tab Manager Plugin yith-woocommerce-tab-manager Cross-Site Scripting ≤ 1.35.0 Fixed in 1.35.1 CVE-2024-35698 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2024-35730 Patchstack
7.1 High Auto Coupons for WooCommerce Plugin woo-auto-coupons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.14 Fixed in 3.0.15 CVE-2024-35733 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute ≤ 2.2.80 CVE-2024-4042 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget ≤ 5.8.15 CVE-2024-5612 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-1988 Wordfence
4.3 Medium WooCommerce Tools Plugin woo-tools Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Module Deactivation ≤ 1.2.9 CVE-2024-1689 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.22 CVE-2024-5188 Wordfence
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
4.3 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Exposure 2.7.1 – 2.7.2 CVE-2024-5665 Wordfence
6.4 Medium SellKit – Funnel builder and checkout optimizer for WooCommerce to sell more, faster Plugin sellkit Cross-Site Scripting Funnel builder and checkout optimizer for WooCommerce to sell more, faster <= 1.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9.8 CVE-2024-4608 Wordfence
8.8 High XootiX Framework <= Various Plugin Versions Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Update ≤ 2.6, ≤ 2.6.1, 2.5, … CVE-2024-5324 Wordfence
4.9 Medium Woocommerce – Recent Purchases Plugin woo-recent-purchases Local File Inclusion Recent Purchases plugin <= 1.0.1 - File Inclusion ≤ 1.0.1 CVE-2024-35634 Patchstack
8.8 High XforWooCommerce Plugin Local File Inclusion Authenticated Local File Inclusion ≤ 2.0.2 CVE-2024-33628 Patchstack
6.5 Medium Booster Elite for WooCommerce Plugin Authentication Bypass Authenticated Production Creation/Modification < 7.1.3 Fixed in 7.1.3 CVE-2023-51511 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Authentication Bypass Authenticated Production Creation/Modification ≤ 7.1.2 Fixed in 7.1.3 CVE-2023-48747 Patchstack
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
5.3 Medium Claudio Sanches – Checkout Cielo for WooCommerce Plugin woocommerce-checkout-cielo Broken Access Control Checkout Cielo for WooCommerce <= 1.1.0 - Insufficient Verification of Data Authenticity to Order Payment Status Update No login needed ≤ 1.1.0 CVE-2024-1718 Wordfence
9.8 Critical Social Login Lite For WooCommerce Plugin social-login-lite-for-woocommerce Authentication Bypass No login needed ≤ 1.6.0 CVE-2024-4552 Wordfence
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.4 Medium WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce Plugin wp-cafe Cross-Site Scripting Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode ≤ 2.2.24 CVE-2024-5427 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget ≤ 5.5.4 CVE-2024-5341 Wordfence
6.4 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.5.3 CVE-2024-5039 Wordfence
6.4 Medium Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Carousel Widget ≤ 5.8.14 CVE-2024-5086 Wordfence
5.3 Medium WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly Plugin tour-booking-manager Broken Access Control WpTravelly <= 1.7.1 - Missing Authorization via ttbm_new_place_save No login needed ≤ 1.7.1 CVE-2024-0434 Wordfence
7.2 High YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.4.0 CVE-2024-4455 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.5.1 CVE-2024-4484 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only