WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,851–1,900 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 38 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.5.2 CVE-2024-4485 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization ≤ 5.7.17 CVE-2024-3626 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-3155 Wordfence
8.8 High HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin woocommerce-products-filter Remote Code Execution ≤ 1.3.5.2 Fixed in 1.3.5.3 CVE-2024-32680 Patchstack
9.8 Critical Simple Registration for WooCommerce Plugin woocommerce-simple-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.6 CVE-2024-32511 Patchstack
8.3 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Local File Inclusion No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2024-27971 Patchstack
7.2 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Privilege Escalation ≤ 4.2.1 Fixed in 4.3.0 CVE-2023-51546 Patchstack
9.8 Critical Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-51481 Patchstack
7.2 High EAN for WooCommerce Plugin ean-for-woocommerce Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 4.8.9 Fixed in 4.9.0 CVE-2024-34370 Patchstack
7.6 High WooCommerce One Page Checkout Plugin Local File Inclusion ≤ 2.3.0 Fixed in 2.4.0 CVE-2023-35881 Patchstack
5.3 Medium Conditional Checkout Fields for WooCommerce Plugin Authentication Bypass Broken Authentication No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2022-45070 Patchstack
4.3 Medium ReviewX – Multi-criteria Rating & Reviews for WooCommerce Plugin Broken Access Control Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization ≤ 1.6.27 CVE-2024-3609 Wordfence
4.4 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection ≤ 2.4.9 Fixed in 2.5.0 CVE-2024-34751 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.20 CVE-2024-4624 Wordfence
5.3 Medium YITH WooCommerce Gift Cards Plugin yith-woocommerce-gift-cards Broken Access Control Missing Authorization to Unauthenticated WooCommerce Settings Update No login needed ≤ 4.12.0 CVE-2024-0870 Wordfence
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.8 Fixed in 1.4.9 CVE-2024-35167 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-34812 Patchstack
6.5 Medium Orders Tracking for WooCommerce Plugin woo-orders-tracking Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.10 CVE-2024-4039 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' ≤ 5.9.19 CVE-2024-4275 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' ≤ 5.9.19 CVE-2024-4448 Wordfence
6.5 Medium Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro Plugin back-in-stock-notifier-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.3.1 CVE-2024-4038 Wordfence
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares ≤ 4.8.1, ≤ 2.1.10, ≤ 1.9.3 Fixed in 4.9.0 CVE-2024-4233 Patchstack
8.5 High Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Path Traversal Arbitrary File Download and Deletion ≤ 4.0.17 Fixed in 4.0.18 CVE-2024-32807 Patchstack
5.5 Medium Where Did You Hear About Us Checkout Field for WooCommerce Plugin wc-customer-source Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-2752 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
5.3 Medium 2Checkout Payment Gateway for WooCommerce Plugin woocommerce-2checkout-payment Broken Access Control Missing Authorization via sniff_ins No login needed ≤ 6.2 CVE-2024-0629 Wordfence
7.2 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp SQL Injection Authenticated (AccountingManager+) SQL Injection ≤ 1.13.1 CVE-2024-1173 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id ≤ 2.8.7 CVE-2024-3991 Wordfence
6.5 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.1.8 CVE-2024-3734 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-3045 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.17 CVE-2024-4156 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.15 CVE-2024-4003 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.8.0 CVE-2024-3047 Wordfence
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.8 CVE-2024-3957 Wordfence
6.5 Medium Min and Max Purchase for WooCommerce Plugin min-and-max-purchase-for-woocommerce Cross-Site Scripting ≤ 2.0.0 CVE-2024-33949 Patchstack
6.5 Medium WooCommerce AWeber Newsletter Subscription Plugin Broken Access Control Unauthenticated Access Token Change/Reset No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2024-33944 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Broken Access Control ≤ 1.3.0 Fixed in 1.3.2 CVE-2024-33956 Patchstack
8.1 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Email Verification and Authentication Bypass due to Insufficient Randomness No login needed ≤ 2.7.4 CVE-2024-4185 Wordfence
4.3 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-33585 Patchstack
10.0 Critical OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Arbitrary File Upload Unauthenticated API Access to Arbitrary File Upload No login needed ≤ 12.4 Fixed in 12.5 CVE-2024-33566 Patchstack
6.4 Medium WPC Composite Products for WooCommerce Plugin wpc-composite-products Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 7.2.7 CVE-2024-2838 Wordfence
4.3 Medium Flexible Shipping Plugin flexible-shipping Broken Access Control ≤ 4.24.15 Fixed in 4.24.16 CVE-2024-32828 Patchstack
9.8 Critical Product Addons & Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Unauthenticated Arbitrary File Upload via ppom_upload_file No login needed ≤ 32.0.18 CVE-2024-3962 Wordfence
9.1 Critical Advanced Order Export For WooCommerce Plugin woo-order-export-lite Remote Code Execution ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-31266 Patchstack
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure No login needed ≤ 5.9.15 CVE-2024-3733 Wordfence
6.5 Medium Order Limit for WooCommerce Plugin wc-order-limit-lite Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-32675 Patchstack
5.3 Medium TrackShip for WooCommerce Plugin trackship-for-woocommerce Broken Access Control No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-32678 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only