WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium MarketKing Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.70 CVE-2026-85311 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2026-85303 Patchstack
9.8 Critical YITH Request a Quote for WooCommerce Premium Plugin yith-woocommerce-request-a-quote-premium Broken Access Control No login needed < 4.46.0 Fixed in 4.46.0 CVE-2026-84238 Patchstack
6.5 Medium Product Variations Swatches for WooCommerce Plugin product-variations-swatches-for-woocommerce Cross-Site Scripting ≤ 1.1.18 Fixed in 1.1.19 CVE-2026-81282 Patchstack
6.5 Medium Pre-Orders for WooCommerce Plugin pre-orders-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3 CVE-2026-84849 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2026-84760 Patchstack
7.5 High WooCommerce Product Attachment Plugin woo-product-attachment Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3.3 CVE-2026-81774 Patchstack
7.1 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Cross-Site Scripting No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2026-81288 Patchstack
4.3 Medium CatalogX Plugin woocommerce-catalog-enquiry Content Injection Unauthenticated Email Content Injection via Shared Transient No login needed < 6.1.3 Fixed in 6.1.3 CVE-2026-79621 WPScan
5.3 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Unauthenticated Vendor PII and Payout Data Disclosure via stores REST Endpoint No login needed 5.0.13 – < 5.0.15 Fixed in 5.0.15 CVE-2026-74927 WPScan
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-81762 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Information Disclosure Sensitive Data Exposure ≤ 4.0.0 Fixed in 4.0.1 CVE-2026-81280 Patchstack
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored XSS via 'comment' Parameter No login needed < 5.118.0 Fixed in 5.118.0 CVE-2026-76585 WPScan
9.8 Critical Custom User Registration Fields for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout No login needed ≤ 2.2.3 CVE-2026-15369 Wordfence
9.1 Critical Total Processing Card Payments for WooCommerce Plugin Server-Side Request Forgery Unauthenticated SSRF leading to Payment Bypass and Gateway Credential Disclosure No login needed ≤ 7.3 CVE-2026-16947 WPScan
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Aggregated Review Form No login needed ≤ 5.106.0 CVE-2026-6176 Wordfence
8.5 High Suggestion Engine for WooCommerce Plugin woo-suggestion-engine SQL Injection ≤ 2.0.11 Fixed in 2.0.12 CVE-2026-81277 Patchstack
7.1 High Music Player for WooCommerce Plugin music-player-for-woocommerce Cross-Site Scripting No login needed ≤ 1.8.9 Fixed in 1.9.0 CVE-2026-78283 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78257 Patchstack
8.6 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Broken Access Control No login needed ≤ 0.4.62 Fixed in 0.4.63 CVE-2026-27330 Patchstack
4.3 Medium Notifima Plugin woocommerce-product-stock-alert Broken Access Control Subscriber+ Stock Alert Unsubscription via IDOR < 3.1.4 Fixed in 3.1.4 CVE-2026-78139 WPScan
4.3 Medium Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Information Disclosure Subscriber+ Campaign Configuration Disclosure via wcct_quick_view_html < 2.21.0 Fixed in 2.21.0 CVE-2026-78138 WPScan
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce Plugin Price Manipulation Unauthenticated Arbitrary Price Manipulation via BOGO Add-to-Cart No login needed < 2.1.2 Fixed in 2.1.2 CVE-2026-78137 WPScan
9.8 Critical ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce Plugin erp Arbitrary File Upload Unauthenticated Arbitrary File Upload via CRM Email Connect IMAP Attachment No login needed ≤ 1.17.8 CVE-2026-18080 Wordfence
7.5 High WooCommerce Lottery Plugin woocommerce-lottery SQL Injection Unauthenticated Time-Based SQL Injection via 'orderby' and 'order' Parameters No login needed ≤ 2.2.9 CVE-2026-18884 Wordfence
8.7 High Order Tip for WooCommerce Plugin order-tip-woo Arbitrary File Deletion Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajax < 1.6.0 Fixed in 1.6.0 CVE-2026-77693 WPScan
7.2 High ShopEngine Elementor WooCommerce Builder Addon Plugin shopengine Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation to WXR Import '<wp_option>' Nodes ≤ 4.9.4 CVE-2026-75971 Wordfence
9.8 Critical Affiliate Pro - Affiliate Program for WooCommerce & Plugin wp-wc-affiliate-program Privilege Escalation Affiliate Program for WooCommerce & WordPress plugin <= 8.9.1 - Privilege Escalation No login needed ≤ 8.9.1 CVE-2026-32558 Patchstack
8.6 High ShopBuilder Pro – Elementor WooCommerce Builder Addons Plugin shopbuilder-pro Arbitrary File Deletion Elementor WooCommerce Builder Addons plugin <= 2.2.0 - Arbitrary File Deletion No login needed ≤ 2.2.0 CVE-2026-32477 Patchstack
8.6 High WooCommerce File Approval Plugin woocommerce-file-approval Arbitrary File Deletion No login needed ≤ 10.7 CVE-2026-28171 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-78258 Patchstack
4.3 Medium WooCommerce Bookings Plugin Broken Access Control Subscriber+ Draft Bookable Product Creation via Missing Authorization < 3.9.0 Fixed in 3.9.0 CVE-2026-14853 WPScan
6.5 Medium WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Path Traversal Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' Parameter ≤ 4.9.8 CVE-2026-18027 Wordfence
7.5 High Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Other Unauthenticated Improper Input Validation to Price Bypass via Add-to-Cart POST Request No login needed ≤ 1.6.21 CVE-2026-2996 Wordfence
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Information Disclosure Unauthenticated Password-Protected Product Information Disclosure No login needed < 1.34.1 Fixed in 1.34.1 CVE-2026-16612 WPScan
4.2 Medium LitExtension: Store to WooCommerce Migration Plugin Cross-Site Request Forgery Connector Token Takeover via CSRF No login needed ≤ 1.2.5 CVE-2026-15046 WPScan
9.8 Critical Abandoned Cart Pro for WooCommerce Plugin woocommerce-abandon-cart-pro Privilege Escalation No login needed ≤ 10.4.0 CVE-2026-66682 Patchstack
7.1 High Paymob for WooCommerce Plugin paymob-for-woocommerce Cross-Site Scripting No login needed ≤ 4.1.10 Fixed in 4.1.11 CVE-2026-66611 Patchstack
7.1 High Swatchly – WooCommerce Variation Swatches for Products Plugin swatchly Cross-Site Scripting WooCommerce Variation Swatches for Products plugin <= 1.4.13 - Cross Site Scripting (XSS) No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2026-66605 Patchstack
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control < 2.0.8 Fixed in 2.0.8 CVE-2026-73363 Patchstack
8.5 High YITH WooCommerce Membership Premium Plugin yith-woocommerce-membership-premium SQL Injection ≤ 2.33.0 Fixed in 2.33.1 CVE-2026-32552 Patchstack
5.3 Medium Membership For WooCommerce Plugin membership-for-woocommerce Information Disclosure Unauthenticated Member Data Disclosure via REST Consumer Secret Bypass No login needed < 3.1.2 Fixed in 3.1.2 CVE-2026-19709 WPScan
5.4 Medium B2BKing Plugin b2bking-wholesale-for-woocommerce Broken Access Control ≤ 5.2.30 Fixed in 5.2.40 CVE-2026-66589 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.8.7 CVE-2026-74009 Patchstack
6.5 Medium Flutterwave WooCommerce Plugin rave-woocommerce-payment-gateway Authentication Bypass Broken Authentication No login needed ≤ 3.3.0 CVE-2026-73399 Patchstack
6.5 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Authentication Bypass Broken Authentication No login needed 3.2.0 CVE-2026-73398 Patchstack
7.1 High MWB HubSpot for WooCommerce Plugin makewebbetter-hubspot-for-woocommerce Authentication Bypass Broken Authentication ≤ 1.6.7 CVE-2026-73396 Patchstack
4.9 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Path Traversal Arbitrary File Download ≤ 6.6.47 Fixed in 6.6.48 CVE-2026-73383 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.18 Fixed in 3.0.19 CVE-2026-73345 Patchstack
7.5 High Extra Product Options & Add-Ons for WooCommerce Plugin woocommerce-tm-extra-product-options Path Traversal Arbitrary File Download No login needed < 7.6 Fixed in 7.6 CVE-2026-73181 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only