WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–176 of 176 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
10.0 Critical InPost for WooCommerce Plugin woo-inpost Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Delete No login needed ≤ 1.4.0, ≤ 1.4.4 CVE-2024-6500 Wordfence
9.1 Critical HUSKY Plugin woocommerce-products-filter Privilege Escalation ≤ 1.3.6.1 Fixed in 1.3.6.2 CVE-2024-43121 Patchstack
9.8 Critical WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.7.5 - Authentication Bypass to Account Takeover No login needed ≤ 2.7.5 CVE-2024-7503 Wordfence
9.8 Critical YayExtra – WooCommerce Extra Product Options Plugin yayextra Arbitrary File Upload WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file Function No login needed ≤ 1.3.7 CVE-2024-7257 Wordfence
9.8 Critical WooCommerce - Social Login Plugin Broken Access Control Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation No login needed ≤ 2.7.3 CVE-2024-6636 Wordfence
9.8 Critical HUSKY - Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection No login needed ≤ 1.3.6 CVE-2024-6457 Wordfence
9.3 Critical Woocommerce OpenPos Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.4 CVE-2024-37933 Patchstack
9.8 Critical Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed ≤ 5.7.25 CVE-2024-6172 Wordfence
9.8 Critical Themify - WooCommerce Product Filter Plugin themify-wc-product-filter SQL Injection WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter No login needed ≤ 1.4.9 CVE-2024-6027 Wordfence
9.8 Critical WooCommerce - Social Login Plugin PHP Object Injection Social Login <= 2.6.2 - Unauthenticated PHP Object Injection No login needed ≤ 2.6.2 CVE-2024-5871 Wordfence
9.0 Critical CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.1 CVE-2024-4371 Wordfence
9.8 Critical Social Login Lite For WooCommerce Plugin social-login-lite-for-woocommerce Authentication Bypass No login needed ≤ 1.6.0 CVE-2024-4552 Wordfence
9.8 Critical Simple Registration for WooCommerce Plugin woocommerce-simple-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.6 CVE-2024-32511 Patchstack
9.8 Critical Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-51481 Patchstack
10.0 Critical OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Arbitrary File Upload Unauthenticated API Access to Arbitrary File Upload No login needed ≤ 12.4 Fixed in 12.5 CVE-2024-33566 Patchstack
9.8 Critical Product Addons & Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Unauthenticated Arbitrary File Upload via ppom_upload_file No login needed ≤ 32.0.18 CVE-2024-3962 Wordfence
9.1 Critical Advanced Order Export For WooCommerce Plugin woo-order-export-lite Remote Code Execution ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-31266 Patchstack
9.1 Critical Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-30231 Patchstack
9.1 Critical Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Arbitrary File Upload WordPress Mollie Payments for WooCommerce Plugin <= 7.3.11 is vulnerable to Arbitrary File Upload ≤ 7.3.11 Fixed in 7.3.12 CVE-2023-6090 Patchstack
9.8 Critical NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor Plugin notificationx SQL Injection Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection No login needed ≤ 2.8.2 CVE-2024-1698 Wordfence
10.0 Critical WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin Arbitrary File Upload WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload No login needed ≤ 3.5.12 Fixed in 3.5.13 CVE-2024-25925 Patchstack
9.8 Critical Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.6.5.1 CVE-2024-0610 Wordfence
9.8 Critical Stripe Payment Plugin for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.7.9 CVE-2024-0705 Wordfence
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only