WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 2,001–2,050 of 2,114 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | WooCommerce POS | Information Disclosure Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure |
≤ 1.4.11 |
CVE-2024-2384 |
Wordfence | |
| 6.1 Medium | Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms | SQL Injection Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id No login needed |
≤ 1.82.0 |
CVE-2024-2387 |
Wordfence | |
| 4.3 Medium | Builder for WooCommerce reviews shortcodes – ReviewShort | Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.01.3 Fixed in 1.01.4 |
CVE-2024-29093 |
Patchstack | |
| 5.9 Medium | WooCommerce Google Feed Manager | Cross-Site Scripting |
≤ 2.2.0 Fixed in 2.3.0 |
CVE-2024-29112 |
Patchstack | |
| 7.1 High | WooThumbs for WooCommerce by Iconic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.5.3 Fixed in 5.5.4 |
CVE-2024-29116 |
Patchstack | |
| 7.1 High | WooCommerce License Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-29121 |
Patchstack | |
| 7.1 High | WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management | Cross-Site Scripting No login needed |
≤ 4.2.9 Fixed in 4.3 |
CVE-2024-27959 |
Patchstack | |
| 5.3 Medium | Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates | Broken Access Control Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 2.6.6 |
CVE-2024-1857 |
Wordfence | |
| 5.4 Medium | WooCommerce PDF Invoice Builder | Cross-Site Request Forgery No login needed |
≤ 1.2.101 Fixed in 1.2.102 |
CVE-2023-51486 |
Patchstack | |
| 4.3 Medium | Customize My Account for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.8.3 Fixed in 1.8.4 |
CVE-2023-51369 |
Patchstack | |
| 4.3 Medium | HUSKY – Products Filter for WooCommerce (formerly WOOF) | Cross-Site Request Forgery No login needed |
≤ 1.3.4.3 Fixed in 1.3.4.4 |
CVE-2023-50861 |
Patchstack | |
| 5.9 Medium | Doofinder for WooCommerce | Cross-Site Scripting |
≤ 2.1.8 Fixed in 2.1.9 |
CVE-2024-25596 |
Patchstack | |
| 8.8 High | HUSKY – Products Filter for WooCommerce Professional | SQL Injection Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL Injection |
≤ 1.3.5.2 |
CVE-2024-1795 |
Wordfence | |
| 6.4 Medium | HUSKY – Products Filter for WooCommerce Professional | Cross-Site Scripting Products Filter for WooCommerce Professional <= 1.3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3.5.1 |
CVE-2024-1796 |
Wordfence | |
| 7.5 High | Product Carousel Slider & Grid Ultimate for WooCommerce | PHP Object Injection Authenticated(Contributor+) PHP Object Injection |
≤ 1.9.7 |
CVE-2024-1950 |
Wordfence | |
| 4.3 Medium | SMS Alert Order Notifications – WooCommerce | Cross-Site Request Forgery WooCommerce <= 3.6.9 - Cross-Site Request Forgery No login needed |
≤ 3.6.9 |
CVE-2024-1489 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Broken Access Control Missing Authorization No login needed |
≤ 3.0.14 |
CVE-2024-0683 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Data Table |
≤ 5.9.9 |
CVE-2024-1537 |
Wordfence | |
| 8.8 High | Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce | SQL Injection Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce <= 7.0.7 - Authenticated (Subscriber+) SQL Injection |
≤ 7.0.7 |
CVE-2024-1203 |
Wordfence | |
| 8.1 High | WooCommerce Add to Cart Custom Redirect | Broken Access Control Authenticated(Contributor+) Missing Authorization to Limited Arbitrary Options Update |
≤ 1.2.13 |
CVE-2024-1862 |
Wordfence | |
| 4.3 Medium | TeraWallet – Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds | Broken Access Control Best WooCommerce Wallet System With Cashback Rewards, Partial Payment, Wallet Refunds <= 1.4.10 - Missing Authorization to Authenticated (Subscriber+) User Email Export |
≤ 1.4.10 |
CVE-2024-1690 |
Wordfence | |
| 7.4 High | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar |
≤ 5.9.9 |
CVE-2024-1536 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.0.14 |
CVE-2024-2395 |
Wordfence | |
| 8.8 High | Elite Booster for WooCommerce | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 7.1.7 |
CVE-2024-1986 |
Wordfence | |
| 8.8 High | PDF Invoices and Packing Slips For WooCommerce | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.3.7 |
CVE-2024-1773 |
Wordfence | |
| 6.4 Medium | Booster for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde |
≤ 7.1.7 |
CVE-2024-1534 |
Wordfence | |
| 5.3 Medium | Password Protected Store for WooCommerce | Information Disclosure Information Exposure via REST API No login needed |
≤ 2.2 |
CVE-2024-1088 |
Wordfence | |
| 5.3 Medium | NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce | Broken Access Control Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 - Missing Authorization to Unauthenticated System Information Disclosure No login needed |
≤ 2.17.0, ≤ 2.18.0 |
CVE-2024-1120 |
Wordfence | |
| 9.1 Critical | Mollie Payments for WooCommerce | Arbitrary File Upload WordPress Mollie Payments for WooCommerce Plugin <= 7.3.11 is vulnerable to Arbitrary File Upload |
≤ 7.3.11 Fixed in 7.3.12 |
CVE-2023-6090 |
Patchstack | |
| 8.8 High | Avada | Website Builder For WordPress & WooCommerce | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.11.4 |
CVE-2024-1468 |
Wordfence | |
| 4.3 Medium | Customer Reviews for WooCommerce | Broken Access Control WordPress Customer Reviews for WooCommerce Plugin <= 5.38.1 is vulnerable to Broken Access Control |
≤ 5.38.1 Fixed in 5.38.2 |
CVE-2023-51692 |
Patchstack | |
| 5.4 Medium | MailerLite – WooCommerce integration | Cross-Site Request Forgery WooCommerce integration Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2023-52223 |
Patchstack | |
| 4.3 Medium | Custom Order Statuses for WooCommerce | Cross-Site Request Forgery WordPress Custom Order Statuses for WooCommerce Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.2 |
CVE-2024-25930 |
Patchstack | |
| 4.3 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_plugin_activation No login needed |
≤ 1.4.4 |
CVE-2024-0767 |
Wordfence | |
| 8.8 High | Conversios | SQL Injection Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory |
≤ 7.0.7 |
CVE-2024-0786 |
Wordfence | |
| 4.3 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Broken Access Control Missing Authorization via templates_ajax_request |
≤ 1.4.4 |
CVE-2024-0766 |
Wordfence | |
| 6.3 Medium | Oliver POS – A WooCommerce Point of Sale (POS) | Cross-Site Request Forgery A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request Forgery No login needed |
≤ 2.4.1.8 |
CVE-2024-1954 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_set_default_card No login needed |
≤ 20221130 |
CVE-2024-0431 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_delete_card No login needed |
≤ 20221130 |
CVE-2024-0432 |
Wordfence | |
| 4.3 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_theme_activation No login needed |
≤ 1.4.4 |
CVE-2024-0768 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_unset_default_card No login needed |
≤ 20221130 |
CVE-2024-0433 |
Wordfence | |
| 9.8 Critical | NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor | SQL Injection Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection No login needed |
≤ 2.8.2 |
CVE-2024-1698 |
Wordfence | |
| 5.4 Medium | Thank You Page Customizer for WooCommerce – Increase Your Sales | Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.1.2 |
CVE-2024-1687 |
Wordfence | |
| 4.3 Medium | Thank You Page Customizer for WooCommerce – Increase Your Sales | Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export |
≤ 1.1.2 |
CVE-2024-1686 |
Wordfence | |
| 5.3 Medium | WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit | Information Disclosure WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure No login needed |
≤ 1.0.9 |
CVE-2024-1436 |
Patchstack | |
| 10.0 Critical | WooCommerce Easy Checkout Field Editor, Fees & Discounts | Arbitrary File Upload WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload No login needed |
≤ 3.5.12 Fixed in 3.5.13 |
CVE-2024-25925 |
Patchstack | |
| 5.4 Medium | SuperFaktura WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.40.3 |
CVE-2024-1758 |
Wordfence | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 5.3 Medium | WooCommerce Google Sheet Connector | Broken Access Control Missing Authorization No login needed |
≤ 1.3.11 |
CVE-2024-1562 |
Wordfence | |
| 5.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery |
≤ 5.9.8 |
CVE-2024-1171 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.