WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 201–250 of 2,122 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | MultiVendorX | Broken Access Control No login needed |
≤ 5.0.19 |
CVE-2026-66651 |
Patchstack | |
| 5.3 Medium | ShopSmart Loyalty for WooCommerce | Information Disclosure Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone No login needed |
≤ 1.0.0 |
CVE-2026-14832 |
WPScan | |
| 7.5 High | Extra Product Options Builder for WooCommerce | Information Disclosure Unauthenticated Customer File Disclosure via getpublicfileupload No login needed |
< 1.2.176 Fixed in 1.2.176 |
CVE-2026-19728 |
WPScan | |
| 7.2 High | WCPOS | Remote Code Execution Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine |
≤ 1.9.14 |
CVE-2026-17581 |
Wordfence | |
| 7.2 High | Autopay | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter No login needed |
≤ 5.0.0 |
CVE-2026-15002 |
Wordfence | |
| 5.3 Medium | Product Table & List Builder For WooCommerce | Content Injection Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter No login needed |
≤ 5.6.0 |
CVE-2026-15441 |
Wordfence | |
| 7.5 High | Product Feed PRO for WooCommerce | Information Disclosure Unauthenticated Feed Configuration Disclosure No login needed |
< 13.5.7 Fixed in 13.5.7 |
CVE-2026-16611 |
WPScan | |
| 8.6 High | Paymob for WooCommerce | SQL Injection Unauthenticated SQL Injection via Paymob Callback Pixel Lookup No login needed |
< 4.1.9 Fixed in 4.1.9 |
CVE-2026-15205 |
WPScan | |
| 7.1 High | Samex - Clean, Minimal Shop WooCommerce | Cross-Site Scripting WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) No login needed |
≤ 2.5, ≤ 1.7 |
CVE-2026-28154 |
Patchstack | |
| 5.3 Medium | Revolut Gateway for WooCommerce | Broken Access Control No login needed |
< 4.22.10 Fixed in 4.22.10 |
CVE-2026-73353 |
Patchstack | |
| 7.6 High | MailChimp For WooCommerce | SQL Injection |
< 6.2 Fixed in 6.2 |
CVE-2026-73346 |
Patchstack | |
| 7.1 High | Colissimo Officiel : Méthodes de livraison pour WooCommerce | Cross-Site Scripting No login needed |
≤ 2.10.0 Fixed in 3.0.0 |
CVE-2026-66697 |
Patchstack | |
| 7.1 High | MultiParcels Shipping For WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.30.36 |
CVE-2026-66655 |
Patchstack | |
| 7.1 High | Local Delivery Drivers for WooCommerce | Cross-Site Scripting No login needed |
≤ 3.0.0 |
CVE-2026-66468 |
Patchstack | |
| 7.5 High | StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart | Broken Access Control No login needed |
≤ 2.1.1 |
CVE-2026-66466 |
Patchstack | |
| 9.8 Critical | Cartify | Privilege Escalation Account Takeover No login needed |
≤ 1.3.0.1 |
CVE-2026-66465 |
Patchstack | |
| 7.5 High | WooCommerce Appointments | Information Disclosure Sensitive Data Exposure No login needed |
≤ 5.3.8 |
CVE-2026-66462 |
Patchstack | |
| 7.5 High | SMEPay: UPI Gateway for WooCommerce | Price Manipulation Payment Bypass No login needed |
≤ 1.0.5 |
CVE-2026-66461 |
Patchstack | |
| 6.5 Medium | AfterShip Tracking | Cross-Site Scripting |
≤ 1.18.1 |
CVE-2026-66460 |
Patchstack | |
| 7.5 High | MultiVendorX | Broken Access Control No login needed |
≤ 5.0.10 Fixed in 5.0.11 |
CVE-2026-66441 |
Patchstack | |
| 9.3 Critical | Active Products Tables for WooCommerce | SQL Injection No login needed |
≤ 1.1.1 Fixed in 2.1.2 |
CVE-2026-66436 |
Patchstack | |
| 7.5 High | Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) | Broken Access Control No login needed |
≤ 1.0.7 Fixed in 1.0.8 |
CVE-2026-66431 |
Patchstack | |
| 7.5 High | Taxi Booking Manager for WooCommerce | Broken Access Control No login needed |
≤ 2.0.3 Fixed in 2.0.5 |
CVE-2026-27345 |
Patchstack | |
| 9.8 Critical | Customer Email Verification for WooCommerce | Privilege Escalation Unauthenticated Account Takeover via Type-Juggling Authentication Bypass No login needed |
2.4.0 – < 3.2.6 Fixed in 3.2.6 |
CVE-2026-14182 |
WPScan | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed |
< 9.2.1 Fixed in 9.2.1 |
CVE-2026-16621 |
WPScan | |
| 6.5 Medium | Wallet System for WooCommerce | Price Manipulation Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount |
< 2.7.10 Fixed in 2.7.10 |
CVE-2026-15045 |
WPScan | |
| 5.3 Medium | Order Sync with Zendesk for WooCommerce | Information Disclosure Unauthenticated Customer Order Data Disclosure No login needed |
< 2.2.3 Fixed in 2.2.3 |
CVE-2026-19073 |
WPScan | |
| 9.8 Critical | WooCommerce Subscriptions | Remote Code Execution Unauthenticated RCE via PHP Object Injection No login needed |
4.7.0 – < 9.1.0 Fixed in 9.1.0 |
CVE-2026-18391 |
WPScan | |
| 9.1 Critical | TeraWallet - Wallet for WooCommerce | Broken Access Control Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up No login needed |
< 1.6.10 Fixed in 1.6.10 |
CVE-2026-16538 |
WPScan | |
| 9.8 Critical | Gift Cards For WooCommerce Pro | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
< 4.2.10 Fixed in 4.2.10 |
CVE-2026-15039 |
WPScan | |
| 9.8 Critical | Product Input Fields for WooCommerce | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
2.0.0 – < 2.0.2 Fixed in 2.0.2 |
CVE-2026-19089 |
WPScan | |
| 8.8 High | Autopay / Blue Media for WooCommerce | Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed |
< 5.0.1 Fixed in 5.0.1 |
CVE-2026-14293 |
WPScan | |
| 5.4 Medium | Customer Reviews for WooCommerce | Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions |
< 5.116.0 Fixed in 5.116.0 |
CVE-2026-14941 |
WPScan | |
| 3.7 Low | Restore PayPal Standard for WooCommerce | Price Manipulation Payment Bypass via PDT Underpayment No login needed |
≤ 3.1.0 |
CVE-2026-17016 |
WPScan | |
| 5.3 Medium | Restore PayPal Standard for WooCommerce | Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed |
≤ 3.1.0 |
CVE-2026-17012 |
WPScan | |
| 6.5 Medium | Cancel Order & Request Woocommerce | Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed |
< 1.3.4.34 Fixed in 1.3.4.34 |
CVE-2026-18603 |
WPScan | |
| 7.5 High | WPC Order Tip for WooCommerce | Information Disclosure Unauthenticated Order Data Disclosure No login needed |
< 3.3.1 Fixed in 3.3.1 |
CVE-2026-18357 |
WPScan | |
| 5.9 Medium | Subscriptions for WooCommerce | Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15211 |
WPScan | |
| 8.8 High | Subscriptions for WooCommerce | Remote Code Execution Shop Manager+ Arbitrary Plugin Installation |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15215 |
WPScan | |
| 4.3 Medium | Subscriptions for WooCommerce | Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR |
< 2.0.1 Fixed in 2.0.1 |
CVE-2026-15214 |
WPScan | |
| 7.5 High | WPC Name Your Price for WooCommerce | Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed |
< 2.2.5 Fixed in 2.2.5 |
CVE-2026-16620 |
WPScan | |
| 5.3 Medium | Event Booking Manager for WooCommerce (Pro) | Price Manipulation Unauthenticated Payment Bypass via Client-Controlled Ticket Price No login needed |
< 5.0.3 Fixed in 5.0.3 |
CVE-2026-16067 |
WPScan | |
| 7.5 High | CoCart | Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed |
< 4.9.0 Fixed in 4.9.0 |
CVE-2026-10524 |
WPScan | |
| 5.3 Medium | Easy Booking | Other Unauthenticated Minimum Booking Duration Bypass No login needed |
< 3.5.0 Fixed in 3.5.0 |
CVE-2026-14831 |
WPScan | |
| 7.5 High | Payment Plugins for PayPal WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed |
< 2.0.20 Fixed in 2.0.20 |
CVE-2026-13399 |
WPScan | |
| 7.5 High | Payment Gateway for Redsys & WooCommerce Lite | Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed |
< 7.0.2 Fixed in 7.0.2 |
CVE-2026-12584 |
WPScan | |
| 7.5 High | Integrate PhonePe with WooCommerce | Price Manipulation Unauthenticated Payment Bypass via Transaction ID Reuse No login needed |
≤ 1.2.1 |
CVE-2026-10599 |
WPScan | |
| 7.1 High | WooCommerce Multilingual & Multicurrency | Cross-Site Scripting No login needed |
≤ 5.5.6 Fixed in 5.5.7 |
CVE-2026-66711 |
Patchstack | |
| 9.1 Critical | CTX Feed | Remote Code Execution |
≤ 6.6.42 Fixed in 6.6.43 |
CVE-2026-66709 |
Patchstack | |
| 7.1 High | Facebook for WooCommerce | Cross-Site Scripting No login needed |
≤ 3.7.5 Fixed in 3.7.6 |
CVE-2026-66707 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.