WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.19 CVE-2026-66651 Patchstack
5.3 Medium ShopSmart Loyalty for WooCommerce Plugin Information Disclosure Unauthenticated Sensitive Information Disclosure via shopsmart_check_phone No login needed ≤ 1.0.0 CVE-2026-14832 WPScan
7.5 High Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Information Disclosure Unauthenticated Customer File Disclosure via getpublicfileupload No login needed < 1.2.176 Fixed in 1.2.176 CVE-2026-19728 WPScan
7.2 High WCPOS Plugin woocommerce-pos Remote Code Execution Authenticated (Shop Manager+) Code Injection via 'thermal' Template Engine ≤ 1.9.14 CVE-2026-17581 Wordfence
7.2 High Autopay Plugin platnosci-online-blue-media Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'bm_woocommerce_css_editor_content' Parameter No login needed ≤ 5.0.0 CVE-2026-15002 Wordfence
5.3 Medium Product Table & List Builder For WooCommerce Plugin wc-product-table-lite Content Injection Unauthenticated CSS Injection via 'laptop_scroll_offset' Parameter No login needed ≤ 5.6.0 CVE-2026-15441 Wordfence
7.5 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Information Disclosure Unauthenticated Feed Configuration Disclosure No login needed < 13.5.7 Fixed in 13.5.7 CVE-2026-16611 WPScan
8.6 High Paymob for WooCommerce Plugin paymob-for-woocommerce SQL Injection Unauthenticated SQL Injection via Paymob Callback Pixel Lookup No login needed < 4.1.9 Fixed in 4.1.9 CVE-2026-15205 WPScan
7.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Cross-Site Scripting WordPress Samex and M.Anh WordPress themes affected by Cross Site Scripting (XSS) No login needed ≤ 2.5, ≤ 1.7 CVE-2026-28154 Patchstack
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control No login needed < 4.22.10 Fixed in 4.22.10 CVE-2026-73353 Patchstack
7.6 High MailChimp For WooCommerce Plugin mailchimp-for-woocommerce SQL Injection < 6.2 Fixed in 6.2 CVE-2026-73346 Patchstack
7.1 High Colissimo Officiel : Méthodes de livraison pour WooCommerce Plugin colissimo-shipping-methods-for-woocommerce Cross-Site Scripting No login needed ≤ 2.10.0 Fixed in 3.0.0 CVE-2026-66697 Patchstack
7.1 High MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.30.36 CVE-2026-66655 Patchstack
7.1 High Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Cross-Site Scripting No login needed ≤ 3.0.0 CVE-2026-66468 Patchstack
7.5 High StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart Plugin storegrowth-sales-booster Broken Access Control No login needed ≤ 2.1.1 CVE-2026-66466 Patchstack
9.8 Critical Cartify Theme cartify-multipurpose-woocommerce-wordpress-theme Privilege Escalation Account Takeover No login needed ≤ 1.3.0.1 CVE-2026-66465 Patchstack
7.5 High WooCommerce Appointments Plugin woocommerce-appointments Information Disclosure Sensitive Data Exposure No login needed ≤ 5.3.8 CVE-2026-66462 Patchstack
7.5 High SMEPay: UPI Gateway for WooCommerce Plugin smepay-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 1.0.5 CVE-2026-66461 Patchstack
6.5 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Cross-Site Scripting ≤ 1.18.1 CVE-2026-66460 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 5.0.10 Fixed in 5.0.11 CVE-2026-66441 Patchstack
9.3 Critical Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce SQL Injection No login needed ≤ 1.1.1 Fixed in 2.1.2 CVE-2026-66436 Patchstack
7.5 High Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK) Plugin clink-gateway-for-woocommerce Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-66431 Patchstack
7.5 High Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.3 Fixed in 2.0.5 CVE-2026-27345 Patchstack
9.8 Critical Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Privilege Escalation Unauthenticated Account Takeover via Type-Juggling Authentication Bypass No login needed 2.4.0 – < 3.2.6 Fixed in 3.2.6 CVE-2026-14182 WPScan
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Price Manipulation Unauthenticated Payment Bypass via PayPal Advanced Return Handler No login needed < 9.2.1 Fixed in 9.2.1 CVE-2026-16621 WPScan
6.5 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Price Manipulation Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount < 2.7.10 Fixed in 2.7.10 CVE-2026-15045 WPScan
5.3 Medium Order Sync with Zendesk for WooCommerce Plugin mwb-zendesk-woo-order-sync Information Disclosure Unauthenticated Customer Order Data Disclosure No login needed < 2.2.3 Fixed in 2.2.3 CVE-2026-19073 WPScan
9.8 Critical WooCommerce Subscriptions Plugin Remote Code Execution Unauthenticated RCE via PHP Object Injection No login needed 4.7.0 – < 9.1.0 Fixed in 9.1.0 CVE-2026-18391 WPScan
9.1 Critical TeraWallet - Wallet for WooCommerce Plugin Broken Access Control Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up No login needed < 1.6.10 Fixed in 1.6.10 CVE-2026-16538 WPScan
9.8 Critical Gift Cards For WooCommerce Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 4.2.10 Fixed in 4.2.10 CVE-2026-15039 WPScan
9.8 Critical Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 2.0.0 – < 2.0.2 Fixed in 2.0.2 CVE-2026-19089 WPScan
8.8 High Autopay / Blue Media for WooCommerce Plugin Cross-Site Scripting Unauthenticated Stored XSS via CSS Editor No login needed < 5.0.1 Fixed in 5.0.1 CVE-2026-14293 WPScan
5.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Subscriber+ Missing Authorization via Multiple Settings AJAX Actions < 5.116.0 Fixed in 5.116.0 CVE-2026-14941 WPScan
3.7 Low Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via PDT Underpayment No login needed ≤ 3.1.0 CVE-2026-17016 WPScan
5.3 Medium Restore PayPal Standard for WooCommerce Plugin Price Manipulation Payment Bypass via Unvalidated receiver_email No login needed ≤ 3.1.0 CVE-2026-17012 WPScan
6.5 Medium Cancel Order & Request Woocommerce Plugin Information Disclosure Unauthenticated Order Content Disclosure via Reorder AJAX Actions No login needed < 1.3.4.34 Fixed in 1.3.4.34 CVE-2026-18603 WPScan
7.5 High WPC Order Tip for WooCommerce Plugin wpc-order-tip Information Disclosure Unauthenticated Order Data Disclosure No login needed < 3.3.1 Fixed in 3.3.1 CVE-2026-18357 WPScan
5.9 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Price Manipulation Payment Bypass via Attacker-Supplied PayPal Capture Token No login needed < 2.0.1 Fixed in 2.0.1 CVE-2026-15211 WPScan
8.8 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Remote Code Execution Shop Manager+ Arbitrary Plugin Installation < 2.0.1 Fixed in 2.0.1 CVE-2026-15215 WPScan
4.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Information Disclosure Subscriber+ Subscription Detail Disclosure via IDOR < 2.0.1 Fixed in 2.0.1 CVE-2026-15214 WPScan
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Price Manipulation Unauthenticated Price Manipulation via Select Mode No login needed < 2.2.5 Fixed in 2.2.5 CVE-2026-16620 WPScan
5.3 Medium Event Booking Manager for WooCommerce (Pro) Plugin Price Manipulation Unauthenticated Payment Bypass via Client-Controlled Ticket Price No login needed < 5.0.3 Fixed in 5.0.3 CVE-2026-16067 WPScan
7.5 High CoCart Plugin cart-rest-api-for-woocommerce Price Manipulation Unauthenticated Arbitrary Price Manipulation No login needed < 4.9.0 Fixed in 4.9.0 CVE-2026-10524 WPScan
5.3 Medium Easy Booking Plugin woocommerce-easy-booking-system Other Unauthenticated Minimum Booking Duration Bypass No login needed < 3.5.0 Fixed in 3.5.0 CVE-2026-14831 WPScan
7.5 High Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Price Manipulation Unauthenticated Payment Bypass via Reuse of a Completed PayPal Order No login needed < 2.0.20 Fixed in 2.0.20 CVE-2026-13399 WPScan
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Unauthenticated Payment Confirmation via Unverified Inespay Callback No login needed < 7.0.2 Fixed in 7.0.2 CVE-2026-12584 WPScan
7.5 High Integrate PhonePe with WooCommerce Plugin Price Manipulation Unauthenticated Payment Bypass via Transaction ID Reuse No login needed ≤ 1.2.1 CVE-2026-10599 WPScan
7.1 High WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Cross-Site Scripting No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2026-66711 Patchstack
9.1 Critical CTX Feed Plugin webappick-product-feed-for-woocommerce Remote Code Execution ≤ 6.6.42 Fixed in 6.6.43 CVE-2026-66709 Patchstack
7.1 High Facebook for WooCommerce Plugin facebook-for-woocommerce Cross-Site Scripting No login needed ≤ 3.7.5 Fixed in 3.7.6 CVE-2026-66707 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only