WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High APIExperts Square for WooCommerce Plugin woosquare SQL Injection ≤ 4.7.1 Fixed in 4.7.2 CVE-2026-45211 Patchstack
8.1 High WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion ≤ 6.7.25 CVE-2026-2554 Wordfence
7.5 High Payment Gateway for Redsys & WooCommerce Lite Plugin woo-redsys-gateway-light Other Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation No login needed ≤ 7.0.0 CVE-2026-5050 Wordfence
7.5 High Accept Cryptocurrencies with Plisio Plugin plisio-payment-gateway-for-woocommerce Price Manipulation Payment Bypass No login needed ≤ 2.0.5 CVE-2026-6372 Patchstack
8.6 High Product Filter for WooCommerce by WBW Plugin woo-product-filter SQL Injection Unauthenticated SQLi No login needed < 3.1.3 Fixed in 3.1.3 CVE-2026-3830 WPScan
7.5 High WCAPF – WooCommerce Ajax Product Filter Plugin wc-ajax-product-filter SQL Injection WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.3 CVE-2026-3396 Wordfence
7.1 High Extra Fees Plugin for WooCommerce Plugin woo-conditional-product-fees-for-checkout Cross-Site Request Forgery No login needed ≤ 4.3.3 CVE-2026-39671 Patchstack
7.6 High FOX Plugin woocommerce-currency-switcher SQL Injection ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39497 Patchstack
8.8 High Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed 13.4.6 – 13.5.2.1 CVE-2026-3499 Wordfence
8.1 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation ≤ 6.7.25 CVE-2026-4896 Wordfence
7.1 High Riode Plugin riode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ < 1.6.29 Fixed in 1.6.29 CVE-2026-32528 Patchstack
7.1 High Abandoned Cart Recovery for WooCommerce Plugin woo-abandoned-cart-recovery Cross-Site Scripting No login needed ≤ <= 1.1.10 Fixed in 1.1.11 CVE-2026-32526 Patchstack
8.6 High WooCommerce Support Ticket System Plugin woocommerce-support-ticket-system Arbitrary File Deletion No login needed ≤ < 18.5 Fixed in 18.5 CVE-2026-32522 Patchstack
7.7 High Comments Import & Export Plugin comments-import-export-woocommerce Broken Access Control ≤ <= 2.4.9 Fixed in 2.5.0 CVE-2026-32441 Patchstack
8.2 High Product Rearrange for WooCommerce Plugin products-rearrange-woocommerce Broken Access Control No login needed ≤ <= 1.2.2 CVE-2026-31921 Patchstack
8.8 High WooCommerce Infinite Scroll Plugin sb-woocommerce-infinite-scroll PHP Object Injection ≤ 1.6.2 CVE-2026-27045 Patchstack
7.5 High File Uploader for WooCommerce Plugin file-uploader-for-woocommerce Arbitrary File Upload Path Traversal No login needed ≤ 1.0.4 CVE-2026-25397 Patchstack
7.5 High Commerce Coinbase For WooCommerce Plugin commerce-coinbase-for-woocommerce Broken Access Control No login needed ≤ 1.6.6 CVE-2026-25396 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.9.0 Fixed in 6.0.0 CVE-2026-25317 Patchstack
7.5 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Authentication Bypass Bypass Vulnerability No login needed ≤ 1.8.10 Fixed in 1.9.0 CVE-2026-24372 Patchstack
7.5 High Helpdesk Support Ticket System for WooCommerce Plugin support-ticket-system-for-woocommerce Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2026-23977 Patchstack
7.2 High Product Feed for WooCommerce Plugin webtoffee-product-feed PHP Object Injection ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-22480 Patchstack
7.3 High ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Remote Code Execution WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution No login needed ≤ 2.2.12 CVE-2025-10679 Wordfence
7.5 High Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2026-25443 Patchstack
7.5 High WowStore – Store Builder & Product Blocks for WooCommerce Plugin product-blocks SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed ≤ 4.4.3 CVE-2026-2579 Wordfence
7.2 High Checkout Field Editor (Checkout Manager) for WooCommerce Plugin woo-checkout-field-editor-pro Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field No login needed ≤ 2.1.7 CVE-2026-3231 Wordfence
7.5 High WooCommerce Plugin woocommerce Cross-Site Request Forgery Arbitrary Admin User Creation via CSRF No login needed 5.4.0 – < 5.4.4, 5.5.0 – < 5.4.5, 5.6.0 – < 5.6.3, … Fixed in 5.4.4 CVE-2026-3589 WPScan
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.6 Fixed in 2.2.7 CVE-2026-27541 Patchstack
7.1 High Claue - Clean, Minimal Elementor WooCommerce Theme claue Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.7 CVE-2026-27376 Patchstack
7.5 High WooCommerce Order Details Plugin woocommerce-order-details Broken Access Control No login needed ≤ 3.1 CVE-2026-27374 Patchstack
8.8 High Woocommerce Category Banner Management Plugin banner-management-for-woocommerce PHP Object Injection ≤ 2.5.1 CVE-2026-22354 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.1 CVE-2026-22352 Patchstack
7.1 High RVCFDI para Woocommerce Plugin rvcfdi-para-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.1.8 CVE-2025-69386 Patchstack
7.1 High WooCommerce Bulk Product Editor Plugin woocommerce-quick-product-editor Broken Access Control ≤ 3.0 CVE-2025-69381 Patchstack
7.2 High Product Filter for WooCommerce Plugin prdctfltr Privilege Escalation ≤ 9.1.2 CVE-2025-69378 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.9 Fixed in 2.6.0 CVE-2025-69328 Patchstack
7.5 High Sync Master Sheet – Product Sync with Google Sheet for WooCommerce Plugin product-sync-master-sheet Broken Access Control Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-68834 Patchstack
7.5 High WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Local File Inclusion ≤ 5.0 Fixed in 5.1 CVE-2025-68552 Patchstack
7.1 High Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.1.1 Fixed in 8.1.2 CVE-2025-68501 Patchstack
7.3 High Plugin BlueX for WooCommerce Plugin bluex-for-woocommerce Broken Access Control No login needed ≤ 3.1.6 CVE-2025-68022 Patchstack
7.5 High Product Table and List Builder for WooCommerce Lite Plugin wc-product-table-lite SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed ≤ 4.6.2 CVE-2026-2232 Wordfence
7.5 High Sales Countdown Timer for WooCommerce and Plugin sctv-sales-countdown-timer Local File Inclusion ≤ 1.1.9 Fixed in 1.1.9 CVE-2026-27052 Patchstack
7.2 High YITH WooCommerce Compare Plugin yith-woocommerce-compare PHP Object Injection Deserialization of untrusted data ≤ 3.6.0 Fixed in 3.7.0 CVE-2026-22333 Patchstack
7.2 High CTX Feed – WooCommerce Product Feed Manager Plugin webappick-product-feed-for-woocommerce Broken Access Control WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation ≤ 6.6.11 CVE-2025-12975 Wordfence
8.8 High Advanced AJAX Product Filters Plugin woocommerce-ajax-filters PHP Object Injection Authenticated (Author+) PHP Object Injection via Live Composer Compatibility ≤ 3.1.9.6 CVE-2026-1426 Wordfence
7.2 High Product Addons for Woocommerce – Product Options with Custom Fields Plugin woo-custom-product-addons Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter ≤ 3.1.0 CVE-2026-2296 Wordfence
7.2 High Cart All In One For WooCommerce Plugin woo-cart-all-in-one Remote Code Execution Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting ≤ 1.1.21 CVE-2026-2019 Wordfence
7.7 High Zarinpal Gateway for WooCommerce Plugin zarinpal-woocommerce-payment-gateway Broken Access Control Improper Access Control to Payment Status Update No login needed ≤ 5.0.16 CVE-2026-2592 Wordfence
7.5 High Flexi Product Slider and Grid for WooCommerce Plugin flexi-product-slider-grid Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute ≤ 1.0.5 CVE-2026-1988 Wordfence
7.5 High BlueSnap Payment Gateway for WooCommerce Plugin bluesnap-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation No login needed ≤ 3.4.0 CVE-2026-0692 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only