WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 201–250 of 675 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.5 High | APIExperts Square for WooCommerce | SQL Injection |
≤ 4.7.1 Fixed in 4.7.2 |
CVE-2026-45211 |
Patchstack | |
| 8.1 High | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.25 - Authenticated (Vendor+) Insecure Direct Object Reference to Arbitrary User Deletion |
≤ 6.7.25 |
CVE-2026-2554 |
Wordfence | |
| 7.5 High | Payment Gateway for Redsys & WooCommerce Lite | Other Improper Verification of Cryptographic Signature to Unauthenticated Payment Status Manipulation No login needed |
≤ 7.0.0 |
CVE-2026-5050 |
Wordfence | |
| 7.5 High | Accept Cryptocurrencies with Plisio | Price Manipulation Payment Bypass No login needed |
≤ 2.0.5 |
CVE-2026-6372 |
Patchstack | |
| 8.6 High | Product Filter for WooCommerce by WBW | SQL Injection Unauthenticated SQLi No login needed |
< 3.1.3 Fixed in 3.1.3 |
CVE-2026-3830 |
WPScan | |
| 7.5 High | WCAPF – WooCommerce Ajax Product Filter | SQL Injection WooCommerce Ajax Product Filter <= 4.2.3 - Unauthenticated Time-Based SQL Injection No login needed |
≤ 4.2.3 |
CVE-2026-3396 |
Wordfence | |
| 7.1 High | Extra Fees Plugin for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 4.3.3 |
CVE-2026-39671 |
Patchstack | |
| 7.6 High | FOX | SQL Injection |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2026-39497 |
Patchstack | |
| 8.8 High | Product Feed PRO for WooCommerce by AdTribes – Product Feeds for WooCommerce | Cross-Site Request Forgery Product Feeds for WooCommerce 13.4.6 - 13.5.2.1 - Cross-Site Request Forgery to Multiple Administrative Actions No login needed |
13.4.6 – 13.5.2.1 |
CVE-2026-3499 |
Wordfence | |
| 8.1 High | WCFM - WooCommerce Frontend Manager | Broken Access Control WooCommerce Frontend Manager <= 6.7.25 - Insecure Direct Object References to Autenticated (Vendor+) Arbitrary Post/Product Manipulation |
≤ 6.7.25 |
CVE-2026-4896 |
Wordfence | |
| 7.1 High | Riode | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ < 1.6.29 Fixed in 1.6.29 |
CVE-2026-32528 |
Patchstack | |
| 7.1 High | Abandoned Cart Recovery for WooCommerce | Cross-Site Scripting No login needed |
≤ <= 1.1.10 Fixed in 1.1.11 |
CVE-2026-32526 |
Patchstack | |
| 8.6 High | WooCommerce Support Ticket System | Arbitrary File Deletion No login needed |
≤ < 18.5 Fixed in 18.5 |
CVE-2026-32522 |
Patchstack | |
| 7.7 High | Comments Import & Export | Broken Access Control |
≤ <= 2.4.9 Fixed in 2.5.0 |
CVE-2026-32441 |
Patchstack | |
| 8.2 High | Product Rearrange for WooCommerce | Broken Access Control No login needed |
≤ <= 1.2.2 |
CVE-2026-31921 |
Patchstack | |
| 8.8 High | WooCommerce Infinite Scroll | PHP Object Injection |
≤ 1.6.2 |
CVE-2026-27045 |
Patchstack | |
| 7.5 High | File Uploader for WooCommerce | Arbitrary File Upload Path Traversal No login needed |
≤ 1.0.4 |
CVE-2026-25397 |
Patchstack | |
| 7.5 High | Commerce Coinbase For WooCommerce | Broken Access Control No login needed |
≤ 1.6.6 |
CVE-2026-25396 |
Patchstack | |
| 7.5 High | Print Invoice & Delivery Notes for WooCommerce | Broken Access Control No login needed |
≤ 5.9.0 Fixed in 6.0.0 |
CVE-2026-25317 |
Patchstack | |
| 7.5 High | Subscriptions for WooCommerce | Authentication Bypass Bypass Vulnerability No login needed |
≤ 1.8.10 Fixed in 1.9.0 |
CVE-2026-24372 |
Patchstack | |
| 7.5 High | Helpdesk Support Ticket System for WooCommerce | Broken Access Control No login needed |
≤ 2.1.2 Fixed in 2.1.3 |
CVE-2026-23977 |
Patchstack | |
| 7.2 High | Product Feed for WooCommerce | PHP Object Injection |
≤ 2.3.3 Fixed in 2.3.4 |
CVE-2026-22480 |
Patchstack | |
| 7.3 High | ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More | Remote Code Execution WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Limited Remote Code Execution No login needed |
≤ 2.2.12 |
CVE-2025-10679 |
Wordfence | |
| 7.5 High | Fraud Prevention For Woocommerce | Broken Access Control Arbitrary Content Deletion No login needed |
≤ 2.3.3 Fixed in 2.3.4 |
CVE-2026-25443 |
Patchstack | |
| 7.5 High | WowStore – Store Builder & Product Blocks for WooCommerce | SQL Injection Store Builder & Product Blocks for WooCommerce <= 4.4.3 - Unauthenticated SQL Injection via 'search' Parameter No login needed |
≤ 4.4.3 |
CVE-2026-2579 |
Wordfence | |
| 7.2 High | Checkout Field Editor (Checkout Manager) for WooCommerce | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Block Checkout Custom Radio Field No login needed |
≤ 2.1.7 |
CVE-2026-3231 |
Wordfence | |
| 7.5 High | WooCommerce | Cross-Site Request Forgery Arbitrary Admin User Creation via CSRF No login needed |
5.4.0 – < 5.4.4, 5.5.0 – < 5.4.5, 5.6.0 – < 5.6.3, … Fixed in 5.4.4 |
CVE-2026-3589 |
WPScan | |
| 7.2 High | Wholesale Suite | Privilege Escalation |
≤ 2.2.6 Fixed in 2.2.7 |
CVE-2026-27541 |
Patchstack | |
| 7.1 High | Claue - Clean, Minimal Elementor WooCommerce | Cross-Site Scripting Clean, Minimal Elementor WooCommerce Theme theme <= 2.2.7 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.7 |
CVE-2026-27376 |
Patchstack | |
| 7.5 High | WooCommerce Order Details | Broken Access Control No login needed |
≤ 3.1 |
CVE-2026-27374 |
Patchstack | |
| 8.8 High | Woocommerce Category Banner Management | PHP Object Injection |
≤ 2.5.1 |
CVE-2026-22354 |
Patchstack | |
| 7.1 High | Persian Woocommerce SMS | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 7.1.1 |
CVE-2026-22352 |
Patchstack | |
| 7.1 High | RVCFDI para Woocommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 8.1.8 |
CVE-2025-69386 |
Patchstack | |
| 7.1 High | WooCommerce Bulk Product Editor | Broken Access Control |
≤ 3.0 |
CVE-2025-69381 |
Patchstack | |
| 7.2 High | Product Filter for WooCommerce | Privilege Escalation |
≤ 9.1.2 |
CVE-2025-69378 |
Patchstack | |
| 8.8 High | Booking and Rental Manager | PHP Object Injection |
≤ 2.5.9 Fixed in 2.6.0 |
CVE-2025-69328 |
Patchstack | |
| 7.5 High | Sync Master Sheet – Product Sync with Google Sheet for WooCommerce | Broken Access Control Product Sync with Google Sheet for WooCommerce plugin <= 1.1.3 - Broken Access Control No login needed |
≤ 1.1.3 Fixed in 1.1.4 |
CVE-2025-68834 |
Patchstack | |
| 7.5 High | WooCommerce Coming Soon Product with Countdown | Local File Inclusion |
≤ 5.0 Fixed in 5.1 |
CVE-2025-68552 |
Patchstack | |
| 7.1 High | Mollie Payments for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 8.1.1 Fixed in 8.1.2 |
CVE-2025-68501 |
Patchstack | |
| 7.3 High | Plugin BlueX for WooCommerce | Broken Access Control No login needed |
≤ 3.1.6 |
CVE-2025-68022 |
Patchstack | |
| 7.5 High | Product Table and List Builder for WooCommerce Lite | SQL Injection Unauthenticated Time-Based SQL Injection via 'search' Parameter No login needed |
≤ 4.6.2 |
CVE-2026-2232 |
Wordfence | |
| 7.5 High | Sales Countdown Timer for WooCommerce and | Local File Inclusion |
≤ 1.1.9 Fixed in 1.1.9 |
CVE-2026-27052 |
Patchstack | |
| 7.2 High | YITH WooCommerce Compare | PHP Object Injection Deserialization of untrusted data |
≤ 3.6.0 Fixed in 3.7.0 |
CVE-2026-22333 |
Patchstack | |
| 7.2 High | CTX Feed – WooCommerce Product Feed Manager | Broken Access Control WooCommerce Product Feed Manager <= 6.6.11 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation |
≤ 6.6.11 |
CVE-2025-12975 |
Wordfence | |
| 8.8 High | Advanced AJAX Product Filters | PHP Object Injection Authenticated (Author+) PHP Object Injection via Live Composer Compatibility |
≤ 3.1.9.6 |
CVE-2026-1426 |
Wordfence | |
| 7.2 High | Product Addons for Woocommerce – Product Options with Custom Fields | Remote Code Execution Product Options with Custom Fields <= 3.1.0 - Authenticated (Shop Manager+) Code Injection via Conditional Logic 'operator' Parameter |
≤ 3.1.0 |
CVE-2026-2296 |
Wordfence | |
| 7.2 High | Cart All In One For WooCommerce | Remote Code Execution Authenticated (Administrator+) Code Injection via 'sc_assign_page' Setting |
≤ 1.1.21 |
CVE-2026-2019 |
Wordfence | |
| 7.7 High | Zarinpal Gateway for WooCommerce | Broken Access Control Improper Access Control to Payment Status Update No login needed |
≤ 5.0.16 |
CVE-2026-2592 |
Wordfence | |
| 7.5 High | Flexi Product Slider and Grid for WooCommerce | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' Shortcode Attribute |
≤ 1.0.5 |
CVE-2026-1988 |
Wordfence | |
| 7.5 High | BlueSnap Payment Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Manipulation No login needed |
≤ 3.4.0 |
CVE-2026-0692 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.