WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 201–250 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Product Specifications for Woocommerce Plugin product-specifications Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Attribute/Group Creation, Modification, and Deletion via 'dwps_modify_groups' and 'dwps_modify_attributes' AJAX Actions ≤ 0.8.9 CVE-2026-11364 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Information Disclosure via 'id' Parameter ≤ 5.0.4 CVE-2026-11987 Wordfence
4.3 Medium Bopo – WooCommerce Product Bundle Builder Plugin bopo-woo-product-bundle-builder Information Disclosure WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure ≤ 1.1.6 Fixed in 1.2.0 CVE-2026-57664 Patchstack
5.3 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2026-57660 Patchstack
4.3 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery No login needed ≤ 6.8.0 Fixed in 6.8.1 CVE-2026-57637 Patchstack
6.5 Medium FunnelKit Payment Gateway for Stripe WooCommerce Plugin funnelkit-stripe-woo-payment-gateway Cross-Site Request Forgery No login needed ≤ 1.14.0.3 Fixed in 1.14.0.4 CVE-2026-57635 Patchstack
5.4 Medium Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Broken Access Control ≤ 1.19.0 Fixed in 1.19.1 CVE-2026-57632 Patchstack
6.5 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2026-56048 Patchstack
5.3 Medium Printcart Web to Print Product Designer for WooCommerce Plugin Information Disclosure Unauthenticated Folder Content Disclosure via Path Traversal No login needed ≤ 2.4.8 CVE-2025-10268 WPScan
6.5 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control No login needed ≤ 33.0.18 Fixed in 34.0.0 CVE-2026-56050 Patchstack
5.4 Medium UPI QR Code Payment Gateway for WooCommerce Plugin upi-qr-code-payment-for-woocommerce Broken Access Control ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-56023 Patchstack
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2026-56013 Patchstack
5.3 Medium WhatsOrder Plugin whatsorder-instant-checkout-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs No login needed ≤ 1.0.1 CVE-2026-9612 Wordfence
6.4 Medium Avalon23 Products Filter for WooCommerce Plugin avalon23-products-filter-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.1.6 CVE-2026-8865 Wordfence
6.1 Medium Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_auctions_bids_list No login needed ≤ 2.4.5 CVE-2026-4110 WPScan
4.9 Medium Woosa Plugin integration-marktplaats-for-woocommerce Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter ≤ 2.0.5 CVE-2026-7547 Wordfence
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' Parameter No login needed ≤ 4.3.6 CVE-2026-12137 Wordfence
6.4 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.3.6 CVE-2026-12136 Wordfence
4.9 Medium Advanced Order Export For WooCommerce Plugin woo-order-export-lite SQL Injection Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter ≤ 4.0.10 CVE-2026-11360 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers ≤ 5.0.3 CVE-2026-10023 Wordfence
6.5 Medium WooCommerce Anti-Fraud Plugin woocommerce-anti-fraud Broken Access Control No login needed ≤ 7.2.6 Fixed in 7.2.7 CVE-2026-49072 Patchstack
6.5 Medium WooCommerce Dropshipping Plugin woocommerce-dropshipping Authentication Bypass Broken Authentication No login needed ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-49071 Patchstack
6.5 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter No login needed ≤ 10.7.0 CVE-2026-2381 Wordfence
6.5 Medium Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting ≤ 1.5.3.2 Fixed in 1.5.3.3 CVE-2026-39540 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Cross-Site Request Forgery No login needed ≤ 2.0.10 Fixed in 2.0.11 CVE-2022-47150 Patchstack
5.4 Medium Advanced AJAX Product Filters Plugin woocommerce-ajax-filters Broken Access Control Broken Access Control + CSRF ≤ 1.6.3.3 Fixed in 1.6.3.4 CVE-2022-45813 Patchstack
4.6 Medium YITH WooCommerce Product Slider Carousel Plugin yith-woocommerce-product-slider-carousel Cross-Site Request Forgery ≤ 1.16.0 Fixed in 1.16.1 CVE-2022-44630 Patchstack
4.3 Medium WpEvently Plugin mage-eventpress Cross-Site Request Forgery No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-32110 Patchstack
4.3 Medium FastPicker, an order picker and order management system (oms) for WooCommerce on steroids Plugin fastpicker Cross-Site Request Forgery Cross-Site Request Forgery via Settings Save No login needed ≤ 1.0.2 CVE-2026-8904 Wordfence
4.3 Medium JTL-Connector for WooCommerce Plugin woo-jtl-connector Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Modification via Multiple Functions ≤ 2.4.1 CVE-2026-9234 Wordfence
4.3 Medium PeachPay Plugin peachpay-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Unlink No login needed ≤ 1.120.46 CVE-2026-9618 Wordfence
4.3 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.6 - Authenticated (Subscriber+) Authorization Bypass via User-Controlled Key to 'wooc_order_user_roles' Parameter ≤ 1.4.6 CVE-2026-9241 Wordfence
4.3 Medium Account Manager for WooCommerce Plugin account-manager-woocommerce Broken Access Control ≤ 2.1.2 CVE-2022-41656 Patchstack
4.7 Medium Facebook for WooCommerce Plugin facebook-for-woocommerce Open Redirect No login needed ≤ 3.7.0 CVE-2026-49059 Patchstack
4.3 Medium Product Import Export for WooCommerce Plugin product-import-export-for-woo Broken Access Control ≤ 2.5.6 Fixed in 2.5.7 CVE-2026-48971 Patchstack
6.5 Medium Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-42725 Patchstack
5.4 Medium ShopLentor - WooCommerce Builder for Elementor & Gutenberg Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg <= 3.3.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Product Grid 'blockUniqId' Block Attribute ≤ 3.3.8 CVE-2026-6287 Wordfence
5.3 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2026-25426 Patchstack
6.5 Medium Stripe Payment Gateway for WooCommerce Plugin payment-gateway-stripe-and-woocommerce-integration Authentication Bypass Broken Authentication No login needed ≤ 5.0.7 Fixed in 5.0.8 CVE-2026-45217 Patchstack
4.9 Medium B2BKing Plugin b2bking-wholesale-for-woocommerce Broken Access Control < 5.2.10 Fixed in 5.2.10 CVE-2026-27346 Patchstack
4.3 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Broken Access Control ≤ 2.14.0 CVE-2026-24527 Patchstack
6.1 Medium GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'failed_orders' No login needed ≤ 1.4.0 CVE-2026-6417 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Lite Widget ≤ 6.4.11 CVE-2026-5243 Wordfence
5.5 Medium Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Cross-Site Scripting WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS 1.2.3 CVE-2020-37174 VulnCheck
5.5 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'text' Attribute ≤ 3.1.6 CVE-2025-14767 Wordfence
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.3.0 CVE-2025-14033 Wordfence
6.4 Medium Cost of Goods: Product Cost & Profit Calculator for WooCommerce Plugin cost-of-goods-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2026-6962 Wordfence
5.3 Medium Slek Gateway for WooCommerce Plugin slek-gateway-for-woocommerce Information Disclosure Unauthenticated Insufficiently Protected Credentials via Payment Redirect Form Hidden Fields No login needed ≤ 1.0 CVE-2026-7626 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 4.12.0 Fixed in 4.13.0 CVE-2026-27329 Patchstack
5.3 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Broken Access Control Missing Authorization to Unauthenticated PIX Payment QR Code Image Disclosure No login needed ≤ 8.7.11 CVE-2026-3208 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only