WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via media[].href Parameter No login needed ≤ 5.97.0 CVE-2026-1316 Wordfence
7.2 High WCFM - WooCommerce Frontend Manager Plugin wc-frontend-manager Broken Access Control WooCommerce Frontend Manager <= 6.7.24 - Authenticated (Shop Manager+) Arbitrary Options Update ≤ 6.7.24 CVE-2026-0845 Wordfence
7.5 High VidShop – Shoppable Videos for WooCommerce Plugin vidshop-for-woocommerce SQL Injection Shoppable Videos for WooCommerce <= 1.1.4 - Unauthenticated Time-Based SQL Injection via 'fields' No login needed ≤ 1.1.4 CVE-2026-0702 Wordfence
8.5 High FooEvents for WooCommerce Plugin fooevents SQL Injection ≤ 1.20.4 Fixed in 1.20.5 CVE-2025-69045 Patchstack
8.1 High Bajaar - Highly Customizable WooCommerce Theme bajaar Local File Inclusion Highly Customizable WooCommerce WordPress Theme theme <= 2.1.0 - Local File Inclusion No login needed ≤ 2.1.0 CVE-2025-69004 Patchstack
7.1 High Omnichannel for WooCommerce Plugin codistoconnect Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-68041 Patchstack
7.1 High GLS Shipping for WooCommerce Plugin gls-shipping-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-68011 Patchstack
8.1 High Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy Plugin dokan-lite Broken Access Control Build Your Own Amazon, eBay, Etsy <= 4.2.4 - Insecure Direct Object Reference to PayPal Account Takeover and Sensitive Information Disclosure ≤ 4.2.4 CVE-2025-14977 Wordfence
7.5 High WooCommerce Square Plugin woocommerce-square Broken Access Control Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id No login needed 4.2.0 – < 4.2.3, 4.3.0 – < 4.3.2, 4.4.0 – < 4.4.2, … Fixed in 4.2.3 CVE-2025-13457 Wordfence
7.2 High Brevo for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.49 CVE-2025-14436 Wordfence
8.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-ei SQL Injection ≤ 5.4 CVE-2025-22713 Patchstack
7.5 High Reviewify Plugin review-for-discount Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary WooCommerce Coupon Creation No login needed ≤ 1.0.7 CVE-2025-14070 Wordfence
8.2 High iPaymu Payment Gateway for WooCommerce Plugin ipaymu-for-woocommerce Price Manipulation Missing Authentication to Unauthenticated Payment Bypass and Order Information Disclosure No login needed ≤ 2.0.2 CVE-2026-0656 Wordfence
7.1 High Woocommerce Sales Funnel Builder Plugin woosales Cross-Site Scripting Reflected Cross Site Scripting (XSS) vulnerability in AA-Team WordPress plugins No login needed ≤ 1.1, ≤ 1.2 CVE-2025-30631 Patchstack
7.5 High Knowband Mobile App Builder for wooCommerce Plugin Broken Access Control Unauthenticated Arbitrary User Deletion No login needed < 3.0.0 Fixed in 3.0.0 CVE-2025-13029 WPScan
7.2 High Lucky Wheel for WooCommerce – Spin a Sale Plugin woo-lucky-wheel Remote Code Execution Spin a Sale <= 1.1.13 - Authenticated (Administrator+) PHP Code Injection via Conditional Tags ≤ 1.1.13 CVE-2025-14509 Wordfence
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
8.5 High Brands for WooCommerce Plugin brands-for-woocommerce SQL Injection ≤ 3.8.6.3 Fixed in 3.8.6.4 CVE-2025-68519 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-64266 Patchstack
7.5 High WooCommerce Recover Abandoned Cart Plugin rac Broken Access Control Arbitrary Content Deletion No login needed ≤ 24.6.0 Fixed in 24.7.0 CVE-2025-64222 Patchstack
8.8 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce PHP Object Injection Deserialization of untrusted data ≤ 6.5.0 Fixed in 6.5.1 CVE-2025-60083 Patchstack
8.1 High Riode Plugin riode Local File Inclusion No login needed ≤ 1.6.23 CVE-2025-60071 Patchstack
7.2 High Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Privilege Escalation ≤ 1.2 Fixed in 1.3 CVE-2025-49379 Patchstack
7.5 High افزونه پیامک ووکامرس فوق حرفه ای (جدید) payamito sms woocommerce Plugin payamito-sms-woocommerce SQL Injection Unauthenticated Time-Based Blind SQL Injection No login needed ≤ 1.3.5 CVE-2025-13077 Wordfence
7.5 High FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder SQL Injection Funnel Builder for WooCommerce Checkout <= 3.13.1.5 - Unauthenticated SQL Injection No login needed ≤ 3.13.1.5 CVE-2025-14169 Wordfence
7.5 High Hippoo Mobile App for WooCommerce Plugin hippoo Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 1.7.1 CVE-2025-13339 Wordfence
7.2 High Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration - Powered by Codisto Plugin codistoconnect Cross-Site Scripting Powered by Codisto <= 1.3.65 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.65 CVE-2025-11727 Wordfence
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.5.17 CVE-2025-13387 Wordfence
7.5 High SKT PayPal for WooCommerce Plugin skt-paypal-for-woocommerce Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.4 CVE-2025-7820 Wordfence
8.8 High Vitepos – Point of Sale (POS) for WooCommerce Plugin vitepos-lite Arbitrary File Upload Point of Sale (POS) for WooCommerce <= 3.3.0 - Authenticated (Subscriber+) Arbitrary File Upload to Remote Code Execution ≤ 3.3.0 CVE-2025-13156 Wordfence
7.5 High Live sales notification for WooCommerce Plugin Broken Access Control Missing Authorization to Unauthenticated Customer Data Exposure No login needed ≤ 2.3.39 CVE-2025-12955 Wordfence
7.2 High Checkout Files Upload for WooCommerce Plugin checkout-files-upload-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.2.1 CVE-2025-4212 Wordfence
8.8 High Category and Product Woocommerce Tabs Plugin category-and-product-woocommerce-tabs Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2025-13088 Wordfence
7.1 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.1.10 CVE-2025-12411 Wordfence
7.5 High Payment Plugins Braintree For WooCommerce Plugin woo-payment-gateway Broken Access Control Missing Authorization to Payment Token Exposure and Transaction Fraud No login needed ≤ 3.2.78 CVE-2025-12903 Wordfence
7.1 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting No login needed ≤ 7.2.5 Fixed in 7.2.6 CVE-2025-64196 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Local File Inclusion ≤ 3.1.3 Fixed in 3.1.3 CVE-2025-60248 Patchstack
7.5 High WooCommerce Store Toolkit Plugin woocommerce-store-toolkit Local File Inclusion No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-60204 Patchstack
7.5 High Store Exporter Plugin woocommerce-exporter Local File Inclusion No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2025-60203 Patchstack
7.5 High Premmerce Product Search for WooCommerce Plugin premmerce-search Local File Inclusion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-60194 Patchstack
7.5 High Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60192 Patchstack
7.5 High Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Local File Inclusion No login needed ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-60191 Patchstack
7.5 High PoloPag – Pix Automático para Woocommerce Plugin wc-polo-payments Local File Inclusion Pix Automático para Woocommerce plugin <= 2.0.9 - Local File Inclusion No login needed ≤ 2.0.9 Fixed in 3.0.0 CVE-2025-60189 Patchstack
7.1 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Cross-Site Scripting No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-49904 Patchstack
7.5 High Crypto Payment Gateway with Payeer for WooCommerce Plugin crypto-payment-gateway-with-payeer-for-woocommerce Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.0.3 CVE-2025-11890 Wordfence
7.5 High WPC Name Your Price for WooCommerce Plugin wpc-name-your-price Broken Access Control Unauthenticated Price Alteration No login needed ≤ 2.1.9 CVE-2025-12115 Wordfence
8.6 High WooCommerce Designer Pro Theme Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 1.9.28 CVE-2025-10897 Wordfence
7.5 High HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.7.1 - Unauthenticated SQL Injection via `phrase` Parameter No login needed ≤ 1.3.7.1 CVE-2025-11735 Wordfence
7.1 High NikanWP WooCommerce Reporting Plugin wc-reports-lite Cross-Site Request Forgery No login needed ≤ 1.0.0 Fixed in 3.0.0 CVE-2025-62957 Patchstack
8.8 High Simple Registration for WooCommerce Plugin woocommerce-simple-registration Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Role Request Approval No login needed ≤ 1.5.8 CVE-2025-12095 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only