WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium NextMove Lite - Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Cross-Site Scripting Thank You Page for WooCommerce <= 2.23.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'xlwcty_current_date' Shortcode ≤ 2.23.0 CVE-2026-0703 Wordfence
5.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Information Disclosure Unauthenticated Information Disclosure in Store Reviews REST API Endpoint No login needed ≤ 4.3.1 CVE-2026-3504 Wordfence
4.4 Medium Call for Price for WooCommerce Plugin woocommerce-call-for-price Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Call for Price' Label Settings ≤ 4.2.0 CVE-2026-6447 Wordfence
6.4 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attribute ≤ 4.2.8 CVE-2026-6725 Wordfence
6.5 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 2.0.0 Fixed in 2.0.1 CVE-2026-28040 Patchstack
4.3 Medium Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update via ni_order_export_action AJAX Action No login needed ≤ 3.1.6 CVE-2026-4140 Wordfence
6.1 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'crsearch' No login needed ≤ 5.101.0 CVE-2026-3355 Wordfence
5.9 Medium Mini Ajax Cart for WooCommerce Plugin mini-ajax-woo-cart Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2026-6370 Patchstack
6.5 Medium Germanized for WooCommerce Plugin woocommerce-germanized Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.20.5 CVE-2026-2582 Wordfence
4.4 Medium WholeSale Products Dynamic Pricing Management WooCommerce Plugin wholesale-products-dynamic-pricing-management-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.2 CVE-2026-4479 Wordfence
6.5 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Arbitrary Wishlist Renaming via IDOR No login needed < 4.13.0 Fixed in 4.13.0 CVE-2026-4432 WPScan
5.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Authentication Bypass Unauthenticated Authentication Bypass to Arbitrary Review Submission via 'key' Parameter No login needed ≤ 5.103.0 CVE-2026-4664 Wordfence
4.4 Medium Experto Dashboard for WooCommerce Plugin experto-custom-dashboard Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Navigation Font Size' Setting ≤ 1.0.4 CVE-2026-3574 Wordfence
6.5 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Product Data Modification No login needed ≤ 1.1.5 CVE-2026-1672 Wordfence
4.3 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Request Forgery Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net <= 1.1.5 - Cross-Site Request Forgery to Taxonomy Term Deletion No login needed ≤ 1.1.5 CVE-2026-1673 Wordfence
5.3 Medium Book Previewer for Woocommerce Plugin book-previewer-for-woocommerce Broken Access Control No login needed ≤ 1.0.6 CVE-2026-39668 Patchstack
5.3 Medium Product Price by Formula for WooCommerce Plugin product-price-by-formula-for-woocommerce Broken Access Control No login needed ≤ 2.5.6 CVE-2026-39662 Patchstack
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control No login needed ≤ 4.8.2 CVE-2026-39656 Patchstack
5.4 Medium GlobalPayments WooCommerce Plugin global-payments-woocommerce Server-Side Request Forgery No login needed ≤ 1.18.0 CVE-2026-39645 Patchstack
5.3 Medium Payment Plugins for PayPal WooCommerce Plugin pymntpl-paypal-woocommerce Broken Access Control No login needed ≤ 2.0.13 CVE-2026-39643 Patchstack
5.3 Medium Doofinder for WooCommerce Plugin doofinder-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.10.13 Fixed in 2.10.14 CVE-2026-39542 Patchstack
6.5 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Cross-Site Scripting ≤ 4.7.1.1 Fixed in 4.7.2 CVE-2026-39508 Patchstack
5.3 Medium FOX Plugin woocommerce-currency-switcher Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2026-39501 Patchstack
4.4 Medium Whole Enquiry Cart for WooCommerce Plugin whole-cart-enquiry Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'woowhole_success_msg' Parameter ≤ 1.2.1 CVE-2026-2838 Wordfence
6.4 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar ≤ 6.4.9 CVE-2026-3311 Wordfence
6.5 Medium WooPayments Plugin woocommerce-payments Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update via save_upe_appearance_ajax No login needed ≤ 10.5.1 CVE-2026-1710 Wordfence
6.5 Medium ViaBill – WooCommerce Plugin viabill-woocommerce Broken Access Control WooCommerce plugin <= 1.1.53 - Settings Change No login needed ≤ 1.1.53 CVE-2026-25469 Patchstack
6.5 Medium Product Slider for WooCommerce Plugin woocommerce-products-slider Broken Access Control ≤ 1.13.61 Fixed in 1.13.62 CVE-2026-25455 Patchstack
6.8 Medium Product File Upload for WooCommerce Plugin products-file-upload-for-woocommerce Arbitrary File Upload Arbitrary File Deletion No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2026-25328 Patchstack
6.5 Medium Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Broken Access Control ≤ 2.6.0 Fixed in 2.6.1 CVE-2026-23972 Patchstack
6.5 Medium Product Filter for WooCommerce by WBW Plugin woo-product-filter Broken Access Control Missing Authorization to Unauthenticated Filter Data Deletion via TRUNCATE TABLE No login needed ≤ 3.1.2 CVE-2026-3138 Wordfence
5.3 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Information Disclosure WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.2.12 CVE-2025-10734 Wordfence
5.3 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Information Disclosure WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information Exposure to Data Export No login needed ≤ 2.2.12 CVE-2025-10731 Wordfence
6.5 Medium ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More Plugin reviewx Broken Access Control WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.10 - Incorrect Authorization to Unauthenticated Information Exposure and Data Manipulation No login needed ≤ 2.2.10 CVE-2025-10736 Wordfence
6.5 Medium ilGhera Carta Docente for WooCommerce Plugin wc-carta-docente Path Traversal Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'cert' Parameter ≤ 1.5.0 CVE-2026-2421 Wordfence
5.3 Medium Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Subscription Cancellation No login needed ≤ 1.9.2 CVE-2026-1926 Wordfence
5.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control No login needed ≤ 7.11.3 Fixed in 7.11.3 CVE-2026-32586 Patchstack
5.3 Medium Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Broken Access Control No login needed ≤ 1.6.18 Fixed in 1.6.19 CVE-2026-32457 Patchstack
6.5 Medium Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2026-32450 Patchstack
6.5 Medium Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Request Forgery No login needed ≤ 13.5.2 Fixed in 13.5.2.1 CVE-2026-32443 Patchstack
5.4 Medium Gift Up Gift Cards for WordPress and WooCommerce Plugin gift-up Server-Side Request Forgery No login needed ≤ 3.1.7 Fixed in 3.1.8 CVE-2026-32412 Patchstack
5.3 Medium WBW Currency Switcher for WooCommerce Plugin woo-currency Broken Access Control No login needed ≤ 2.2.5 Fixed in 2.2.6 CVE-2026-32410 Patchstack
4.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2026-32407 Patchstack
4.3 Medium WPC Product Bundles for WooCommerce Plugin woo-product-bundle Broken Access Control ≤ 8.4.5 Fixed in 8.4.6 CVE-2026-32406 Patchstack
6.5 Medium TeraWallet – For WooCommerce Plugin woo-wallet Other For WooCommerce plugin <= 1.5.15 - Race Condition ≤ 1.5.15 Fixed in 1.5.16 CVE-2026-32398 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Elementor WooCommerce Builder Addons plugin <= 3.2.4 - Sensitive Data Exposure No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-32372 Patchstack
4.3 Medium Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free Broken Access Control ≤ 4.7.1 Fixed in 4.7.1.1 CVE-2026-31919 Patchstack
6.5 Medium WooCommerce Coming Soon Product with Countdown Plugin woo-coming-soon-product Cross-Site Scripting ≤ 5.0 CVE-2026-27354 Patchstack
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Paidy Order Manipulation No login needed ≤ 2.8.4 CVE-2026-1305 Wordfence
5.3 Medium WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Content Injection No login needed ≤ 1.4.4 CVE-2026-28132 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only