WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.1.4 CVE-2025-10861 Wordfence
7.6 High Advanced Coupons for WooCommerce Coupons Plugin advanced-coupons-for-woocommerce-free SQL Injection ≤ 4.6.8 Fixed in 4.6.9 CVE-2025-62015 Patchstack
8.8 High Product Table For WooCommerce Plugin product-table-for-woocommerce PHP Object Injection ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-62008 Patchstack
7.1 High SUMO Memberships for WooCommerce Plugin sumomemberships Cross-Site Request Forgery No login needed ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-62005 Patchstack
8.8 High SUMO Memberships for WooCommerce Plugin sumomemberships Privilege Escalation ≤ 7.8.0 Fixed in 7.9.0 CVE-2025-60222 Patchstack
8.8 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Privilege Escalation Custom Signup Fields plugin <= 3.2.3 - Privilege Escalation ≤ 3.2.3 CVE-2025-60211 Patchstack
7.1 High Easy Woocommerce Customizer Plugin easy-woocommerce-customizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-59006 Patchstack
7.1 High WhatsApp Chat for WordPress and WooCommerce Plugin tw-whatsapp-chat-rotator Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-53422 Patchstack
7.1 High Woocommerce Envato Affiliates Plugin wooenvato Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-53297 Patchstack
7.1 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Cross-Site Scripting No login needed ≤ 2.20.0 CVE-2025-52736 Patchstack
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting No login needed ≤ 1.8.6 CVE-2025-49958 Patchstack
7.1 High WooCommerce Registration Fields Plugin - Custom Signup Fields Plugin extendons-registration-fields Cross-Site Scripting Custom Signup Fields plugin <= 3.2.3 - Cross Site Scripting (XSS) No login needed ≤ 3.2.3 CVE-2025-49947 Patchstack
7.2 High Wholesale Suite Plugin woocommerce-wholesale-prices Privilege Escalation ≤ 2.2.4.2 Fixed in 2.2.5 CVE-2025-49924 Patchstack
8.6 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.2.23 Fixed in 4.2.24 CVE-2025-49916 Patchstack
7.1 High WooCommerce Vehicle Parts Finder Plugin woo-vehicle-parts-finder Cross-Site Scripting No login needed ≤ 3.7 Fixed in 3.8 CVE-2025-49911 Patchstack
7.5 High PPOM – Product Addons & Custom Fields for WooCommerce Plugin woocommerce-product-addon SQL Injection Product Addons & Custom Fields for WooCommerce <= 33.0.15 - Unauthenticated SQL Injection No login needed ≤ 33.0.15 CVE-2025-11691 Wordfence
8.8 High XStore | Multipurpose WooCommerce Theme Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 9.5.4 CVE-2025-11746 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
7.5 High OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Path Traversal Unauthenticated Arbitrary File Read No login needed < 14 Fixed in 14 CVE-2025-10162 WPScan
7.1 High GST for WooCommerce Plugin gst-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-60173 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High Flexible PDF Invoices for WooCommerce & Plugin flexible-invoices Cross-Site Request Forgery No login needed ≤ 6.0.13 Fixed in 6.0.14 CVE-2025-57977 Patchstack
8.5 High Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection ≤ 3.6.2 Fixed in 3.6.3 CVE-2025-58686 Patchstack
7.1 High WooCommerce Booking Bundle Hours Plugin woo-booking-bundle-hours Cross-Site Request Forgery No login needed ≤ 0.7.4 Fixed in 0.7.5 CVE-2025-58991 Patchstack
7.1 High WooCommerce Photo Reviews Plugin woocommerce-photo-reviews Cross-Site Scripting No login needed ≤ 1.3.13 CVE-2025-47570 Patchstack
7.5 High WooCommerce Payment Gateway for Saferpay Plugin woocommerce-payment-gateway-for-saferpay Path Traversal No login needed ≤ 0.4.9 CVE-2025-48317 Patchstack
7.6 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.12 Fixed in 3.0.13 CVE-2025-58788 Patchstack
8.1 High Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Unauthenticated Double Extension Arbitrary File Upload No login needed ≤ 7.2.4 CVE-2024-13342 Wordfence
7.7 High WooCommerce csv import export Plugin extendons-eo-wooimport-export Arbitrary File Deletion ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-54029 Patchstack
7.5 High Maya Business Plugin paymaya-checkout-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-53208 Patchstack
8.1 High WooCommerce OTP Login With Phone Number, OTP Verification Plugin login-with-phone-number Authentication Bypass No login needed ≤ 1.8.47 CVE-2025-8342 Wordfence
7.5 High Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts No login needed ≤ 1.5.4 CVE-2025-6025 Wordfence
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Request Forgery No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-53575 Patchstack
7.2 High Kadence WooCommerce Email Designer Plugin kadence-woocommerce-email-designer Privilege Escalation ≤ 1.5.16 Fixed in 1.5.17 CVE-2025-54697 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.9.0 Fixed in 3.0.0 CVE-2025-54692 Patchstack
7.1 High WooCommerce Shop Page Builder Plugin dzs-wootable Cross-Site Scripting No login needed ≤ 2.27.7 CVE-2025-28999 Patchstack
8.5 High WooCommerce Point Of Sale (POS) Plugin woo-point-of-salepos SQL Injection ≤ 1.4 CVE-2025-52820 Patchstack
8.1 High WooCommerce Purchase Orders Plugin wc-purchase-orders Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.0.2 CVE-2025-5391 Wordfence
8.8 High B1.lt for WooCommerce Plugin b1-accounting Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Injection ≤ 2.2.57 CVE-2025-6718 Wordfence
7.5 High Easy Video Player Wordpress & WooCommerce Plugin fwdevp Path Traversal Arbitrary File Download No login needed ≤ 10.0 CVE-2025-28955 Patchstack
8.5 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection Subscriber+ SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-47645 Patchstack
7.1 High PW WooCommerce On Sale! Plugin pw-woocommerce-on-sale Broken Access Control ≤ 1.39 Fixed in 1.40 CVE-2025-49888 Patchstack
8.2 High Counter live visitors for WooCommerce Plugin counter-visitor-for-woocommerce Arbitrary File Deletion Unauthenticated Arbitrary File Deletion in wcvisitor_get_block No login needed ≤ 1.3.6 CVE-2025-7359 Wordfence
8.5 High Printcart Web to Print Product Designer for WooCommerce Plugin printcart-integration SQL Injection ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-24780 Patchstack
7.2 High Amazon Products to WooCommerce Plugin import-products-to-wc Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 1.2.7 CVE-2025-5817 Wordfence
7.5 High WPB Category Slider for WooCommerce Plugin wpb-woocommerce-category-slider Local File Inclusion ≤ 1.71 CVE-2025-53281 Patchstack
7.1 High Additional Order Filters for WooCommerce Plugin additional-order-filters-for-woocommerce Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.22 Fixed in 1.23 CVE-2025-53271 Patchstack
7.1 High WPCRM - CRM for Contact form CF7 & WooCommerce Plugin wpcrm Cross-Site Scripting CRM for Contact form CF7 & WooCommerce plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 CVE-2025-24774 Patchstack
8.1 High MBStore - Digital WooCommerce Plugin mbstore Local File Inclusion Digital WooCommerce WordPress Theme <= 2.3 - Local File Inclusion No login needed ≤ 2.3 CVE-2025-28947 Patchstack
7.1 High Woocommerce Line Notify Plugin woo-line-notify Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-30972 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only