WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 301–350 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 7 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Unauthenticated Email Relay No login needed ≤ 6.4.7 CVE-2026-2385 Wordfence
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.9.0 CVE-2026-24946 Patchstack
6.5 Medium Cartify - WooCommerce Gutenberg Theme cartify Broken Access Control WooCommerce Gutenberg WordPress Theme theme <= 1.3 - Arbitrary Content Deletion ≤ 1.3 CVE-2025-69385 Patchstack
5.3 Medium Primer MyData for Woocommerce Plugin primer-mydata Path Traversal No login needed ≤ 4.2.8 Fixed in 4.2.9 CVE-2025-69325 Patchstack
6.5 Medium Addonify Floating Cart For WooCommerce Plugin addonify-floating-cart Broken Access Control No login needed ≤ 1.2.17 CVE-2025-68025 Patchstack
6.5 Medium Addonify – WooCommerce Wishlist Plugin addonify-wishlist Broken Access Control WooCommerce Wishlist plugin <= 2.0.15 - Settings Change No login needed ≤ 2.0.15 Fixed in 2.0.16 CVE-2025-68024 Patchstack
6.5 Medium Addonify – Compare Products For WooCommerce Plugin addonify-compare-products Broken Access Control Compare Products For WooCommerce plugin <= 1.1.17 - Settings Change No login needed ≤ 1.1.17 Fixed in 1.1.18 CVE-2025-68023 Patchstack
6.5 Medium UPI QR Code Payment Gateway for WooCommerce Plugin upi-qr-code-payment-for-woocommerce Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.6.1 CVE-2025-67969 Patchstack
4.3 Medium YayMail Plugin yaymail Broken Access Control WooCommerce Email Customizer plugin <= 4.3.2 - Broken Access Control ≤ 4.3.2 Fixed in 4.3.3 CVE-2026-27327 Patchstack
4.3 Medium WiserReview Product Reviews for WooCommerce Plugin wiser-review Broken Access Control ≤ 2.9 Fixed in 3.0 CVE-2026-25318 Patchstack
5.3 Medium Alma Plugin alma-gateway-for-woocommerce Broken Access Control No login needed ≤ 5.16.1 Fixed in 5.16.2 CVE-2026-24999 Patchstack
5.3 Medium Ultimate Gift Cards For WooCommerce Plugin woo-gift-cards-lite Broken Access Control No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2026-24375 Patchstack
4.3 Medium Whatsiplus Scheduled Notification for Woocommerce Plugin whatsiplus-scheduled-notification-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to 'wsnfw_save_users_settings' AJAX Action No login needed ≤ 1.0.1 CVE-2026-1455 Wordfence
5.3 Medium Mega Store Woocommerce Theme mega-store-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Page Creation and Settings Change No login needed ≤ 5.9 CVE-2025-14357 Wordfence
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 7.8.5 CVE-2025-13930 Wordfence
5.3 Medium Razorpay for WooCommerce Plugin woo-razorpay Broken Access Control Missing Authentication to Unauthenticated Order Modification No login needed ≤ 4.7.8 CVE-2025-14294 Wordfence
5.3 Medium Checkout Field Manager (Checkout Manager) for WooCommerce Plugin woocommerce-checkout-manager Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 7.8.1 CVE-2025-12500 Wordfence
6.4 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.2.11 CVE-2025-12375 Wordfence
4.3 Medium The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Broken Access Control Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.4.7 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' ≤ 6.4.7 CVE-2026-2386 Wordfence
4.3 Medium PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control Missing Authorization to Authenticated (Subscriber+) Peppol Identifier Modification ≤ 5.6.0 CVE-2026-1906 Wordfence
4.3 Medium EmailKit – Email Customizer for WooCommerce & WP Plugin emailkit Broken Access Control Email Customizer for WooCommerce & WP <= 1.6.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Title Modification ≤ 1.6.2 CVE-2026-1925 Wordfence
4.3 Medium Order Splitter for WooCommerce Plugin wc-order-splitter Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Information Exposure ≤ 5.3.5 CVE-2025-12075 Wordfence
5.8 Medium Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) Plugin Broken Access Control Uni CPO (Premium) <= 4.9.60 - Missing Authorization to Unauthenticated Arbitrary Attachment and Dropbox File Deletion No login needed ≤ 4.9.60 CVE-2025-13391 Wordfence
4.3 Medium Invoct – PDF Invoices & Billing for WooCommerce Plugin kirilkirkov-pdf-invoice-manager Broken Access Control PDF Invoices & Billing for WooCommerce <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Information Exposure ≤ 1.6 CVE-2026-1748 Wordfence
6.5 Medium OpenPix Plugin openpix-for-woocommerce Broken Access Control Subscriber+ Payment Gateway Settings Reset ≤ 2.13.3 CVE-2025-15400 WPScan
4.3 Medium WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Plugin wc-multivendor-membership Broken Access Control WooCommerce Memberships for Multivendor Marketplace <= 2.11.8 - Insecure Direct Object Reference to Update Membership Payment ≤ 2.11.8 CVE-2025-15147 Wordfence
4.9 Medium SIBS - WooCommerce Plugin sibs-woocommerce SQL Injection WooCommerce <= 2.2.0 - Authenticated (Admin+) SQL Injection via 'referencedId' Parameter ≤ 2.2.0 CVE-2026-1370 Wordfence
5.3 Medium Fortis for WooCommerce Plugin fortis-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Update to Paid via 'wc-api' Endpoint No login needed ≤ 1.2.0 CVE-2026-0679 Wordfence
6.5 Medium MyRewards – Loyalty Points and Rewards for WooCommerce Plugin woorewards Broken Access Control Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification ≤ 5.6.1 CVE-2025-15260 Wordfence
5.3 Medium Chapa Payment Gateway Plugin for WooCommerce Plugin chapa-payment-gateway-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.3 CVE-2025-15482 Wordfence
5.3 Medium Advanced WooCommerce Product Sales Reporting Plugin webd-woocommerce-advanced-reporting-statistics Information Disclosure Sensitive Data Exposure No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2026-24992 Patchstack
4.4 Medium Order Minimum/Maximum Amount Limits for WooCommerce Plugin order-minimum-amount-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via Hide Add to Cart Content Fields ≤ 4.6.8 CVE-2026-1381 Wordfence
5.3 Medium Link Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Partial Payment Creation/Cancellation No login needed ≤ 2.8.0 CVE-2025-14971 Wordfence
5.3 Medium Wizit Gateway for WooCommerce Plugin wizit-gateway-for-woocommerce Broken Access Control Missing Authentication to Unauthenticated Arbitrary Order Cancellation No login needed ≤ 1.3.1 CVE-2025-14843 Wordfence
5.3 Medium File Uploads Addon for WooCommerce Plugin woo-addon-uploads Arbitrary File Upload Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2026-24625 Patchstack
5.3 Medium Bayarcash WooCommerce Plugin bayarcash-wc Broken Access Control No login needed ≤ 4.3.13 Fixed in 4.3.14 CVE-2026-24606 Patchstack
6.5 Medium Hyyan WooCommerce Polylang Integration Plugin woo-poly-integration Broken Access Control ≤ 1.5.0 CVE-2026-24585 Patchstack
5.3 Medium SumUp Payment Gateway For WooCommerce Plugin sumup-payment-gateway-for-woocommerce Broken Access Control No login needed ≤ 2.7.9 Fixed in 2.7.10 CVE-2026-24583 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control ≤ 2.9.5 Fixed in 2.9.6 CVE-2026-24581 Patchstack
5.3 Medium Ryviu – Product Reviews for WooCommerce Plugin ryviu Broken Access Control Product Reviews for WooCommerce plugin <= 3.1.26 - Broken Access Control No login needed ≤ 3.1.26 CVE-2026-24562 Patchstack
4.3 Medium Fraud Prevention For Woocommerce Plugin woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers Information Disclosure Sensitive Data Exposure ≤ 2.3.2 Fixed in 2.3.3 CVE-2026-24553 Patchstack
6.5 Medium Email Inquiry & Cart Options for WooCommerce Plugin woocommerce-email-inquiry-cart-options Cross-Site Scripting ≤ 3.5.0 CVE-2026-24526 Patchstack
5.3 Medium YITH WooCommerce Request A Quote Plugin yith-woocommerce-request-a-quote Broken Access Control No login needed ≤ 2.46.0 Fixed in 2.46.1 CVE-2026-24366 Patchstack
5.4 Medium Stock Manager for WooCommerce Plugin woocommerce-stock-manager Cross-Site Request Forgery No login needed ≤ 3.6.0 Fixed in 3.6.0 CVE-2026-24365 Patchstack
5.3 Medium CTX Feed Plugin webappick-product-feed-for-woocommerce Broken Access Control No login needed ≤ 6.6.18 Fixed in 6.6.19 CVE-2026-22461 Patchstack
6.5 Medium onepay Payment Gateway For WooCommerce Plugin onepay-payment-gateway-for-woocommerce Broken Access Control Other Vulnerability Type No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-68016 Patchstack
6.5 Medium Payment Gateway Authorize.Net CIM for WooCommerce Plugin authnet-cim-for-woo Broken Access Control Arbitrary Content Deletion ≤ 2.1.2 CVE-2025-68013 Patchstack
6.5 Medium TaxCloud for WooCommerce Plugin simple-sales-tax Broken Access Control No login needed ≤ 8.3.8 Fixed in 8.4.0 CVE-2025-67958 Patchstack
5.3 Medium PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net) Plugin peachpay-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 1.119.8 CVE-2025-14978 Wordfence
5.3 Medium PAYGENT for WooCommerce Plugin woocommerce-for-paygent-payment-main Broken Access Control Missing Authorization to Unauthenticated Payment Callback Manipulation No login needed ≤ 2.4.6 CVE-2025-14078 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only