WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High Samex - Clean, Minimal Shop WooCommerce Theme samex Local File Inclusion Clean, Minimal Shop WooCommerce WordPress Theme <= 2.6 - Local File Inclusion No login needed ≤ 2.6 CVE-2023-25998 Patchstack
7.1 High SpecFit-Virtual Try On Woocommerce Plugin try-on-for-woocommerce Cross-Site Scripting No login needed ≤ 8.0.3 CVE-2025-23973 Patchstack
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.7 Fixed in 1.3.7.1 CVE-2025-52708 Patchstack
8.5 High Woocommerce Partial Shipment Plugin wc-partial-shipment SQL Injection ≤ 3.2 Fixed in 3.3 CVE-2025-48118 Patchstack
8.1 High Zagg - Electronics & Accessories WooCommerce Theme Local File Inclusion Electronics & Accessories WooCommerce WordPress Theme <= 1.4.1 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.1 CVE-2025-4200 Wordfence
8.1 High BodyCenter - Gym, Fitness WooCommerce Theme bodycenter Local File Inclusion Gym, Fitness WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2023-25999 Patchstack
8.1 High Valen - Sport, Fashion WooCommerce Plugin valen Local File Inclusion Sport, Fashion WooCommerce WordPress Theme <= 2.4 - Local File Inclusion No login needed ≤ 2.4 CVE-2025-28945 Patchstack
7.1 High Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-47463 Patchstack
7.1 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert Cross-Site Scripting No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47487 Patchstack
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Path Traversal Light plugin <= 2.4.37 - Arbitrary File Download No login needed ≤ 2.4.37 CVE-2025-48124 Patchstack
7.5 High MultiVendorX Plugin dc-woocommerce-multi-vendor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48261 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.8.1 Fixed in 2.8.2 CVE-2025-49265 Patchstack
7.6 High Persian Woocommerce SMS Plugin persian-woocommerce-sms SQL Injection ≤ 7.0.10 Fixed in 7.1.0 CVE-2025-49315 Patchstack
7.5 High WooCommerce Orders & Customers Exporter Plugin woocommerce-orders-customers-exporter Information Disclosure Sensitive Data Exposure No login needed ≤ 5.0 CVE-2025-48331 Patchstack
8.1 High eMagicOne Store Manager for WooCommerce Plugin store-manager-connector Arbitrary File Upload Unauthenticated Arbitrary File Upload via set_file() No login needed ≤ 1.2.5 CVE-2025-4336 Wordfence
8.8 High Subaccounts for WooCommerce Plugin subaccounts-for-woocommerce Privilege Escalation Account Takeover ≤ 1.6.6 Fixed in 1.6.7 CVE-2025-47461 Patchstack
7.1 High Order Delivery Date Pro for WooCommerce Plugin Cross-Site Scripting Reflected XSS No login needed 2.0 – < 12.4.0 Fixed in 12.4.0 CVE-2025-2929 WPScan
7.1 High Booster Plus for WooCommerce Plugin booster-plus-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.4 Fixed in 7.2.5 CVE-2025-39446 Patchstack
7.5 High Product Category Slider for WooCommerce Plugin woo-category-slider-by-pluginever Local File Inclusion ≤ 4.3.4 Fixed in 4.3.5 CVE-2025-39364 Patchstack
7.1 High Better Customer List for WooCommerce Plugin woo-better-customer-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-39537 Patchstack
7.1 High Import Export For WooCommerce Plugin import-export-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.2 CVE-2025-48144 Patchstack
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Privilege Escalation WooCommerce <= 3.8.1 - Authenticated (Subscriber+) Privilege Escalation via handleWpLoginCreateUserAction Function ≤ 3.8.1 CVE-2025-3876 Wordfence
7.3 High Wolmart | Multi-Vendor Marketplace WooCommerce Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution in wolmart_loadmore No login needed ≤ 1.8.11 CVE-2024-13793 Wordfence
8.8 High Open Close WooCommerce Store Plugin woc-open-close Local File Inclusion ≤ 4.9.9 CVE-2025-47649 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
7.6 High ELEX Product Feed for WooCommerce Plugin elex-product-feed SQL Injection ≤ 3.1.2 CVE-2025-47643 Patchstack
7.6 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing SQL Injection ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-47544 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
8.8 High Challan Plugin webappick-pdf-invoice-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.7.58 Fixed in 3.7.59 CVE-2025-47462 Patchstack
7.6 High TrackShip for WooCommerce Plugin trackship-for-woocommerce SQL Injection ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-47460 Patchstack
8.8 High Woocommerce Multiple Addresses Plugin woocommerce-multiple-addresses Privilege Escalation Authenticated (Subscriber+) Privilege Escalation ≤ 1.0.7.1 CVE-2025-4335 Wordfence
7.5 High Advance Seat Reservation Management for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.3 CVE-2024-13344 Wordfence
8.8 High Integração entre Eduzz e Woocommerce Plugin integracao-entre-eduzz-e-wc-powers Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 1.7.5 CVE-2025-3906 Wordfence
7.5 High Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin excel-like-price-change-for-woocommerce-and-wp-e-commerce-light Local File Inclusion Light plugin <= 2.4.37 - Local File Inclusion No login needed ≤ 2.4.37 CVE-2025-39378 Patchstack
7.5 High Checkout Field Visibility for WooCommerce Plugin checkout-field-visibility-for-woocommerce Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.4.0 CVE-2025-39391 Patchstack
7.1 High Shipping with Venipak for WooCommerce Plugin wc-venipak-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.3 Fixed in 1.22.5 CVE-2025-24553 Patchstack
7.1 High Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.23 Fixed in 1.4.23.1 CVE-2025-24586 Patchstack
7.1 High QR Code for WooCommerce Plugin wc-qr-codes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-27322 Patchstack
7.1 High 17TRACK for WooCommerce Plugin 17track Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 CVE-2025-27324 Patchstack
7.1 High WooCommerce HTML5 Video Plugin woocommerce-html5-video Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.10 CVE-2025-27343 Patchstack
7.1 High Revamp CRM for WooCommerce Plugin revampcrm-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-32512 Patchstack
7.1 High Make Email Customizer for WooCommerce Plugin make-email-customizer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 CVE-2025-32511 Patchstack
7.1 High WooCommerce Estimate and Quote Plugin wc-estimate-and-quote Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2.5 CVE-2025-32514 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-32522 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2025-32530 Patchstack
7.1 High DN Shipping by Weight for WooCommerce Plugin dn-shipping-by-weight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-32535 Patchstack
7.1 High Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.7 Fixed in 2.2.0 CVE-2025-32533 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only