WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 351–400 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation ≤ 2.7.2 CVE-2025-14450 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Broken Access Control Missing Authorization to Unauthenticated Rede Order Logs Deletion No login needed ≤ 5.1.5 CVE-2026-0942 Wordfence
5.3 Medium Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit Plugin woo-rede Other Unauthenticated Order Status Manipulation No login needed ≤ 5.1.2 CVE-2026-0939 Wordfence
6.5 Medium MailerLite - WooCommerce integration Plugin woo-mailerlite Broken Access Control WooCommerce integration <= 3.1.3 - Missing Authorization to Data Deletion ≤ 3.1.3 CVE-2026-1000 Wordfence
5.3 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Full Path Disclosure via 'pdf' Parameter No login needed ≤ 6.4.8 CVE-2025-15526 Wordfence
5.3 Medium PayHere Payment Gateway Plugin for WooCommerce Plugin payhere-payment-gateway Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.3.9 CVE-2025-15475 Wordfence
5.3 Medium Perfit WooCommerce Plugin perfit-woocommerce Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 1.0.1 CVE-2025-14173 Wordfence
5.3 Medium Netcash WooCommerce Payment Gateway Plugin netcash-pay-now-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 4.1.3 CVE-2025-14880 Wordfence
4.9 Medium Shipping Rates by City for WooCommerce Plugin flat-shipping-rate-by-city-for-woocommerce SQL Injection Authenticated (Shop Manager+) SQL Injection via 'cities' Parameter ≤ 1.0.3 CVE-2026-0678 Wordfence
5.3 Medium miniOrange OTP Verification and SMS Notification for WooCommerce Plugin miniorange-sms-order-notification-otp-verification Broken Access Control Missing Authorization to Unauthenticated Notification Settings Modification No login needed ≤ 4.3.8 CVE-2025-14948 Wordfence
6.4 Medium BIALTY - Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce Plugin bulk-image-alt-text-with-yoast Cross-Site Scripting Bulk Image Alt Text (Alt tag, Alt Attribute) with Yoast SEO + WooCommerce <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2025-15019 Wordfence
5.3 Medium Japanized for WooCommerce Plugin woocommerce-for-japan Broken Access Control Missing Authorization to Unauthenticated Order Status Modification No login needed ≤ 2.7.17 CVE-2025-14886 Wordfence
5.3 Medium Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Change No login needed ≤ 3.1.4 CVE-2025-14460 Wordfence
4.4 Medium Email Customizer for WooCommerce | Drag and Drop Email Templates Builder Plugin email-customizer-for-woocommerce Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Email Template Content ≤ 2.6.7 CVE-2025-13974 Wordfence
6.4 Medium QR Code for WooCommerce order emails, PDF invoices, packing slips Plugin qr-code-tag-for-wc-from-goaskle-com Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Shortcode Attributes ≤ 1.9.42 CVE-2025-14626 Wordfence
6.1 Medium Premmerce WooCommerce Customers Manager Plugin woo-customers-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.14 CVE-2025-13369 Wordfence
6.1 Medium HBLPAY Payment Gateway for WooCommerce Plugin hblpay-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'cusdata' Parameter No login needed ≤ 5.0.0 CVE-2025-14875 Wordfence
6.4 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via displayName Parameter ≤ 5.93.1 CVE-2025-14891 Wordfence
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-69334 Patchstack
5.3 Medium ilGhera Support System for WooCommerce Plugin wc-support-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Deletion No login needed ≤ 1.2.6 CVE-2025-14034 Wordfence
6.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 2.7.3 Fixed in 2.7.4 CVE-2025-68029 Patchstack
5.4 Medium WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Server-Side Request Forgery No login needed ≤ 1.0.7 CVE-2025-62088 Patchstack
4.3 Medium Order Cancellation & Returns for WooCommerce Plugin wc-order-cancellation-return Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.1.11 CVE-2025-49352 Patchstack
4.3 Medium Orders Chat for WooCommerce Plugin orders-chat-for-woocommerce Broken Access Control ≤ 1.2.0 CVE-2025-49356 Patchstack
4.3 Medium Live Shopping & Shoppable Videos For WooCommerce Plugin live-shopping-video-streams Cross-Site Request Forgery No login needed ≤ 2.2.0 CVE-2025-62080 Patchstack
5.3 Medium Live Shopping & Shoppable Videos For WooCommerce Plugin live-shopping-video-streams Broken Access Control No login needed ≤ 2.2.0 CVE-2025-62081 Patchstack
5.4 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Broken Access Control ≤ 2.8.2 Fixed in 2.8.3 CVE-2025-62091 Patchstack
5.9 Medium WooCommerce Parcelas Plugin woocommerce-parcelas Cross-Site Scripting ≤ 1.3.5 CVE-2025-62750 Patchstack
6.5 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting ≤ 4.4.3 Fixed in 4.4.4 CVE-2025-62096 Patchstack
6.5 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.5 CVE-2025-62748 Patchstack
5.3 Medium ShopMagic Plugin shopmagic-for-woocommerce Broken Access Control No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2025-69093 Patchstack
6.5 Medium Combo Offers WooCommerce Plugin woo-combo-offers Cross-Site Scripting ≤ 4.2 Fixed in 4.3 CVE-2025-69088 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 3.2.0 - Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-69027 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
5.3 Medium Product Loops for WooCommerce Plugin product-loops Broken Access Control No login needed ≤ 2.1.2 CVE-2025-68994 Patchstack
5.3 Medium Share, Print and PDF Products for WooCommerce Plugin share-print-pdf-woocommerce Broken Access Control No login needed ≤ 3.1.2 CVE-2025-68993 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-68528 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.0 - Broken Access Control No login needed ≤ 2.7.0 Fixed in 2.7.1 CVE-2023-52210 Patchstack
6.1 Medium Product Table for WooCommerce Plugin woo-product-table Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.0.8 CVE-2025-12398 Wordfence
5.4 Medium FiboSearch – Ajax Search for WooCommerce Plugin ajax-search-for-woocommerce Cross-Site Scripting Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via thegem_te_search Shortcode ≤ 1.32.0 CVE-2025-14298 Wordfence
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' ≤ 1.3.7.3 CVE-2025-13110 Wordfence
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-67929 Patchstack
5.3 Medium Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Broken Access Control No login needed ≤ 4.0.49 Fixed in 4.0.50 CVE-2025-66128 Patchstack
5.3 Medium OnPay.io for WooCommerce Plugin onpay-io-for-woocommerce Broken Access Control No login needed ≤ 1.0.47 Fixed in 1.0.48 CVE-2025-64638 Patchstack
5.9 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter No login needed ≤ 6.4.8 CVE-2025-13439 Wordfence
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Content Injection Unauthenticated HTML Injection No login needed ≤ 2.10.0 CVE-2025-9207 Wordfence
5.3 Medium Eyewear prescription form Plugin eyewear-prescription-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion No login needed ≤ 6.0.1 CVE-2025-14365 Wordfence
6.4 Medium YITH WooCommerce Quick View Plugin yith-woocommerce-quick-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode ≤ 2.7.0 CVE-2025-8617 Wordfence
5.3 Medium Eyewear prescription form Plugin eyewear-prescription-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation No login needed ≤ 6.0.1 CVE-2025-14366 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only