WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 2,122 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical 워드프레스 결제 심플페이 Plugin pgall-for-woocommerce SQL Injection No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2026-56036 Patchstack
7.5 High CorvusPay WooCommerce Payment Gateway Plugin corvuspay-woocommerce-integration Authentication Bypass Broken Authentication No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2026-56029 Patchstack
9.9 Critical Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload ≤ 8.0.1 Fixed in 8.0.2 CVE-2026-56027 Patchstack
7.5 High Paymob for WooCommerce Plugin paymob-for-woocommerce Broken Access Control No login needed ≤ 4.1.2 CVE-2026-56025 Patchstack
8.8 High Abandoned Cart Pro for WooCommerce Plugin woocommerce-abandon-cart-pro Privilege Escalation ≤ 10.4.0 Fixed in 10.4.1 CVE-2026-56010 Patchstack
5.3 Medium Printcart Web to Print Product Designer for WooCommerce Plugin Information Disclosure Unauthenticated Folder Content Disclosure via Path Traversal No login needed ≤ 2.4.8 CVE-2025-10268 WPScan
6.5 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control No login needed ≤ 33.0.18 Fixed in 34.0.0 CVE-2026-56050 Patchstack
8.3 High APIExperts Square for WooCommerce Plugin woosquare Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.3 Fixed in 4.7.4 CVE-2026-54848 Patchstack
7.1 High Advanced Order Export For WooCommerce Plugin woo-order-export-lite Cross-Site Scripting No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2026-56042 Patchstack
5.4 Medium UPI QR Code Payment Gateway for WooCommerce Plugin upi-qr-code-payment-for-woocommerce Broken Access Control ≤ 1.6.2 Fixed in 1.6.3 CVE-2026-56023 Patchstack
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2026-56013 Patchstack
9.3 Critical Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist SQL Injection No login needed ≤ 1.1.11 Fixed in 1.1.12 CVE-2026-54849 Patchstack
7.5 High InPost PL Plugin inpost-for-woocommerce Broken Access Control Unauthenticated WooCommerce Order Parcel-Locker Hijacking No login needed < 1.9.1 Fixed in 1.9.1 CVE-2026-9702 WPScan
5.3 Medium WhatsOrder Plugin whatsorder-instant-checkout-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs No login needed ≤ 1.0.1 CVE-2026-9612 Wordfence
6.4 Medium Avalon23 Products Filter for WooCommerce Plugin avalon23-products-filter-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 1.1.6 CVE-2026-8865 Wordfence
7.1 High Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_manage_auctions No login needed ≤ 2.4.5 CVE-2026-4259 WPScan
6.1 Medium Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_auctions_bids_list No login needed ≤ 2.4.5 CVE-2026-4110 WPScan
9.8 Critical WooCommerce Plugin woocommerce Remote Code Execution WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php No login needed 7.1.0 CVE-2022-50972 VulnCheck
4.9 Medium Woosa Plugin integration-marktplaats-for-woocommerce Path Traversal Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter ≤ 2.0.5 CVE-2026-7547 Wordfence
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' Parameter No login needed ≤ 4.3.6 CVE-2026-12137 Wordfence
6.4 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.3.6 CVE-2026-12136 Wordfence
4.9 Medium Advanced Order Export For WooCommerce Plugin woo-order-export-lite SQL Injection Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter ≤ 4.0.10 CVE-2026-11360 Wordfence
4.3 Medium Dokan: AI Powered WooCommerce Multivendor Marketplace Solution Plugin dokan-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers ≤ 5.0.3 CVE-2026-10023 Wordfence
9.3 Critical Cargo Shipping Location for WooCommerce Plugin cargo-shipping-location-for-woocommerce SQL Injection No login needed ≤ 5.6 Fixed in 5.7 CVE-2026-54815 Patchstack
9.8 Critical Registration Form for WooCommerce Plugin registration-form-for-woocommerce Privilege Escalation No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2026-54807 Patchstack
6.5 Medium WooCommerce Anti-Fraud Plugin woocommerce-anti-fraud Broken Access Control No login needed ≤ 7.2.6 Fixed in 7.2.7 CVE-2026-49072 Patchstack
6.5 Medium WooCommerce Dropshipping Plugin woocommerce-dropshipping Authentication Bypass Broken Authentication No login needed ≤ 5.2.4 Fixed in 5.2.5 CVE-2026-49071 Patchstack
9.8 Critical WooCommerce Product Filters Plugin woocommerce-product-filters PHP Object Injection No login needed < 2.0.6 Fixed in 2.0.6 CVE-2026-40725 Patchstack
7.6 High MultiLoca Plugin woocommerce-multi-locations-inventory-management Privilege Escalation ≤ 4.2.15 Fixed in 4.2.16 CVE-2026-39546 Patchstack
8.5 High WooCommerce Frontend Manager – Ultimate Plugin wc-frontend-manager-ultimate SQL Injection Ultimate plugin < 6.7.7 - SQL Injection < 6.7.7 Fixed in 6.7.7 CVE-2026-22335 Patchstack
7.5 High Woocommerce Book Price Plugin woo-book-price Path Traversal Arbitrary File Download No login needed ≤ 1.3 CVE-2026-22334 Patchstack
10.0 Critical WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Arbitrary File Upload No login needed ≤ 1.0.7 CVE-2025-69129 Patchstack
7.5 High WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Path Traversal Arbitrary File Download No login needed ≤ 1.0.7 CVE-2025-69131 Patchstack
6.5 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter No login needed ≤ 10.7.0 CVE-2026-2381 Wordfence
7.5 High WooCommerce POS Plugin woocommerce-pos Broken Access Control No login needed ≤ 1.8.14 Fixed in 1.9.0 CVE-2026-52711 Patchstack
7.1 High Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.2 Fixed in 5.2.3 CVE-2026-39437 Patchstack
7.5 High ABC Crypto Checkout Plugin payerurl-crypto-currency-payment-gateway-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-52695 Patchstack
7.5 High Signature Add-On for WooCommerce Plugin woocommerce-digital-signature Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-52694 Patchstack
7.5 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Price Manipulation No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2026-49110 Patchstack
8.2 High Hippoo Mobile App for WooCommerce Plugin hippoo Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-49065 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Path Traversal Arbitrary File Download No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2026-49061 Patchstack
7.5 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2026-49056 Patchstack
7.5 High WPC Product Bundles for WooCommerce Plugin woo-product-bundle Broken Access Control No login needed ≤ 8.5.3 Fixed in 8.5.4 CVE-2026-48883 Patchstack
7.5 High Montonio for WooCommerce Plugin montonio-for-woocommerce Broken Access Control No login needed ≤ 10.1.2 Fixed in 10.1.3 CVE-2026-48873 Patchstack
7.5 High Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Authentication Bypass Broken Authentication No login needed ≤ 1.18.0 Fixed in 1.18.1 CVE-2026-42668 Patchstack
8.2 High AI Product Search for WooCommerce – Motive Commerce Search Plugin motive-commerce-search Broken Access Control Motive Commerce Search plugin <= 1.38.2 - Broken Access Control No login needed ≤ 1.38.2 Fixed in 1.38.3 CVE-2026-42664 Patchstack
9.3 Critical Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce SQL Injection No login needed ≤ 4.5.1 Fixed in 4.5.2 CVE-2026-42386 Patchstack
7.5 High Redsys for WooCommerce Light Plugin woo-redsys-gateway-light Broken Access Control No login needed ≤ 7.0.0 Fixed in 7.0.1 CVE-2026-40741 Patchstack
6.5 Medium Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting ≤ 1.5.3.2 Fixed in 1.5.3.3 CVE-2026-39540 Patchstack
7.2 High Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce PHP Object Injection ≤ 1.6.19 Fixed in 1.6.20 CVE-2026-39499 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only