WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack
7.5 High WooCommerce Loyal Customers Plugin woocommerce-loyal-customer Broken Access Control No login needed ≤ 2.6 CVE-2025-32544 Patchstack
7.1 High MSRP (RRP) Pricing for WooCommerce Plugin msrp-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 Fixed in 2.0.0 CVE-2025-32552 Patchstack
8.2 High Add Product Frontend for WooCommerce Plugin add-product-frontend-for-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.8 CVE-2025-32593 Patchstack
7.1 High WooCommerce TBC Credit Card Payment Gateway (Free) Plugin woo-tbc-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-32611 Patchstack
7.1 High Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.12 Fixed in 3.1.13 CVE-2025-32628 Patchstack
7.1 High Mobile App for WooCommerce Plugin mobile-app-for-woocommerce Cross-Site Scripting No login needed ≤ 0.4.61 CVE-2025-32638 Patchstack
7.1 High Product Excel Import Export & Bulk Edit for WooCommerce Plugin webd-woocommerce-product-excel-importer-bulk-edit Cross-Site Scripting No login needed ≤ 4.7 CVE-2025-32674 Patchstack
7.5 High StoreContrl Woocommerce Plugin storecontrl-wp-connection Path Traversal Arbitrary File Download No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2025-39568 Patchstack
7.5 High Klarna Checkout for WooCommerce Plugin Denial of Service DoS via Excessive Logging No login needed < 2.13.5 Fixed in 2.13.5 CVE-2024-13925 WPScan
7.5 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce Local File Inclusion ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-27011 Patchstack
7.5 High Barcode Generator for WooCommerce Plugin embedding-barcodes-into-product-pages-and-orders Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-32929 Patchstack
8.6 High Oxygen MyData for WooCommerce Plugin oxygen-mydata Arbitrary File Deletion No login needed ≤ 1.0.64 Fixed in 1.0.65 CVE-2025-32631 Patchstack
8.1 High WooCommerce Pickupp Plugin wc-pickupp Local File Inclusion No login needed ≤ 2.4.3 CVE-2025-32587 Patchstack
7.1 High ABA PayWay Payment Gateway for WooCommerce Plugin aba-payway-woocommerce-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-32586 Patchstack
7.1 High WooCommerce Sales MIS Report Plugin woocommerce-mis-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 CVE-2025-32541 Patchstack
7.1 High Store Exporter Plugin woocommerce-exporter Cross-Site Scripting Store Exporter plugin <= 2.7.4 - Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2025-32539 Patchstack
7.1 High MyWorks WooCommerce Sync for QuickBooks Online Plugin myworks-woo-sync-for-quickbooks-online Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.2 CVE-2025-32524 Patchstack
7.1 High WooCommerce – Payphone Gateway Plugin wc-payphone-gateway Cross-Site Scripting Payphone Gateway plugin <= 3.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-32523 Patchstack
8.2 High CardGate Payments for WooCommerce Plugin cardgate SQL Injection No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-32119 Patchstack
8.5 High Review Stars Count For WooCommerce Plugin review-stars-count-for-woocommerce SQL Injection ≤ 2.0 CVE-2025-32687 Patchstack
7.1 High Pagopar – WooCommerce Gateway Plugin pagopar-woocommerce-gateway Cross-Site Request Forgery WooCommerce Gateway plugin <= 2.7.1 - CSRF to Stored XSS No login needed ≤ 2.7.1 Fixed in 2.8.0 CVE-2025-31032 Patchstack
7.5 High Woo Product Feed For Marketing Channels Plugin woocommerce-to-google-merchant-center Broken Access Control No login needed ≤ 1.9.0 CVE-2025-31377 Patchstack
7.1 High ChillPay WooCommerce Plugin chillpay-payment-gateway Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-32570 Patchstack
7.1 High FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.22.8 Fixed in 2.22.9 CVE-2025-32659 Patchstack
7.5 High Fami WooCommerce Compare Plugin fami-woocommerce-compare Local File Inclusion No login needed ≤ 1.0.5 CVE-2025-31405 Patchstack
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed 4.0.1 – 7.2.4 CVE-2024-13708 Wordfence
8.1 High Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed 4.0.1 – 7.2.4 CVE-2024-13744 Wordfence
7.5 High Ni WooCommerce Product Enquiry Plugin ni-woocommerce-product-enquiry Broken Access Control No login needed ≤ 4.1.8 CVE-2025-31580 Patchstack
8.5 High Order Splitter for WooCommerce Plugin woo-order-splitter SQL Injection ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-31089 Patchstack
7.1 High Plugin Oficial – Getnet para WooCommerce Plugin wc-checkout-getnet Cross-Site Scripting Getnet para WooCommerce plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.8.0 CVE-2025-30906 Patchstack
8.8 High WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce Plugin wpc-smart-linked-products Privilege Escalation ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-30825 Patchstack
7.2 High Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 7.2.4 CVE-2024-12278 Wordfence
7.1 High Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.4 Fixed in 4.2.4 CVE-2025-30924 Patchstack
7.1 High SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-30917 Patchstack
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.1 High Pesapal Gateway for Woocommerce Plugin pesapal-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-30579 Patchstack
7.5 High Accounting for WooCommerce Plugin accounting-for-woocommerce Local File Inclusion No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2025-30835 Patchstack
7.1 High GlobalPayments WooCommerce Plugin global-payments-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.2 Fixed in 1.13.3 CVE-2025-22767 Patchstack
7.1 High Já-Já Pagamentos for WooCommerce Plugin wc-ja-ja-pagamentos-multicaixa-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51624 Patchstack
7.5 High HUSKY Plugin woocommerce-products-filter Local File Inclusion ≤ 1.3.6.4 Fixed in 1.3.6.5 CVE-2025-26890 Patchstack
7.6 High MC Woocommerce Wishlist Plugin smart-wishlist-for-more-convert SQL Injection ≤ 1.8.9 Fixed in 1.9.0 CVE-2025-30879 Patchstack
7.1 High Currency Switcher for WooCommerce Plugin currency-switcher-for-woocommerce Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.7 Fixed in 0.0.8 CVE-2025-30857 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.16 Fixed in 1.0.17 CVE-2025-30791 Patchstack
8.8 High WPC Smart Upsell Funnel for WooCommerce Plugin wpc-smart-upsell-funnel Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-30772 Patchstack
7.6 High FlexStock Plugin stock-sync-with-google-sheet-for-woocommerce SQL Injection ≤ 3.13.1 Fixed in 3.13.2 CVE-2025-30765 Patchstack
7.1 High Custom Product Stickers for Woocommerce Plugin custom-product-stickers-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 CVE-2025-28889 Patchstack
7.1 High In Stock Mailer for WooCommerce Plugin in-stock-mailer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-26566 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only