WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 401–450 of 1,255 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Hippoo Mobile App for WooCommerce Plugin hippoo Broken Access Control Missing Authorization to Unauthenticated Limited File Write No login needed ≤ 1.7.1 CVE-2025-12655 Wordfence
5.3 Medium Product Filtering by Categories, Tags, Price Range for WooCommerce Plugin filter-plus Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 1.1.6 CVE-2025-13314 Wordfence
5.3 Medium Premmerce Wishlist for WooCommerce Plugin premmerce-woocommerce-wishlist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion No login needed ≤ 1.1.10 CVE-2025-13440 Wordfence
4.3 Medium Kirim.Email WooCommerce Integration Plugin kirimemail-woocommerce-integration Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.2.9 CVE-2025-14165 Wordfence
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Broken Access Control Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update ≤ 1.2.13 CVE-2025-12783 Wordfence
5.3 Medium Campay Woocommerce Payment Gateway Plugin campay-api Price Manipulation Unauthenticated Payment Bypass No login needed ≤ 1.2.2 CVE-2025-12883 Wordfence
4.3 Medium Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Product Field Group Duplication and Publication No login needed ≤ 1.6.17 CVE-2025-13924 Wordfence
5.4 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Broken Access Control No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2025-63024 Patchstack
5.3 Medium Payment Gateway for PayPal on WooCommerce Plugin woo-paypal-gateway Broken Access Control No login needed ≤ 9.0.53 Fixed in 9.0.54 CVE-2025-63023 Patchstack
4.3 Medium WooCommerce Payment Gateway - Paysera Plugin woo-payment-gateway-paysera Broken Access Control Paysera plugin <= 3.10.0 - Broken Access Control ≤ 3.10.0 Fixed in 3.11.0 CVE-2025-63015 Patchstack
4.3 Medium MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Broken Access Control ≤ 1.30.12 Fixed in 1.30.13 CVE-2025-62995 Patchstack
5.3 Medium Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control No login needed ≤ 4.7.1 CVE-2025-62870 Patchstack
5.3 Medium Virtuaria PagBank / PagSeguro para Woocommerce Plugin virtuaria-pagseguro Broken Access Control No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-62151 Patchstack
4.3 Medium WebToffee eCommerce Marketing Automation Plugin decorator-woocommerce-email-customizer Broken Access Control ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-67599 Patchstack
4.3 Medium WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips Broken Access Control ≤ 4.9.1 Fixed in 5.0.0 CVE-2025-67589 Patchstack
5.3 Medium Constant Contact + WooCommerce Plugin constant-contact-woocommerce Broken Access Control No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-67580 Patchstack
5.3 Medium Pixel Manager for WooCommerce Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Sensitive Data Exposure No login needed ≤ 1.51.1 Fixed in 1.52.0 CVE-2025-67564 Patchstack
6.5 Medium Multi-Step Checkout for WooCommerce Plugin wp-multi-step-checkout Cross-Site Scripting ≤ 2.33 Fixed in 2.34 CVE-2025-67542 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Search, Filters & Merchandising for WooCommerce Plugin instantsearch-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation ≤ 3.0.67 CVE-2025-12091 Wordfence
6.1 Medium Live Sales Notification for Woocommerce – Woomotiv Plugin woomotiv Cross-Site Scripting Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting No login needed ≤ 3.6.3 CVE-2025-13137 Wordfence
4.3 Medium WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors Plugin wc-vendors Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed ≤ 2.6.4 CVE-2025-12130 Wordfence
5.4 Medium PDF Catalog for WooCommerce Plugin pdf-catalog-for-woocommerce Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.18 CVE-2025-12191 Wordfence
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' ≤ 1.3.7.2 CVE-2025-13109 Wordfence
5.3 Medium Quick View for WooCommerce Plugin woo-quickview Information Disclosure Unauthenticated Private Product Disclosure No login needed ≤ 2.2.17 CVE-2025-12584 Wordfence
5.3 Medium QODE Wishlist for WooCommerce Plugin qode-wishlist-for-woocommerce Broken Access Control Unauthenticated Insecure Direct Object Reference to Wishlist Update No login needed ≤ 1.2.7 CVE-2025-13157 Wordfence
5.3 Medium Hide Category by User Role for WooCommerce Plugin hide-category-by-user-role-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Cache Flushing No login needed ≤ 2.3.1 CVE-2025-13441 Wordfence
6.1 Medium Customer Reviews Collector for WooCommerce Plugin customer-reviews-collector-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.6.1 CVE-2025-12123 Wordfence
4.3 Medium Refund Request for WooCommerce Plugin refund-request-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Refund Status Update ≤ 1.0 CVE-2025-12634 Wordfence
5.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 14 CVE-2025-13389 Wordfence
6.5 Medium Wishlist for WooCommerce Plugin th-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 1.1.3 CVE-2025-12040 Wordfence
4.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages ≤ 14 CVE-2025-13452 Wordfence
6.5 Medium Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.6.2 CVE-2025-10144 Wordfence
5.3 Medium Show Variations as Single Products Woocommerce Plugin woo-show-single-variations-shop-category Broken Access Control No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-66114 Patchstack
5.3 Medium Cart Weight for WooCommerce Plugin woo-cart-weight Broken Access Control No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66109 Patchstack
4.3 Medium Product Feed for WooCommerce Plugin webtoffee-product-feed Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-66089 Patchstack
5.3 Medium Custom Order Numbers for WooCommerce Plugin custom-order-numbers-for-woocommerce Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2025-66071 Patchstack
4.3 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control ≤ 33.0.16 Fixed in 33.0.17 CVE-2025-66069 Patchstack
5.3 Medium BigBuy Dropshipping Connector for WooCommerce Plugin bigbuy-wc-dropshipping-connector Information Disclosure Unauthenticated IP Spoofing to phpinfo() Exposure No login needed ≤ 2.0.5 CVE-2025-12039 Wordfence
5.4 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read ≤ 4.5.5 CVE-2025-12881 Wordfence
4.3 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation ≤ 4.5.5 CVE-2025-12086 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode ≤ 3.13.1.2 CVE-2025-12878 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename No login needed ≤ 4.10.0 CVE-2025-12427 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Information Disclosure Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion No login needed ≤ 4.10.0 CVE-2025-12777 Wordfence
5.3 Medium Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed ≤ 1.49.2 CVE-2025-12545 Wordfence
4.3 Medium wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce Plugin catalog-mode-pricing-enquiry-forms-promotions Broken Access Control Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce <= 1.2.2 - Missing Authorization to Sensitive Information Disclosure ≤ 1.2.2 CVE-2025-12639 Wordfence
5.3 Medium Cryptocurrency Payment Gateway for WooCommerce Plugin triplea-cryptocurrency-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 2.0.25 CVE-2025-12392 Wordfence
4.3 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-64382 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting ≤ 7.3.2 Fixed in 7.4.0 CVE-2025-64380 Patchstack
4.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control ≤ 7.4.0 Fixed in 7.5.0 CVE-2025-64379 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only