WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 401–450 of 1,255 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Hippoo Mobile App for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Limited File Write No login needed |
≤ 1.7.1 |
CVE-2025-12655 |
Wordfence | |
| 5.3 Medium | Product Filtering by Categories, Tags, Price Range for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Modification No login needed |
≤ 1.1.6 |
CVE-2025-13314 |
Wordfence | |
| 5.3 Medium | Premmerce Wishlist for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Wishlist Deletion No login needed |
≤ 1.1.10 |
CVE-2025-13440 |
Wordfence | |
| 4.3 Medium | Kirim.Email WooCommerce Integration | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.9 |
CVE-2025-14165 |
Wordfence | |
| 4.3 Medium | Premmerce Brands for WooCommerce | Broken Access Control Missing Authorization To Authenticated (Subscriber+) Brand Permalink Settings Update |
≤ 1.2.13 |
CVE-2025-12783 |
Wordfence | |
| 5.3 Medium | Campay Woocommerce Payment Gateway | Price Manipulation Unauthenticated Payment Bypass No login needed |
≤ 1.2.2 |
CVE-2025-12883 |
Wordfence | |
| 4.3 Medium | Advanced Product Fields (Product Addons) for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Product Field Group Duplication and Publication No login needed |
≤ 1.6.17 |
CVE-2025-13924 |
Wordfence | |
| 5.4 Medium | Order Delivery Date for WooCommerce | Broken Access Control No login needed |
≤ 4.3.1 Fixed in 4.3.2 |
CVE-2025-63024 |
Patchstack | |
| 5.3 Medium | Payment Gateway for PayPal on WooCommerce | Broken Access Control No login needed |
≤ 9.0.53 Fixed in 9.0.54 |
CVE-2025-63023 |
Patchstack | |
| 4.3 Medium | WooCommerce Payment Gateway - Paysera | Broken Access Control Paysera plugin <= 3.10.0 - Broken Access Control |
≤ 3.10.0 Fixed in 3.11.0 |
CVE-2025-63015 |
Patchstack | |
| 4.3 Medium | MultiParcels Shipping For WooCommerce | Broken Access Control |
≤ 1.30.12 Fixed in 1.30.13 |
CVE-2025-62995 |
Patchstack | |
| 5.3 Medium | Eupago Gateway For Woocommerce | Broken Access Control No login needed |
≤ 4.7.1 |
CVE-2025-62870 |
Patchstack | |
| 5.3 Medium | Virtuaria PagBank / PagSeguro para Woocommerce | Broken Access Control No login needed |
≤ 3.6.3 Fixed in 3.6.4 |
CVE-2025-62151 |
Patchstack | |
| 4.3 Medium | WebToffee eCommerce Marketing Automation | Broken Access Control |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2025-67599 |
Patchstack | |
| 4.3 Medium | WooCommerce PDF Invoices & Packing Slips | Broken Access Control |
≤ 4.9.1 Fixed in 5.0.0 |
CVE-2025-67589 |
Patchstack | |
| 5.3 Medium | Constant Contact + WooCommerce | Broken Access Control No login needed |
≤ 2.4.1 Fixed in 2.4.2 |
CVE-2025-67580 |
Patchstack | |
| 5.3 Medium | Pixel Manager for WooCommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.51.1 Fixed in 1.52.0 |
CVE-2025-67564 |
Patchstack | |
| 6.5 Medium | Multi-Step Checkout for WooCommerce | Cross-Site Scripting |
≤ 2.33 Fixed in 2.34 |
CVE-2025-67542 |
Patchstack | |
| 4.3 Medium | Thank You Page Customizer for WooCommerce | Broken Access Control |
≤ 1.1.8 Fixed in 1.1.9 |
CVE-2025-66528 |
Patchstack | |
| 4.3 Medium | Search, Filters & Merchandising for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation |
≤ 3.0.67 |
CVE-2025-12091 |
Wordfence | |
| 6.1 Medium | Live Sales Notification for Woocommerce – Woomotiv | Cross-Site Scripting Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting No login needed |
≤ 3.6.3 |
CVE-2025-13137 |
Wordfence | |
| 4.3 Medium | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed |
≤ 2.6.4 |
CVE-2025-12130 |
Wordfence | |
| 5.4 Medium | PDF Catalog for WooCommerce | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 1.1.18 |
CVE-2025-12191 |
Wordfence | |
| 4.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' |
≤ 1.3.7.2 |
CVE-2025-13109 |
Wordfence | |
| 5.3 Medium | Quick View for WooCommerce | Information Disclosure Unauthenticated Private Product Disclosure No login needed |
≤ 2.2.17 |
CVE-2025-12584 |
Wordfence | |
| 5.3 Medium | QODE Wishlist for WooCommerce | Broken Access Control Unauthenticated Insecure Direct Object Reference to Wishlist Update No login needed |
≤ 1.2.7 |
CVE-2025-13157 |
Wordfence | |
| 5.3 Medium | Hide Category by User Role for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Cache Flushing No login needed |
≤ 2.3.1 |
CVE-2025-13441 |
Wordfence | |
| 6.1 Medium | Customer Reviews Collector for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.6.1 |
CVE-2025-12123 |
Wordfence | |
| 4.3 Medium | Refund Request for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Refund Status Update |
≤ 1.0 |
CVE-2025-12634 |
Wordfence | |
| 5.3 Medium | Admin and Customer Messages After Order for WooCommerce: OrderConvo | Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed |
≤ 14 |
CVE-2025-13389 |
Wordfence | |
| 6.5 Medium | Wishlist for WooCommerce | Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed |
≤ 1.1.3 |
CVE-2025-12040 |
Wordfence | |
| 4.3 Medium | Admin and Customer Messages After Order for WooCommerce: OrderConvo | Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages |
≤ 14 |
CVE-2025-13452 |
Wordfence | |
| 6.5 Medium | Perfect Brands for WooCommerce | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 3.6.2 |
CVE-2025-10144 |
Wordfence | |
| 5.3 Medium | Show Variations as Single Products Woocommerce | Broken Access Control No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2025-66114 |
Patchstack | |
| 5.3 Medium | Cart Weight for WooCommerce | Broken Access Control No login needed |
≤ 1.9.11 Fixed in 1.9.12 |
CVE-2025-66109 |
Patchstack | |
| 4.3 Medium | Product Feed for WooCommerce | Broken Access Control |
≤ 2.3.1 Fixed in 2.3.2 |
CVE-2025-66089 |
Patchstack | |
| 5.3 Medium | Custom Order Numbers for WooCommerce | Broken Access Control No login needed |
≤ 1.11.0 Fixed in 1.11.1 |
CVE-2025-66071 |
Patchstack | |
| 4.3 Medium | PPOM for WooCommerce | Broken Access Control |
≤ 33.0.16 Fixed in 33.0.17 |
CVE-2025-66069 |
Patchstack | |
| 5.3 Medium | BigBuy Dropshipping Connector for WooCommerce | Information Disclosure Unauthenticated IP Spoofing to phpinfo() Exposure No login needed |
≤ 2.0.5 |
CVE-2025-12039 |
Wordfence | |
| 5.4 Medium | Return Refund and Exchange For WooCommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read |
≤ 4.5.5 |
CVE-2025-12881 |
Wordfence | |
| 4.3 Medium | Return Refund and Exchange For WooCommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation |
≤ 4.5.5 |
CVE-2025-12086 |
Wordfence | |
| 6.4 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Cross-Site Scripting Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode |
≤ 3.13.1.2 |
CVE-2025-12878 |
Wordfence | |
| 5.3 Medium | YITH WooCommerce Wishlist | Broken Access Control Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename No login needed |
≤ 4.10.0 |
CVE-2025-12427 |
Wordfence | |
| 5.3 Medium | YITH WooCommerce Wishlist | Information Disclosure Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion No login needed |
≤ 4.10.0 |
CVE-2025-12777 |
Wordfence | |
| 5.3 Medium | Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more | Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed |
≤ 1.49.2 |
CVE-2025-12545 |
Wordfence | |
| 4.3 Medium | wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce | Broken Access Control Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce <= 1.2.2 - Missing Authorization to Sensitive Information Disclosure |
≤ 1.2.2 |
CVE-2025-12639 |
Wordfence | |
| 5.3 Medium | Cryptocurrency Payment Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed |
≤ 2.0.25 |
CVE-2025-12392 |
Wordfence | |
| 4.3 Medium | Order Export & Order Import for WooCommerce | Broken Access Control |
≤ 2.6.7 Fixed in 2.6.8 |
CVE-2025-64382 |
Patchstack | |
| 6.5 Medium | Booster for WooCommerce | Cross-Site Scripting |
≤ 7.3.2 Fixed in 7.4.0 |
CVE-2025-64380 |
Patchstack | |
| 4.3 Medium | Booster for WooCommerce | Broken Access Control |
≤ 7.4.0 Fixed in 7.5.0 |
CVE-2025-64379 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.