WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,151–5,200 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 104 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.3 High Userpro Plugin userpro Local File Inclusion No login needed ≤ 5.1.9 CVE-2024-56214 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
8.8 High WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Plugin wte-elementor-widgets Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion ≤ 1.3.7 CVE-2024-12272 Wordfence
8.8 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Request Forgery Cross-Site Request Forgery to Password Reset No login needed ≤ 3.3.43 CVE-2024-12771 Wordfence
8.5 High WPLMS Plugin wplms_plugin SQL Injection Subscriber+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56047 Patchstack
7.6 High WPLMS Plugin wplms_plugin SQL Injection Instructor+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56053 Patchstack
8.8 High WPLMS Plugin wplms_plugin Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56048 Patchstack
7.1 High Advance Menu Manager Plugin advance-menu-manager Broken Access Control Settings Change ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-54381 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56049 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Arbitrary Directory Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56055 Patchstack
8.5 High WPLMS Plugin wplms_plugin Remote Code Execution Student+ Remote Code Execution (RCE) ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56051 Patchstack
7.1 High Saoshyant Element Plugin saoshyant-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-51646 Patchstack
7.1 High Bootstrap Buttons Plugin bootstrap-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49677 Patchstack
7.1 High Device Detector Plugin device-detector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2024-56010 Patchstack
7.1 High hmd Plugin hmd Cross-Site Scripting No login needed ≤ 2.0 Fixed in 2.2 CVE-2024-54350 Patchstack
7.1 High Image Mapper Plugin image-mapper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.5.3 CVE-2024-56016 Patchstack
8.5 High Dr Affiliate Plugin dr-affiliate SQL Injection ≤ 1.2.3 CVE-2024-55975 Patchstack
8.5 High Saksh Escrow System Plugin saksh-escrow-system SQL Injection ≤ 2.4 CVE-2024-55984 Patchstack
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack
8.5 High YDS Support Ticket System Plugin yds-support-ticket-system SQL Injection ≤ 1.0 CVE-2024-55985 Patchstack
8.1 High Axeptio Plugin axeptio-sdk-integration Local File Inclusion No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-54270 Patchstack
7.5 High Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56008 Patchstack
8.8 High CRM WordPress Plugin – RepairBuddy Plugin Broken Access Control RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation ≤ 3.8120 CVE-2024-12259 Wordfence
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.23 Fixed in 1.24 CVE-2024-56017 Patchstack
7.5 High EazyDocs Plugin eazydocs Local File Inclusion ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-54376 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54284 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54283 Patchstack
7.5 High WP-NERD Toolkit Plugin wp-nerd-toolkit Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-54279 Patchstack
7.1 High tydskrif Theme tydskrif Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2024-54257 Patchstack
7.1 High Advanced Options Editor Plugin advanced-options-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-54249 Patchstack
7.1 High Tidy Up Plugin tidy-up Cross-Site Request Forgery CSRF to Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2024-56015 Patchstack
7.1 High 3D Avatar User Profile Plugin 3d-avatar-user-profile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-54358 Patchstack
8.2 High Banner System Plugin banner-system Broken Access Control No login needed ≤ 1.0.0 CVE-2024-54359 Patchstack
7.1 High Feedpress Generator Plugin feedpress-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-54364 Patchstack
8.8 High KH Easy User Settings Plugin kh-easy-user-settings Privilege Escalation ≤ 1.0.0 CVE-2024-54365 Patchstack
7.5 High Sogrid Plugin sogrid Local File Inclusion No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-54374 Patchstack
8.8 High Quietly Insights Plugin quietly-insights Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.2.2 CVE-2024-54378 Patchstack
7.5 High Woolook Plugin woolook Local File Inclusion No login needed ≤ 1.7.0 CVE-2024-54375 Patchstack
7.5 High WP Cookies Enabler Plugin wp-cookies-enabler Local File Inclusion No login needed ≤ 1.0.1 CVE-2024-54380 Patchstack
8.8 High Minterpress Plugin minterpress Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.0.5 CVE-2024-54379 Patchstack
7.2 High Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.83 Fixed in 2.0.85 CVE-2024-54385 Patchstack
7.1 High Posts Date Ranges Plugin posts-date-ranges Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2024-54387 Patchstack
7.1 High Increase Sociability Plugin increase-sociability Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.0 CVE-2024-54395 Patchstack
7.1 High TagGator Plugin taggator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.54 CVE-2024-54390 Patchstack
7.1 High Comments On Feed Plugin comments-on-feed Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-54406 Patchstack
7.1 High Visual Recent Posts Plugin visual-recent-posts Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.3 CVE-2024-54403 Patchstack
7.1 High Evernote Sync Plugin evernote-sync Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.0 CVE-2024-54422 Patchstack
8.5 High TSB Occasion Editor Plugin tsb-occasion-editor SQL Injection ≤ 1.2.1 CVE-2024-55973 Patchstack
8.5 High Mimoos Plugin devoluciones-packback SQL Injection ≤ 1.2 CVE-2024-55974 Patchstack
8.5 High Wr Age Verification Plugin wr-age-verification SQL Injection ≤ 2.0.0 CVE-2024-55979 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only