WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,301–5,350 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 107 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.3 High JupiterX Core Plugin jupiterx-core Broken Access Control Multiple Auth. Broken Access Control 3.0.0 – 3.3.0 Fixed in 3.3.5 CVE-2023-38385 Patchstack
7.3 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Broken Access Control No login needed ≤ 23.0211 Fixed in 23.0212 CVE-2023-36510 Patchstack
7.6 High Surfer Plugin surferseo Broken Access Control ≤ 1.3.2.357 Fixed in 1.3.3.379 CVE-2023-35037 Patchstack
8.8 High Spam protection, AntiSpam, FireWall by CleanTalk Plugin cleantalk-spam-protect Broken Access Control ≤ 6.10 Fixed in 6.11 CVE-2023-33996 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
7.5 High WCP Contact Form Plugin wcp-contact-form Broken Access Control No login needed ≤ 3.1.0 CVE-2023-32520 Patchstack
7.3 High Woo Custom Emails Plugin woo-custom-emails Broken Access Control No login needed ≤ 2.2 CVE-2023-32507 Patchstack
7.5 High Easing Slider Plugin easing-slider Broken Access Control Plugin Settings Reset No login needed ≤ 3.0.8 CVE-2023-30490 Patchstack
7.5 High Video Gallery – YouTube Gallery Plugin gallery-videos Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2023-25988 Patchstack
7.7 High Best WordPress Gallery Plugin – FooGallery Plugin Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.26 CVE-2023-6947 Wordfence
7.1 High AIO Contact Plugin aio-contact Cross-Site Scripting Unauthenticated Site-Wide Cross Site Scripting (XSS) No login needed ≤ 2.8.1 CVE-2024-54219 Patchstack
7.1 High FAT Services Booking Plugin fat-services-booking Cross-Site Scripting Subscriber+ Site-Wide Cross Site Scripting (XSS) No login needed ≤ 5.6 CVE-2024-54220 Patchstack
7.5 High Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Local File Inclusion ≤ 1.3.9 CVE-2024-53790 Patchstack
7.1 High Country Blocker Plugin country-blocker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.2 CVE-2024-54226 Patchstack
7.5 High Designer Plugin designer Local File Inclusion ≤ 1.4.1 Fixed in 1.5.0 CVE-2024-54225 Patchstack
7.5 High Ebook Store Plugin ebook-store Authentication Bypass Broken Authentication No login needed ≤ 5.775 Fixed in 5.78 CVE-2023-22701 Patchstack
7.5 High Quick Paypal Payments Plugin quick-paypal-payments Broken Access Control No login needed ≤ 5.7.25 Fixed in 5.7.26 CVE-2023-25714 Patchstack
8.6 High Japanized For WooCommerce Plugin woocommerce-for-japan Broken Access Control Multiple Broken Access Control No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2023-47698 Patchstack
8.2 High Stripe Payments Plugin stripe-payments Broken Access Control No login needed ≤ 2.0.79 Fixed in 2.0.80 CVE-2023-48286 Patchstack
7.1 High LadiApp Plugin ladipage Broken Access Control Broken Access Control lead to XSS No login needed ≤ 4.4 CVE-2023-49158 Patchstack
8.2 High Flexible Woocommerce Checkout Field Editor Plugin flexible-woocommerce-checkout-field-editor Broken Access Control No login needed ≤ 2.0.1 CVE-2023-49817 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ 5.2.3.0 Fixed in 5.2.3.1 CVE-2023-49831 Patchstack
8.1 High Smart Forms Plugin smart-forms Broken Access Control Authenticated Arbitrary Options Change ≤ 2.6.84 Fixed in 2.6.85 CVE-2023-49856 Patchstack
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
7.1 High WP GeoNames Plugin wp-geonames Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 Fixed in 1.9 CVE-2024-53812 Patchstack
7.1 High Pie Register Premium Plugin pie-register-premium Cross-Site Scripting No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-53821 Patchstack
7.1 High Block Controller Plugin block-controller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.3 CVE-2024-54208 Patchstack
7.1 High Awesome Shortcodes Plugin awesome-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-54209 Patchstack
7.1 High Paloma Widget Plugin postman-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.14 CVE-2024-54205 Patchstack
7.7 High ARForms Plugin arforms Path Traversal < 7.0.2 Fixed in 7.0.2 CVE-2024-54216 Patchstack
8.5 High WP Mailster Plugin wp-mailster SQL Injection ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53807 Patchstack
8.5 High NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection ≤ 8.7.8 Fixed in 8.7.9 CVE-2024-53808 Patchstack
8.5 High Pinpoint Booking System Plugin booking-system SQL Injection ≤ 2.9.9.5.1 Fixed in 2.9.9.5.2 CVE-2024-53815 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
7.5 High WP Mailster Plugin wp-mailster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53804 Patchstack
7.5 High All Bootstrap Blocks Plugin all-bootstrap-blocks Local File Inclusion ≤ 1.3.19 Fixed in 1.3.20 CVE-2024-53824 Patchstack
7.5 High WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53805 Patchstack
8.1 High Pie Register - Social Sites Login (Add on) Plugin Authentication Bypass User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 1.7.9 CVE-2024-11293 Wordfence
7.1 High Open edX LMS Plugin edunext-openedx-integrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2024-52452 Patchstack
7.1 High Library Bookshelves Plugin library-bookshelves Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 5.9 CVE-2024-52453 Patchstack
7.1 High GoQSmile Plugin goqsmile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52455 Patchstack
7.1 High GoQMieruca Plugin goqmieruca Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2024-52454 Patchstack
7.1 High Youneeq Recommendations Plugin youneeq-panel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.7 CVE-2024-52457 Patchstack
7.1 High Awesome Studio Plugin awesome-studio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2024-52456 Patchstack
7.1 High Chameleoni Jobs Plugin chameleon-jobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-52459 Patchstack
7.1 High TM Islamic Helper Plugin tm-islamic-helper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52458 Patchstack
7.1 High AtaraPay WooCommerce Payment Gateway Plugin atarapay-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-52460 Patchstack
7.1 High WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.2 CVE-2024-52462 Patchstack
7.1 High Infinite Slider Plugin infinite-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-52461 Patchstack
7.1 High amr shortcodes Plugin amr-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2024-52464 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only