WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,651–5,700 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 114 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
5.4 Medium 10Web Map Builder for Google Maps Plugin wd-google-maps Broken Access Control Notice Dismissal ≤ 1.0.73 Fixed in 1.0.74 CVE-2023-45272 Patchstack
6.5 Medium IMPress Listings Plugin wp-listings Broken Access Control No login needed ≤ 2.6.2 CVE-2023-45633 Patchstack
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
4.3 Medium Subscribe to Category Plugin subscribe-to-category Broken Access Control WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to Broken Access Control ≤ 2.7.4 CVE-2022-43476 Patchstack
4.3 Medium LuckyWP Scripts Control Plugin luckywp-scripts-control Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2023-47778 Patchstack
4.3 Medium 10WebAnalytics Plugin wd-google-analytics Broken Access Control ≤ 1.2.12 CVE-2023-47807 Patchstack
5.3 Medium Porto Theme - Functionality Plugin porto-functionality Broken Access Control No login needed ≤ 2.12.1 Fixed in 2.12.1 CVE-2023-48739 Patchstack
4.3 Medium FS Poster Plugin fs-poster Cross-Site Request Forgery No login needed ≤ 6.5.8 Fixed in 6.5.9 CVE-2024-37237 Patchstack
4.3 Medium WP Job Manager - Resume Manager Plugin wp-job-manager-resumes Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-37241 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Request Forgery No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37438 Patchstack
4.3 Medium Schema Lite Theme schema-lite Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2024-37452 Patchstack
5.4 Medium BuddyBoss Theme buddyboss-theme Cross-Site Request Forgery No login needed ≤ 2.4.61 Fixed in 2.5.01 CVE-2024-37925 Patchstack
4.3 Medium Point Theme point Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-37931 Patchstack
4.3 Medium i-amaze Theme i-amaze Cross-Site Request Forgery No login needed ≤ 1.3.7 CVE-2024-38731 Patchstack
4.3 Medium Patricia Blog Theme patricia-blog Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2024-38732 Patchstack
4.3 Medium i-transform Theme i-transform Cross-Site Request Forgery No login needed ≤ 3.0.9 CVE-2024-38764 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.69.234 Fixed in 1.70.236 CVE-2024-38778 Patchstack
6.5 Medium Coins MarketCap Plugin coins-marketcap Cross-Site Scripting ≤ 5.5.8 Fixed in 5.5.9 CVE-2024-56257 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56302 Patchstack
6.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.8 Fixed in 5.9 CVE-2024-56266 Patchstack
6.6 Medium ACF City Selector Plugin acf-city-selector Arbitrary File Upload ≤ 1.14.0 Fixed in 1.15.0 CVE-2024-56264 Patchstack
6.5 Medium GS Shots for Dribbble Plugin gs-dribbble-portfolio Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-56263 Patchstack
6.5 Medium GS Coaches Plugin gs-coach Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56262 Patchstack
6.5 Medium Project Showcase Plugin gs-projects Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56261 Patchstack
6.5 Medium ShopElement Plugin shopelement Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-56260 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.84 Fixed in 2.3.85 CVE-2024-56259 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.20 Fixed in 1.3.21 CVE-2024-56258 Patchstack
4.3 Medium AyeCode Connect Plugin ayecode-connect Broken Access Control ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-56255 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
5.4 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.36 Fixed in 1.10.37 CVE-2024-56253 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-56252 Patchstack
4.3 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Cross-Site Request Forgery No login needed ≤ 5.0.28.decaf Fixed in 5.0.31.decaf CVE-2024-56251 Patchstack
4.9 Medium WPMasterToolKit Plugin wpmastertoolkit Path Traversal Arbitrary File Download ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56248 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2024-56246 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
5.4 Medium Ashe Extra Plugin ashe-extra Broken Access Control ≤ 1.2.92 Fixed in 1.3 CVE-2024-56244 Patchstack
4.3 Medium WPSSO Core Plugin wpsso Broken Access Control ≤ 18.18.1 Fixed in 18.18.2 CVE-2024-56243 Patchstack
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.14 Fixed in 2.1.15 CVE-2024-56242 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-56241 Patchstack
6.5 Medium Pronamic Google Maps Plugin pronamic-google-maps Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2024-56240 Patchstack
6.5 Medium Themify Audio Dock Plugin themify-audio-dock Cross-Site Scripting ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-56239 Patchstack
5.3 Medium Floating Action Buttons Plugin floating-action-buttons Broken Access Control No login needed ≤ 0.9.1 Fixed in 1.0.1 CVE-2024-56238 Patchstack
5.9 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-56237 Patchstack
4.3 Medium Hestia Nginx Cache Plugin hestia-nginx-cache Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2024-56236 Patchstack
4.3 Medium Email Address Encoder Plugin email-address-encoder Cross-Site Request Forgery No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-43927 Patchstack
6.5 Medium Smartsupp – live chat, chatbots, AI and lead generation Plugin smartsupp-live-chat Cross-Site Request Forgery No login needed ≤ 3.6 Fixed in 3.7 CVE-2024-38790 Patchstack
5.3 Medium Telegram Bot & Channel Plugin telegram-bot Cross-Site Request Forgery No login needed ≤ 3.8.2 Fixed in 4.0.1 CVE-2024-38789 Patchstack
4.3 Medium Matomo Analytics Plugin matomo Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to Notice Dismissal No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2024-38766 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only