WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,801–5,850 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 117 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.32 Fixed in 7.33 CVE-2023-44988 Patchstack
5.3 Medium Schema App Structured Data Plugin schema-app-structured-data-for-schemaorg Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.23.1 Fixed in 1.23.2 CVE-2023-44258 Patchstack
6.5 Medium Inline Footnotes Plugin inline-footnotes Cross-Site Scripting ≤ 2.3.0 CVE-2024-56019 Patchstack
6.5 Medium SvegliaT Buttons Plugin svegliat-buttons Cross-Site Scripting ≤ 1.3.0 CVE-2024-56020 Patchstack
6.5 Medium Category Post Shortcode Plugin category-post-shortcode Cross-Site Scripting ≤ 2.4 CVE-2024-56021 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.987 Fixed in 1.7.1 CVE-2024-56062 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
5.4 Medium Landing Page Cat Plugin landing-page-cat Broken Access Control ≤ 1.7.4 Fixed in 1.7.5 CVE-2024-49686 Patchstack
4.3 Medium Smart Manager Plugin smart-manager-for-wp-e-commerce Broken Access Control ≤ 8.45.0 Fixed in 8.46.0 CVE-2024-49687 Patchstack
5.3 Medium My Wp Brand Plugin my-wp-brand Broken Access Control Hide menu & Hide Plugin plugin <= 1.1.2 - Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-49694 Patchstack
4.3 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-49698 Patchstack
4.3 Medium Paytium Plugin paytium Broken Access Control ≤ 4.4.10 Fixed in 4.4.11 CVE-2024-51667 Patchstack
6.5 Medium Torod Plugin torod Broken Access Control Settings Change No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-55995 Patchstack
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Broken Access Control MightyForms plugin <= 1.3.9 - Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2024-56002 Patchstack
6.5 Medium WP-CRM System Plugin wp-crm-system Broken Access Control WP-CRM System plugin <= 3.2.9.1 - Broken Access Control No login needed ≤ 3.2.9.1 Fixed in 3.4.0 CVE-2024-55991 Patchstack
6.5 Medium Smart Shopify Product Plugin smart-shopify-product Broken Access Control Arbitrary Content Deletion ≤ 1.0.2 CVE-2024-56031 Patchstack
5.3 Medium WP Cleanfix Plugin wp-cleanfix Broken Access Control No login needed ≤ 5.6.2 Fixed in 5.7.0 CVE-2023-48775 Patchstack
4.3 Medium WooCommerce Subscriptions Plugin woocommerce-subscriptions Broken Access Control < 5.8.0 Fixed in 5.8.0 CVE-2023-50850 Patchstack
6.5 Medium WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-56221 Patchstack
6.5 Medium Ledenbeheer Plugin ledenbeheer-external-connection Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-56224 Patchstack
6.5 Medium SaasPricing Plugin saaspricing Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-56231 Patchstack
5.4 Medium VW Automobile Lite Plugin vw-automobile-lite Broken Access Control ≤ 2.1 CVE-2024-56234 Patchstack
4.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56227 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control ≤ 4.0.6.1 Fixed in 4.0.8 CVE-2024-56219 Patchstack
4.3 Medium Download Manager Plugin download-manager Broken Access Control ≤ 3.3.03 Fixed in 3.3.04 CVE-2024-56217 Patchstack
4.3 Medium Member Directory and Contact Form Plugin pta-member-directory Broken Access Control ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-56215 Patchstack
6.5 Medium Coupon Plugin coupon-lite Cross-Site Scripting ≤ 1.2.2 CVE-2024-56235 Patchstack
5.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Cross-Site Scripting ≤ 2.3.1 Fixed in 2.4.0 CVE-2024-56256 Patchstack
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Request Forgery Dynamic Text Extension plugin <= 5.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.0.1 Fixed in 5.0.2 CVE-2024-56218 Patchstack
5.4 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56222 Patchstack
4.3 Medium SearchIQ Plugin searchiq Cross-Site Request Forgery No login needed ≤ 4.6 Fixed in 4.7 CVE-2024-56229 Patchstack
6.5 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 4.0.7 Fixed in 4.0.9 CVE-2024-56213 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Local File Inclusion ≤ 7.6.3 Fixed in 7.6.5 CVE-2024-56216 Patchstack
4.3 Medium Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages Plugin Cross-Site Request Forgery No login needed ≤ 3.2.7 CVE-2024-12636 Wordfence
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
6.4 Medium WordPress Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.7 CVE-2024-12622 Wordfence
6.1 Medium Bitcoin Lightning Publisher Plugin bitcoin-lightning-publisher Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.1 CVE-2024-12100 Wordfence
6.4 Medium NACC Plugin nacc-wordpress-plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2024-12506 Wordfence
6.4 Medium Sell Tickets Online – TicketSource Ticket Shop Plugin ticketsource-events Cross-Site Scripting TicketSource Ticket Shop for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.0.2 CVE-2024-11784 Wordfence
5.3 Medium Page Restriction WordPress (WP) – Protect WP Pages/Post Plugin page-and-post-restriction Information Disclosure Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.3.6 CVE-2024-11297 Wordfence
6.5 Medium Fusion Plugin fusion Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37962 Patchstack
6.5 Medium WP Menu Image Plugin wp-menu-image Broken Access Control No login needed ≤ 2.2 Fixed in 2.3 CVE-2024-52485 Patchstack
6.5 Medium Order Delivery & Pickup Location Date Time Plugin order-delivery-pickup-location-date-time-free-version Broken Access Control Settings Change No login needed ≤ 1.1.0 CVE-2024-55997 Patchstack
6.1 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via 'number' No login needed ≤ 1.4.7 CVE-2024-12395 Wordfence
6.1 Medium Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS Plugin sikshya Cross-Site Scripting Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter No login needed ≤ 0.0.21 CVE-2024-12127 Wordfence
6.4 Medium CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Plugin support-x Cross-Site Scripting WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.6 CVE-2024-12443 Wordfence
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed ≤ 7.11.10 Fixed in 7.11.11 CVE-2024-54357 Patchstack
4.3 Medium Caldera SMTP Mailer Plugin caldera-smtp-mailer Broken Access Control ≤ 1.0.1 CVE-2024-56003 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only