WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,901–5,950 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 119 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Gou Manage My Account Menu Plugin gou-wc-account-tabs Broken Access Control No login needed ≤ 1.0.1.8 Fixed in 1.0.1.9 CVE-2024-54310 Patchstack
6.5 Medium PostBox Plugin postbox-email-logs Information Disclosure Sensitive Data Exposure ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-54309 Patchstack
5.9 Medium Cryptocurrency Price Widget Plugin cryptocurrency-price-widget Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-54308 Patchstack
4.3 Medium AIcomments Plugin aicomments Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-54307 Patchstack
4.3 Medium AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot Plugin ai-seo-translator Cross-Site Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-54306 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Cross-Site Request Forgery No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-54300 Patchstack
4.3 Medium Car Dealer Plugin cardealer Broken Access Control ≤ 4.46 Fixed in 4.48 CVE-2024-54298 Patchstack
6.5 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-54289 Patchstack
6.5 Medium Advanced Blog Post Block Plugin advanced-blog-post-block Cross-Site Scripting ≤ 1.0.4 CVE-2024-54287 Patchstack
6.5 Medium Smaily for WP Plugin smaily-for-wp Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2024-54286 Patchstack
4.3 Medium News Ticker for Elementor Plugin news-ticker-for-elementor Broken Access Control ≤ 2.1.3 CVE-2024-54278 Patchstack
6.5 Medium Nias course Plugin nias-course Cross-Site Scripting ≤ 1.2.10 CVE-2024-54277 Patchstack
6.5 Medium Poll Builder Plugin poll-builder Cross-Site Scripting ≤ 1.3.5 CVE-2024-54276 Patchstack
6.5 Medium Radius Blocks Plugin radius-blocks Cross-Site Scripting ≤ 2.1.2 Fixed in 2.2.0 CVE-2024-54272 Patchstack
5.4 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Settings Change ≤ 8.0.2 CVE-2024-54271 Patchstack
4.3 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Broken Access Control ≤ 1.64.0 Fixed in 1.64.1 CVE-2024-54268 Patchstack
4.3 Medium CM Answers Plugin cm-answers Broken Access Control ≤ 3.2.6 Fixed in 3.2.7 CVE-2024-54267 Patchstack
6.5 Medium DELUCKS SEO Plugin delucks-seo Path Traversal Arbitrary File Download ≤ 2.7.0 CVE-2024-54259 Patchstack
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Cross-Site Scripting ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-54250 Patchstack
6.5 Medium FAQs Plugin faqs Cross-Site Scripting ≤ 1.0.2 CVE-2024-54246 Patchstack
6.5 Medium Clients Plugin clients Cross-Site Scripting ≤ 1.1.4 CVE-2024-54245 Patchstack
6.5 Medium Easy Replace Plugin easy-replace Cross-Site Scripting ≤ 1.3 CVE-2024-54244 Patchstack
6.5 Medium Echoza Plugin echoza Cross-Site Scripting ≤ 0.1.1 CVE-2024-54243 Patchstack
6.5 Medium Simple Notification Plugin simple-notification Broken Access Control ≤ 1.3 CVE-2024-54242 Patchstack
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium Comment Blacklist Updater Plugin comment-blacklist-updater Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.2.0 CVE-2023-44147 Patchstack
5.4 Medium Inactive Logout Plugin inactive-logout Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2023-44142 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.3 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control ≤ 4.6.14 Fixed in 4.6.15 CVE-2023-41951 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-41875 Patchstack
4.3 Medium SAML SP Single Sign On Plugin miniorange-saml-20-single-sign-on Broken Access Control SSO Login plugin <= 5.0.4 - Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2023-41873 Patchstack
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2023-41870 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.4 Fixed in 0.6.2.5 CVE-2023-41869 Patchstack
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Slider Pro Plugin sliderpro Broken Access Control ≤ 4.8.6 Fixed in 4.8.7 CVE-2023-41865 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.0 Fixed in 14.1 CVE-2023-41862 Patchstack
5.4 Medium Click To Tweet Plugin click-to-tweet Broken Access Control No login needed ≤ 2.0.14 CVE-2023-41857 Patchstack
5.3 Medium Posts Like Dislike Plugin posts-like-dislike Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2023-41849 Patchstack
5.3 Medium Carousel Slider Plugin carousel-slider Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-41848 Patchstack
5.3 Medium BitPay Checkout for WooCommerce Plugin bitpay-checkout-for-woocommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 5.0.0 CVE-2023-41803 Patchstack
4.3 Medium Super Socializer Plugin super-socializer Broken Access Control ≤ 7.13.54 Fixed in 7.13.55 CVE-2023-41802 Patchstack
5.3 Medium WiserNotify Social Proof Plugin wiser-notify Broken Access Control No login needed ≤ 2.5 Fixed in 2.6 CVE-2023-41690 Patchstack
4.3 Medium Post to Google My Business (Google Business Profile) Plugin post-to-google-my-business Broken Access Control ≤ 3.1.14 Fixed in 3.1.15 CVE-2023-41689 Patchstack
5.4 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Broken Access Control ≤ 1.5 Fixed in 1.51 CVE-2023-41688 Patchstack
6.5 Medium Woocommerce Support System Plugin wc-support-system Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-41686 Patchstack
5.4 Medium TelSender Plugin telsender Broken Access Control Broken Access Control + CSRF ≤ 1.14.11 Fixed in 1.14.12 CVE-2023-41683 Patchstack
5.4 Medium Abandoned Cart Lite for WooCommerce Plugin woocommerce-abandoned-cart Cross-Site Request Forgery ≤ 5.16.1 Fixed in 5.16.2 CVE-2023-41671 Patchstack
6.5 Medium Easy Newsletter Signups Plugin easy-newsletter-signups Broken Access Control No login needed ≤ 1.0.4 CVE-2023-41664 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only