WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,001–6,050 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 121 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control Broken Access Control + CSRF ≤ 2.8.1 Fixed in 2.8.2 CVE-2023-34009 Patchstack
4.3 Medium Easy Social Icons Plugin easy-social-icons Broken Access Control ≤ 3.2.5 Fixed in 3.2.6 CVE-2023-33998 Patchstack
4.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control ≤ 1.8.15 Fixed in 1.8.16 CVE-2023-33995 Patchstack
6.5 Medium Slimstat Analytics Plugin wp-slimstat Broken Access Control No login needed ≤ 5.0.5.1 Fixed in 5.0.6 CVE-2023-33994 Patchstack
4.3 Medium WordPress Backup & Migration Plugin wp-migration-duplicator Broken Access Control ≤ 1.4.0 Fixed in 1.4.1 CVE-2023-33928 Patchstack
6.5 Medium Easy Captcha Plugin easy-captcha Broken Access Control No login needed ≤ 1.0 CVE-2023-33324 Patchstack
5.4 Medium Taggbox Plugin taggbox-widget Broken Access Control ≤ 3.3 Fixed in 3.4 CVE-2023-33215 Patchstack
5.3 Medium WooCommerce Predictive Search Plugin woocommerce-predictive-search Broken Access Control No login needed ≤ 5.8.0 Fixed in 5.8.1 CVE-2023-32963 Patchstack
5.3 Medium Simple Page Ordering Plugin simple-page-ordering Broken Access Control No login needed ≤ 2.5.0 Fixed in 2.5.1 CVE-2023-32798 Patchstack
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control ≤ 1.1.12 Fixed in 1.1.13 CVE-2023-32601 Patchstack
4.3 Medium reCAPTCHA for all Plugin recaptcha-for-all Broken Access Control ≤ 1.22 Fixed in 1.23 CVE-2023-32599 Patchstack
5.4 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Broken Access Control ≤ 1.6.7 Fixed in 1.6.8 CVE-2023-32593 Patchstack
4.3 Medium Soundcloud Is Gold Plugin soundcloud-is-gold Broken Access Control ≤ 2.5.1 CVE-2023-32586 Patchstack
5.4 Medium WP-Chatbot for Messenger Plugin wp-chatbot Broken Access Control ≤ 4.7 Fixed in 4.8 CVE-2023-32581 Patchstack
4.3 Medium Injection Guard Plugin injection-guard Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2023-32574 Patchstack
4.3 Medium WCP Contact Form Plugin wcp-contact-form Broken Access Control ≤ 3.1.0 CVE-2023-32519 Patchstack
6.5 Medium Link Whisper Free Plugin link-whisper Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 0.6.3 Fixed in 0.6.4 CVE-2023-32506 Patchstack
4.3 Medium Viral Mag Theme viral-mag Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 1.0.9 Fixed in 1.1.0 CVE-2023-28990 Patchstack
4.3 Medium Total Theme total Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 2.1.19 Fixed in 2.1.20 CVE-2023-27456 Patchstack
5.3 Medium Coming Soon Landing Page and Maintenance Mode Plugin 8-degree-coming-soon-page Broken Access Control No login needed ≤ 2.2.0 CVE-2022-47429 Patchstack
5.3 Medium Owl Carousel Plugin owl-carousel Broken Access Control No login needed ≤ 0.5.3 CVE-2022-44578 Patchstack
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.2.1 CVE-2023-22697 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control No login needed ≤ 3.8.5 Fixed in 3.8.6 CVE-2022-47594 Patchstack
5.3 Medium APIExperts Square for WooCommerce Plugin woosquare Broken Access Control No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2022-47182 Patchstack
4.3 Medium Depicter Slider Plugin depicter Broken Access Control ≤ 1.9.0 Fixed in 1.9.1 CVE-2022-47176 Patchstack
4.3 Medium Printful Integration for WooCommerce Plugin printful-shipping-for-woocommerce Cross-Site Request Forgery ≤ 2.2.3 Fixed in 2.2.4 CVE-2022-47168 Patchstack
5.3 Medium Trending/Popular Post Slider and Widget Plugin wp-trending-post-slider-and-widget Broken Access Control No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2022-46846 Patchstack
5.4 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46840 Patchstack
4.3 Medium ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Plugin woo-alidropship Broken Access Control Broken Access Control + CSRF ≤ 1.0.21 Fixed in 1.0.22 CVE-2022-46811 Patchstack
4.3 Medium Stock Sync for WooCommerce Plugin stock-sync-for-woocommerce Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2022-46807 Patchstack
6.5 Medium CURCY Plugin woo-multi-currency Broken Access Control Unauthenticated plugin settings change No login needed ≤ 2.1.25 Fixed in 2.1.26 CVE-2022-46796 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery CSRF Plugin Settings Reset No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2022-46795 Patchstack
5.4 Medium Robo Gallery Plugin robo-gallery Broken Access Control Auth. Broken Access Control ≤ 3.2.9 Fixed in 3.2.11 CVE-2022-45841 Patchstack
6.5 Medium Auto Affiliate Links Plugin wp-auto-affiliate-links Broken Access Control Unauth. Broken Access Control No login needed ≤ 6.2.1.5 Fixed in 6.2.1.6 CVE-2022-45840 Patchstack
5.4 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control Auth. Broken Access Control No login needed ≤ 2.9.13 Fixed in 2.9.14 CVE-2022-45826 Patchstack
4.3 Medium Formidable Forms Plugin formidable Broken Access Control No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2022-45806 Patchstack
4.3 Medium eRoom – Zoom Meetings & Webinar Plugin eroom-zoom-meetings-webinar Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2022-43472 Patchstack
6.3 Medium Notibar – Notification Bar Plugin notibar Arbitrary Shortcode Execution Notification Bar for WordPress <= 2.1.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via njt_nofi_text ≤ 2.1.4 CVE-2024-11012 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin Cross-Site Scripting WordPress Page Builder <= 2.8.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.4.4 CVE-2024-11832 Wordfence
6.4 Medium WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more Plugin gs-books-showcase Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-11766 Wordfence
6.4 Medium WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more Plugin gs-portfolio Cross-Site Scripting A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.3 CVE-2024-11765 Wordfence
5.3 Medium Restrict – membership, site, content and user access restrictions Plugin restricted-content Information Disclosure membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.2.8 CVE-2024-11351 Wordfence
4.3 Medium Notibar Plugin notibar Broken Access Control ≤ 2.1.4 Fixed in 2.1.5 CVE-2024-54269 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Information Disclosure WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.3 CVE-2024-11868 Wordfence
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41953 Patchstack
6.5 Medium Analytify Plugin wp-analytify Broken Access Control ≤ 5.4.3 Fixed in 5.5.0 CVE-2024-53814 Patchstack
6.5 Medium AIO Contact Plugin aio-contact Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 2.8.1 CVE-2024-54218 Patchstack
4.3 Medium Team Member Plugin team-showcase-supreme Local File Inclusion Multi Language Supported Team plugin <= 7.4 - Limited Local File Inclusion ≤ 7.4 Fixed in 7.5 CVE-2024-52385 Patchstack
5.3 Medium Pie Register Premium Plugin pie-register-premium Broken Access Control No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-52391 Patchstack
5.3 Medium Jobify Theme jobify Broken Access Control No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52480 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only