WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,051–6,100 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 122 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Chatter Plugin chatter Broken Access Control ≤ 1.0.1 CVE-2024-53785 Patchstack
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-53816 Patchstack
5.4 Medium ARForms Plugin arforms Broken Access Control Subscriber+ Plugin Settings Change ≤ 6.4.1 CVE-2024-54217 Patchstack
6.5 Medium Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Cross-Site Scripting ≤ 1.3.9 CVE-2024-53791 Patchstack
5.4 Medium FloristPress Plugin bakkbone-florist-companion Broken Access Control Nonce Leakage to Broken Access Control ≤ 7.3.0 Fixed in 7.4.0 CVE-2024-53798 Patchstack
6.5 Medium PostX Plugin ultimate-post Cross-Site Scripting ≤ 4.1.15 Fixed in 4.1.16 CVE-2024-53818 Patchstack
6.5 Medium ABCBiz Addons and Templates for Elementor Plugin abcbiz-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-54247 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.6.5 Fixed in 1.4.6.6 CVE-2024-54253 Patchstack
6.3 Medium Message Filter for Contact Form 7 Plugin cf7-message-filter Broken Access Control ≤ 1.6.3 Fixed in 1.6.3.1 CVE-2024-54254 Patchstack
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 20.8.0 Fixed in 20.8.1 CVE-2024-53819 Patchstack
4.3 Medium Super Progressive Web Apps Plugin super-progressive-web-apps Broken Access Control No login needed ≤ 2.2.21 Fixed in 2.2.22 CVE-2023-48277 Patchstack
4.3 Medium Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54227 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Broken Access Control ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-54251 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.7 Fixed in 6.4.8 CVE-2024-54224 Patchstack
6.5 Medium Wot Elementor Widgets Plugin wot-elementor-widgets Cross-Site Scripting ≤ 1.0.1 CVE-2024-54228 Patchstack
6.5 Medium Unlock Addons for Elementor Plugin unlock-addons-for-elementor Cross-Site Scripting ≤ 2.2.4 CVE-2024-54230 Patchstack
6.5 Medium RRAddons for Elementor Plugin rrdevs-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2024-54232 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2024-54260 Patchstack
4.7 Medium Login Widget With Shortcode Plugin login-sidebar-widget Open Redirect No login needed ≤ 6.1.2 CVE-2024-54255 Patchstack
5.3 Medium ARForms Form Builder Plugin arforms-form-builder Content Injection HTML Injection No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-54223 Patchstack
4.3 Medium Kraken.io Image Optimizer Plugin kraken-image-optimizer Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2023-22708 Patchstack
5.2 Medium JobBoardWP – Job Board Listings and Submissions Plugin jobboardwp Broken Access Control Job Board Listings and Submissions plugin <= 1.2.2 - IDOR Leading To Job Removal ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-23715 Patchstack
4.3 Medium Zendesk Support Plugin zendesk Broken Access Control ≤ 1.8.4 Fixed in 1.8.5 CVE-2023-23716 Patchstack
4.3 Medium Shortcodes Plugin wc-shortcodes Broken Access Control No login needed ≤ 3.46 CVE-2023-23725 Patchstack
5.4 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change No login needed ≤ 3.5.1.0 Fixed in 3.5.1.1 CVE-2023-23726 Patchstack
4.3 Medium Enhanced Text Widget Plugin enhanced-text-widget Broken Access Control ≤ 1.5.8 Fixed in 1.5.9 CVE-2023-23823 Patchstack
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Activate_Plugin No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23834 Patchstack
5.4 Medium Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2023-23868 Patchstack
5.4 Medium WP-RecentComments Plugin wp-recentcomments Broken Access Control ≤ 2.2.7 CVE-2023-23886 Patchstack
5.3 Medium Easy Google Analytics Plugin easy-google-analytics-for-wordpress Broken Access Control No login needed ≤ 1.6.0 CVE-2023-23887 Patchstack
5.3 Medium Simple Giveaways Plugin giveasap Broken Access Control No login needed ≤ 2.48.0 Fixed in 2.48.1 CVE-2023-23893 Patchstack
5.3 Medium Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.7.4 Fixed in 9.7.5 CVE-2023-23975 Patchstack
4.7 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.1.82 Fixed in 1.1.83 CVE-2023-23895 Patchstack
5.4 Medium Reviews and Rating – Google My Business Plugin g-business-reviews-rating Broken Access Control Google My Business plugin <= 4.14 - Broken Access Control No login needed ≤ 4.14 Fixed in 4.15 CVE-2023-23986 Patchstack
5.0 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24407 Patchstack
4.3 Medium PayPal Brasil para WooCommerce Plugin paypal-brasil-para-woocommerce Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2023-25026 Patchstack
6.5 Medium Quick Contact Form Plugin quick-contact-form Broken Access Control No login needed ≤ 8.0.3.1 Fixed in 8.0.4 CVE-2023-25035 Patchstack
4.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control ≤ 1.2.34 Fixed in 1.2.35 CVE-2023-25037 Patchstack
5.3 Medium Fantastic Content Protector Free Plugin fantastic-content-protector-free Broken Access Control No login needed ≤ 2.6 CVE-2023-25048 Patchstack
4.3 Medium We’re Open! Plugin opening-hours Broken Access Control No login needed ≤ 1.45 Fixed in 1.46 CVE-2023-25067 Patchstack
5.3 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2023-25060 Patchstack
6.5 Medium Protected Posts Logout Button Plugin protected-posts-logout-button Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2023-25454 Patchstack
5.3 Medium WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Broken Access Control Arbitrary Content Deletion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2023-25455 Patchstack
5.4 Medium Easy Table of Contents Plugin easy-table-of-contents Broken Access Control ≤ 2.0.45.2 Fixed in 2.0.46 CVE-2023-25469 Patchstack
5.3 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.7 CVE-2023-25703 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2023-25486 Patchstack
5.4 Medium Fontiran Plugin fontiran Broken Access Control ≤ 2.1 CVE-2023-25791 Patchstack
5.4 Medium Apollo13 Framework Extensions Plugin apollo13-framework-extensions Broken Access Control ≤ 1.8.10 Fixed in 1.9.0 CVE-2023-25959 Patchstack
5.5 Medium Filebird Plugin filebird Broken Access Control ≤ 5.1.4 Fixed in 5.1.5 CVE-2023-25966 Patchstack
5.3 Medium Advanced Text Widget Plugin advanced-text-widget Broken Access Control No login needed ≤ 2.1.2 CVE-2023-26520 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only