WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 6,101–6,150 of 8,943 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Top 10 | Broken Access Control Popular posts plugin for WordPress plugin <= 3.2.3 - Broken Access Control |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2023-25993 |
Patchstack | |
| 6.5 Medium | WP Repost | Broken Access Control No login needed |
≤ 0.1 |
CVE-2023-26522 |
Patchstack | |
| 5.4 Medium | WP users media | Broken Access Control |
≤ 4.2.3 |
CVE-2023-27428 |
Patchstack | |
| 6.3 Medium | Total Poll Lite | Broken Access Control |
≤ 4.8.6 Fixed in 4.8.7 |
CVE-2023-27449 |
Patchstack | |
| 5.4 Medium | Rife Elementor Extensions & Templates | Broken Access Control |
≤ 1.1.10 Fixed in 1.2.0 |
CVE-2023-27454 |
Patchstack | |
| 5.3 Medium | Stock Ticker | Broken Access Control No login needed |
≤ 3.23.0 Fixed in 3.23.1 |
CVE-2023-27626 |
Patchstack | |
| 4.3 Medium | Site Reviews | Broken Access Control |
≤ 6.5.0 Fixed in 6.6.0 |
CVE-2023-27625 |
Patchstack | |
| 4.3 Medium | Backup Bank: WordPress Backup | Broken Access Control |
≤ 4.0.28 |
CVE-2023-28165 |
Patchstack | |
| 4.3 Medium | Chankhe | Broken Access Control Authenticated Arbitrary Plugin Activation |
≤ 1.0.5 |
CVE-2023-28416 |
Patchstack | |
| 4.3 Medium | Real Estate Directory | Broken Access Control Authenticated Arbitrary Plugin Activation |
≤ 1.0.5 Fixed in 1.0.6 |
CVE-2023-28532 |
Patchstack | |
| 5.4 Medium | Dynamics 365 Integration | Broken Access Control |
≤ 1.3.12 Fixed in 1.3.13 |
CVE-2023-28417 |
Patchstack | |
| 5.3 Medium | Branded Social Images | Broken Access Control No login needed |
≤ 1.1.0 Fixed in 1.1.1 |
CVE-2023-28536 |
Patchstack | |
| 5.4 Medium | TH Variation Swatches | Cross-Site Request Forgery No login needed |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2023-28688 |
Patchstack | |
| 6.5 Medium | JS Job Manager | Broken Access Control |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2023-28689 |
Patchstack | |
| 6.3 Medium | Remove Duplicate Posts | Broken Access Control |
≤ 1.3.5 Fixed in 1.3.6 |
CVE-2023-29237 |
Patchstack | |
| 5.3 Medium | Product Category Tree | Broken Access Control No login needed |
≤ 2.5 |
CVE-2023-29173 |
Patchstack | |
| 5.4 Medium | LuckyWP Scripts Control | Broken Access Control |
≤ 1.2.1 Fixed in 1.2.2 |
CVE-2023-29239 |
Patchstack | |
| 4.3 Medium | Dynamics 365 Integration | Broken Access Control |
≤ 1.3.13 Fixed in 1.3.14 |
CVE-2023-29422 |
Patchstack | |
| 5.3 Medium | User Registration | Broken Access Control No login needed |
≤ 2.3.2.1 Fixed in 2.3.3 |
CVE-2023-29429 |
Patchstack | |
| 4.3 Medium | qTranslate X Cleanup and WPML Import | Broken Access Control |
≤ 3.0.1 Fixed in 3.0.2 |
CVE-2023-29431 |
Patchstack | |
| 5.4 Medium | tencentcloud-cos | Broken Access Control |
≤ 1.0.7 |
CVE-2023-29433 |
Patchstack | |
| 5.3 Medium | Stamped.io Product Reviews & UGC for WooCommerce | Broken Access Control No login needed |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2023-30479 |
Patchstack | |
| 4.3 Medium | Blogger Buzz | Broken Access Control |
≤ 1.2.2 |
CVE-2023-30476 |
Patchstack | |
| 4.3 Medium | Square | Broken Access Control |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2023-30486 |
Patchstack | |
| 5.3 Medium | Featured Post Creative | Broken Access Control No login needed |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2023-30488 |
Patchstack | |
| 4.3 Medium | Easy Appointments | Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) No login needed |
≤ 3.10.7 Fixed in 3.11.1 |
CVE-2023-30748 |
Patchstack | |
| 6.5 Medium | Sharkdropship for AliExpress Dropship and Affiliate | Broken Access Control Multiple Broken Access Control vulnerabilities No login needed |
≤ 2.2.3 Fixed in 2.2.5 |
CVE-2023-30870 |
Patchstack | |
| 4.3 Medium | Smart WooCommerce Search | Broken Access Control |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2023-30783 |
Patchstack | |
| 5.4 Medium | WP Docs | Broken Access Control |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2023-30873 |
Patchstack | |
| 4.3 Medium | Display custom fields in the frontend – Post and User Profile Fields | Broken Access Control |
≤ 1.2.0 Fixed in 1.2.1 |
CVE-2023-31073 |
Patchstack | |
| 5.4 Medium | WP Quick Post Duplicator | Broken Access Control |
≤ 2.0 Fixed in 2.1 |
CVE-2023-31214 |
Patchstack | |
| 5.4 Medium | Extended Post Status | Broken Access Control |
≤ 1.0.19 Fixed in 1.0.20 |
CVE-2023-32094 |
Patchstack | |
| 5.3 Medium | WRC Pricing Tables | Broken Access Control No login needed |
≤ 2.3.7 Fixed in 2.3.8 |
CVE-2023-32293 |
Patchstack | |
| 4.3 Medium | SALERT | Broken Access Control |
≤ 1.2.1 Fixed in 1.2.2 |
CVE-2023-32126 |
Patchstack | |
| 6.5 Medium | Ni WooCommerce Sales Report | Broken Access Control |
≤ 3.7.3 Fixed in 3.7.4 |
CVE-2023-32299 |
Patchstack | |
| 5.4 Medium | Mini Cart Drawer For WooCommerce | Broken Access Control No login needed |
≤ 4.0.0 Fixed in 4.0.1 |
CVE-2023-47694 |
Patchstack | |
| 4.3 Medium | Welcome Email Editor | Broken Access Control |
≤ 5.0.6 Fixed in 5.0.7 |
CVE-2023-47756 |
Patchstack | |
| 4.3 Medium | Essential Blocks for Gutenberg | Broken Access Control |
≤ 4.2.0 Fixed in 4.2.1 |
CVE-2023-47760 |
Patchstack | |
| 4.3 Medium | Simple 301 Redirects by BetterLinks | Broken Access Control |
≤ 2.0.7 Fixed in 2.0.8 |
CVE-2023-47761 |
Patchstack | |
| 4.3 Medium | WP Custom Admin Interface | Broken Access Control |
≤ 7.31 Fixed in 7.32 |
CVE-2023-47763 |
Patchstack | |
| 4.3 Medium | BetterDocs | Broken Access Control |
≤ 2.5.2 Fixed in 2.5.3 |
CVE-2023-47762 |
Patchstack | |
| 6.5 Medium | Ditty | Broken Access Control No login needed |
≤ 3.1.24 Fixed in 3.1.25 |
CVE-2023-47764 |
Patchstack | |
| 4.3 Medium | miniorange otp verification | Broken Access Control |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2023-47776 |
Patchstack | |
| 4.3 Medium | EasyAzon | Broken Access Control Amazon Associates Affiliate Plugin plugin <= 5.1.0 - Broken Access Control |
≤ 5.1.0 Fixed in 5.1.1 |
CVE-2023-47780 |
Patchstack | |
| 4.3 Medium | Acme Fix Images | Broken Access Control |
≤ 1.0.0 Fixed in 2.0.0 |
CVE-2023-47793 |
Patchstack | |
| 5.3 Medium | WPCafe | Broken Access Control No login needed |
≤ 2.2.22 Fixed in 2.2.23 |
CVE-2023-47805 |
Patchstack | |
| 4.3 Medium | WP Like Button | Broken Access Control |
≤ 1.7.0 |
CVE-2023-47820 |
Patchstack | |
| 5.4 Medium | MP3 Audio Player for Music, Radio & Podcast by Sonaar | Broken Access Control |
≤ 4.10 Fixed in 4.10.1 |
CVE-2023-47822 |
Patchstack | |
| 5.3 Medium | FormCraft | Broken Access Control Contact Form Builder for WordPress plugin <= 1.2.7 - Broken Access Control No login needed |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2023-47823 |
Patchstack | |
| 6.5 Medium | Restaurant & Cafe Addon for Elementor | Broken Access Control No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2023-47826 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.