WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,151–6,200 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 124 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Live Preview for Contact Form 7 Plugin cf7-live-preview Broken Access Control ≤ 1.2.0 CVE-2023-47830 Patchstack
5.4 Medium WP Meta and Date Remover Plugin wp-meta-and-date-remover Broken Access Control ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-47836 Patchstack
5.3 Medium SearchIQ Plugin searchiq Broken Access Control No login needed ≤ 4.4 Fixed in 4.5 CVE-2023-47832 Patchstack
4.3 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Broken Access Control ≤ 2.4.1 Fixed in 2.4.2 CVE-2023-47838 Patchstack
4.3 Medium Analytify Plugin wp-analytify Broken Access Control ≤ 5.1.1 Fixed in 5.2.0 CVE-2023-47841 Patchstack
5.3 Medium PayTR Taksit Tablosu Plugin paytr-taksit-tablosu-woocommerce Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-47847 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Broken Access Control + CSRF ≤ 2.2.5 Fixed in 2.2.6 CVE-2023-47869 Patchstack
4.3 Medium BlossomThemes Email Newsletter Plugin blossomthemes-email-newsletter Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2023-47849 Patchstack
4.3 Medium Contact Form to Any API Plugin contact-form-to-any-api Broken Access Control ≤ 1.1.6 Fixed in 1.1.7 CVE-2023-47871 Patchstack
6.5 Medium WCMultiShipping Plugin wc-multishipping Broken Access Control ≤ 2.3.5 Fixed in 2.3.6 CVE-2023-48274 Patchstack
5.4 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.1.4 Fixed in 6.1.5 CVE-2023-48324 Patchstack
5.4 Medium TextMe SMS Plugin textme-sms-integration Broken Access Control ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-48287 Patchstack
4.3 Medium Mail Bank - #1 Mail SMTP Plugin wp-mail-bank Broken Access Control #1 Mail SMTP Plugin for WordPress plugin <= 4.0.14 - Broken Access Control ≤ 4.0.14 CVE-2023-48332 Patchstack
4.3 Medium Easy Social Feed Plugin easy-facebook-likebox Broken Access Control ≤ 6.5.1 Fixed in 6.5.2 CVE-2023-48740 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Broken Access Control No login needed ≤ 2.1.10 Fixed in 2.2 CVE-2023-48750 Patchstack
5.4 Medium IdeaPush Plugin ideapush Broken Access Control < 8.58 Fixed in 8.58 CVE-2023-48774 Patchstack
5.4 Medium canvasio3D Light Plugin canvasio3d-light Broken Access Control ≤ 2.5.0 CVE-2023-48776 Patchstack
6.5 Medium 360 Javascript Viewer Plugin 360deg-javascript-viewer Broken Access Control No login needed ≤ 1.7.11 Fixed in 1.7.12 CVE-2023-48779 Patchstack
5.3 Medium Button Generator – easily Button Builder Plugin button-generation Broken Access Control easily Button Builder plugin <= 2.3.8 - Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2023-49154 Patchstack
4.3 Medium GoDaddy Email Marketing Plugin godaddy-email-marketing-sign-up-forms Broken Access Control ≤ 1.4.3 CVE-2023-49156 Patchstack
6.5 Medium Database for CF7 Plugin database-for-cf7 Broken Access Control ≤ 1.2.4 Fixed in 1.2.5 CVE-2023-49167 Patchstack
5.3 Medium Enhanced Text Widget Plugin enhanced-text-widget Broken Access Control No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2023-49192 Patchstack
5.3 Medium Hubbub Lite Plugin social-pug Broken Access Control No login needed ≤ 1.30.0 Fixed in 1.30.1 CVE-2023-49193 Patchstack
5.3 Medium Importify (Dropshipping WooCommerce) Plugin importify Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2023-49194 Patchstack
4.3 Medium PageLayer Plugin pagelayer Broken Access Control ≤ 1.7.7 Fixed in 1.7.8 CVE-2023-49196 Patchstack
5.4 Medium Eventin Plugin wp-event-solution Broken Access Control Authenticated Notice Dismissal ≤ 3.3.52 Fixed in 3.3.53 CVE-2023-49756 Patchstack
4.3 Medium Bulk Edit Post Titles Plugin bulk-edit-post-titles Broken Access Control ≤ 5.0.0 CVE-2023-49754 Patchstack
5.4 Medium Elementor Timeline Widget Plugin 3r-elementor-timeline-widget Broken Access Control Notice Dismissal ≤ 2.2 Fixed in 2.3 CVE-2023-49755 Patchstack
5.4 Medium Awesome Support Plugin awesome-support Broken Access Control Broken Access Control + CSRF ≤ 6.1.10 Fixed in 6.1.11 CVE-2023-49757 Patchstack
4.3 Medium WP Booking System Plugin wp-booking-system Broken Access Control ≤ 2.0.19.2 Fixed in 2.0.19.3 CVE-2023-49758 Patchstack
5.3 Medium Webflow Pages Plugin webflow-pages Broken Access Control No login needed ≤ 1.0.8 Fixed in 1.1.0 CVE-2023-49818 Patchstack
4.3 Medium Social Media Feather Plugin social-media-feather Broken Access Control ≤ 2.1.3 Fixed in 2.1.4 CVE-2023-49861 Patchstack
5.3 Medium Site Reviews Plugin site-reviews Broken Access Control No login needed ≤ 6.10.2 Fixed in 6.10.3 CVE-2023-49832 Patchstack
4.3 Medium Login With Ajax Plugin login-with-ajax Broken Access Control No login needed ≤ 4.1 Fixed in 4.2 CVE-2023-49859 Patchstack
4.3 Medium Post Duplicator Plugin post-duplicator Broken Access Control ≤ 2.31 Fixed in 2.32 CVE-2023-49835 Patchstack
4.3 Medium Custom Login Plugin custom-login Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2023-49858 Patchstack
6.5 Medium Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy Plugin woo-aliexpress-dropshipping Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2023-49848 Patchstack
4.3 Medium Shortcoder Plugin shortcoder Broken Access Control ≤ 6.3 Fixed in 6.3.1 CVE-2023-49849 Patchstack
5.3 Medium WP Simple HTML Sitemap Plugin wp-simple-html-sitemap Broken Access Control No login needed ≤ 2.7 Fixed in 2.8 CVE-2023-49850 Patchstack
5.3 Medium Square Thumbnails Plugin square-thumbnails Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2023-49851 Patchstack
6.5 Medium Awesome Support Plugin awesome-support Broken Access Control No login needed ≤ 6.1.7 Fixed in 6.1.8 CVE-2023-49857 Patchstack
5.3 Medium Alt Manager Plugin alt-manager Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2023-50373 Patchstack
4.3 Medium Product Filter by WBW Plugin woo-product-filter Broken Access Control ≤ 2.5.0 Fixed in 2.5.1 CVE-2023-50877 Patchstack
5.3 Medium Google Language Translator Plugin google-language-translator Broken Access Control Google Language Translator plugin <= 6.0.19 - Broken Access Control No login needed ≤ 6.0.19 Fixed in 6.0.20 CVE-2023-50375 Patchstack
4.3 Medium Molongui Plugin molongui-authorship Broken Access Control ≤ 4.7.3 Fixed in 4.7.4 CVE-2023-50876 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.2 Fixed in 4.13.3 CVE-2023-50882 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2023-50884 Patchstack
5.3 Medium User Feedback Plugin userfeedback-lite Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2023-50887 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Broken Access Control No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2023-50904 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only