WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 6,151–6,200 of 8,943 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Live Preview for Contact Form 7 | Broken Access Control |
≤ 1.2.0 |
CVE-2023-47830 |
Patchstack | |
| 5.4 Medium | WP Meta and Date Remover | Broken Access Control |
≤ 2.3.0 Fixed in 2.3.1 |
CVE-2023-47836 |
Patchstack | |
| 5.3 Medium | SearchIQ | Broken Access Control No login needed |
≤ 4.4 Fixed in 4.5 |
CVE-2023-47832 |
Patchstack | |
| 4.3 Medium | Conditional Fields for Contact Form 7 | Broken Access Control |
≤ 2.4.1 Fixed in 2.4.2 |
CVE-2023-47838 |
Patchstack | |
| 4.3 Medium | Analytify | Broken Access Control |
≤ 5.1.1 Fixed in 5.2.0 |
CVE-2023-47841 |
Patchstack | |
| 5.3 Medium | PayTR Taksit Tablosu | Broken Access Control No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2023-47847 |
Patchstack | |
| 4.3 Medium | wpForo Forum | Broken Access Control Broken Access Control + CSRF |
≤ 2.2.5 Fixed in 2.2.6 |
CVE-2023-47869 |
Patchstack | |
| 4.3 Medium | BlossomThemes Email Newsletter | Broken Access Control |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2023-47849 |
Patchstack | |
| 4.3 Medium | Contact Form to Any API | Broken Access Control |
≤ 1.1.6 Fixed in 1.1.7 |
CVE-2023-47871 |
Patchstack | |
| 6.5 Medium | WCMultiShipping | Broken Access Control |
≤ 2.3.5 Fixed in 2.3.6 |
CVE-2023-48274 |
Patchstack | |
| 5.4 Medium | Awesome Support | Broken Access Control |
≤ 6.1.4 Fixed in 6.1.5 |
CVE-2023-48324 |
Patchstack | |
| 5.4 Medium | TextMe SMS | Broken Access Control |
≤ 1.9.0 Fixed in 1.9.1 |
CVE-2023-48287 |
Patchstack | |
| 4.3 Medium | Mail Bank - #1 Mail SMTP | Broken Access Control #1 Mail SMTP Plugin for WordPress plugin <= 4.0.14 - Broken Access Control |
≤ 4.0.14 |
CVE-2023-48332 |
Patchstack | |
| 4.3 Medium | Easy Social Feed | Broken Access Control |
≤ 6.5.1 Fixed in 6.5.2 |
CVE-2023-48740 |
Patchstack | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Broken Access Control No login needed |
≤ 2.1.10 Fixed in 2.2 |
CVE-2023-48750 |
Patchstack | |
| 5.4 Medium | IdeaPush | Broken Access Control |
< 8.58 Fixed in 8.58 |
CVE-2023-48774 |
Patchstack | |
| 5.4 Medium | canvasio3D Light | Broken Access Control |
≤ 2.5.0 |
CVE-2023-48776 |
Patchstack | |
| 6.5 Medium | 360 Javascript Viewer | Broken Access Control No login needed |
≤ 1.7.11 Fixed in 1.7.12 |
CVE-2023-48779 |
Patchstack | |
| 5.3 Medium | Button Generator – easily Button Builder | Broken Access Control easily Button Builder plugin <= 2.3.8 - Broken Access Control No login needed |
≤ 2.3.8 Fixed in 2.3.9 |
CVE-2023-49154 |
Patchstack | |
| 4.3 Medium | GoDaddy Email Marketing | Broken Access Control |
≤ 1.4.3 |
CVE-2023-49156 |
Patchstack | |
| 6.5 Medium | Database for CF7 | Broken Access Control |
≤ 1.2.4 Fixed in 1.2.5 |
CVE-2023-49167 |
Patchstack | |
| 5.3 Medium | Enhanced Text Widget | Broken Access Control No login needed |
≤ 1.6.3 Fixed in 1.6.4 |
CVE-2023-49192 |
Patchstack | |
| 5.3 Medium | Hubbub Lite | Broken Access Control No login needed |
≤ 1.30.0 Fixed in 1.30.1 |
CVE-2023-49193 |
Patchstack | |
| 5.3 Medium | Importify (Dropshipping WooCommerce) | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.0.4 Fixed in 1.0.5 |
CVE-2023-49194 |
Patchstack | |
| 4.3 Medium | PageLayer | Broken Access Control |
≤ 1.7.7 Fixed in 1.7.8 |
CVE-2023-49196 |
Patchstack | |
| 5.4 Medium | Eventin | Broken Access Control Authenticated Notice Dismissal |
≤ 3.3.52 Fixed in 3.3.53 |
CVE-2023-49756 |
Patchstack | |
| 4.3 Medium | Bulk Edit Post Titles | Broken Access Control |
≤ 5.0.0 |
CVE-2023-49754 |
Patchstack | |
| 5.4 Medium | Elementor Timeline Widget | Broken Access Control Notice Dismissal |
≤ 2.2 Fixed in 2.3 |
CVE-2023-49755 |
Patchstack | |
| 5.4 Medium | Awesome Support | Broken Access Control Broken Access Control + CSRF |
≤ 6.1.10 Fixed in 6.1.11 |
CVE-2023-49757 |
Patchstack | |
| 4.3 Medium | WP Booking System | Broken Access Control |
≤ 2.0.19.2 Fixed in 2.0.19.3 |
CVE-2023-49758 |
Patchstack | |
| 5.3 Medium | Webflow Pages | Broken Access Control No login needed |
≤ 1.0.8 Fixed in 1.1.0 |
CVE-2023-49818 |
Patchstack | |
| 4.3 Medium | Social Media Feather | Broken Access Control |
≤ 2.1.3 Fixed in 2.1.4 |
CVE-2023-49861 |
Patchstack | |
| 5.3 Medium | Site Reviews | Broken Access Control No login needed |
≤ 6.10.2 Fixed in 6.10.3 |
CVE-2023-49832 |
Patchstack | |
| 4.3 Medium | Login With Ajax | Broken Access Control No login needed |
≤ 4.1 Fixed in 4.2 |
CVE-2023-49859 |
Patchstack | |
| 4.3 Medium | Post Duplicator | Broken Access Control |
≤ 2.31 Fixed in 2.32 |
CVE-2023-49835 |
Patchstack | |
| 4.3 Medium | Custom Login | Broken Access Control |
≤ 4.1.0 Fixed in 4.1.1 |
CVE-2023-49858 |
Patchstack | |
| 6.5 Medium | Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy | Broken Access Control No login needed |
≤ 2.1.1 Fixed in 2.1.2 |
CVE-2023-49848 |
Patchstack | |
| 4.3 Medium | Shortcoder | Broken Access Control |
≤ 6.3 Fixed in 6.3.1 |
CVE-2023-49849 |
Patchstack | |
| 5.3 Medium | WP Simple HTML Sitemap | Broken Access Control No login needed |
≤ 2.7 Fixed in 2.8 |
CVE-2023-49850 |
Patchstack | |
| 5.3 Medium | Square Thumbnails | Broken Access Control Broken Access Control + CSRF No login needed |
≤ 1.1.1 Fixed in 1.1.2 |
CVE-2023-49851 |
Patchstack | |
| 6.5 Medium | Awesome Support | Broken Access Control No login needed |
≤ 6.1.7 Fixed in 6.1.8 |
CVE-2023-49857 |
Patchstack | |
| 5.3 Medium | Alt Manager | Broken Access Control No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2023-50373 |
Patchstack | |
| 4.3 Medium | Product Filter by WBW | Broken Access Control |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2023-50877 |
Patchstack | |
| 5.3 Medium | Google Language Translator | Broken Access Control Google Language Translator plugin <= 6.0.19 - Broken Access Control No login needed |
≤ 6.0.19 Fixed in 6.0.20 |
CVE-2023-50375 |
Patchstack | |
| 4.3 Medium | Molongui | Broken Access Control |
≤ 4.7.3 Fixed in 4.7.4 |
CVE-2023-50876 |
Patchstack | |
| 5.3 Medium | ProfilePress | Broken Access Control No login needed |
≤ 4.13.2 Fixed in 4.13.3 |
CVE-2023-50882 |
Patchstack | |
| 6.5 Medium | LA-Studio Element Kit for Elementor | Broken Access Control No login needed |
≤ 1.1.5 Fixed in 1.1.6 |
CVE-2023-50884 |
Patchstack | |
| 5.3 Medium | User Feedback | Broken Access Control No login needed |
≤ 1.0.10 Fixed in 1.0.11 |
CVE-2023-50887 |
Patchstack | |
| 5.4 Medium | Product Catalog Enquiry for WooCommerce by MultiVendorX | Broken Access Control |
≤ 5.0.2 Fixed in 5.0.3 |
CVE-2023-50899 |
Patchstack | |
| 5.3 Medium | Poll Maker | Broken Access Control No login needed |
≤ 4.8.0 Fixed in 4.8.1 |
CVE-2023-50904 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.