WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,501–6,550 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 131 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Safe Ai Malware Protection for WP Plugin safe-ai-malware-protection-for-wp Broken Access Control Missing Authorization to Unauthenticated Database Export No login needed ≤ 1.0.17 CVE-2024-12269 Wordfence
8.8 High WP Image Uploader Plugin wp-image-uploader Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.0.1 CVE-2024-13720 Wordfence
7.3 High Contact Form & SMTP Plugin for WordPress by PirateForms Plugin pirate-forms Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.6.0 CVE-2024-13453 Wordfence
7.5 High WooCommerce Wishlist Plugin smart-wishlist-for-more-convert Information Disclosure Unauthenticated Wishlist Disclosure via download_pdf_file Function No login needed ≤ 1.8.7 CVE-2024-13694 Wordfence
7.1 High Bulk Me Now Plugin Cross-Site Scripting Stored XSS via Shortcode No login needed ≤ 2.0 CVE-2024-12708 WPScan
7.1 High Bulk Me Now Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2024-12638 WPScan
7.1 High Tourmaster Plugin Cross-Site Scripting Reflected XSS No login needed < 5.3.5 Fixed in 5.3.5 CVE-2024-12400 WPScan
7.2 High Flexible Wishlist for WooCommerce Plugin flexible-wishlist Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via wishlist_name Parameter No login needed ≤ 1.2.25 CVE-2024-13696 Wordfence
7.1 High Competition Form Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2024-12749 WPScan
7.2 High WS Form LITE and PRO Plugin ws-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.10.13 CVE-2024-13509 Wordfence
7.5 High Eventer Plugin SQL Injection Unauthenticated SQL Injection via eventer_get_attendees No login needed ≤ 3.9.8 CVE-2024-11135 Wordfence
7.1 High Fare Calculator Plugin fare-calculator Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-23982 Patchstack
8.8 High Better Find and Replace Plugin real-time-auto-find-and-replace Privilege Escalation ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-24734 Patchstack
7.1 High WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms Plugin cf7-dynamics-crm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-24708 Patchstack
7.1 High WP Multistore Locator Plugin wp-multi-store-locator Cross-Site Scripting No login needed ≤ 2.4.7 Fixed in 2.5.1 CVE-2025-24680 Patchstack
7.1 High Music Store Plugin music-store Cross-Site Scripting WordPress eCommerce Plugin <= 1.1.19 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.2.0 CVE-2025-24626 Patchstack
7.1 High Edwiser Bridge Plugin edwiser-bridge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.8 Fixed in 3.1.0 CVE-2025-24593 Patchstack
7.1 High LawPress – Law Firm Website Management Plugin lawpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2025-23756 Patchstack
7.1 High The Loops Plugin the-loops Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23754 Patchstack
7.1 High CGD Arrange Terms Plugin shopp-arrange Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-23752 Patchstack
7.1 High CubePM Plugin cubepm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23574 Patchstack
7.1 High RSVPMaker Volunteer Roles Plugin rsvpmaker-volunteer-roles Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23531 Patchstack
7.1 High Simple Locator Plugin simple-locator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-22513 Patchstack
8.1 High Morkva UA Shipping Plugin morkva-ua-shipping Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.20 CVE-2025-24685 Patchstack
7.1 High Passwordless WP – Login with your glance or fingerprint Plugin passwordless-wp Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23792 Patchstack
7.1 High Shipdeo Plugin shipdeo-woo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-23457 Patchstack
7.1 High WP Triggers Lite Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.5.3 CVE-2024-13094 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-13057 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13056 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13055 WPScan
7.1 High Dental Optimizer Patient Generator App Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13052 WPScan
7.2 High Altra Side Menu Plugin SQL Injection Admin+ SQL Injection ≤ 2.0 CVE-2024-12773 WPScan
7.1 High WC Affiliate Plugin wc-affiliate Cross-Site Scripting Reflected XSS No login needed ≤ 2.3.9 CVE-2024-12321 WPScan
8.8 High Zox News Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.16.0 CVE-2024-11936 Wordfence
8.8 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.7.2 CVE-2024-11641 Wordfence
7.3 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10633 Wordfence
7.2 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Broken Access Control Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10574 Wordfence
7.5 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin SQL Injection Unauthenticated SQL Injection via id No login needed 7.0.0 – 8.8.0, 20.0.0 – 21.8.0, 30.0.0 – 31.8.0 CVE-2024-10628 Wordfence
7.5 High Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.14.5 CVE-2024-13562 Wordfence
7.2 High Custom Product Tabs Lite for WooCommerce Plugin woocommerce-custom-product-tabs-lite PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.9.0 CVE-2024-12600 Wordfence
8.8 High ThemeREX Addons Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.33.0 CVE-2025-0682 Wordfence
7.6 High Email Subscription Popup Plugin email-subscribe SQL Injection ≤ 1.2.23 Fixed in 1.2.24 CVE-2025-24587 Patchstack
7.1 High Roi Calculator Plugin roi-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24756 Patchstack
8.5 High Bug Library Plugin bug-library SQL Injection ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-24728 Patchstack
7.6 High RSVP and Event Management Plugin rsvp SQL Injection ≤ 2.7.14 Fixed in 2.7.15 CVE-2025-24683 Patchstack
8.5 High SERPed.net Plugin serped-net SQL Injection ≤ 4.4 Fixed in 4.6 CVE-2025-24669 Patchstack
8.5 High Form Builder CP Plugin cp-easy-form-builder SQL Injection ≤ 1.2.41 Fixed in 1.2.42 CVE-2025-24672 Patchstack
7.6 High WPDM – Premium Packages Plugin wpdm-premium-packages SQL Injection Sell Digital Products Securely plugin <= 5.9.6 - SQL Injection ≤ 5.9.6 Fixed in 5.9.7 CVE-2025-24659 Patchstack
7.6 High Simple Download Monitor Plugin simple-download-monitor SQL Injection ≤ 3.9.25 Fixed in 3.9.26 CVE-2025-24663 Patchstack
7.1 High MachForm Shortcode Plugin machform-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-24636 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only