WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,601–6,650 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 133 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Church Admin Plugin church-admin Broken Access Control ≤ 4.4.4 Fixed in 4.4.5 CVE-2024-37440 Patchstack
5.3 Medium Defender Security Plugin defender-security Broken Access Control No login needed ≤ 4.7.1 Fixed in 4.7.3 CVE-2024-37444 Patchstack
4.3 Medium WP Job Manager - Resume Manager Plugin Broken Access Control ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-37443 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities plugin <= 5.8.7 - Broken Access Control ≤ 5.8.7 Fixed in 5.8.8 CVE-2024-37453 Patchstack
5.3 Medium CRM Perks Forms Plugin crm-perks-forms Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-37463 Patchstack
5.3 Medium Noptin Plugin newsletter-optin-box Broken Access Control Noptin plugin <= 3.4.2 - Broken Access Control No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2024-37456 Patchstack
5.3 Medium Newsmatic Theme newsmatic Broken Access Control No login needed ≤ 1.3.1 Fixed in 1.3.3 CVE-2024-37468 Patchstack
5.3 Medium Newspack Newsletters Plugin newspack-newsletters Broken Access Control No login needed ≤ 2.13.2 Fixed in 2.13.3 CVE-2024-37475 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Broken Access Control No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37481 Patchstack
6.5 Medium Newspack Content Converter Plugin Broken Access Control ≤ 0.1.5 Fixed in 1.0.0 CVE-2024-37477 Patchstack
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37482 Patchstack
4.3 Medium Business One Page Theme business-one-page Broken Access Control Broken Access Control on Notice Dismissal No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-37505 Patchstack
5.4 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37483 Patchstack
6.5 Medium Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.1.7 Fixed in 1.8.1.8 CVE-2024-37510 Patchstack
5.3 Medium Charitable Plugin charitable Broken Access Control No login needed ≤ 1.8.1.7 Fixed in 1.8.1.8 CVE-2024-37506 Patchstack
6.3 Medium Featured Image from URL Plugin featured-image-from-url Broken Access Control ≤ 4.8.2 Fixed in 4.8.3 CVE-2024-37516 Patchstack
5.3 Medium Chained Quiz Plugin chained-quiz Broken Access Control No login needed ≤ 1.3.2.8 Fixed in 1.3.2.9 CVE-2024-37921 Patchstack
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.13.7 Fixed in 2.13.8 CVE-2024-37517 Patchstack
6.3 Medium User Activity Log Pro Plugin Broken Access Control Subscriber+ Multiple Broken Access Control ≤ 2.3.4 CVE-2024-37929 Patchstack
5.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control No login needed ≤ 0.6.2.9 Fixed in 0.6.3 CVE-2024-37926 Patchstack
5.3 Medium iPanorama 360 WordPress Virtual Tour Builder Plugin ipanorama-360-virtual-tour-builder-lite Broken Access Control No login needed ≤ 1.8.3 Fixed in 1.8.4 CVE-2024-38690 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.2 - Broken Access Control No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-38702 Patchstack
4.3 Medium WP GoToWebinar Plugin wp-gotowebinar Broken Access Control ≤ 15.6 Fixed in 15.7 CVE-2024-38695 Patchstack
6.3 Medium EmbedPress Plugin embedpress Broken Access Control ≤ 4.0.4 Fixed in 4.0.5 CVE-2024-38707 Patchstack
4.3 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-38719 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Broken Access Control ≤ 1.68.232 Fixed in 1.69.234 CVE-2024-38714 Patchstack
4.3 Medium Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Broken Access Control ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38727 Patchstack
5.4 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Broken Access Control ≤ 24.0422 Fixed in 24.0712 CVE-2024-38737 Patchstack
5.4 Medium Meks Video Importer Plugin meks-video-importer Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2024-38733 Patchstack
5.4 Medium Packlink PRO shipping module Plugin packlink-pro-shipping Broken Access Control ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-38740 Patchstack
5.3 Medium Plum: Spin Wheel & Email Pop-up Plugin qodeblock Broken Access Control No login needed ≤ 2.0 CVE-2024-38743 Patchstack
5.3 Medium Wholesale Suite Plugin woocommerce-wholesale-prices Broken Access Control No login needed ≤ 2.1.12 Fixed in 2.2.0 CVE-2024-38745 Patchstack
5.3 Medium Arconix Shortcodes Plugin arconix-shortcodes Broken Access Control No login needed ≤ 2.1.11 Fixed in 2.1.12 CVE-2024-38769 Patchstack
5.3 Medium EleForms Plugin all-contact-form-integration-for-elementor Broken Access Control No login needed ≤ 2.9.9.9 CVE-2024-38748 Patchstack
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2024-38771 Patchstack
6.5 Medium Titan Anti-spam & Security Plugin anti-spam Broken Access Control ≤ 7.3.6 Fixed in 7.3.8 CVE-2024-38777 Patchstack
5.4 Medium SiteGround Security Plugin sg-security Broken Access Control ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-38774 Patchstack
5.3 Medium Language Translate Widget for WordPress – ConveyThis Plugin conveythis-translate Broken Access Control Non-arbitrary Options Update No login needed ≤ 234 Fixed in 235 CVE-2024-38792 Patchstack
5.3 Medium Arconix FAQ Plugin arconix-faq Broken Access Control No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2024-38783 Patchstack
5.3 Medium Custom Query Blocks Plugin post-type-archive-mapping Broken Access Control No login needed ≤ 5.2.0 Fixed in 5.3.0 CVE-2024-38794 Patchstack
5.4 Medium Youzify Plugin youzify Broken Access Control ≤ 1.2.6 Fixed in 1.2.8 CVE-2024-39635 Patchstack
5.3 Medium Icegram Plugin icegram Broken Access Control Unauthenticated Message Duplication No login needed ≤ 3.1.24 Fixed in 3.1.25 CVE-2024-39625 Patchstack
6.5 Medium WP Social Feed Gallery Plugin insta-gallery Broken Access Control No login needed ≤ 4.3.9 Fixed in 4.4.0 CVE-2024-39640 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Broken Access Control + CSRF ≤ 4.24.7 Fixed in 4.24.8 CVE-2024-39639 Patchstack
5.3 Medium Sign-up Sheets Plugin sign-up-sheets Broken Access Control No login needed ≤ 2.2.12 Fixed in 2.2.13 CVE-2024-39654 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43118 Patchstack
5.3 Medium TypeSquare Webfonts Plugin xserver-typesquare-webfonts Broken Access Control No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-43120 Patchstack
4.3 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control ≤ 2.0.12 Fixed in 2.0.13 CVE-2024-43119 Patchstack
6.5 Medium Robin image optimizer Plugin robin-image-optimizer Broken Access Control ≤ 1.6.9 Fixed in 1.7.0 CVE-2024-43122 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.1 Fixed in 3.2.2 CVE-2024-43136 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only