WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,651–6,700 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 134 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Broken Access Control ≤ 2.6 Fixed in 2.6.1 CVE-2024-43134 Patchstack
4.3 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 2.7.3 Fixed in 2.7.4 CVE-2024-43142 Patchstack
6.3 Medium AMP for WP Plugin accelerated-mobile-pages Broken Access Control ≤ 1.0.96.1 Fixed in 1.0.97 CVE-2024-43146 Patchstack
6.4 Medium Registrations for the Events Calendar Plugin registrations-for-the-events-calendar Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-43143 Patchstack
4.3 Medium FormCraft Plugin formcraft-form-builder Broken Access Control ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-43157 Patchstack
4.3 Medium Advanced Cron Manager – debug & control Plugin advanced-cron-manager Broken Access Control debug & control plugin <= 2.5.9 - Broken Access Control ≤ 2.5.9 Fixed in 2.5.10 CVE-2024-43154 Patchstack
4.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Broken Access Control ≤ 3.2.12 Fixed in 3.3.1 CVE-2024-43162 Patchstack
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control No login needed ≤ 1.11.6 Fixed in 1.12.0 CVE-2024-43159 Patchstack
6.5 Medium Bitly Plugin wp-bitly Broken Access Control No login needed ≤ 2.7.2 CVE-2024-43209 Patchstack
4.3 Medium Send Emails with Mandrill Plugin send-emails-with-mandrill Broken Access Control ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-43208 Patchstack
5.9 Medium MailChimp Subscribe Forms Plugin mailchimp-subscribe-sm Cross-Site Scripting Stored Cross-Site Scripting ≤ 4.0.9.9 CVE-2024-43211 Patchstack
4.3 Medium Social Slider Feed Plugin instagram-slider-widget Broken Access Control ≤ 2.2.2 Fixed in 2.2.5 CVE-2024-43215 Patchstack
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control ≤ 4.0.3.2 Fixed in 4.0.4.0 CVE-2024-43223 Patchstack
5.3 Medium Persian WooCommerce Plugin persian-woocommerce Broken Access Control No login needed ≤ 7.1.6 Fixed in 9.0.0 CVE-2024-43219 Patchstack
4.3 Medium WP Search Analytics Plugin search-analytics Broken Access Control ≤ 1.4.9 Fixed in 1.4.10 CVE-2024-43229 Patchstack
5.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-43253 Patchstack
5.4 Medium Clearfy Cache Plugin clearfy Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2024-43260 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-43254 Patchstack
5.4 Medium Backup and Restore Plugin wp-backitup Broken Access Control ≤ 1.50 CVE-2024-43268 Patchstack
5.4 Medium Icegram Collect Plugin icegram-rainmaker Broken Access Control ≤ 1.3.14 Fixed in 1.3.15 CVE-2024-43273 Patchstack
5.3 Medium Backup and Restore Plugin wp-backitup Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.50 CVE-2024-43270 Patchstack
5.3 Medium UsersWP Plugin userswp Broken Access Control No login needed ≤ 1.2.15 Fixed in 1.2.16 CVE-2024-43277 Patchstack
5.8 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control The Ultimate Help Desk plugin <= 2.8.6 - Broken Access Control No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-43274 Patchstack
6.3 Medium Presto Player Plugin presto-player Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-43285 Patchstack
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2024-43293 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-43290 Patchstack
4.3 Medium Flash & HTML5 Video Plugin html5-video-player Broken Access Control ≤ 2.5.30 Fixed in 2.5.31 CVE-2024-43296 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2024-43298 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2024-43297 Patchstack
4.3 Medium Fonts Plugin olympus-google-fonts Broken Access Control ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43302 Patchstack
5.4 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.1.9 Fixed in 7.2.0 CVE-2024-43312 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
4.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control ≤ 1.3.9.3 Fixed in 1.3.9.4 CVE-2024-43314 Patchstack
4.3 Medium Photo Engine Plugin wplr-sync Broken Access Control ≤ 6.4.0 Fixed in 6.4.1 CVE-2024-43332 Patchstack
5.3 Medium ReviewX Plugin reviewx Broken Access Control No login needed ≤ 1.6.28 Fixed in 1.6.29 CVE-2024-43323 Patchstack
4.3 Medium Order Tracking Plugin order-tracking Broken Access Control WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control ≤ 3.3.12 Fixed in 3.3.13 CVE-2024-43343 Patchstack
6.5 Medium Hello Agency Theme hello-agency Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-43341 Patchstack
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control ≤ 5.3.0 Fixed in 5.5.7 CVE-2024-43355 Patchstack
5.3 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-43923 Patchstack
5.3 Medium YARPP Plugin yet-another-related-posts-plugin Broken Access Control No login needed ≤ 5.30.10 CVE-2024-43919 Patchstack
5.4 Medium JobSearch Plugin wp-jobsearch Broken Access Control ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43928 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control ≤ 1.8.14 Fixed in 1.8.15 CVE-2024-43925 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Broken Access Control ≤ 5.6.2 Fixed in 5.6.3 CVE-2024-43932 Patchstack
6.5 Medium JobSearch Plugin Broken Access Control No login needed ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43929 Patchstack
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Settings Change ≤ 2.1.10 Fixed in 2.1.11 CVE-2024-43937 Patchstack
5.4 Medium LWS Affiliation Plugin lws-affiliation Broken Access Control ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43962 Patchstack
6.5 Medium Memberpress Plugin Broken Access Control No login needed ≤ 1.11.34 Fixed in 1.11.35 CVE-2024-43956 Patchstack
4.3 Medium Newspack Plugin newspack-plugin Broken Access Control ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-43968 Patchstack
6.5 Medium ReviveNews Theme revivenews Broken Access Control No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-43974 Patchstack
4.3 Medium GetPaid Plugin invoicing Broken Access Control ≤ 2.8.11 Fixed in 2.8.12 CVE-2024-43973 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only