WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 6,951–7,000 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Notify Odoo | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0.0 Fixed in 1.0.1 |
CVE-2024-56299 |
Patchstack | |
| 7.5 High | Post/Page Copying Tool | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2024-56300 |
Patchstack | |
| 7.1 High | ProductDyno | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.24 Fixed in 1.0.25 |
CVE-2025-22320 |
Patchstack | |
| 7.1 High | OZ Canonical | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.5 |
CVE-2025-22324 |
Patchstack | |
| 7.1 High | Autocompleter | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3.5.2 |
CVE-2025-22325 |
Patchstack | |
| 7.1 High | 5centsCDN | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 25.4.15 |
CVE-2025-22326 |
Patchstack | |
| 7.1 High | Elevio | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 4.4.1 |
CVE-2025-22328 |
Patchstack | |
| 7.1 High | Wizhi Multi Filters by Wenprise | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.8.6 |
CVE-2025-22336 |
Patchstack | |
| 7.1 High | wpSOL | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2.0 |
CVE-2025-22343 |
Patchstack | |
| 7.1 High | WP Simple Sitemap | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 0.2 |
CVE-2025-22342 |
Patchstack | |
| 8.2 High | BSK Forms Blacklist | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 3.9 Fixed in 4.0 |
CVE-2025-22347 |
Patchstack | |
| 8.5 High | DynamicTags | SQL Injection |
≤ 1.4.0 Fixed in 1.4.1 |
CVE-2025-22348 |
Patchstack | |
| 7.6 High | Auction | SQL Injection |
≤ 3.7 |
CVE-2025-22349 |
Patchstack | |
| 7.6 High | ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes | SQL Injection |
≤ 1.4.9 Fixed in 1.5.0 |
CVE-2025-22352 |
Patchstack | |
| 7.6 High | Contact Form 7 Database – CFDB7 | SQL Injection CFDB7 plugin <= 1.0.0 - SQL Injection |
≤ 1.0.0 |
CVE-2025-22351 |
Patchstack | |
| 7.1 High | BVD Easy Gallery Manager | Cross-Site Scripting No login needed |
≤ 1.0.6 |
CVE-2025-22353 |
Patchstack | |
| 7.1 High | Kikx Simple Post Author Filter | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-22355 |
Patchstack | |
| 7.1 High | Target Notifications | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.1 |
CVE-2025-22357 |
Patchstack | |
| 7.1 High | SyncFields | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1 |
CVE-2025-22359 |
Patchstack | |
| 7.1 High | Wp advertising management | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.3 |
CVE-2025-22358 |
Patchstack | |
| 7.5 High | Ach Invoice App | Local File Inclusion No login needed |
≤ 1.0.1 |
CVE-2025-22364 |
Patchstack | |
| 7.5 High | MIPL WC Multisite Sync | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 1.1.5 |
CVE-2024-12152 |
Wordfence | |
| 8.8 High | Croma Music | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in ironMusic_ajax |
≤ 3.6 |
CVE-2024-12202 |
Wordfence | |
| 8.8 High | SMS Alert Order Notifications – WooCommerce | Broken Access Control WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update |
≤ 3.7.6 |
CVE-2024-11725 |
Wordfence | |
| 7.1 High | JoomSport | Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed |
≤ 5.6.17 |
CVE-2024-12633 |
Wordfence | |
| 8.8 High | Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload |
≤ 1.3.1 |
CVE-2024-12471 |
Wordfence | |
| 8.6 High | Host PHP Info | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure No login needed |
≤ 1.0.4 |
CVE-2024-12535 |
Wordfence | |
| 7.5 High | Error Log Viewer By WP Guru | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed |
≤ 1.0.1.3 |
CVE-2024-12849 |
Wordfence | |
| 8.8 High | ThePerfectWedding.nl Widget | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.8 |
CVE-2024-12322 |
Wordfence | |
| 8.1 High | Compare Products for WooCommerce | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 3.2.1 |
CVE-2024-12313 |
Wordfence | |
| 7.5 High | Popup – MailChimp, GetResponse and ActiveCampaign Intergrations | SQL Injection MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Unauthenticated SQL Injection No login needed |
≤ 3.2.6 |
CVE-2024-12157 |
Wordfence | |
| 7.2 High | Custom Product Tabs for WooCommerce | PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection |
≤ 1.8.5 |
CVE-2024-11465 |
Wordfence | |
| 7.5 High | Woomotiv | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 3.6.1 |
CVE-2024-12416 |
Wordfence | |
| 8.8 High | UpdraftPlus: WP Backup & Migration | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
1.23.8 – 1.24.11 |
CVE-2024-10957 |
Wordfence | |
| 8.8 High | Backup Migration | PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' No login needed |
≤ 1.4.6 |
CVE-2024-10932 |
Wordfence | |
| 7.3 High | WordPress Popular Posts | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 7.1.0 |
CVE-2024-11733 |
Wordfence | |
| 7.1 High | JetEngine | Broken Access Control |
≤ 3.2.4 Fixed in 3.2.5 |
CVE-2023-48758 |
Patchstack | |
| 8.8 High | ListingPro | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed |
≤ 2.9.4 Fixed in 2.9.5 |
CVE-2024-39623 |
Patchstack | |
| 7.1 High | Olivia | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.9.5 |
CVE-2024-56014 |
Patchstack | |
| 7.1 High | Interactive UK Map | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 3.4.8 Fixed in 3.4.9 |
CVE-2024-56267 |
Patchstack | |
| 7.6 High | Just Writing Statistics | SQL Injection |
≤ 4.7 Fixed in 4.8 |
CVE-2024-56250 |
Patchstack | |
| 7.6 High | WP Post Author | SQL Injection |
≤ 3.8.2 Fixed in 3.8.3 |
CVE-2024-56247 |
Patchstack | |
| 7.1 High | Simple Proxy | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2024-56026 |
Patchstack | |
| 7.1 High | AdWork Media EZ Content Locker | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.0 |
CVE-2024-56025 |
Patchstack | |
| 7.1 High | Custom Dashboard Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2024-56024 |
Patchstack | |
| 7.1 High | WP eCommerce Quickpay | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.0 |
CVE-2024-56023 |
Patchstack | |
| 7.1 High | Preloader by WordPress Monsters | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.3 |
CVE-2024-56022 |
Patchstack | |
| 7.1 High | BU Section Editing | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.9.9 |
CVE-2024-56018 |
Patchstack | |
| 7.5 High | Ultimate Addons for Contact Form 7 | Broken Access Control No login needed |
≤ 3.2.6 Fixed in 3.2.7 |
CVE-2023-47693 |
Patchstack | |
| 7.5 High | EazyDocs | Broken Access Control No login needed |
≤ 2.3.5 Fixed in 2.3.6 |
CVE-2023-47648 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.