WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,951–7,000 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 140 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Notify Odoo Plugin notify-odoo Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 Fixed in 1.0.1 CVE-2024-56299 Patchstack
7.5 High Post/Page Copying Tool Plugin postpage-import-export-with-custom-fields-taxonomies Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-56300 Patchstack
7.1 High ProductDyno Plugin productdyno Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.24 Fixed in 1.0.25 CVE-2025-22320 Patchstack
7.1 High OZ Canonical Plugin oz-canonical Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-22324 Patchstack
7.1 High Autocompleter Plugin autocompleter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.5.2 CVE-2025-22325 Patchstack
7.1 High 5centsCDN Plugin 5centscdn Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 25.4.15 CVE-2025-22326 Patchstack
7.1 High Elevio Plugin elevio Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.4.1 CVE-2025-22328 Patchstack
7.1 High Wizhi Multi Filters by Wenprise Plugin wizhi-multi-filters Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.8.6 CVE-2025-22336 Patchstack
7.1 High wpSOL Plugin wpsol Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 CVE-2025-22343 Patchstack
7.1 High WP Simple Sitemap Plugin wp-simple-sitemap Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2 CVE-2025-22342 Patchstack
8.2 High BSK Forms Blacklist Plugin bsk-gravityforms-blacklist Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 3.9 Fixed in 4.0 CVE-2025-22347 Patchstack
8.5 High DynamicTags Plugin dynamictags SQL Injection ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-22348 Patchstack
7.6 High Auction Plugin wp-auctions SQL Injection ≤ 3.7 CVE-2025-22349 Patchstack
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
7.6 High Contact Form 7 Database – CFDB7 Plugin advanced-cf7-database SQL Injection CFDB7 plugin <= 1.0.0 - SQL Injection ≤ 1.0.0 CVE-2025-22351 Patchstack
7.1 High BVD Easy Gallery Manager Plugin bvd-easy-gallery-manager Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-22353 Patchstack
7.1 High Kikx Simple Post Author Filter Plugin sa-post-author-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22355 Patchstack
7.1 High Target Notifications Plugin target-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-22357 Patchstack
7.1 High SyncFields Plugin syncfields Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-22359 Patchstack
7.1 High Wp advertising management Plugin advertising-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-22358 Patchstack
7.5 High Ach Invoice App Plugin ach-invoice-app Local File Inclusion No login needed ≤ 1.0.1 CVE-2025-22364 Patchstack
7.5 High MIPL WC Multisite Sync Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.1.5 CVE-2024-12152 Wordfence
8.8 High Croma Music Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in ironMusic_ajax ≤ 3.6 CVE-2024-12202 Wordfence
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Broken Access Control WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.7.6 CVE-2024-11725 Wordfence
7.1 High JoomSport Plugin joomsport-sports-league-results-management Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed ≤ 5.6.17 CVE-2024-12633 Wordfence
8.8 High Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator Plugin post-saint Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.3.1 CVE-2024-12471 Wordfence
8.6 High Host PHP Info Plugin host-php-info Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.0.4 CVE-2024-12535 Wordfence
7.5 High Error Log Viewer By WP Guru Plugin error-log-viewer-wp Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed ≤ 1.0.1.3 CVE-2024-12849 Wordfence
8.8 High ThePerfectWedding.nl Widget Plugin theperfectweddingnl-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.8 CVE-2024-12322 Wordfence
8.1 High Compare Products for WooCommerce Plugin woocommerce-compare-products PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.2.1 CVE-2024-12313 Wordfence
7.5 High Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Plugin ultimate-popup-creator SQL Injection MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Unauthenticated SQL Injection No login needed ≤ 3.2.6 CVE-2024-12157 Wordfence
7.2 High Custom Product Tabs for WooCommerce Plugin yikes-inc-easy-custom-woocommerce-product-tabs PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection ≤ 1.8.5 CVE-2024-11465 Wordfence
7.5 High Woomotiv Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.6.1 CVE-2024-12416 Wordfence
8.8 High UpdraftPlus: WP Backup & Migration Plugin updraftplus PHP Object Injection Unauthenticated PHP Object Injection No login needed 1.23.8 – 1.24.11 CVE-2024-10957 Wordfence
8.8 High Backup Migration Plugin backup-backup PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' No login needed ≤ 1.4.6 CVE-2024-10932 Wordfence
7.3 High WordPress Popular Posts Plugin wordpress-popular-posts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.0 CVE-2024-11733 Wordfence
7.1 High JetEngine Plugin jet-engine Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-48758 Patchstack
8.8 High ListingPro Theme listingpro Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39623 Patchstack
7.1 High Olivia Theme olivia Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.5 CVE-2024-56014 Patchstack
7.1 High Interactive UK Map Plugin interactive-uk-map Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2024-56267 Patchstack
7.6 High Just Writing Statistics Plugin just-writing-statistics SQL Injection ≤ 4.7 Fixed in 4.8 CVE-2024-56250 Patchstack
7.6 High WP Post Author Plugin wp-post-author SQL Injection ≤ 3.8.2 Fixed in 3.8.3 CVE-2024-56247 Patchstack
7.1 High Simple Proxy Plugin simple-proxy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-56026 Patchstack
7.1 High AdWork Media EZ Content Locker Plugin adwork-media-ez-content-locker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2024-56025 Patchstack
7.1 High Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-56024 Patchstack
7.1 High WP eCommerce Quickpay Plugin wp-ecommerce-quickpay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2024-56023 Patchstack
7.1 High Preloader by WordPress Monsters Plugin preloader-sws Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2024-56022 Patchstack
7.1 High BU Section Editing Plugin bu-section-editing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.9 CVE-2024-56018 Patchstack
7.5 High Ultimate Addons for Contact Form 7 Plugin ultimate-addons-for-contact-form-7 Broken Access Control No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2023-47693 Patchstack
7.5 High EazyDocs Plugin eazydocs Broken Access Control No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2023-47648 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only