WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,151–7,200 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 144 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Mollie for Contact Form 7 Plugin cf7-mollie SQL Injection ≤ 5.0.0 CVE-2024-55990 Patchstack
7.5 High EduAdmin Booking Plugin eduadmin-booking Local File Inclusion ≤ 5.2.0 Fixed in 5.3.0 CVE-2024-54373 Patchstack
8.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.24.5 CVE-2024-11721 Wordfence
7.2 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.24.5 CVE-2024-11720 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.1 CVE-2024-11711 Wordfence
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
7.2 High Crafthemes Demo Import Plugin crafthemes-demo-import Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload in process_uploaded_files ≤ 3.3 CVE-2024-9698 Wordfence
7.1 High Fancy Roller Scroller Plugin fancy-roller-scroller Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-54351 Patchstack
7.1 High FloristPress Plugin bakkbone-florist-companion Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.0 Fixed in 7.3.0 CVE-2024-54347 Patchstack
7.1 High WP Quick Shop Plugin wp-quick-shop Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-54344 Patchstack
7.1 High Connect Contact Form 7 to Constant Contact Plugin connect-contact-form-7-to-constant-contact-v3 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2024-54343 Patchstack
7.1 High STAGGS Plugin staggs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54342 Patchstack
7.1 High LabelGrid Tools Plugin label-grid-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.58 Fixed in 1.3.59 CVE-2024-54341 Patchstack
7.1 High Simple Presenter Plugin simple-presenter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-54340 Patchstack
7.1 High geoFlickr Plugin geoflickr Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.4 CVE-2024-54339 Patchstack
7.1 High DX Dark Site Plugin devrix-dark-site Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.1 Fixed in 1.1.1 CVE-2024-54337 Patchstack
8.8 High Projectopia Plugin projectopia-core Privilege Escalation Account Takeover ≤ 5.1.7 Fixed in 5.1.8 CVE-2024-54336 Patchstack
7.1 High ImmoToolBox Connect Plugin immotoolbox-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 Fixed in 1.4.0 CVE-2024-54335 Patchstack
7.1 High Check Pincode For Woocommerce Plugin check-pincode-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2024-54333 Patchstack
7.2 High Hurrakify Plugin hurrakify Server-Side Request Forgery No login needed ≤ 2.4 Fixed in 8.0.1 CVE-2024-54330 Patchstack
7.1 High CleverNode Related Content Plugin clevernode-related-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-54329 Patchstack
7.1 High Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 2.0.0 CVE-2024-54328 Patchstack
7.1 High UNIVERSAM Plugin universam-demo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.59 Fixed in 8.59 CVE-2024-54327 Patchstack
7.1 High CarDealerPress Plugin cardealerpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.2410.02 Fixed in 6.7.2411.00 CVE-2024-54325 Patchstack
7.1 High SMSify Plugin smsify Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.4 Fixed in 6.1.0 CVE-2024-54324 Patchstack
7.1 High Media Downloader Plugin media-downloader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.7.4 Fixed in 0.4.7.5 CVE-2024-54322 Patchstack
7.1 High ICDSoft Reseller Store Plugin icdsoft-reseller-store Cross-Site Scripting WordPress ICDSoft Reseller Store plugin<= 2.4.5 -Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 Fixed in 2.5.0 CVE-2024-54320 Patchstack
7.1 High Kundgenerator Plugin kundgenerator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-54319 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2024-54312 Patchstack
7.1 High J&T Express Malaysia Plugin jt-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 Fixed in 2.0.15 CVE-2024-54305 Patchstack
8.5 High Hive Support Plugin hive-support SQL Injection ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-54304 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-54303 Patchstack
7.1 High VPSUForm Plugin v-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-54302 Patchstack
7.1 High FormFacade Plugin formfacade Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54301 Patchstack
7.1 High Revi.io Plugin revi-io-customer-and-product-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.3 Fixed in 5.8.0 CVE-2024-54299 Patchstack
7.1 High Role Includer Plugin role-includer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2024-54290 Patchstack
7.1 High LDD Directory Lite Plugin ldd-directory-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3 CVE-2024-54288 Patchstack
7.2 High WP Mega Menu Plugin wp-megamenu PHP Object Injection ≤ 1.4.2 CVE-2024-54282 Patchstack
7.1 High CSV to html Plugin csv-to-html Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.08 Fixed in 3.15 CVE-2024-54275 Patchstack
7.1 High WordPress HelpDesk & Support Ticket System Plugin – Octrace Support Plugin octrace-support Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.7 CVE-2024-54274 Patchstack
7.1 High ImageRecycle pdf & image compression Plugin imagerecycle-pdf-image-compression Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-54266 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-54265 Patchstack
7.1 High Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-54264 Patchstack
8.5 High Ni CRM Lead Plugin ni-crm-lead SQL Injection ≤ 1.3.0 CVE-2024-54258 Patchstack
7.1 High Easy Blocks pro Plugin easy-blocks-pro Broken Access Control ≤ 1.0.21 CVE-2024-54256 Patchstack
8.8 High eewee admin custom Plugin eewee-admincustom Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.8.2.4 CVE-2024-54248 Patchstack
7.1 High Blaze Online eParcel for WooCommerce Plugin blaze-online-eparcel-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2024-54240 Patchstack
7.1 High Board Document Manager from CHUHPL Plugin board-document-manager-from-chuhpl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2024-54238 Patchstack
7.1 High Ni CRM Lead Plugin ni-crm-lead Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-54237 Patchstack
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only