WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,201–7,250 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 145 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.86 CVE-2024-54235 Patchstack
7.1 High Advanced Control Manager for WordPress by ItalyStrap Plugin advanced-control-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16.0 CVE-2024-54233 Patchstack
7.1 High Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 CVE-2024-54231 Patchstack
8.1 High Premmerce User Roles Plugin premmerce-user-roles Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2023-41130 Patchstack
7.5 High Redirection for Contact Form 7 Plugin wpcf7-redirect Broken Access Control No login needed ≤ 2.9.2 Fixed in 3.0.0 CVE-2023-39920 Patchstack
8.3 High JupiterX Core Plugin jupiterx-core Broken Access Control Multiple Auth. Broken Access Control 3.0.0 – 3.3.0 Fixed in 3.3.5 CVE-2023-38385 Patchstack
7.3 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Broken Access Control No login needed ≤ 23.0211 Fixed in 23.0212 CVE-2023-36510 Patchstack
7.6 High Surfer Plugin surferseo Broken Access Control ≤ 1.3.2.357 Fixed in 1.3.3.379 CVE-2023-35037 Patchstack
8.8 High Spam protection, AntiSpam, FireWall by CleanTalk Plugin cleantalk-spam-protect Broken Access Control ≤ 6.10 Fixed in 6.11 CVE-2023-33996 Patchstack
7.5 High Portfolio Gallery – Responsive Image Gallery Plugin gallery-portfolio Broken Access Control Responsive Image Gallery plugin <= 1.4.6 - Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-32585 Patchstack
7.5 High WCP Contact Form Plugin wcp-contact-form Broken Access Control No login needed ≤ 3.1.0 CVE-2023-32520 Patchstack
7.3 High Woo Custom Emails Plugin woo-custom-emails Broken Access Control No login needed ≤ 2.2 CVE-2023-32507 Patchstack
7.5 High Easing Slider Plugin easing-slider Broken Access Control Plugin Settings Reset No login needed ≤ 3.0.8 CVE-2023-30490 Patchstack
7.5 High Video Gallery – YouTube Gallery Plugin gallery-videos Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2023-25988 Patchstack
8.1 High MainWP Child Plugin mainwp-child Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation No login needed ≤ 5.3.3 CVE-2024-10783 Wordfence
8.1 High Print Science Designer Plugin print-science-designer PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.3.152 CVE-2024-12312 Wordfence
7.2 High AI-Engine Plugin SQL Injection Admin+ SQLi < 2.6.5 Fixed in 2.6.5 CVE-2024-10499 WPScan
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed ≤ 3.8.19 CVE-2024-11052 Wordfence
7.5 High WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Plugin wp-courses Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed ≤ 3.2.21 CVE-2024-12172 Wordfence
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
8.8 High Opt-In Downloads Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.07 CVE-2024-10590 Wordfence
7.3 High Grid Plus – Unlimited grid layout Plugin grid-plus Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed ≤ 1.3.5 CVE-2024-10910 Wordfence
8.1 High OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) <= 6.26.3 - Authentication Bypass No login needed ≤ 6.26.3 CVE-2024-10111 Wordfence
8.8 High de:branding Plugin debranding Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update ≤ 1.0.2 CVE-2024-11443 Wordfence
8.8 High HQ Rental Software Plugin hq-rental-software Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.29 CVE-2024-11689 Wordfence
7.1 High RapidLoad – Optimize Web Vitals Automatically Plugin unusedcss Broken Access Control Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection ≤ 2.4.2 CVE-2024-11840 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
7.7 High Best WordPress Gallery Plugin – FooGallery Plugin Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.26 CVE-2023-6947 Wordfence
8.5 High WPForms Plugin wpforms-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation 1.8.4 – 1.9.2.1 CVE-2024-11205 Wordfence
7.1 High AIO Contact Plugin aio-contact Cross-Site Scripting Unauthenticated Site-Wide Cross Site Scripting (XSS) No login needed ≤ 2.8.1 CVE-2024-54219 Patchstack
7.1 High FAT Services Booking Plugin fat-services-booking Cross-Site Scripting Subscriber+ Site-Wide Cross Site Scripting (XSS) No login needed ≤ 5.6 CVE-2024-54220 Patchstack
7.5 High Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Local File Inclusion ≤ 1.3.9 CVE-2024-53790 Patchstack
7.1 High Country Blocker Plugin country-blocker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.2 CVE-2024-54226 Patchstack
7.5 High Designer Plugin designer Local File Inclusion ≤ 1.4.1 Fixed in 1.5.0 CVE-2024-54225 Patchstack
7.5 High Ebook Store Plugin ebook-store Authentication Bypass Broken Authentication No login needed ≤ 5.775 Fixed in 5.78 CVE-2023-22701 Patchstack
7.5 High Quick Paypal Payments Plugin quick-paypal-payments Broken Access Control No login needed ≤ 5.7.25 Fixed in 5.7.26 CVE-2023-25714 Patchstack
8.6 High Japanized For WooCommerce Plugin woocommerce-for-japan Broken Access Control Multiple Broken Access Control No login needed ≤ 2.6.4 Fixed in 2.6.5 CVE-2023-47698 Patchstack
8.2 High Stripe Payments Plugin stripe-payments Broken Access Control No login needed ≤ 2.0.79 Fixed in 2.0.80 CVE-2023-48286 Patchstack
7.1 High LadiApp Plugin ladipage Broken Access Control Broken Access Control lead to XSS No login needed ≤ 4.4 CVE-2023-49158 Patchstack
8.2 High Flexible Woocommerce Checkout Field Editor Plugin flexible-woocommerce-checkout-field-editor Broken Access Control No login needed ≤ 2.0.1 CVE-2023-49817 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ 5.2.3.0 Fixed in 5.2.3.1 CVE-2023-49831 Patchstack
8.1 High Smart Forms Plugin smart-forms Broken Access Control Authenticated Arbitrary Options Change ≤ 2.6.84 Fixed in 2.6.85 CVE-2023-49856 Patchstack
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
8.8 High Gallery Plugin multi-gallery PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.3 CVE-2024-11501 Wordfence
7.2 High FileOrganizer Plugin fileorganizer Local File Inclusion Authenticated (Administrator+) Local JavaScript File Inclusion ≤ 1.1.4 CVE-2024-11010 Wordfence
7.5 High Beautiful Taxonomy Filters Plugin beautiful-taxonomy-filters SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.4.3 CVE-2024-12270 Wordfence
8.1 High Swift Performance Lite Plugin swift-performance-lite Local File Inclusion Unauthenticated Local PHP File Inclusion via 'ajaxify' No login needed ≤ 2.3.7.1 CVE-2024-10516 Wordfence
7.1 High WP GeoNames Plugin wp-geonames Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 Fixed in 1.9 CVE-2024-53812 Patchstack
7.1 High Pie Register Premium Plugin pie-register-premium Cross-Site Scripting No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-53821 Patchstack
7.1 High Block Controller Plugin block-controller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.3 CVE-2024-54208 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only