WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,251–7,300 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 146 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Awesome Shortcodes Plugin awesome-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-54209 Patchstack
7.1 High Paloma Widget Plugin postman-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.14 CVE-2024-54205 Patchstack
7.7 High ARForms Plugin arforms Path Traversal < 7.0.2 Fixed in 7.0.2 CVE-2024-54216 Patchstack
8.5 High WP Mailster Plugin wp-mailster SQL Injection ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53807 Patchstack
8.5 High NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection ≤ 8.7.8 Fixed in 8.7.9 CVE-2024-53808 Patchstack
8.5 High Pinpoint Booking System Plugin booking-system SQL Injection ≤ 2.9.9.5.1 Fixed in 2.9.9.5.2 CVE-2024-53815 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
7.5 High WP Mailster Plugin wp-mailster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53804 Patchstack
7.5 High All Bootstrap Blocks Plugin all-bootstrap-blocks Local File Inclusion ≤ 1.3.19 Fixed in 1.3.20 CVE-2024-53824 Patchstack
7.5 High WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53805 Patchstack
7.5 High KiviCare – Clinic & Patient Management System (EHR) Plugin kivicare-clinic-management-system SQL Injection Clinic & Patient Management System (EHR) <= 3.6.4 - Unauthenticated SQL Injection No login needed ≤ 3.6.4 CVE-2024-11728 Wordfence
7.5 High Verowa Connect Plugin verowa-connect SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.0.1 CVE-2024-11460 Wordfence
8.1 High Soledad Theme Local File Inclusion Unauthenticated Limited Local File Inclusion No login needed ≤ 8.5.9 CVE-2024-11289 Wordfence
8.8 High AI Quiz | Quiz Maker Plugin ai-quiz Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 1.1 CVE-2024-11323 Wordfence
8.1 High Login With OTP Plugin otp-login Authentication Bypass Authentication Bypass via Weak OTP No login needed ≤ 1.4.2 CVE-2024-11178 Wordfence
7.5 High WP Hide & Security Enhancer Plugin wp-hide-security-enhancer Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Contents Deletion No login needed ≤ 2.5.1 CVE-2024-11585 Wordfence
8.8 High Pubnews Theme pubnews Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 1.0.7 CVE-2024-10578 Wordfence
7.2 High YouTube Gallery and Vimeo Gallery Plugin gallery-videos SQL Injection Authenticated (Administrator+) SQL Injection ≤ 2.4.2 CVE-2024-10247 Wordfence
8.8 High Free Responsive Testimonials, Social Proof Reviews, and Customer Reviews – Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Local File Inclusion Stars Testimonials <= 3.3.3 - Authenticated (Contributor+) Local File Inclusion ≤ 3.3.3 CVE-2024-11429 Wordfence
8.8 High Accessibility by AllAccessible Plugin allaccessible Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update ≤ 1.3.4 CVE-2024-11643 Wordfence
7.5 High Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Local File Inclusion WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion ≤ 3.0 CVE-2024-11952 Wordfence
7.5 High TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control Missing Authorization to Unauthenticated Plugin Setup Wizard Access No login needed ≤ 2.9.1 CVE-2024-10567 Wordfence
8.1 High Pie Register - Social Sites Login (Add on) Plugin Authentication Bypass User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 1.7.9 CVE-2024-11293 Wordfence
7.3 High Authors List Plugin authors-list Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via update_authors_list_ajax No login needed ≤ 2.0.4 CVE-2024-10952 Wordfence
8.8 High Funnelforms Free Plugin funnelforms-free PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 3.7.5.1 CVE-2024-10587 Wordfence
7.5 High Advanced File Manager Plugin file-manager-advanced Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 5.2.10 CVE-2024-11391 Wordfence
7.1 High Open edX LMS Plugin edunext-openedx-integrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2024-52452 Patchstack
7.1 High Library Bookshelves Plugin library-bookshelves Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 5.9 CVE-2024-52453 Patchstack
7.1 High GoQSmile Plugin goqsmile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52455 Patchstack
7.1 High GoQMieruca Plugin goqmieruca Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2024-52454 Patchstack
7.1 High Youneeq Recommendations Plugin youneeq-panel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.7 CVE-2024-52457 Patchstack
7.1 High Awesome Studio Plugin awesome-studio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2024-52456 Patchstack
7.1 High Chameleoni Jobs Plugin chameleon-jobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-52459 Patchstack
7.1 High TM Islamic Helper Plugin tm-islamic-helper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52458 Patchstack
7.1 High AtaraPay WooCommerce Payment Gateway Plugin atarapay-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-52460 Patchstack
7.1 High WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.2 CVE-2024-52462 Patchstack
7.1 High Infinite Slider Plugin infinite-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-52461 Patchstack
7.1 High amr shortcodes Plugin amr-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2024-52464 Patchstack
7.1 High Post By Email Plugin post-by-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4b CVE-2024-52463 Patchstack
7.1 High Explara Events Plugin explara-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2024-52466 Patchstack
7.1 High LGPD Framework Plugin lgpd-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2024-52465 Patchstack
7.1 High LeadBoxer Plugin leadboxer Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2024-52468 Patchstack
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
7.1 High WooCommerce Price Alert Plugin price-alert-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-52469 Patchstack
7.1 High Document & Data Automation Plugin document-data-automation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-52477 Patchstack
7.1 High LeanPress Plugin leanpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-52483 Patchstack
7.1 High Ortto Plugin autopilot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.19 Fixed in 1.0.21 CVE-2024-52482 Patchstack
7.1 High Wc Recently viewed products Plugin wc-recently-viewed-products Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52484 Patchstack
7.1 High ITERAS Plugin iteras Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-53710 Patchstack
7.1 High Kevin's Plugin kevins-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 CVE-2024-53712 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only