WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,351–7,400 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 148 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High SP Blog Designer Plugin sp-blog-designer Local File Inclusion ≤ 1.0.0 CVE-2024-52498 Patchstack
7.5 High Pricing table addon for elementor Plugin pricing-table-addon-for-elementor Local File Inclusion ≤ 1.0.0 CVE-2024-52499 Patchstack
7.5 High Office Locator Plugin office-locator Local File Inclusion ≤ 1.3.0 CVE-2024-52501 Patchstack
7.5 High Jobify Theme jobify Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52481 Patchstack
7.2 High Rank Math SEO Plugin seo-by-rank-math Remote Code Execution Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) ≤ 1.0.231 Fixed in 1.0.232 CVE-2024-11620 Patchstack
7.2 High File Manager Pro – Filester Plugin filester Local File Inclusion Filester <= 1.8.5 - Authenticated (Administrator+) Local JavaScript File Inclusion ≤ 1.8.5 CVE-2024-9669 Wordfence
7.5 High File Manager Pro – Filester Plugin filester Arbitrary File Upload Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.8.6 CVE-2024-8066 Wordfence
7.2 High Total Upkeep Plugin boldgrid-backup Remote Code Execution Authenticated (Administrator+) Remote Code Execution via Backup Settings ≤ 1.16.6 CVE-2024-9461 Wordfence
7.2 High Booking calendar, Appointment Booking System Plugin booking-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.2.15 CVE-2024-9504 Wordfence
8.1 High Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Broken Access Control Authorization Bypass due to Missing Empty Value Check to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 6.44 CVE-2024-10781 Wordfence
7.5 High Security & Malware scan by CleanTalk Plugin security-malware-firewall Broken Access Control Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection No login needed ≤ 2.145 CVE-2024-10570 Wordfence
8.8 High Booking & Appointment Plugin for WooCommerce Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 6.9.0 CVE-2024-10729 Wordfence
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
8.8 High WPGYM Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 67.1.0 CVE-2024-9941 Wordfence
7.5 High MP3 Sticky Player Plugin Path Traversal Unauthenticated Arbitrary File Read/Download No login needed ≤ 8.0 CVE-2024-10803 Wordfence
8.8 High School Management Plugin Arbitrary File Upload Authenticated (Student+) Arbitrary File Upload ≤ 91.5.0 CVE-2024-9660 Wordfence
8.8 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.4.2 CVE-2024-10873 Wordfence
8.8 High WP-Orphanage Extended Plugin wp-orphanage-extended Cross-Site Request Forgery Cross-Site Request Forgery to Orphan Account Privilege Escalation No login needed ≤ 1.2 CVE-2024-11415 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
7.5 High Tutor LMS Plugin tutor SQL Injection Unauthenticated SQL Injection via rating_filter No login needed ≤ 2.7.6 CVE-2024-10400 Wordfence
7.2 High Activity Log – Monitor & Record User Changes Plugin aryo-activity-log Cross-Site Scripting Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scripting via Event Context No login needed ≤ 2.11.1 CVE-2024-10788 Wordfence
8.8 High Contact Form 7 Email Add on Plugin cf7-email-add-on Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.9 CVE-2024-10898 Wordfence
7.2 High Grid View Gallery Plugin grid-view-gallery PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 1.0 CVE-2024-11409 Wordfence
7.1 High Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.2 CVE-2024-52470 Patchstack
7.1 High Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.37 CVE-2024-52471 Patchstack
7.1 High Weather Atlas Widget Plugin weather-atlas Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-52472 Patchstack
7.1 High HTML5 Lyrics Karaoke Player Plugin html5-lyrics-karaoke-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 CVE-2024-52473 Patchstack
8.8 High Clone Plugin wp-clone-by-wp-academy PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialized_replace' No login needed ≤ 2.4.6 CVE-2024-10913 Wordfence
8.8 High Banner System Plugin banner-system Privilege Escalation ≤ 1.0.0 CVE-2024-52437 Patchstack
8.8 High de:branding Plugin debranding Privilege Escalation ≤ 1.0.2 CVE-2024-52438 Patchstack
8.2 High Post Ideas Plugin post-ideas Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 2 CVE-2024-52451 Patchstack
7.5 High Ultimate Classified Listings Plugin ultimate-classified-listings Local File Inclusion ≤ 1.7 CVE-2024-52448 Patchstack
7.5 High Bootscraper Plugin wp-bootscraper Local File Inclusion No login needed ≤ 2.1.0 Fixed in 4.0.0 CVE-2024-52449 Patchstack
7.5 High nBlocks Plugin nblocks Local File Inclusion ≤ 1.0.2 CVE-2024-52450 Patchstack
8.8 High QRMenu Restaurant QR Menu Lite Plugin qrmenu-lite PHP Object Injection ≤ 1.0.4 CVE-2024-52445 Patchstack
8.8 High Buying Buddy IDX CRM Plugin buying-buddy-idx-crm Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 1.2.8 Fixed in 2.0.0 CVE-2024-52446 Patchstack
7.5 High Opal Woo Custom Product Variation Plugin opal-woo-custom-product-variation Arbitrary File Deletion No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-52444 Patchstack
8.6 High Contact Page With Google Map Plugin contact-page-with-google-map Arbitrary File Deletion No login needed ≤ 1.6.1 CVE-2024-52447 Patchstack
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.8.6 CVE-2024-10899 Wordfence
8.1 High Image Optimizer, Resizer and CDN – Sirv Plugin sirv Broken Access Control Sirv <= 7.3.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Option Deletion ≤ 7.3.0 CVE-2024-10855 Wordfence
7.1 High Hebrew Date Plugin hebrewdates Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.0 Fixed in 2.3.0 CVE-2024-52388 Patchstack
7.1 High Events Manager Pro – extended Plugin events-manager-pro-extended Cross-Site Request Forgery extended plugin <= 0.1 - CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-50532 Patchstack
7.1 High Domain Sharding Plugin domain-sharding Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-50533 Patchstack
7.1 High Sticky Social Bar Plugin sticky-social-bar Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-51631 Patchstack
7.1 High World Prayer Time Plugin world-prayer-time Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-50534 Patchstack
7.1 High Simple Page Specific Sidebars Plugin page-specific-sidebars Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.14.1 CVE-2024-51633 Patchstack
7.1 High SH Slideshow Plugin sh-slideshow Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.3 CVE-2024-51632 Patchstack
7.1 High While Loading Plugin while-it-is-loading Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2024-51635 Patchstack
7.1 High Webriti Custom Login Plugin webriti-custom-login-page Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3 CVE-2024-51634 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only