WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,451–7,500 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 150 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High DigiPass Plugin digipass Path Traversal Arbitrary File Download No login needed ≤ 0.3.0 CVE-2024-52378 Patchstack
7.5 High Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin ai-auto-tool Broken Access Control No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2024-52383 Patchstack
8.1 High ZIJ KART Plugin zij-kart Local File Inclusion No login needed ≤ 1.1 CVE-2024-52381 Patchstack
8.6 High Global Gateway e4 | Payeezy Gateway | Plugin globe-gateway-e4 Arbitrary File Deletion No login needed ≤ 2.0 CVE-2024-52371 Patchstack
8.8 High Migration, Backup, Staging – WPvivid Plugin wpvivid-backuprestore PHP Object Injection WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection No login needed ≤ 0.9.107 CVE-2024-10962 Wordfence
8.6 High Automation By Autonami Plugin SQL Injection Unauthenticated SQLi No login needed < 3.3.0 Fixed in 3.3.0 CVE-2024-9186 WPScan
8.8 High WordPress User Extra Fields Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 16.6 CVE-2024-10800 Wordfence
7.5 High LUNA RADIO PLAYER Plugin Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 6.24.01.24 CVE-2024-10816 Wordfence
7.3 High WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts Plugin wedevs-project-manager Broken Access Control Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass No login needed ≤ 2.6.13 CVE-2024-10174 Wordfence
8.1 High Advanced Order Export For WooCommerce Plugin woo-order-export-lite PHP Object Injection Unauthenticated PHP Object Injection via Order Details No login needed ≤ 3.5.5 CVE-2024-10828 Wordfence
8.8 High GPX Viewer Plugin gpx-viewer Broken Access Control Authenticated (Subscriber+) Arbitrary File Creation ≤ 2.2.9 CVE-2024-10629 Wordfence
8.5 High L Squared Hub WP Plugin l-squared-hub-wp-virtual-device SQL Injection ≤ 1.0 CVE-2024-51820 Patchstack
8.5 High WP Contest Plugin wp-contest SQL Injection ≤ 1.0.0 CVE-2024-51837 Patchstack
8.5 High Horsemanager Plugin fruitcake-horsemanager SQL Injection ≤ 1.3 CVE-2024-51843 Patchstack
8.5 High Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection ≤ 1.0.2 CVE-2024-51845 Patchstack
8.5 High Gboy Custom Google Map Plugin gboy-custom-google-map SQL Injection ≤ 1.2 CVE-2024-51882 Patchstack
7.3 High WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay No login needed ≤ 8.8.08.007 CVE-2024-10958 Wordfence
8.5 High Blrt WP Embed Plugin blrt-wp-embed SQL Injection ≤ 1.6.9 CVE-2024-51606 Patchstack
8.5 High AmaDiscount Plugin amadiscount SQL Injection ≤ 1.0 CVE-2024-51608 Patchstack
8.5 High WP EIS Plugin wp-eis SQL Injection ≤ 1.3.3 CVE-2024-51623 Patchstack
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.25 CVE-2024-51647 Patchstack
7.1 High CF7 WOW Styler Plugin cf7-styler Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2024-51689 Patchstack
7.1 High Wp Slide Categorywise Plugin wp-slide-categorywise Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51690 Patchstack
7.1 High Admin Amplify Plugin wpr-admin-amplify Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51691 Patchstack
7.1 High Bing Search API Integration Plugin abbs-bing-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2024-51692 Patchstack
7.1 High Search order by product SKU for WooCommerce Plugin search-order-by-product-sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2024-51693 Patchstack
7.1 High Geotagged Media Plugin geotagged-media Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.0 CVE-2024-51694 Patchstack
7.1 High Fabrica Synced Pattern Instances Plugin fabrica-reusable-block-instances Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2024-51695 Patchstack
7.1 High Content Syndication Toolkit Reader Plugin content-syndication-toolkit-reader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2024-51696 Patchstack
7.1 High Doofinder Plugin doofinder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.4 CVE-2024-51697 Patchstack
7.1 High Master Bar Plugin master-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51698 Patchstack
7.1 High Buooy Sticky Header Plugin buooy-sticky-header Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.2 CVE-2024-51699 Patchstack
7.1 High MG Post Contributors Plugin mg-post-contributors Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3. CVE-2024-51701 Patchstack
7.1 High SrcSet Responsive Images Plugin truenorth-srcset Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-51702 Patchstack
7.1 High WP-Basics Plugin wp-basics Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-51703 Patchstack
7.1 High imPress Plugin wp-js-impress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.4 CVE-2024-51704 Patchstack
7.1 High WP MMenu Lite Plugin wp-mmenu-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-51705 Patchstack
7.1 High UW Freelancer Plugin uw-freelancer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-51706 Patchstack
7.1 High WP Visual Adverts Plugin wp-visual-adverts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.0 CVE-2024-51707 Patchstack
7.1 High Narnoo Commerce Manager Plugin narnoo-commerce-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.0 CVE-2024-51708 Patchstack
7.1 High TeleAdmin Plugin teleadmin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-51709 Patchstack
7.1 High Responsive Data Table Plugin responsive-data-table Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51710 Patchstack
7.1 High Saragna Plugin saragna-social-stream Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51711 Patchstack
7.1 High Jigoshop – Store Toolkit Plugin jigoshop-store-toolkit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2024-51712 Patchstack
7.1 High HQ60 Fidelity Card Plugin hq60-fidelity-card Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2024-51713 Patchstack
7.1 High User Password Reset Plugin user-password-reset Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51714 Patchstack
7.1 High Twitter real time search scrolling Plugin twitter-real-time-search-scrolling Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0 CVE-2024-51716 Patchstack
7.1 High Ajax Content Filter Plugin ajax-content-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51717 Patchstack
7.1 High Simple Modal Plugin simplemodal Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2024-51718 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only