WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,501–7,550 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 151 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Simplistic SEO Plugin simplistic-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.0 CVE-2024-51719 Patchstack
7.1 High SVT Simple Plugin svt-simple Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-51759 Patchstack
7.1 High Dashing Memberships Plugin dashing-memberships Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51760 Patchstack
7.1 High WPHelpful Plugin wphelpful Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2024-51761 Patchstack
7.3 High Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Arbitrary Shortcode Execution Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.13.0 CVE-2024-10261 Wordfence
7.3 High The FOX – Currency Switcher Professional for WooCommerce Plugin Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.2 CVE-2024-10640 Wordfence
7.1 High PropertyShift Plugin propertyshift Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-51762 Patchstack
7.1 High Team Showcase and Slider – Team Members Builder Plugin team-showcase-ultimate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51763 Patchstack
7.1 High Conversion Helper Plugin conversion-helper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2024-10676 Patchstack
7.1 High Daily Image Plugin daily-image Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51776 Patchstack
7.1 High Satisfaction Reports from Help Scout Plugin happiness-reports-for-help-scout Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-51778 Patchstack
7.1 High Don't Break The Code Plugin dont-break-the-code Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ .3.1 CVE-2024-51779 Patchstack
7.1 High eewee admin custom Plugin eewee-admincustom Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.2.4 CVE-2024-51780 Patchstack
7.1 High Firework Shoppable Live Video Plugin firework-videos Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.3 CVE-2024-51781 Patchstack
8.5 High Administrator Z Plugin administrator-z SQL Injection ≤ 2024.10.21 Fixed in 2024.10.21 CVE-2024-50524 Patchstack
8.5 High Lodgix.com Vacation Rental Website Builder Plugin lodgixcom-vacation-rental-listing-management-booking-plugin SQL Injection ≤ 3.9.73 CVE-2024-50539 Patchstack
8.5 High RSVP ME Plugin rsvp-me SQL Injection ≤ 1.9.9 CVE-2024-50544 Patchstack
8.5 High Easy Gallery Plugin simple-gallery-odihost SQL Injection ≤ 1.4 CVE-2024-51570 Patchstack
8.5 High 5 Stars Rating Funnel Plugin 5-stars-rating-funnel SQL Injection ≤ 1.4.01 CVE-2024-51579 Patchstack
8.5 High Website price calculator Plugin price-calculator-to-your-website SQL Injection ≤ 4.1 CVE-2024-51601 Patchstack
8.5 High Simple Job Manager Plugin simple-job-manager SQL Injection ≤ 1.1 CVE-2024-51602 Patchstack
8.5 High Golf Tracker Plugin golf-tracker SQL Injection ≤ 0.7 CVE-2024-51607 Patchstack
8.5 High Market 360 Viewer Plugin market-360-viewer SQL Injection ≤ 1.01 CVE-2024-51619 Patchstack
8.5 High Porsline Plugin porsline SQL Injection ≤ 1.0.2 Fixed in 1.1 CVE-2024-51620 Patchstack
8.5 High Download-Mirror-Counter Plugin wp-download-mirror-counter SQL Injection ≤ 1.1 CVE-2024-51621 Patchstack
8.5 High Quran Shortcode Plugin quran-shortcode SQL Injection ≤ 1.5 CVE-2024-51625 Patchstack
7.1 High Loginplus Plugin loginplus Cross-Site Scripting No login needed ≤ 1.2 CVE-2024-51782 Patchstack
7.1 High Forms: 3rd-Party Post Again Plugin forms-3rdparty-post-again Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3 CVE-2024-51783 Patchstack
7.1 High FriendStore for WooCommerce Plugin friendstore-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.2 CVE-2024-51784 Patchstack
8.8 High WooCommerce Support Ticket System Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 17.7 CVE-2024-10626 Wordfence
8.8 High Th Shop Mania Theme th-shop-mania Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.4.9 CVE-2024-10674 Wordfence
8.8 High Top Store Theme top-store Broken Access Control Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.5.4 CVE-2024-10673 Wordfence
8.1 High Social Share, Social Login and Social Comments Plugin – Super Socializer Plugin Authentication Bypass Super Socializer <= 7.13.68 - Authentication Bypass via Disqus OAuth provider No login needed ≤ 7.13.68 CVE-2024-9946 Wordfence
8.1 High Heateor Social Login Plugin Authentication Bypass Authentication Bypass via Disqus OAuth provider No login needed ≤ 1.1.35 CVE-2024-10020 Wordfence
7.5 High Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup Information Disclosure WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log No login needed ≤ 2.2.13 CVE-2024-10028 Wordfence
7.3 High Tickera – WordPress Event Ticketing Plugin tickera-event-ticketing-system Arbitrary Shortcode Execution WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.5.4.4 CVE-2024-10263 Wordfence
8.8 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.1 CVE-2024-10711 Wordfence
8.1 High Social Login - WordPress / WooCommerce Plugin Authentication Bypass WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 2.7.7 CVE-2024-10114 Wordfence
8.1 High Loginizer Security and Loginizer Plugin loginizer Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 1.9.2 CVE-2024-10097 Wordfence
8.5 High Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection ≤ 1.1 CVE-2024-51626 Patchstack
7.6 High BetterLinks Plugin betterlinks SQL Injection ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-51672 Patchstack
7.5 High Stacks Mobile App Builder Plugin stacks-mobile-app-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.3 CVE-2024-50528 Patchstack
7.5 High WP Hotel Booking Plugin wp-hotel-booking Local File Inclusion ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-51582 Patchstack
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-47314 Patchstack
7.7 High WishList Member X Plugin Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37108 Patchstack
8.2 High WishList Member X Plugin Cross-Site Scripting Unautenticated Plugin Settings Change Leading to Stored XSS No login needed ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37106 Patchstack
8.8 High Hercules Core Plugin Broken Access Control Subscriber+ Arbitrary Settings Change/Access ≤ 6.5 Fixed in 6.7 CVE-2024-37232 Patchstack
7.5 High Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37277 Patchstack
8.5 High Newspack Blocks Plugin Arbitrary File Deletion Contributor+ Arbitrary Directory Deletion ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37423 Patchstack
8.2 High Woffice Core Plugin woffice-core Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 5.4.8 Fixed in 5.4.9 CVE-2024-37470 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only