WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,551–7,600 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 152 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Upload Fields for WPForms Plugin upload-fields-for-wpforms Broken Access Control No login needed ≤ 1.0.2 CVE-2024-35661 Patchstack
5.4 Medium Simple COD Fees for WooCommerce Plugin simple-cod-fee-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-35662 Patchstack
5.3 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Broken Access Control No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-31276 Patchstack
6.5 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.8 Fixed in 3.9.9 CVE-2024-31284 Patchstack
6.3 Medium Easy Social Share Buttons Plugin Broken Access Control Multiple Broken Access Control ≤ 9.4 Fixed in 9.5 CVE-2024-31307 Patchstack
4.3 Medium Tracking Code Manager Plugin tracking-code-manager Broken Access Control ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-31347 Patchstack
4.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control ≤ 4.3.1 Fixed in 4.3.2 CVE-2024-31350 Patchstack
5.3 Medium Email Subscribers & Newsletters Plugin email-subscribers Broken Access Control No login needed ≤ 5.7.13 Fixed in 5.7.14 CVE-2024-31352 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
4.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control ≤ 0.1.0.24 Fixed in 0.1.0.25 CVE-2024-32701 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.5 Fixed in 0.6.2.6 CVE-2024-31423 Patchstack
5.4 Medium AI Post Generator | AutoWriter Plugin ai-post-generator Broken Access Control ≤ 3.3 Fixed in 3.4 CVE-2024-32713 Patchstack
4.3 Medium Academy LMS Plugin academy Broken Access Control ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-32714 Patchstack
5.3 Medium 5 Stars Rating Funnel Plugin 5-stars-rating-funnel Broken Access Control No login needed ≤ 1.2.67 Fixed in 1.3.02 CVE-2024-32725 Patchstack
5.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-32727 Patchstack
5.3 Medium Vision Interactive Plugin vision Broken Access Control Image Map Builder plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-32779 Patchstack
4.3 Medium Advanced Testimonial Carousel for Elementor Plugin advanced-testimonial-carousel-for-elementor Broken Access Control ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-32783 Patchstack
4.3 Medium CookieHub Plugin cookiehub Broken Access Control ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-32784 Patchstack
4.3 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Broken Access Control ≤ 3.7.1 Fixed in 3.7.2 CVE-2024-32787 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.7.3 Fixed in 3.7.4 CVE-2024-32792 Patchstack
5.4 Medium WP LinkedIn Auto Publish Plugin wp-linkedin-auto-publish Broken Access Control ≤ 8.11 Fixed in 8.12 CVE-2024-32797 Patchstack
5.3 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2024-32799 Patchstack
4.3 Medium WP GoToWebinar Plugin wp-gotowebinar Broken Access Control ≤ 14.46 Fixed in 15.1 CVE-2024-32804 Patchstack
6.5 Medium Social Snap Plugin socialsnap Broken Access Control No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-32805 Patchstack
5.3 Medium USPS Shipping for WooCommerce – Live Rates Plugin flexible-shipping-usps Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed ≤ 1.9.4 Fixed in 1.10.0 CVE-2024-32811 Patchstack
5.3 Medium Integrate Google Drive Plugin integrate-google-drive Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.3.91 CVE-2024-32813 Patchstack
5.3 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32814 Patchstack
4.3 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Broken Access Control Meta Data and Taxonomies Filter plugin <= 1.3.3 - Broken Access Control ≤ 1.3.3 Fixed in 1.3.3.1 CVE-2024-32818 Patchstack
5.3 Medium Social Share Icons & Social Share Buttons Plugin ultimate-social-media-plus Broken Access Control Broken Access Control lead to Notice Dismissal No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2024-32820 Patchstack
4.3 Medium Total Poll Lite Plugin totalpoll-lite Broken Access Control ≤ 4.9.9 Fixed in 4.10.0 CVE-2024-32821 Patchstack
5.4 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-32824 Patchstack
5.3 Medium WZone Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 14.0.10 CVE-2024-33545 Patchstack
4.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Broken Access Control ≤ 3.2.5 Fixed in 3.2.6 CVE-2024-33572 Patchstack
4.3 Medium Aiomatic Plugin Broken Access Control ≤ 1.9.3 Fixed in 1.9.4 CVE-2024-34435 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on API No login needed ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-35660 Patchstack
4.3 Medium Debug Log Manager Plugin debug-log-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-35669 Patchstack
5.3 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.11 Fixed in 3.9.12 CVE-2024-31274 Patchstack
5.3 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control No login needed ≤ 2.8.3 Fixed in 2.8.4 CVE-2024-31273 Patchstack
4.3 Medium Flexible Checkout Fields for WooCommerce Plugin flexible-checkout-fields Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-31267 Patchstack
4.3 Medium Announcer – Notification & message bars Plugin announcer Broken Access Control Notification & message bars plugin <= 6.0 - Broken Access Control ≤ 6.0 Fixed in 6.0.1 CVE-2024-31261 Patchstack
4.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-31252 Patchstack
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control ≤ 3.5.2 Fixed in 3.6.0 CVE-2024-31248 Patchstack
5.3 Medium Whizzy Plugin whizzy Broken Access Control No login needed ≤ 1.1.18 CVE-2024-30544 Patchstack
5.3 Medium Tainacan Plugin tainacan Broken Access Control No login needed ≤ 0.20.7 Fixed in 0.20.8 CVE-2024-30529 Patchstack
4.3 Medium Sliced Invoices Plugin sliced-invoices Broken Access Control ≤ 3.9.2 Fixed in 3.9.3 CVE-2024-30517 Patchstack
4.3 Medium Events Manager Plugin events-manager Broken Access Control ≤ 6.4.6.4 Fixed in 6.4.7 CVE-2024-30515 Patchstack
6.5 Medium JCH Optimize Plugin jch-optimize Broken Access Control ≤ 4.0.0 Fixed in 4.0.1 CVE-2024-30481 Patchstack
6.5 Medium YITH WooCommerce Account Funds Premium Plugin Broken Access Control ≤ 1.33.0 Fixed in 1.34.0 CVE-2024-30470 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.4.9 Fixed in 4.4.10 CVE-2024-30467 Patchstack
5.4 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.4 Fixed in 5.3.5 CVE-2024-30466 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only