WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,701–7,750 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 155 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Antispam Bee Plugin antispam-bee Authentication Bypass Country IP Restriction Bypass No login needed ≤ 2.11.3 Fixed in 2.11.4 CVE-2023-41134 Patchstack
6.5 Medium Cartpauj Register Captcha Plugin cartpauj-register-captcha Authentication Bypass Captcha Bypass No login needed ≤ 1.0.02 Fixed in 2.0.0 CVE-2023-40673 Patchstack
5.4 Medium Tabs & Accordion Plugin tabs Content Injection ≤ 1.3.10 CVE-2023-40557 Patchstack
5.3 Medium WP-PostRatings Plugin wp-postratings Other Rating limit Bypass No login needed ≤ 1.91 Fixed in 1.91.1 CVE-2023-40332 Patchstack
5.4 Medium Discussion Board Plugin wp-discussion-board Content Injection ≤ 2.4.8 Fixed in 2.4.9 CVE-2023-39161 Patchstack
6.5 Medium Pinpoint Booking System Plugin booking-system Other Parameter Tampering No login needed ≤ 2.9.9.3.4 Fixed in 2.9.9.3.5 CVE-2023-38520 Patchstack
5.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Authentication Bypass IP Bypass Vulnerability No login needed ≤ 2.29.1 Fixed in 2.29.2 CVE-2023-37865 Patchstack
5.3 Medium Hide My WP Ghost Plugin hide-my-wp Authentication Bypass Security Plugin plugin <= 5.0.25 - Captcha Bypass No login needed ≤ 5.0.25 Fixed in 5.0.26 CVE-2023-34001 Patchstack
4.3 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.31 Fixed in 1.3.32 CVE-2023-28494 Patchstack
5.4 Medium Insert or Embed Articulate Content into Plugin Remote Code Execution Author+ Upload to RCE ≤ 4.3000000023 CVE-2024-0757 WPScan
4.3 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.4.10 Fixed in 1.4.11 CVE-2023-28492 Patchstack
4.3 Medium CP Contact Form with Paypal Plugin cp-contact-form-with-paypal Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.34 Fixed in 1.3.35 CVE-2023-27460 Patchstack
4.3 Medium Calculated Fields Form Plugin calculated-fields-form Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.1.120 Fixed in 1.1.121 CVE-2023-26523 Patchstack
4.3 Medium Search in Place Plugin search-in-place Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.104 Fixed in 1.0.105 CVE-2023-26521 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email Spoofing No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23738 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23735 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Authentication Bypass WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23730 Patchstack
4.3 Medium Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-35632 Patchstack
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.5 Medium ChaosTheory Theme chaostheory Cross-Site Scripting ≤ 1.3 Fixed in 1.3.2 CVE-2024-34766 Patchstack
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-34767 Patchstack
6.5 Medium Elegant Blocks Plugin elegant-blocks Cross-Site Scripting Amazing Gutenberg Blocks plugin <= 1.7 - Cross Site Scripting (XSS) ≤ 1.7 CVE-2024-34769 Patchstack
6.5 Medium Popup Maker WP Plugin popup-maker-wp Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-34770 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.16 Fixed in 2.0.17 CVE-2024-34789 Patchstack
5.9 Medium ImageMagick Sharpen Resized Images Theme imagemagick-sharpen-resized-images Cross-Site Scripting ≤ 1.1.7 CVE-2024-34790 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.0.9 Fixed in 1.2 CVE-2024-34791 Patchstack
5.9 Medium WP Next Post Navi Plugin wp-next-post-navi Cross-Site Scripting ≤ 1.8.3 CVE-2024-34793 Patchstack
6.5 Medium Tainacan Plugin tainacan Cross-Site Scripting ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34795 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-34796 Patchstack
5.9 Medium Simple Popup Manager Plugin simple-popup-manager Cross-Site Scripting ≤ 1.3.5 CVE-2024-34797 Patchstack
6.5 Medium Praison SEO Plugin seo-wordpress Cross-Site Scripting ≤ 4.0.15 Fixed in 4.0.16 CVE-2024-34801 Patchstack
5.3 Medium Contact Form Widget Plugin new-contact-form-widget Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34754 Patchstack
5.3 Medium Debug Log – Manger Tool Plugin debug-log-config-tool Information Disclosure Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2024-34798 Patchstack
4.3 Medium Fastly Plugin fastly Broken Access Control ≤ 1.2.25 Fixed in 1.2.26 CVE-2024-34803 Patchstack
4.4 Medium Blocksy Companion Plugin blocksy-companion Server-Side Request Forgery ≤ 2.0.42 Fixed in 2.0.43 CVE-2024-35633 Patchstack
4.4 Medium Ninja Tables Plugin ninja-tables Server-Side Request Forgery ≤ 5.0.9 Fixed in 5.0.10 CVE-2024-35635 Patchstack
4.4 Medium Church Admin Plugin church-admin Server-Side Request Forgery ≤ 4.3.6 Fixed in 4.4.0 CVE-2024-35637 Patchstack
4.3 Medium ActiveDEMAND Plugin activedemand Cross-Site Request Forgery No login needed ≤ 0.2.43 CVE-2024-35638 Patchstack
5.9 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2024-35639 Patchstack
5.9 Medium Safety Exit Plugin safety-exit Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2024-35640 Patchstack
5.9 Medium Just Writing Statistics Plugin just-writing-statistics Cross-Site Scripting ≤ 4.5 Fixed in 4.6 CVE-2024-35641 Patchstack
5.9 Medium Site Favicon Plugin site-favicon Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2024-35642 Patchstack
5.9 Medium WP Back Button Plugin wp-back-button Cross-Site Scripting ≤ 1.1.3 CVE-2024-35643 Patchstack
5.9 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-35645 Patchstack
5.9 Medium Smartarget Message Bar Plugin smartarget-message-bar Cross-Site Scripting ≤ 1.5 CVE-2024-35646 Patchstack
5.9 Medium Global Notification Bar Plugin global-notification-bar Cross-Site Scripting ≤ 1.0.1 CVE-2024-35647 Patchstack
4.3 Medium Uploadcare File Uploader and Adaptive Delivery (beta) Plugin uploadcare Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed ≤ 3.0.11 CVE-2024-35636 Patchstack
6.4 Medium WordPress Infinite Scroll – Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting ≤ 7.1.1 CVE-2024-4711 Wordfence
6.4 Medium Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX Plugin ultimate-post Cross-Site Scripting PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 4.1.1 CVE-2024-5223 Wordfence
5.3 Medium WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly Plugin tour-booking-manager Broken Access Control WpTravelly <= 1.7.1 - Missing Authorization via ttbm_new_place_save No login needed ≤ 1.7.1 CVE-2024-0434 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only