WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,701–7,750 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 155 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-5429 WPScan
8.8 High Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors Plugin publishpress-authors Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary User Email Update and Account Takeover ≤ 4.7.1 CVE-2024-9215 Wordfence
8.1 High Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Authentication Bypass No login needed ≤ 3.6.0 CVE-2024-9861 Wordfence
7.1 High disconnected Theme disconnected Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-49268 Patchstack
7.5 High Ahime Image Printer Plugin ahime-image-printer Path Traversal Arbitrary File Download No login needed ≤ 1.0.0 CVE-2024-49245 Patchstack
7.5 High MaxSlider Plugin maxslider Local File Inclusion ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-47351 Patchstack
7.5 High Top Bar – PopUps – by WPOptin Plugin wpoptin Local File Inclusion No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-47645 Patchstack
7.5 High SB Random Posts Widget Plugin sb-random-posts-widget Local File Inclusion ≤ 1.0 Fixed in 1.1 CVE-2024-48029 Patchstack
7.5 High Maan Addons For Elementor Plugin maan-elementor-addons Local File Inclusion ≤ 1.0.1 CVE-2024-49251 Patchstack
8.8 High TAKETIN To WP Membership Plugin taketin-to-wp-membership PHP Object Injection ≤ 2.8.17 CVE-2024-49226 Patchstack
8.8 High Free Stock Photos Foter Plugin free-stock-photos-foter PHP Object Injection No login needed ≤ 1.5.4 CVE-2024-49227 Patchstack
8.8 High LiteSpeed Cache Plugin litespeed-cache Path Traversal ≤ 6.4.1 Fixed in 6.5.1 CVE-2024-47637 Patchstack
8.6 High Analyse Uploads Plugin analyse-uploads Arbitrary File Deletion No login needed ≤ 0.5 CVE-2024-49253 Patchstack
8.8 High Migration, Backup, Staging – WPvivid Plugin Arbitrary File Upload WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 0.9.35 CVE-2020-36842 Wordfence
7.1 High Google Language Translator Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 6.0.10 Fixed in 6.0.10 CVE-2021-4452 Wordfence
7.3 High Timetable and Event Schedule by MotoPress Plugin mp-timetable Broken Access Control Missing Authorization No login needed ≤ 2.3.8 CVE-2020-36840 Wordfence
7.3 High WP Popup Builder – Popup Forms and Marketing Lead Generation Plugin wp-popup-builder Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed ≤ 1.3.5 CVE-2024-9061 Wordfence
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_profile' ≤ 4.3.7 CVE-2023-7294 Wordfence
8.3 High WP Lead Plus X Plugin free-sales-funnel-squeeze-pages-landing-page-builder-templates-make Cross-Site Request Forgery No login needed ≤ 0.99 CVE-2020-36839 Wordfence
8.8 High File Manager Pro Plugin filester Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 8.3.9 CVE-2024-8507 Wordfence
7.2 High Rich Reviews Plugin Cross-Site Scripting Stored Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2019-25216 Wordfence
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_account' ≤ 4.3.7 CVE-2023-7291 Wordfence
7.2 High ShopWP Plugin wpshopify Broken Access Control Missing Authorization to Stored Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2019-25214 Wordfence
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 4.6.4 CVE-2021-4447 Wordfence
7.2 High MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin Cross-Site Scripting The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting No login needed < 3.1.3 Fixed in 3.1.3 CVE-2016-15041 Wordfence
7.5 High Download Monitor Plugin download-monitor Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 4.7.51 CVE-2022-4972 Wordfence
8.8 High Post Grid Plugin post-grid SQL Injection Contributor+ SQL Injection < 2.1.13 Fixed in 2.1.13 CVE-2021-4450 Wordfence
8.3 High Formidable Form Builder Plugin formidable Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed < 2.05.03 Fixed in 2.05.03 CVE-2017-20192 Wordfence
7.5 High File Manager Pro Plugin filester Remote Code Execution Unauthenticated Backup File Download and Upload No login needed ≤ 8.3.9 CVE-2024-8746 Wordfence
8.0 High WP Fastest Cache Plugin wp-fastest-cache Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion < 0.9.0.3 Fixed in 0.9.0.3 CVE-2020-36836 Wordfence
7.3 High ARI-Adminer Plugin Broken Access Control Missing Authorization and No Direct File Access Restrictions No login needed ≤ 1.1.14 CVE-2019-25215 Wordfence
8.3 High Mapplic Lite and Mapplic <= (Various Versions) Plugin Server-Side Request Forgery Server Side Request Forgery to Cross-Site Scirpting No login needed < 1.0.1, < 6.2 Fixed in 1.0.1 CVE-2012-10018 Wordfence
7.3 High Kaswara Modern VC Addons Plugin Broken Access Control Missing Authorization No login needed ≤ 3.0.1 CVE-2021-4448 Wordfence
7.4 High Facebook Chat Plugin Broken Access Control Missing Capabilities Check < 1.6 Fixed in 1.6 CVE-2020-36838 Wordfence
7.3 High Product Filter by WooBeWoo Plugin Broken Access Control Missing Authorization No login needed ≤ 1.4.9 CVE-2021-4444 Wordfence
7.4 High File Manager Pro Plugin filester Arbitrary File Upload Unauthenticated Limited JavaScript File Upload No login needed ≤ 8.3.9 CVE-2024-8918 Wordfence
8.1 High AppPresser – Mobile App Framework Plugin apppresser Privilege Escalation Mobile App Framework <= 4.4.4 - Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 4.4.4 CVE-2024-9305 Wordfence
7.3 High AADMY – Add Auto Date Month Year Into Posts Plugin auto-date-year-month Arbitrary Shortcode Execution Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.1 CVE-2024-9837 Wordfence
8.8 High WP 2FA with Telegram Plugin two-factor-login-telegram Authentication Bypass Authenticated (Subscriber+) Authentication Bypass ≤ 3.0 CVE-2024-9687 Wordfence
7.2 High Slimstat Analytics Plugin wp-slimstat Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.2.6 CVE-2024-9548 Wordfence
7.2 High Boost Your Blog's Engagement with WP Post Author Plugin wp-post-author SQL Injection Authenticated (Administrator+) SQL Injection ≤ 3.8.1 CVE-2024-8757 Wordfence
8.8 High Bot for Telegram on WooCommerce Plugin bot-for-telegram-on-woocommerce Information Disclosure Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass ≤ 1.2.7 CVE-2024-9821 Wordfence
8.5 High Tainacan Plugin tainacan SQL Injection ≤ 0.21.8 Fixed in 0.21.9 CVE-2024-48040 Patchstack
8.5 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule SQL Injection ≤ 1.22.21 Fixed in 1.22.22 CVE-2024-48020 Patchstack
7.2 High TS Poll – Survey, Versus Poll, Image Poll, Video Poll Plugin poll-wp SQL Injection Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter ≤ 2.4.0 CVE-2024-9022 Wordfence
7.3 High Shortcodes AnyWhere Plugin shortcodes-anywhere Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0.1 CVE-2024-9581 Wordfence
8.8 High WP Users Masquerade Plugin wp-users-masquerade Authentication Bypass Authenticated (Subscriber+) Authentication Bypass ≤ 2.0.0 CVE-2024-9522 Wordfence
7.2 High UserPlus Plugin userplus Privilege Escalation Authenticated (Editor+) Registration Form Update to Privilege Escalation ≤ 2.0 CVE-2024-9519 Wordfence
7.6 High Zoho Flow Plugin zoho-flow SQL Injection ≤ 2.7.1 Fixed in 2.8.1 CVE-2024-47334 Patchstack
8.5 High pretix Widget Plugin pretix-widget Local File Inclusion Local File Inclusion in pretix-widget WordPress plugin 1.0.0 – 1.0.5 Fixed in 1.0.6 CVE-2024-9575 rami.io

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only