WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,751–7,800 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 156 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation Plugin optinmonster Cross-Site Scripting WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.16.1 CVE-2024-4045 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.13.0 CVE-2024-4366 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block ≤ 2.12.8 CVE-2024-1814 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block ≤ 2.12.8 CVE-2024-1815 Wordfence
6.4 Medium WordPress + Microsoft Office 365 / Azure AD | LOGIN Plugin wpo365-login Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode ≤ 27.2 CVE-2024-4706 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization ≤ 5.7.17 CVE-2024-3626 Wordfence
4.7 Medium wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin wpdatatables Cross-Site Scripting WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import No login needed ≤ 3.4.2.12 CVE-2024-4895 Wordfence
6.4 Medium Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced Plugin toolbar-extras Cross-Site Scripting WordPress Admin Bar Enhanced <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.9 CVE-2024-3611 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin learnpress Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 4.2.6.6 CVE-2024-4971 Wordfence
5.3 Medium YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin youtube-showcase Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed ≤ 3.3.6 CVE-2024-3268 Wordfence
6.4 Medium WP Table Builder – WordPress Table Plugin wp-table-builder Cross-Site Scripting WordPress Table Plugin <= 1.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.14 CVE-2024-4700 Wordfence
6.4 Medium WordPress Automatic Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter ≤ 3.94.0 CVE-2024-4849 Wordfence
5.3 Medium Flo Forms Plugin flo-forms Broken Access Control No login needed ≤ 1.0.42 CVE-2024-35174 Patchstack
4.3 Medium Integration for Contact Form 7 and Salesforce Plugin cf7-salesforce Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34755 Patchstack
4.3 Medium Integration for Contact Form 7 HubSpot Plugin cf7-hubspot Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-34756 Patchstack
4.3 Medium Clearfy Cache Plugin clearfy Cross-Site Request Forgery ≤ 2.2.1 CVE-2024-34806 Patchstack
4.3 Medium Fast Custom Social Share by CodeBard Plugin fast-custom-social-share-by-codebard Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-34807 Patchstack
4.3 Medium EmpowerWP Theme empowerwp Cross-Site Request Forgery No login needed ≤ 1.0.21 Fixed in 1.0.22 CVE-2024-34809 Patchstack
5.3 Medium Giveaways and Contests Plugin rafflepress Authentication Bypass IP Restriction Bypass No login needed ≤ 1.12.7 Fixed in 1.12.11 CVE-2024-32827 Patchstack
5.3 Medium BP Better Messages Plugin bp-better-messages Authentication Bypass Broken Authentication No login needed ≤ 2.4.32 Fixed in 2.4.33 CVE-2024-32802 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Authentication Bypass IP Bypass No login needed ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-32786 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Other Group Members Limit Bypass ≤ 5.8.2 Fixed in 5.8.3 CVE-2024-32774 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Authentication Bypass Captcha Bypass No login needed ≤ 1.4.56 Fixed in 1.4.57 CVE-2024-32720 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Other Review Score Manipulation No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32685 Patchstack
5.3 Medium Zero Spam Plugin zero-spam Other Bypass Spam Protection No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2024-32521 Patchstack
5.3 Medium weForms Plugin weforms Other Form Submission Restriction Bypass No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-32512 Patchstack
6.3 Medium Church Admin Plugin church-admin Broken Access Control ≤ 4.1.6 Fixed in 4.1.7 CVE-2024-31281 Patchstack
6.5 Medium SellKit Plugin sellkit Path Traversal Arbitrary File Download ≤ 1.8.1 Fixed in 1.8.3 CVE-2024-30509 Patchstack
6.5 Medium BookIt Plugin bookit Other Price Bypass Vulnerability No login needed ≤ 2.4.0 Fixed in 2.4.2 CVE-2024-24715 Patchstack
5.3 Medium Formidable Forms Plugin formidable Content Injection No login needed ≤ 6.7 Fixed in 6.7.1 CVE-2024-23522 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Authentication Bypass IP limit Bypass No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2024-21746 Patchstack
6.3 Medium Ultimate Addons for Beaver Builder Plugin ultimate-addons-for-beaver-builder-lite Path Traversal Limited Arbitrary File Download ≤ 1.35.13 Fixed in 1.35.14 CVE-2023-51401 Patchstack
6.8 Medium Salon booking system Plugin salon-booking-system Privilege Escalation Editor+ Privilege Escalation ≤ 8.6 Fixed in 8.7 CVE-2023-48319 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion ≤ 1.6.3 Fixed in 1.6.4 CVE-2023-47679 Patchstack
5.3 Medium Popup by Supsystic Plugin popup-by-supsystic Information Disclosure Unauthenticated Subscriber Email Addresses Disclosure No login needed ≤ 1.10.19 Fixed in 1.10.20 CVE-2023-46197 Patchstack
6.5 Medium Remote Content Shortcode Plugin remote-content-shortcode Local File Inclusion ≤ 1.5 CVE-2023-45652 Patchstack
5.3 Medium CP Polls Plugin cp-polls Other Polls Limitation Bypass No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24873 Patchstack
5.3 Medium CP Polls Plugin cp-polls Content Injection No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24874 Patchstack
5.3 Medium Defender Security Plugin defender-security Authentication Bypass IP Restriction Bypass No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2024-25595 Patchstack
4.3 Medium Comments Like Dislike Plugin comments-like-dislike Authentication Bypass IP Restriction Bypass Vulnerability ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-25906 Patchstack
5.3 Medium IP Blocker Lite Plugin ip-address-blocker Authentication Bypass No login needed ≤ 11.1.1 CVE-2024-30479 Patchstack
5.3 Medium Newsletter Plugin newsletter Authentication Bypass IP Blacklist Bypass No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2024-30522 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.7 Fixed in 14.8 CVE-2024-30540 Patchstack
5.3 Medium Captcha by BestWebSoft Plugin captcha-bws Authentication Bypass Captcha Bypass No login needed ≤ 5.2.0 Fixed in 5.2.1 CVE-2024-31295 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Other Bypass Vulnerability No login needed ≤ 3.11.2 Fixed in 3.11.3 CVE-2024-31341 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure File Password Lock Bypass No login needed ≤ 3.2.82 Fixed in 3.2.83 CVE-2024-32131 Patchstack
4.3 Medium Pricing Table by Supsystic Plugin pricing-table-by-supsystic Content Injection ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-32790 Patchstack
5.3 Medium WTI Like Post Plugin wti-like-post Authentication Bypass IP Restriction Bypass Vulnerability No login needed ≤ 1.4.6 CVE-2024-33917 Patchstack
6.5 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Arbitrary Shortcode Execution Meta Data and Taxonomies Filter plugin <= 1.3.3.2 - Arbitrary Shortcode Execution No login needed ≤ 1.3.3.2 Fixed in 1.3.3.3 CVE-2024-34434 Patchstack
5.3 Medium Headless CMS Plugin headless-cms Authentication Bypass Broken Authentication No login needed ≤ 2.0.3 CVE-2023-34186 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only