WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 7,801–7,850 of 9,010 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | MH Board | Local File Inclusion No login needed |
≤ 1.3.2.1 |
CVE-2024-44017 |
Patchstack | |
| 7.2 High | Checkout Mestres WP | Local File Inclusion |
≤ 8.6 Fixed in 8.6.1 |
CVE-2024-44030 |
Patchstack | |
| 7.5 High | Migration, Backup, Staging – WPvivid | Information Disclosure WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure No login needed |
0.9.103 – < 0.9.106 Fixed in 0.9.106 |
CVE-2024-7315 |
WPScan | |
| 8.8 High | WP Hotel Booking | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 2.1.2 |
CVE-2024-7855 |
Wordfence | |
| 8.8 High | WP Easy Gallery | SQL Injection Authenticated (Contributor+) SQL Injection via key Parameter |
≤ 4.8.5 |
CVE-2024-9018 |
Wordfence | |
| 8.8 High | UltraPress | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.2.2 |
CVE-2024-7434 |
Wordfence | |
| 8.1 High | KB Support – WordPress Help Desk and Knowledge Base | Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions |
≤ 1.6.6 |
CVE-2024-8548 |
Wordfence | |
| 8.8 High | Empowerment | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.0.2 |
CVE-2024-7433 |
Wordfence | |
| 7.2 High | 123.chat - Video Chat | Cross-Site Scripting Video Chat <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.3.1 |
CVE-2024-7869 |
Wordfence | |
| 8.8 High | Unseen Blog | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.0.0 |
CVE-2024-7432 |
Wordfence | |
| 7.1 High | Broken Link Checker | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.4.0 |
CVE-2024-8981 |
Wordfence | |
| 7.2 High | Cost Calculator Builder | SQL Injection Admin+ SQL Injection |
< 3.2.29 Fixed in 3.2.29 |
CVE-2024-8379 |
WPScan | |
| 8.8 High | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion |
≤ 4.0.8 |
CVE-2024-7149 |
Wordfence | |
| 7.2 High | The Events Calendar | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 6.6.3 |
CVE-2024-6931 |
Wordfence | |
| 7.5 High | AI Chatbot with ChatGPT by AYS | Information Disclosure Unauthenticated OpenAI Key Disclosure No login needed |
< 2.1.0 Fixed in 2.1.0 |
CVE-2024-7713 |
WPScan | |
| 8.8 High | Product Enquiry for WooCommerce | PHP Object Injection Authenticated (Author+) PHP Object Injection in enquiry_detail.php |
≤ 2.2.33.33 |
CVE-2024-8922 |
Wordfence | |
| 7.2 High | GiveWP – Donation Plugin and Fundraising Platform | SQL Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter |
≤ 3.16.1 |
CVE-2024-9130 |
Wordfence | |
| 7.2 High | Advanced File Manager | Local File Inclusion Authenticated (Administrator+) Local JavaScript File Inclusion via fma_locale |
≤ 5.2.8 |
CVE-2024-8704 |
Wordfence | |
| 7.5 High | Advanced File Manager | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 5.2.8 |
CVE-2024-8126 |
Wordfence | |
| 7.2 High | WordPress Visitors | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via HTTP Header No login needed |
≤ 1.0 |
CVE-2022-4541 |
Wordfence | |
| 8.1 High | Jupiter X Core | Authentication Bypass Limited Unauthenticated Authentication Bypass to Account Takeover No login needed |
≤ 4.7.5 |
CVE-2024-7781 |
Wordfence | |
| 7.1 High | Testimonials | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.1 Fixed in 4.0.2 |
CVE-2024-43959 |
Patchstack | |
| 8.8 High | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.12 - Insecure Direct Object Reference to Account Takeover/Privilege Escalation |
≤ 6.7.12 |
CVE-2024-8290 |
Wordfence | |
| 7.2 High | Uncanny Groups for LearnDash | Privilege Escalation Authenticated (Group Leader+) Privilege Escalation |
≤ 6.1.0.1 |
CVE-2024-8349 |
Wordfence | |
| 7.5 High | REST API TO MiniProgram | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 4.7.1 |
CVE-2024-8484 |
Wordfence | |
| 7.2 High | Contact Form to Any API | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Contact Form No login needed |
≤ 1.2.4 |
CVE-2024-7617 |
Wordfence | |
| 7.3 High | Special Text Boxes | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 6.2.4 |
CVE-2024-8481 |
Wordfence | |
| 7.2 High | Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam | Cross-Site Scripting MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.0.1 |
CVE-2024-8914 |
Wordfence | |
| 7.2 High | Easy Digital Downloads – Simple eCommerce for Selling Digital Files | PHP Object Injection Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization |
≤ 3.3.3 |
CVE-2022-2439 |
Wordfence | |
| 7.3 High | MDTF – Meta Data and Taxonomies Filter | Arbitrary Shortcode Execution Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.3.3.3 |
CVE-2024-8623 |
Wordfence | |
| 8.8 High | BA Book Everything | Cross-Site Request Forgery Cross-Site Request Forgery to Email Address Update/Account Takeover No login needed |
≤ 1.6.20 |
CVE-2024-8795 |
Wordfence | |
| 7.5 High | Justified Image Grid | Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed |
≤ 4.6.1 Fixed in 4.7 |
CVE-2024-43989 |
Patchstack | |
| 7.1 High | SureCart | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.29.3 Fixed in 2.29.4 |
CVE-2024-43970 |
Patchstack | |
| 7.1 High | Sunshine Photo Cart | Cross-Site Scripting No login needed |
≤ 3.2.5 Fixed in 3.2.6 |
CVE-2024-43971 |
Patchstack | |
| 7.1 High | Super Store Finder | Cross-Site Scripting No login needed |
≤ 6.9.7 Fixed in 6.9.8 |
CVE-2024-43975 |
Patchstack | |
| 7.1 High | Team Showcase | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.22.25 Fixed in 1.22.26 |
CVE-2024-44002 |
Patchstack | |
| 7.1 High | Spice Starter Sites | Cross-Site Scripting No login needed |
≤ 1.2.5 |
CVE-2024-44003 |
Patchstack | |
| 7.1 High | SKT Templates – Elementor & Gutenberg templates | Cross-Site Scripting Elementor & Gutenberg templates plugin <= 6.14 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.14 Fixed in 6.15 |
CVE-2024-44007 |
Patchstack | |
| 7.1 High | WCFM Marketplace | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.6.11 Fixed in 3.6.12 |
CVE-2024-44009 |
Patchstack | |
| 7.1 High | Name Directory | Cross-Site Scripting Reflected Cross Site Scripting (XSS) |
≤ 1.29.0 Fixed in 1.29.1 |
CVE-2024-43938 |
Patchstack | |
| 7.1 High | Like Button Rating | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.53 Fixed in 2.6.54 |
CVE-2024-44064 |
Patchstack | |
| 7.6 High | Spiffy Calendar | SQL Injection |
≤ 4.9.12 Fixed in 4.9.13 |
CVE-2024-43969 |
Patchstack | |
| 8.8 High | Houzez | Privilege Escalation |
≤ 3.2.4 Fixed in 3.3.0 |
CVE-2024-22303 |
Patchstack | |
| 8.8 High | Houzez Login Register | Privilege Escalation |
≤ 3.2.5 Fixed in 3.3.0 |
CVE-2024-21743 |
Patchstack | |
| 7.2 High | Share This Image | Open Redirect Open Redirect via link Parameter No login needed |
≤ 2.03 |
CVE-2024-8761 |
Wordfence | |
| 8.8 High | PropertyHive | Cross-Site Request Forgery Cross-Site Request Forgery via save_account_details No login needed |
≤ 2.0.19 |
CVE-2024-8490 |
Wordfence | |
| 7.1 High | Opor Ayam | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.8 |
CVE-2024-44053 |
Patchstack | |
| 7.1 High | Filmix | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1 |
CVE-2024-44060 |
Patchstack | |
| 7.1 High | Spiffy Calendar | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.9.13 Fixed in 4.9.14 |
CVE-2024-45458 |
Patchstack | |
| 7.1 High | Product Slider for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.13.50 Fixed in 1.13.51 |
CVE-2024-45459 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.