WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,851–7,900 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 158 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Login with phone number Plugin login-with-phone-number Broken Access Control Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation ≤ 1.7.49 CVE-2024-6482 Wordfence
7.3 High Simple Spoiler Plugin simple-spoiler Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed 1.2 – 1.3 CVE-2024-8479 Wordfence
8.8 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Privilege Escalation Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation ≤ 2.8.11 CVE-2024-8246 Wordfence
7.3 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.1 CVE-2024-8271 Wordfence
7.2 High WP Editor Plugin wp-editor PHP Object Injection Authenticated (Admin+) PHAR Deserialization ≤ 1.2.9 CVE-2022-2446 Wordfence
8.8 High Stream Plugin stream Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 4.0.1 CVE-2024-7423 Wordfence
7.3 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed ≤ 4.15.3 CVE-2024-8269 Wordfence
8.1 High Favicon Generator Plugin Arbitrary File Upload Arbitrary File Upload via CSRF < 2.1 Fixed in 2.1 CVE-2024-7863 WPScan
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
7.2 High Adicon Server Plugin adicon-server-16x16 SQL Injection Admin+ SQL Injection ≤ 1.2 CVE-2024-7766 WPScan
8.1 High WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) Plugin delicious-recipes Remote Code Execution Recipe Plugin for Food Bloggers (formerly Delicious Recipes) <= 1.6.9 - Improper Path Validation to Authenticated (Subscriber+) Arbitrary File Move and Read ≤ 1.6.9 CVE-2024-7626 Wordfence
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid Privilege Escalation Authenticated (Subscriber+) Privilege Escalation 2.2.87 – 2.2.90 CVE-2024-8253 Wordfence
8.8 High Bit File Manager – 100% Free & Open Source File Manager and Code Editor Plugin file-manager Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 6.5.5 CVE-2024-7770 Wordfence
7.3 High Affiliate Super Assistent Plugin amazonsimpleadmin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.5.3 CVE-2024-8478 Wordfence
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Authenticated (Subscriber+) Arbitrary Function Call ≤ 2.2.4 CVE-2024-8268 Wordfence
8.8 High Pinpoint Booking System Plugin booking-system SQL Injection Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection ≤ 2.9.9.5.0 CVE-2024-7112 Wordfence
7.2 High Ninja Forms File Uploads Plugin Arbitrary File Upload Unauthenticated Stored Cross-Site Scripting via File Upload No login needed ≤ 3.3.16 CVE-2024-1596 Wordfence
8.8 High ForumWP – Forum & Discussion Board Plugin forumwp Broken Access Control Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account Takeover ≤ 2.0.2 CVE-2024-8428 Wordfence
7.2 High LifterLMS Plugin lifterlms SQL Injection Authenticated (Admin+) SQL Injection ≤ 7.7.5 CVE-2024-7349 Wordfence
8.8 High Image Optimizer, Resizer and CDN – Sirv Plugin sirv Broken Access Control Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload ≤ 7.2.7 CVE-2024-8480 Wordfence
8.8 High Newsletters Plugin newsletters-lite Privilege Escalation Authenticated Privilege Escalation ≤ 4.9.9.2 CVE-2024-8247 Wordfence
8.1 High Bit File Manager Plugin file-manager Remote Code Execution Unauthenticated Remote Code Execution via Race Condition No login needed 6.0 – 6.5.5 CVE-2024-7627 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.0.8 CVE-2024-8102 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Path Traversal WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download ≤ 3.0.8 CVE-2024-8104 Wordfence
7.5 High Sensei LMS Plugin sensei-lms Broken Access Control Unauthenticated Email Template Leak No login needed < 4.24.2 Fixed in 4.24.2 CVE-2024-7786 WPScan
8.8 High WP Events Manager Plugin wp-events-manager SQL Injection Authenticated (Subscriber+) Time-Based SQL Injection ≤ 2.1.11 CVE-2024-7717 Wordfence
8.8 High Attire Theme attire PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.0.6 CVE-2024-7435 Wordfence
8.8 High Clean Login Plugin clean-login Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.14.5 CVE-2024-8252 Wordfence
8.8 High Betheme Theme PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 27.5.6 CVE-2024-2694 Wordfence
7.1 High Tutor LMS Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.7.2 CVE-2024-5784 Wordfence
7.1 High Magic Post Thumbnail Plugin magic-post-thumbnail Cross-Site Scripting Magic Post Thumbnail plugin <= 5.2.9 - Cross Site Scripting (XSS) No login needed ≤ 5.2.9 Fixed in 5.2.10 CVE-2024-43921 Patchstack
7.1 High Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.3.2 Fixed in 2.8.3.4 CVE-2024-43926 Patchstack
7.1 High WP Armour Extended Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43948 Patchstack
7.1 High Brickscore Plugin Cross-Site Scripting No login needed ≤ 1.4.2.5 CVE-2024-43950 Patchstack
7.1 High IntoTheDark Theme intothedark Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2024-43958 Patchstack
7.1 High YellowPencil Visual CSS Style Editor Plugin yellow-pencil-visual-theme-customizer Cross-Site Scripting No login needed ≤ 7.6.1 Fixed in 7.6.4 CVE-2024-43963 Patchstack
8.2 High SendGrid Plugin wp-sendgrid-mailer SQL Injection No login needed ≤ 1.4 CVE-2024-43965 Patchstack
8.5 High Greenshift Woocommerce Addon Plugin SQL Injection Subscriber+ SQL Injection < 1.9.8 Fixed in 1.9.8 CVE-2024-43943 Patchstack
8.5 High Greenshift Query and Meta Addon Plugin SQL Injection Subscriber+ SQL Injection < 3.9.2 Fixed in 3.9.2 CVE-2024-43942 Patchstack
7.6 High Salon booking system Plugin salon-booking-system SQL Injection Authenticated SQL Injection ≤ 10.7 Fixed in 10.8 CVE-2024-39658 Patchstack
8.5 High Registrations for the Events Calendar Plugin registrations-for-the-events-calendar SQL Injection ≤ 2.12.2 Fixed in 2.12.3 CVE-2024-39638 Patchstack
8.5 High ListingPro Plugin listingpro-plugin SQL Injection ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39620 Patchstack
8.5 High Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto SQL Injection ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-38793 Patchstack
7.6 High WP User Frontend Plugin wp-user-frontend SQL Injection ≤ 4.0.7 Fixed in 4.0.8 CVE-2024-38693 Patchstack
8.8 High Front End Users Plugin front-end-only-users SQL Injection Authenticated (Contributor+) Time-Based SQL Injection ≤ 3.2.28 CVE-2024-7607 Wordfence
8.1 High MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion ≤ 5.7.0.1 CVE-2024-7856 Wordfence
7.2 High Theme Editor Plugin theme-editor PHP Object Injection Authenticated (Admin+) PHAR Deserialization ≤ 2.8 CVE-2022-2440 Wordfence
7.2 High Funnelforms Free Plugin funnelforms-free Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 3.7.3.2 CVE-2024-6311 Wordfence
7.1 High Fonts Plugin olympus-google-fonts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43301 Patchstack
7.1 High MyBookTable Bookstore Plugin mybooktable Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.3.9 Fixed in 3.5.0 CVE-2024-43255 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only