WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,901–7,950 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 159 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High wpForo Forum Plugin wpforo Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43289 Patchstack
7.6 High WP Testimonial Widget Plugin wp-testimonial-widget SQL Injection ≤ 3.1 CVE-2024-43966 Patchstack
8.8 High Image Hotspot by DevVN Plugin devvn-image-hotspot PHP Object Injection Authenticated (Author+) PHP Object Injection ≤ 1.2.5 CVE-2024-7656 Wordfence
7.2 High Simple Job Board Plugin simple-job-board PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 2.12.3 CVE-2024-7351 Wordfence
8.8 High WooCommerce Google Feed Manager Plugin wp-product-feed-manager Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Deletion ≤ 2.8.0 CVE-2024-7258 Wordfence
8.8 High File Manager Pro Plugin filester Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 8.3.7 CVE-2024-7559 Wordfence
7.5 High AcyMailing Plugin acymailing Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function ≤ 9.7.2 CVE-2024-7384 Wordfence
7.2 High LiquidPoll Plugin wp-poll Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via form_data Parameter No login needed ≤ 3.3.78 CVE-2024-7134 Wordfence
8.7 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Arbitrary File Deletion Authenticater (Administrator+) Arbitrary File Deletion 2.0 – 2.13.4 CVE-2024-7782 Wordfence
7.2 High AdRotate – Ad manager & AdSense Ads Plugin adrotate Arbitrary File Upload Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload ≤ 5.13.2 CVE-2022-1206 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection 2.0 – 2.13.9 CVE-2024-7780 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection via getLogHistory Function 2.0 – 2.13.9 CVE-2024-7702 Wordfence
8.8 High Shopping Cart & eCommerce Store Plugin wp-easycart SQL Injection Authenticated (Contributor+) SQL Injection via model_number Parameter ≤ 5.7.2 CVE-2024-7827 Wordfence
7.5 High Landing Page Builder Plugin page-builder-add Local File Inclusion ≤ 1.5.2.0 Fixed in 1.5.2.1 CVE-2024-43345 Patchstack
8.3 High EmbedPress Plugin embedpress Local File Inclusion No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2024-43328 Patchstack
8.5 High Woo Products Widgets For Elementor Plugin woo-products-widgets-for-elementor Local File Inclusion ≤ 2.0.0 CVE-2024-43271 Patchstack
7.1 High Leopard - WordPress offload media Plugin Broken Access Control Subscriber+ Plugin Settings Change ≤ 2.0.36 CVE-2024-43256 Patchstack
7.1 High Bit Form Pro Plugin Broken Access Control Authenticated Plugin Settings Change ≤ 2.6.4 CVE-2024-43250 Patchstack
8.6 High Bit Form Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.6.4 CVE-2024-43248 Patchstack
8.8 High WHMpress Plugin Broken Access Control Subscriber+ Arbitrary Settings Change ≤ 6.2-revision-5 CVE-2024-43247 Patchstack
8.5 High Timeline and History slider Plugin timeline-and-history-slider Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43232 Patchstack
8.5 High JetGridBuilder Plugin jetgridbuilder Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-43221 Patchstack
7.2 High AI Engine Plugin ai-engine Remote Code Execution Admin+ RCE < 2.5.1 Fixed in 2.5.1 CVE-2024-6451 WPScan
8.5 High GeoDirectory Plugin geodirectory SQL Injection ≤ 2.3.61 Fixed in 2.3.62 CVE-2024-43145 Patchstack
8.5 High Unite Gallery Lite Plugin unite-gallery-lite SQL Injection ≤ 1.7.62 CVE-2024-43207 Patchstack
7.6 High Tutor LMS Plugin tutor SQL Injection ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43282 Patchstack
8.5 High SEO Plugin by Squirrly SEO Plugin squirrly-seo SQL Injection ≤ 12.3.19 Fixed in 12.3.20 CVE-2024-43286 Patchstack
7.5 High Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43315 Patchstack
7.1 High Ultimate Membership Pro Plugin indeed-membership-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43241 Patchstack
7.1 High Houzez Theme Cross-Site Scripting No login needed ≤ 3.2.4 Fixed in 3.2.5 CVE-2024-43244 Patchstack
7.1 High WHMpress Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.2-revision-5 CVE-2024-43246 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting No login needed ≤ 4.9.8 Fixed in 4.9.9 CVE-2024-43279 Patchstack
7.1 High White Label CMS Plugin white-label-cms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2024-43303 Patchstack
7.1 High Cryptocurrency Widgets – Price Ticker & Coins List Plugin cryptocurrency-price-ticker-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-43304 Patchstack
7.1 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2024-43306 Patchstack
7.1 High FormFacade Plugin formfacade Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-43313 Patchstack
7.1 High Invite Anyone Plugin invite-anyone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2024-43327 Patchstack
7.1 High PowerPack for Beaver Builder Plugin bbpowerpack Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.37.4 Fixed in 2.37.4 CVE-2024-43330 Patchstack
7.1 High weMail Plugin wemail Cross-Site Scripting No login needed ≤ 1.14.5 Fixed in 1.14.6 CVE-2024-43238 Patchstack
7.1 High Child Theme Creator Plugin orbisius-child-theme-creator Cross-Site Scripting No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-43276 Patchstack
7.1 High Purity Of Soul Theme purity-of-soul Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9 CVE-2024-43348 Patchstack
8.1 High Metform Elementor Contact Form Builder Plugin metform Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed ≤ 3.2.4 CVE-2023-0714 Wordfence
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
8.8 High JetElements Plugin Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion ≤ 2.6.20 CVE-2024-7145 Wordfence
8.8 High JetTabs Plugin Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion ≤ 2.2.3 CVE-2024-7146 Wordfence
7.2 High WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 4.24.8 CVE-2024-7301 Wordfence
8.1 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed ≤ 4.15.2 CVE-2024-7628 Wordfence
8.1 High Zephyr Project Manager Plugin zephyr-project-manager Privilege Escalation Authenticated (Subscriber+) Limited Privilege Escalation ≤ 3.3.101 CVE-2024-7624 Wordfence
8.8 High Depicter — Popup & Slider Builder Plugin depicter Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload ≤ 3.1.1 CVE-2024-4389 Wordfence
7.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-43140 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only