WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,951–8,000 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 160 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.28 Fixed in 2.2.29 CVE-2024-43135 Patchstack
7.5 High Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43131 Patchstack
8.6 High WooCommerce PDF Vouchers Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39651 Patchstack
7.5 High Import and export users and customers Plugin import-users-from-csv-with-meta Information Disclosure Sensitive Information via Imported File No login needed ≤ 1.26.8 Fixed in 1.26.9 CVE-2024-38787 Patchstack
7.5 High HitPay Payment Gateway for WooCommerce Plugin hitpay-payment-gateway Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-38747 Patchstack
7.1 High Contact Form 7 Summary and Print Plugin cf7-summary-and-print Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-38724 Patchstack
7.5 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Information Disclosure Sensitive Data Exposure via Exported File No login needed ≤ 2.5.13 Fixed in 2.5.14 CVE-2024-38699 Patchstack
7.5 High Woocommerce OpenPos Plugin Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 6.4.4 CVE-2024-37935 Patchstack
8.8 High Media Library Assistant Plugin media-library-assistant Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via mla-inline-edit-upload-scripts AJAX Action ≤ 3.18 CVE-2024-6823 Wordfence
7.1 High Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Scripting Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.6.14 - Cross Site Scripting (XSS) No login needed ≤ 2.6.14 Fixed in 2.6.16 CVE-2024-43126 Patchstack
7.1 High Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-43127 Patchstack
7.1 High Post Grid Master Plugin ajax-filter-posts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.10 Fixed in 3.4.11 CVE-2024-43156 Patchstack
7.1 High ParcelPanel Plugin parcelpanel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.2 Fixed in 4.3.3 CVE-2024-43163 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.17 CVE-2024-43213 Patchstack
7.1 High Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2024-43217 Patchstack
7.1 High Form Maker by 10Web Plugin form-maker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.15.26 CVE-2024-43220 Patchstack
7.1 High BSK Forms Blacklist Plugin bsk-gravityforms-blacklist Cross-Site Scripting No login needed ≤ 3.8 Fixed in 3.8.1 CVE-2024-43233 Patchstack
8.8 High Slider by 10Web – Responsive Image Slider Plugin slider-wd SQL Injection Responsive Image Slider <= 1.2.57 - Authenticated (Contributor+) SQL Injection via id Parameter ≤ 1.2.57 CVE-2024-7150 Wordfence
8.8 High LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.6.9.3 - Authenticated (Contributor+) SQL Injection via order Parameter ≤ 4.2.6.9.3 CVE-2024-7548 Wordfence
8.8 High MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 2.2 CVE-2024-7492 Wordfence
8.8 High MultiPurpose Theme multipurpose PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.2.0 CVE-2024-7486 Wordfence
7.2 High News Flash Theme news-flash PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 1.1.0 CVE-2024-7560 Wordfence
8.8 High The Next Theme the-next PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.1.0 CVE-2024-7561 Wordfence
8.5 High Modern Events Calendar Plugin modern-events-calendar-lite Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery ≤ 7.12.1 CVE-2024-6522 Wordfence
8.8 High WPBakery Plugin Local File Inclusion Authenticated (Author+) Local File Inclusion ≤ 7.7 CVE-2024-5709 Wordfence
7.2 High Traffic Manager Plugin traffic-manager Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-7485 Wordfence
8.8 High Horizontal scrolling announcements Plugin horizontal-scrolling-announcements SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 2.4 CVE-2023-5000 Wordfence
8.8 High Blox Page Builder Plugin blox-page-builder Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.65 CVE-2024-6315 Wordfence
7.2 High CRM Perks Forms Plugin crm-perks-forms Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 1.1.3 CVE-2024-7484 Wordfence
7.5 High File Manager Pro – Filester Plugin filester Broken Access Control Filester <= 1.8.2 - Authenticated Plugin Settings Update ≤ 1.8.2 CVE-2024-7031 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Privilege Escalation Authenticated (Administrator+) Privilege Escalation ≤ 3.3.4.1 CVE-2024-7291 Wordfence
7.5 High UsersWP Plugin userswp Information Disclosure Users Information Disclosure No login needed < 1.2.12 Fixed in 1.2.12 CVE-2024-6477 WPScan
7.1 High WP GoToWebinar Plugin wp-gotowebinar Cross-Site Request Forgery CSRF to XSS No login needed ≤ 15.7 Fixed in 15.8 CVE-2024-38776 Patchstack
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
7.5 High Forminator Plugin forminator Information Disclosure HubSpot Developer API Key Sensitive Information Exposure No login needed ≤ 1.29.1 CVE-2024-7389 Wordfence
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-39631 Patchstack
7.1 High Custom 404 Pro Plugin custom-404-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2024-39646 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting No login needed ≤ 1.6.1.1 Fixed in 1.6.2 CVE-2024-39647 Patchstack
7.1 High WooCommerce PDF Vouchers Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39652 Patchstack
7.1 High Tin Canny Reporting for LearnDash Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.0.7 Fixed in 4.3.0.8 CVE-2024-39656 Patchstack
7.1 High WP Fast Total Search Plugin fulltext-search Cross-Site Scripting No login needed ≤ 1.68.232 Fixed in 1.69.234 CVE-2024-39663 Patchstack
7.5 High Zephyr Project Manager Plugin zephyr-project-manager Information Disclosure Sensitive Data Exposure via Export File No login needed ≤ 3.3.99 Fixed in 3.3.100 CVE-2024-38761 Patchstack
8.3 High Better Find and Replace Plugin real-time-auto-find-and-replace PHP Object Injection No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-39636 Patchstack
8.0 High WPForms User Registration Plugin Privilege Escalation Authenticated Privilege Escalation ≤ 2.1.0 Fixed in 2.1.2 CVE-2023-52209 Patchstack
7.1 High MakeStories (for Google Web Stories) Plugin makestories-helper Path Traversal Arbitrary File Download and SSRF ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-38746 Patchstack
7.2 High CTX Feed Plugin webappick-product-feed-for-woocommerce Privilege Escalation Arbitrary Options Update ≤ 6.5.6 Fixed in 6.5.7 CVE-2024-38775 Patchstack
8.0 High ListingPro Plugin listingpro-plugin Local File Inclusion ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39621 Patchstack
8.5 High ListingPro Theme listingpro Local File Inclusion ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39624 Patchstack
8.8 High PowerPack for Beaver Builder Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.33.0 Fixed in 2.33.1 CVE-2024-39633 Patchstack
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.10.14 Fixed in 2.10.15 CVE-2024-39634 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only