WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,001–8,050 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 161 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Email Adding via CSRF No login needed ≤ 1.0.3 CVE-2024-6023 WPScan
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0.3 CVE-2024-6022 WPScan
8.8 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via vendor_id ≤ 1.13.0 CVE-2024-6666 Wordfence
8.0 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery < 1.3.2 Fixed in 1.3.2 CVE-2024-1845 WPScan
7.2 High FULL Plugin full-customer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via License Plan Parameter No login needed ≤ 3.1.12 CVE-2024-6447 Wordfence
7.5 High WishList Member X Plugin Information Disclosure Unauthenticated Settings & Users Data Dump No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37110 Patchstack
7.5 High Newspack Blocks Plugin Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37115 Patchstack
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation ≤ 5.8.9 CVE-2024-6411 Wordfence
8.8 High Houzez CRM Plugin SQL Injection Authenticated (Seller+) SQL Injection ≤ 1.4.2 CVE-2024-5792 Wordfence
8.8 High Advanced File Manager Shortcodes Plugin Path Traversal Authenticated (Contributor+) Directory Traversal ≤ 2.4 CVE-2023-7062 Wordfence
8.8 High Advanced File Manager Shortcode Plugin Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 2.5.3 CVE-2023-7061 Wordfence
8.8 High BookYourTravel Theme Privilege Escalation Subscriber+ Privilege Escalation ≤ 8.18.17 Fixed in 8.18.19 CVE-2024-37952 Patchstack
8.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.27 Fixed in 2.2.28 CVE-2024-37513 Patchstack
8.5 High Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Local File Inclusion ≤ 3.1.3 Fixed in 3.2.1 CVE-2024-37501 Patchstack
7.7 High JetThemeCore Plugin jet-theme-core Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 2.2.1 Fixed in 2.2.1 CVE-2024-37497 Patchstack
8.8 High Zephyr Project Manager Plugin zephyr-project-manager Privilege Escalation ≤ 3.3.97 Fixed in 3.3.99 CVE-2024-37484 Patchstack
8.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-37462 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.31 Fixed in 1.36.32 CVE-2024-37455 Patchstack
7.5 High Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Local File Inclusion Elementor Addons plugin <= 1.1.1 - Local File Inclusion No login needed ≤ 1.1.1 Fixed in 1.2.0 CVE-2024-37419 Patchstack
8.5 High Striking Theme Local File Inclusion ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-37268 Patchstack
7.5 High SP Project & Document Manager Plugin sp-client-document-manager Path Traversal Directory Traversal No login needed ≤ 4.71 CVE-2024-37224 Patchstack
8.5 High Masterstudy Elementor Widgets Theme SQL Injection SQL Injection vulnerability in multiple StylemixThemes premium themes ≤ 1.2.2, ≤ 1.3.0 Fixed in 1.2.3 CVE-2024-37090 Patchstack
8.5 High Zoho Marketing Automation Plugin zoho-marketinghub SQL Injection ≤ 1.2.7 CVE-2024-37225 Patchstack
7.6 High Tutor LMS Plugin tutor SQL Injection ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37256 Patchstack
7.6 High Paid Memberships Pro Plugin paid-memberships-pro SQL Injection Authenticated SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-37486 Patchstack
8.5 High Youzify Plugin youzify SQL Injection ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-37494 Patchstack
8.8 High Pie Register - Basic Plugin pie-register Broken Access Control Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 3.8.3.4 CVE-2024-6069 Wordfence
8.8 High Panda Video Plugin pandavideo Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.4.0 CVE-2024-5456 Wordfence
7.2 High Easy Pixels by JEVNET Plugin easy-pixels-by-jevnet Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.13 CVE-2024-5479 Wordfence
8.8 High ScrollTo Top Plugin scrollto-top Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-6320 Wordfence
8.8 High ScrollTo Bottom Plugin scrollto-bottom Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.1.1 CVE-2024-6321 Wordfence
8.8 High Advanced AJAX Page Loader Plugin advanced-ajax-page-loader Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.7.7 CVE-2024-6310 Wordfence
8.8 High Attachment File Icons (AF Icons) Plugin attachment-file-icons Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.3 CVE-2024-6309 Wordfence
7.2 High Bit Form Plugin bit-form Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.13.3 CVE-2024-6123 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 4.1.2 CVE-2024-6317 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 4.1.2 CVE-2024-6316 Wordfence
7.2 High EventON Plugin eventon-lite Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates No login needed ≤ 2.2.15 CVE-2024-6180 Wordfence
8.8 High Default Thumbnail Plus Plugin default-thumbnail-plus Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.2.3 CVE-2024-6161 Wordfence
8.8 High Modern Events Calendar Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.11.0 CVE-2024-5441 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Time-Based SQL Injection ≤ 1.5.112 CVE-2024-6166 Wordfence
8.8 High Houzez Theme - Functionality Plugin SQL Injection Functionality <= 3.2.2 - Authenticated (Seller+) SQL Injection ≤ 3.2.2 CVE-2024-5793 Wordfence
7.2 High Foxiz Theme Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-37260 Patchstack
7.1 High Woffice Core Plugin Cross-Site Scripting Site Wide Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8 Fixed in 5.4.9 CVE-2024-37471 Patchstack
7.1 High Woffice Plugin woffice Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8 Fixed in 5.4.9 CVE-2024-37472 Patchstack
8.8 High Nested Pages Plugin wp-nested-pages Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 3.2.7 CVE-2024-5943 Wordfence
8.8 High IMGspider Plugin imgspider Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via 'upload' ≤ 2.3.10 CVE-2024-6319 Wordfence
8.8 High IMGspider Plugin imgspider Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via 'upload_img_file' ≤ 2.3.10 CVE-2024-6318 Wordfence
8.8 High Elementor Addons by Livemesh Plugin addons-for-elementor Local File Inclusion Authenticated (Contributor+) Limited Local File Inclusion via Widgets ≤ 8.4 CVE-2024-2385 Wordfence
8.1 High Sola Testimonials Plugin sola-testimonials Cross-Site Request Forgery A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the Wo… No login needed versions prior to 3.0.0 CVE-2024-38345 jpcert
8.8 High WPQA Plugin Cross-Site Request Forgery Arbitrary Category and Tag Follow/Unfollow via CSRF No login needed < 6.1.1 Fixed in 6.1.1 CVE-2024-2376 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only