WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 8,101–8,150 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.5 High | WP Magazine Modules Lite | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.1.2 |
CVE-2024-5574 |
Wordfence | |
| 8.8 High | Photo Gallery, Images, Slider in Rbs Image Gallery | Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed |
≤ 3.2.19 |
CVE-2024-5343 |
Wordfence | |
| 8.8 High | AliExpress Dropshipping with AliNext Lite | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 3.3.5 |
CVE-2024-2381 |
Wordfence | |
| 8.8 High | Photo Video Gallery Master | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.5.3 |
CVE-2024-5724 |
Wordfence | |
| 8.1 High | Login with phone number | Broken Access Control Insecure Password Reset Mechanism No login needed |
≤ 1.7.34 |
CVE-2024-6125 |
Wordfence | |
| 7.4 High | Business Directory | Content Injection Authenticated (Author+) CSV Injection |
≤ 6.4.3 |
CVE-2023-5527 |
Wordfence | |
| 7.1 High | FooEvents for WooCommerce | Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload |
≤ 1.19.20 |
CVE-2024-6000 |
Wordfence | |
| 8.1 High | Popup Builder – Create highly converting, mobile friendly marketing popups | Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure |
≤ 4.3.1 |
CVE-2023-6696 |
Wordfence | |
| 8.8 High | tagDiv Composer | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 4.8 |
CVE-2024-3813 |
Wordfence | |
| 7.4 High | Popup Builder | Broken Access Control Missing Authorization in Multiple AJAX Actions |
≤ 4.3.0 |
CVE-2024-2544 |
Wordfence | |
| 8.8 High | Folders Pro | Arbitrary File Upload Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload |
≤ 3.0.2 |
CVE-2024-2024 |
Wordfence | |
| 8.5 High | ElementsKit PRO | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery |
≤ 3.6.2 |
CVE-2024-4404 |
Wordfence | |
| 7.5 High | WP STAGING PRO - Backup Duplicator & Migration | Cross-Site Request Forgery Backup Duplicator & Migration <= 5.6.0 - Cross-Site Request Forgery to Limited Local File Inclusion No login needed |
≤ 5.6.0 |
CVE-2024-5551 |
Wordfence | |
| 7.3 High | Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling | Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed |
≤ 1.0.21 |
CVE-2024-1094 |
Wordfence | |
| 7.5 High | Download Manager | Broken Access Control Improper Authorization via protectMediaLibrary No login needed |
≤ 3.2.89 |
CVE-2024-2098 |
Wordfence | |
| 8.8 High | Icegram Express | SQL Injection Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id] |
≤ 5.7.22 |
CVE-2024-4845 |
Wordfence | |
| 7.5 High | Consensu.io | Broken Access Control No login needed |
≤ 1.0.1 |
CVE-2023-48280 |
Patchstack | |
| 8.1 High | Slideshow Gallery LITE | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 1.8.1 |
CVE-2024-5543 |
Wordfence | |
| 8.6 High | Post SMTP Mailer/Email Log | Broken Access Control Broken Access Control on API No login needed |
≤ 2.8.6 Fixed in 2.8.7 |
CVE-2023-52233 |
Patchstack | |
| 8.6 High | WC Marketplace | Broken Access Control No login needed |
≤ 4.0.25 Fixed in 4.0.26 |
CVE-2024-24703 |
Patchstack | |
| 8.3 High | Tutor LMS | Broken Access Control Multiple Broken Access Control vulnerabilities |
≤ 2.1.8 Fixed in 2.1.9 |
CVE-2023-25799 |
Patchstack | |
| 8.1 High | Build App Online | Privilege Escalation Account Takeover via Weak Password Reset Mechanism No login needed |
≤ 1.0.22 |
CVE-2023-7264 |
Wordfence | |
| 7.5 High | Ovic Importer | Path Traversal Arbitrary File Download No login needed |
≤ 1.6.3 |
CVE-2024-35754 |
Patchstack | |
| 7.5 High | Strategery Migrations | Arbitrary File Deletion No login needed |
≤ 1.0 |
CVE-2024-35745 |
Patchstack | |
| 8.6 High | Upunzipper | Arbitrary File Deletion No login needed |
≤ 1.0.0 |
CVE-2024-35744 |
Patchstack | |
| 8.6 High | SC filechecker | Arbitrary File Deletion No login needed |
≤ 0.6 |
CVE-2024-35743 |
Patchstack | |
| 8.6 High | Checkout Field Editor for WooCommerce (Pro) | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 3.6.2 Fixed in 3.6.3 |
CVE-2024-35658 |
Patchstack | |
| 7.6 High | Crafthemes Demo Import | Broken Access Control Arbitrary plugin Installation |
≤ 3.3 Fixed in 4.0 |
CVE-2024-34800 |
Patchstack | |
| 8.5 High | Advanced Custom Fields PRO | Remote Code Execution Contributor+ Arbitrary Function Execution |
< 6.2.10 Fixed in 6.2.10 |
CVE-2024-34761 |
Patchstack | |
| 8.2 High | EventPrime | Price Manipulation Booking Price Manipulation No login needed |
≤ 3.3.4 Fixed in 3.3.5 |
CVE-2024-31275 |
Patchstack | |
| 7.5 High | Advanced Local Pickup for WooCommerce | Broken Access Control No login needed |
≤ 1.6.2 Fixed in 1.6.3 |
CVE-2024-31283 |
Patchstack | |
| 7.1 High | WC Marketplace | Broken Access Control |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2024-31304 |
Patchstack | |
| 7.7 High | ARForms | Arbitrary File Deletion Subscriber+ Arbitrary File Deletion |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32703 |
Patchstack | |
| 7.1 High | ARForms | Broken Access Control Subscriber+ Arbitrary WordPress Options Removal |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32704 |
Patchstack | |
| 7.1 High | ARForms | Broken Access Control Subscriber+ Arbitrary Plugin Activation/Deactivation |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32705 |
Patchstack | |
| 7.5 High | Olive One Click Demo Import | Path Traversal Arbitrary File Download No login needed |
≤ 1.1.1 Fixed in 1.1.2 |
CVE-2024-32715 |
Patchstack | |
| 7.5 High | BizPrint | Broken Access Control No login needed |
≤ 4.3.39 Fixed in 4.5.4 |
CVE-2024-32777 |
Patchstack | |
| 8.5 High | Contest Gallery | Arbitrary File Deletion |
≤ 21.3.4 Fixed in 21.3.5 |
CVE-2024-32778 |
Patchstack | |
| 7.5 High | WP Travel Engine | Price Manipulation No login needed |
≤ 5.8.0 Fixed in 5.8.1 |
CVE-2024-32798 |
Patchstack | |
| 7.5 High | WP Time Slots Booking Form | Broken Access Control No login needed |
≤ 1.2.06 Fixed in 1.2.07 |
CVE-2024-33543 |
Patchstack | |
| 8.3 High | WZone | Broken Access Control Site Wide Broken Access Control |
≤ 14.0.10 |
CVE-2024-33547 |
Patchstack | |
| 8.1 High | XStore Core | Broken Access Control Multiple Authenticated Broken Access Control |
≤ 5.3.8 Fixed in 5.3.9 |
CVE-2024-33555 |
Patchstack | |
| 7.5 High | XStore | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 9.3.8 Fixed in 9.3.9 |
CVE-2024-33561 |
Patchstack | |
| 7.6 High | XStore | Broken Access Control |
≤ 9.3.8 Fixed in 9.3.9 |
CVE-2024-33563 |
Patchstack | |
| 8.8 High | XStore | Broken Access Control Arbitrary Option Update |
≤ 9.3.8 Fixed in 9.3.9 |
CVE-2024-33564 |
Patchstack | |
| 7.5 High | Bricksforge | Broken Access Control Unauthenticated Arbitrary WordPress Setting Deletion No login needed |
≤ 2.0.17 Fixed in 2.1.1 |
CVE-2024-31243 |
Patchstack | |
| 8.8 High | Finale Lite | Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation |
≤ 2.18.0 Fixed in 2.18.1 |
CVE-2024-30485 |
Patchstack | |
| 8.8 High | NextMove Lite | Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation |
≤ 2.17.0 Fixed in 2.18.0 |
CVE-2024-25092 |
Patchstack | |
| 8.3 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Broken Access Control Multiple Broken Access Control |
≤ 1.5.65 Fixed in 1.5.66 |
CVE-2023-31080 |
Patchstack | |
| 7.1 High | New Order Notification for Woocommerce | Broken Access Control |
≤ 2.0.2 |
CVE-2024-31098 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.