WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,101–8,150 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 163 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High WP Magazine Modules Lite Plugin wp-magazine-modules-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.1.2 CVE-2024-5574 Wordfence
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
8.8 High AliExpress Dropshipping with AliNext Lite Plugin ali2woo-lite Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 3.3.5 CVE-2024-2381 Wordfence
8.8 High Photo Video Gallery Master Plugin photo-video-gallery-master PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.5.3 CVE-2024-5724 Wordfence
8.1 High Login with phone number Plugin login-with-phone-number Broken Access Control Insecure Password Reset Mechanism No login needed ≤ 1.7.34 CVE-2024-6125 Wordfence
7.4 High Business Directory Plugin business-directory-plugin Content Injection Authenticated (Author+) CSV Injection ≤ 6.4.3 CVE-2023-5527 Wordfence
7.1 High FooEvents for WooCommerce Plugin Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload ≤ 1.19.20 CVE-2024-6000 Wordfence
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
8.8 High tagDiv Composer Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 4.8 CVE-2024-3813 Wordfence
7.4 High Popup Builder Plugin popup-builder Broken Access Control Missing Authorization in Multiple AJAX Actions ≤ 4.3.0 CVE-2024-2544 Wordfence
8.8 High Folders Pro Plugin folders Arbitrary File Upload Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload ≤ 3.0.2 CVE-2024-2024 Wordfence
8.5 High ElementsKit PRO Plugin Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 3.6.2 CVE-2024-4404 Wordfence
7.5 High WP STAGING PRO - Backup Duplicator & Migration Plugin wp-staging Cross-Site Request Forgery Backup Duplicator & Migration <= 5.6.0 - Cross-Site Request Forgery to Limited Local File Inclusion No login needed ≤ 5.6.0 CVE-2024-5551 Wordfence
7.3 High Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin timetics Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 1.0.21 CVE-2024-1094 Wordfence
7.5 High Download Manager Plugin download-manager Broken Access Control Improper Authorization via protectMediaLibrary No login needed ≤ 3.2.89 CVE-2024-2098 Wordfence
8.8 High Icegram Express Plugin email-subscribers SQL Injection Authenticated (Subscriber+) SQL Injection Vulnerability via options[list_id] ≤ 5.7.22 CVE-2024-4845 Wordfence
7.5 High Consensu.io Plugin consensu-io Broken Access Control No login needed ≤ 1.0.1 CVE-2023-48280 Patchstack
8.1 High Slideshow Gallery LITE Plugin slideshow-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.8.1 CVE-2024-5543 Wordfence
8.6 High Post SMTP Mailer/Email Log Plugin post-smtp Broken Access Control Broken Access Control on API No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2023-52233 Patchstack
8.6 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.25 Fixed in 4.0.26 CVE-2024-24703 Patchstack
8.3 High Tutor LMS Plugin tutor Broken Access Control Multiple Broken Access Control vulnerabilities ≤ 2.1.8 Fixed in 2.1.9 CVE-2023-25799 Patchstack
8.1 High Build App Online Plugin build-app-online Privilege Escalation Account Takeover via Weak Password Reset Mechanism No login needed ≤ 1.0.22 CVE-2023-7264 Wordfence
7.5 High Ovic Importer Plugin ovic-import-demo Path Traversal Arbitrary File Download No login needed ≤ 1.6.3 CVE-2024-35754 Patchstack
7.5 High Strategery Migrations Plugin strategery-migrations Arbitrary File Deletion No login needed ≤ 1.0 CVE-2024-35745 Patchstack
8.6 High Upunzipper Plugin upunzipper Arbitrary File Deletion No login needed ≤ 1.0.0 CVE-2024-35744 Patchstack
8.6 High SC filechecker Plugin wp-file-checker Arbitrary File Deletion No login needed ≤ 0.6 CVE-2024-35743 Patchstack
8.6 High Checkout Field Editor for WooCommerce (Pro) Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2024-35658 Patchstack
7.6 High Crafthemes Demo Import Plugin crafthemes-demo-import Broken Access Control Arbitrary plugin Installation ≤ 3.3 Fixed in 4.0 CVE-2024-34800 Patchstack
8.5 High Advanced Custom Fields PRO Plugin Remote Code Execution Contributor+ Arbitrary Function Execution < 6.2.10 Fixed in 6.2.10 CVE-2024-34761 Patchstack
8.2 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Booking Price Manipulation No login needed ≤ 3.3.4 Fixed in 3.3.5 CVE-2024-31275 Patchstack
7.5 High Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-31283 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-31304 Patchstack
7.7 High ARForms Plugin arforms Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 6.4 Fixed in 6.4.1 CVE-2024-32703 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary WordPress Options Removal ≤ 6.4 Fixed in 6.4.1 CVE-2024-32704 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary Plugin Activation/Deactivation ≤ 6.4 Fixed in 6.4.1 CVE-2024-32705 Patchstack
7.5 High Olive One Click Demo Import Plugin olive-one-click-demo-import Path Traversal Arbitrary File Download No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-32715 Patchstack
7.5 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control No login needed ≤ 4.3.39 Fixed in 4.5.4 CVE-2024-32777 Patchstack
8.5 High Contest Gallery Plugin contest-gallery Arbitrary File Deletion ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-32778 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Price Manipulation No login needed ≤ 5.8.0 Fixed in 5.8.1 CVE-2024-32798 Patchstack
7.5 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control No login needed ≤ 1.2.06 Fixed in 1.2.07 CVE-2024-33543 Patchstack
8.3 High WZone Plugin Broken Access Control Site Wide Broken Access Control ≤ 14.0.10 CVE-2024-33547 Patchstack
8.1 High XStore Core Plugin Broken Access Control Multiple Authenticated Broken Access Control ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33555 Patchstack
7.5 High XStore Theme Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33561 Patchstack
7.6 High XStore Theme Broken Access Control ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33563 Patchstack
8.8 High XStore Theme Broken Access Control Arbitrary Option Update ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33564 Patchstack
7.5 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Setting Deletion No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31243 Patchstack
8.8 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.18.0 Fixed in 2.18.1 CVE-2024-30485 Patchstack
8.8 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.17.0 Fixed in 2.18.0 CVE-2024-25092 Patchstack
8.3 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control Multiple Broken Access Control ≤ 1.5.65 Fixed in 1.5.66 CVE-2023-31080 Patchstack
7.1 High New Order Notification for Woocommerce Plugin new-order-notification-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-31098 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only