WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 8,201–8,250 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 165 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Request Forgery No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-31379 Patchstack
4.3 Medium Spotlight Social Media Feeds Plugin spotlight-social-photo-feeds Cross-Site Request Forgery No login needed ≤ 1.6.10 Fixed in 1.6.11 CVE-2024-31381 Patchstack
4.3 Medium Blocksy Plugin blocksy Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2024-31382 Patchstack
4.3 Medium PopularFX Theme popularfx Cross-Site Request Forgery No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-31383 Patchstack
4.3 Medium Spa and Salon Theme spa-and-salon Cross-Site Request Forgery No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-31384 Patchstack
4.3 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31385 Patchstack
4.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Request Forgery No login needed ≤ 1.0.25 Fixed in 1.0.26 CVE-2024-31388 Patchstack
5.4 Medium MihanPanel Plugin mihanpanel-lite Cross-Site Request Forgery No login needed < 12.7 Fixed in 12.7 CVE-2024-31389 Patchstack
4.3 Medium Popup by Supsystic Plugin popup-by-supsystic Broken Access Control ≤ 1.10.27 Fixed in 1.10.28 CVE-2024-31421 Patchstack
4.3 Medium Favicon Plugin favicon-by-realfavicongenerator Cross-Site Request Forgery No login needed ≤ 1.3.29 Fixed in 1.3.30 CVE-2024-31422 Patchstack
5.4 Medium Amelia Plugin ameliabooking Cross-Site Request Forgery No login needed ≤ 1.0.95 Fixed in 1.0.96 CVE-2024-31425 Patchstack
4.3 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Request Forgery No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-31426 Patchstack
4.3 Medium Marker.io Plugin marker-io Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-31427 Patchstack
4.3 Medium The Conference Theme the-conference Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-31428 Patchstack
4.3 Medium Sarada Lite Theme sarada-lite Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-31429 Patchstack
4.3 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-31431 Patchstack
5.3 Medium Restrict Content Plugin restrict-content Broken Access Control No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-31432 Patchstack
4.3 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2024-31433 Patchstack
5.4 Medium Newsletter Plugin newsletter Cross-Site Request Forgery No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2024-31434 Patchstack
4.3 Medium Currency per Product for WooCommerce Plugin currency-per-product-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.7.0 CVE-2024-31920 Patchstack
4.3 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Request Forgery No login needed ≤ 5.2.15 Fixed in 5.2.16 CVE-2024-31921 Patchstack
4.3 Medium WordPress Hosting Benchmark tool Plugin wpbenchmark Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-31922 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-31923 Patchstack
5.4 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Request Forgery No login needed ≤ 1.5.35 Fixed in 1.5.36 CVE-2024-31933 Patchstack
4.3 Medium NewsXpress Theme newsxpress Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-31938 Patchstack
4.3 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.2.104 Fixed in 1.2.105 CVE-2024-31940 Patchstack
5.4 Medium CP Media Player Plugin audio-and-video-player Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.2.0 CVE-2024-31941 Patchstack
4.3 Medium Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-31942 Patchstack
4.3 Medium Before And After Plugin before-and-after Cross-Site Request Forgery No login needed ≤ 3.9 CVE-2024-32084 Patchstack
5.4 Medium Citadela Listing Plugin Cross-Site Request Forgery No login needed < 5.20.0 Fixed in 5.20.0 CVE-2024-32085 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.15.20 Fixed in 6.15.21 CVE-2024-32088 Patchstack
4.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-32089 Patchstack
4.3 Medium Church Admin Plugin church-admin Cross-Site Request Forgery No login needed ≤ 4.0.27 Fixed in 4.0.28 CVE-2024-32090 Patchstack
6.5 Medium Sangar Slider Plugin sangar-slider-lite Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2024-32091 Patchstack
5.4 Medium Kimili Flash Embed Plugin kimili-flash-embed Cross-Site Request Forgery No login needed ≤ 2.5.3 CVE-2024-32092 Patchstack
5.4 Medium Novelist Plugin novelist Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-32093 Patchstack
4.3 Medium Church Content – Sermons, Events and More Plugin church-theme-content Cross-Site Request Forgery No login needed ≤ 2.6 Fixed in 2.6.1 CVE-2024-32094 Patchstack
4.3 Medium MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Request Forgery No login needed < 1.16.9 Fixed in 1.16.9 CVE-2024-32095 Patchstack
5.4 Medium WP Migration Plugin DB & Files – WP Synchro Plugin wpsynchro Cross-Site Request Forgery No login needed ≤ 1.11.2 Fixed in 1.11.3 CVE-2024-32096 Patchstack
5.4 Medium GEO my Plugin geo-my-wp Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-32097 Patchstack
4.3 Medium WP Mail Catcher Plugin wp-mail-catcher Cross-Site Request Forgery No login needed ≤ 2.1.6 Fixed in 2.1.7 CVE-2024-32099 Patchstack
4.3 Medium Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Cross-Site Request Forgery No login needed ≤ 1.14.3 Fixed in 1.14.4 CVE-2024-32101 Patchstack
4.3 Medium Crony Cronjob Manager Plugin crony Cross-Site Request Forgery No login needed ≤ 0.5.0 CVE-2024-32102 Patchstack
5.4 Medium Siteimprove Plugin siteimprove Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-32103 Patchstack
4.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Request Forgery No login needed ≤ 2.18.1 Fixed in 2.18.2 CVE-2024-32104 Patchstack
4.3 Medium Libsyn Publisher Hub Plugin libsyn-podcasting Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-32141 Patchstack
4.3 Medium BEAF Plugin beaf-before-and-after-gallery Cross-Site Request Forgery No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2024-32433 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.20.2 Fixed in 3.21.0 CVE-2024-32434 Patchstack
4.3 Medium AffiEasy Plugin affieasy Cross-Site Request Forgery No login needed ≤ 1.1.4 Fixed in 1.1.6 CVE-2024-32435 Patchstack
4.3 Medium Gift Vouchers Plugin gift-voucher Cross-Site Request Forgery No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-32436 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only