WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,201–8,250 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 165 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection ≤ 12.6 Fixed in 12.7 CVE-2024-35630 Patchstack
8.8 High Elements For Elementor Plugin nd-elements Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Multiple Widget Attributes ≤ 2.1 CVE-2024-5348 Wordfence
7.3 High wpDataTables - Tables & Table Charts (Premium) Plugin Broken Access Control Tables & Table Charts (Premium) <= 6.3.2 - Missing Authorization to DataTable Access & Modification No login needed ≤ 6.3.2 CVE-2024-3821 Wordfence
7.1 High User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation ≤ 3.2.0.1 CVE-2024-4958 Wordfence
8.8 High Content Blocks (Custom Post Widget) Plugin custom-post-widget Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.3.0 CVE-2024-3564 Wordfence
7.5 High Migration Backup Restore Plugin Server-Side Request Forgery Admin+ SSRF No login needed < 3.5.0 Fixed in 3.5.0 CVE-2024-4469 WPScan
7.2 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.30 CVE-2024-2793 Wordfence
8.8 High Responsive Owl Carousel for Elementor Plugin responsive-owl-carousel-elementor Local File Inclusion ≤ 1.2.0 CVE-2024-5345 Wordfence
8.8 High Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX Plugin ultimate-post Broken Access Control PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update ≤ 4.1.2 CVE-2024-5326 Wordfence
7.2 High POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp SQL Injection Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection ≤ 2.9.3 CVE-2024-5207 Wordfence
8.1 High AppPresser Plugin apppresser Authentication Bypass Improper Missing Encryption Exception Handling to Authentication Bypass No login needed ≤ 4.3.2 CVE-2024-4611 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated(Contributor+) Remote Code Execution via template import ≤ 1.5.89 CVE-2023-6743 Wordfence
8.8 High Swiss Toolkit For WP Plugin swiss-toolkit-for-wp Authentication Bypass Authenticated (Contributor+) Authentication Bypass ≤ 1.0.7 CVE-2024-5204 Wordfence
8.8 High KKProgressbar2 Free Plugin kkprogressbar Cross-Site Request Forgery Progress Bar Deletion via CSRF No login needed ≤ 1.1.4.2 CVE-2024-4535 WPScan
7.1 High Business Card Plugin Cross-Site Request Forgery Card Edit via CSRF No login needed ≤ 1.0.0 CVE-2024-4531 WPScan
7.2 High YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.4.0 CVE-2024-4455 Wordfence
8.1 High Email Log Plugin email-log Remote Code Execution Unauthenticated Hook Injection No login needed ≤ 2.4.8 CVE-2024-0867 Wordfence
8.1 High Hash Form – Drag & Drop Form Builder Plugin hash-form PHP Object Injection Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection No login needed ≤ 1.1.0 CVE-2024-5085 Wordfence
8.0 High 140+ Widgets | Best Addons For Elementor – FREE Plugin xpro-elementor-addons PHP Object Injection FREE <= 1.4.3.1 - Authenticated (Contributor+) PHP Object Injection ≤ 1.4.3.1 CVE-2024-4471 Wordfence
8.8 High Unlimited Elements for Elementor Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection via data[post_ids][0] ≤ 1.5.107 CVE-2024-4779 Wordfence
7.5 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Broken Access Control Atarim <= 3.22.6 - Hardcoded Credentials No login needed ≤ 3.22.6 CVE-2024-2038 Wordfence
8.7 High IDonate Plugin idonate Cross-Site Scripting Admin+ Stored XSS ≤ 1.9.0 CVE-2024-3594 WPScan
7.2 High WP Fastest Cache Plugin wp-fastest-cache Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion ≤ 1.2.6 CVE-2024-4347 Wordfence
8.8 High Oxygen Builder Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 4.8.2 CVE-2024-4662 Wordfence
8.5 High MemberPress Plugin Server-Side Request Forgery Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode ≤ 1.11.29 CVE-2024-5031 Wordfence
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform PHP Object Injection PHP Object Injection via extractDynamicValues ≤ 5.1.15 CVE-2024-4157 Wordfence
8.5 High NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Information Disclosure Authenticated(Subscriber+) Sensitive Information Exposure ≤ 4.4.3 CVE-2024-2088 Wordfence
8.8 High Media Library Assistant Plugin media-library-assistant SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 3.15 CVE-2024-3518 Wordfence
7.1 High ShopLentor Plugin woolentor-addons Broken Access Control Missing Authorization to WordPress Option Modification ≤ 2.8.8 CVE-2024-4566 Wordfence
7.1 High Sailthru Triggermail Plugin sailthru-triggermail Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 1.1 CVE-2024-4290 WPScan
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Setting Manipulation No login needed ≤ 5.1.16 CVE-2024-2782 Wordfence
7.5 High Salient Core Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.0.7 CVE-2024-3812 Wordfence
8.8 High Salient Shortcodes Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 1.5.3 CVE-2024-3810 Wordfence
8.8 High Booking Ultra Pro Plugin booking-ultra-pro Privilege Escalation ≤ 1.1.12 Fixed in 1.1.13 CVE-2024-32960 Patchstack
8.8 High Sirv Plugin sirv Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 7.2.2 Fixed in 7.2.3 CVE-2024-32959 Patchstack
8.6 High BuddyForms Plugin buddyforms Path Traversal WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF No login needed ≤ 2.8.8 Fixed in 2.8.9 CVE-2024-32830 Patchstack
8.2 High Chauffeur Taxi Booking System Plugin Authentication Bypass Broken Authentication No login needed ≤ 6.9 Fixed in 7.0 CVE-2024-32692 Patchstack
8.8 High HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin woocommerce-products-filter Remote Code Execution ≤ 1.3.5.2 Fixed in 1.3.5.3 CVE-2024-32680 Patchstack
8.1 High Mailster Plugin mailster Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2024-32523 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Privilege Escalation ≤ 1.7.16 Fixed in 1.7.17 CVE-2024-32507 Patchstack
8.5 High Easy Social Share Buttons Plugin Local File Inclusion ≤ 9.4 Fixed in 9.5 CVE-2024-31300 Patchstack
7.5 High s2Member Pro Plugin s2member Privilege Escalation No login needed ≤ 240315 Fixed in 240325 CVE-2024-31237 Patchstack
8.0 High Rehub Theme Local File Inclusion ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31232 Patchstack
8.3 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Local File Inclusion No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2024-27971 Patchstack
8.8 High Automatic Plugin wp-automatic Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27955 Patchstack
8.5 High Elementor Website Builder Plugin elementor Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization ≤ 3.19.0 Fixed in 3.19.1 CVE-2024-24934 Patchstack
7.5 High Total Upkeep Plugin boldgrid-backup Path Traversal Arbitrary File Download No login needed ≤ 1.15.8 Fixed in 1.15.9 CVE-2024-24869 Patchstack
8.8 High InstaWP Connect Plugin instawp-connect Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-22145 Patchstack
7.2 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Privilege Escalation ≤ 4.2.1 Fixed in 4.3.0 CVE-2023-51546 Patchstack
8.8 High Build App Online Plugin build-app-online Privilege Escalation Authenticated Privilege Escalation ≤ 1.0.19 CVE-2023-51479 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only