WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 8,251–8,300 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 166 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Request Forgery No login needed ≤ 3.3.28 Fixed in 3.3.29 CVE-2024-32437 Patchstack
4.3 Medium SEO Booster Plugin seo-booster Cross-Site Request Forgery No login needed ≤ 3.8.9 Fixed in 3.8.10 CVE-2024-32438 Patchstack
4.3 Medium WP Client Reports Plugin wp-client-reports Cross-Site Request Forgery No login needed ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-32439 Patchstack
4.3 Medium Asgaros Forum Plugin asgaros-forum Cross-Site Request Forgery No login needed ≤ 2.8.0 Fixed in 2.9.0 CVE-2024-32440 Patchstack
4.3 Medium Zoho Campaigns Plugin zoho-campaigns Cross-Site Request Forgery No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-32441 Patchstack
4.3 Medium Zoho Campaigns Plugin zoho-campaigns Cross-Site Request Forgery No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-32442 Patchstack
4.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Request Forgery No login needed ≤ 2.34.2 Fixed in 2.34.3 CVE-2024-32443 Patchstack
5.4 Medium WebinarIgnition Plugin webinar-ignition Cross-Site Request Forgery No login needed ≤ 3.05.8 Fixed in 3.06.0 CVE-2024-32445 Patchstack
5.4 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.5.9 Fixed in 2.5.10 CVE-2024-32446 Patchstack
4.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2024-32447 Patchstack
4.3 Medium Ads.txt Admin Plugin ads-txt-admin Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2024-32448 Patchstack
5.4 Medium RestroPress Plugin restropress Cross-Site Request Forgery No login needed ≤ 3.1.2 Fixed in 3.1.2.1 CVE-2024-32449 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2024-32450 Patchstack
4.3 Medium Legal Pages Plugin legal-pages Cross-Site Request Forgery No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-32451 Patchstack
5.4 Medium WP EasyCart Plugin wp-easycart Cross-Site Request Forgery No login needed ≤ 5.5.19 Fixed in 5.6.0 CVE-2024-32452 Patchstack
4.4 Medium Import Users from CSV Plugin import-users-from-csv PHP Object Injection ≤ 1.2 Fixed in 1.3 CVE-2024-32431 Patchstack
4.4 Medium ActiveCampaign Plugin activecampaign-subscription-forms Server-Side Request Forgery ≤ 8.1.14 Fixed in 8.1.15 CVE-2024-32430 Patchstack
4.4 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Server-Side Request Forgery ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32454 Patchstack
5.5 Medium Product Feed Manager Plugin best-woocommerce-feed Path Traversal Directory Traversal ≤ 7.3.15 Fixed in 7.3.16 CVE-2023-52144 Patchstack
6.5 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting ≤ 2024.2 Fixed in 2024.3 CVE-2024-32079 Patchstack
6.5 Medium Libsyn Publisher Hub Plugin libsyn-podcasting Cross-Site Scripting ≤ 1.4.4 CVE-2024-32140 Patchstack
6.5 Medium Easy Contact Form Lite Plugin contact-form-lite Cross-Site Scripting ≤ 1.1.23 Fixed in 1.1.25 CVE-2024-32147 Patchstack
5.9 Medium MWW Disclaimer Buttons Plugin mww-disclaimer-buttons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.2 Fixed in 3.2 CVE-2024-32428 Patchstack
5.9 Medium Remove Footer Credit Plugin remove-footer-credit Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2024-32429 Patchstack
5.9 Medium POEditor Plugin poeditor Cross-Site Scripting ≤ 0.9.8 Fixed in 0.9.9 CVE-2024-32453 Patchstack
4.3 Medium WooCommerce Shipping Per Product Plugin Broken Access Control ≤ 2.5.4 Fixed in 2.5.5 CVE-2023-51499 Patchstack
5.3 Medium WP Job Manager Plugin wp-job-manager Broken Access Control No login needed ≤ 2.0.0 Fixed in 2.1.0 CVE-2023-52211 Patchstack
5.9 Medium GiveWP Plugin give Cross-Site Scripting Cross Site Scripting (XSS) via render_dropdown ≤ 2.25.1 Fixed in 2.25.2 CVE-2022-40211 Patchstack
4.3 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Cross-Site Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-31235 Patchstack
5.4 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Request Forgery No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-31238 Patchstack
4.3 Medium Nudgify Social Proof, Sales Popup & FOMO Plugin nudgify Cross-Site Request Forgery No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2024-31239 Patchstack
4.3 Medium WP Server Health Stats Plugin wp-server-stats Cross-Site Request Forgery No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-31250 Patchstack
4.3 Medium Community by PeepSo Plugin peepso-core Cross-Site Request Forgery No login needed ≤ 6.3.1.1 Fixed in 6.3.1.2 CVE-2024-31251 Patchstack
5.4 Medium WooCommerce Checkout Field Editor (Checkout Manager) Plugin woo-checkout-regsiter-field-editor Cross-Site Request Forgery No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-31262 Patchstack
5.4 Medium Loan Repayment Calculator and Application Form Plugin quick-interest-slider Cross-Site Request Forgery No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-31263 Patchstack
4.3 Medium Post Views Counter Plugin post-views-counter Cross-Site Request Forgery No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-31264 Patchstack
4.3 Medium AppPresser Plugin apppresser Cross-Site Request Forgery No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2024-31268 Patchstack
4.3 Medium Easy Google Maps Plugin google-maps-easy Cross-Site Request Forgery No login needed ≤ 1.11.11 Fixed in 1.11.12 CVE-2024-31269 Patchstack
4.3 Medium Ultimate Maps by Supsystic Plugin ultimate-maps-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2024-31271 Patchstack
6.3 Medium ARForms Form Builder Plugin arforms-form-builder Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31272 Patchstack
5.4 Medium Generate Child Plugin generate-child-theme Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2024-31279 Patchstack
4.3 Medium Hello Elementor Theme hello-elementor Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-31289 Patchstack
4.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Cross-Site Request Forgery No login needed ≤ 3.2.6 Fixed in 3.2.7 CVE-2024-31293 Patchstack
5.4 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Cross-Site Request Forgery MPG plugin <= 3.4.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-31301 Patchstack
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery No login needed ≤ 2.2.11.1 Fixed in 2.2.12 CVE-2024-31303 Patchstack
4.3 Medium Transcoder Plugin transcoder Cross-Site Request Forgery No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-31305 Patchstack
4.3 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Request Forgery No login needed ≤ 1.7.8 CVE-2024-31354 Patchstack
4.3 Medium Benchmark Email Lite Plugin benchmark-email-lite Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-31360 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.7.8 Fixed in 5.7.9 CVE-2024-31362 Patchstack
4.3 Medium LifterLMS Plugin lifterlms Cross-Site Request Forgery No login needed ≤ 7.5.0 Fixed in 7.5.1 CVE-2024-31363 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only