WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,301–8,350 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 167 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Visualizer: Tables and Charts Manager Plugin visualizer Broken Access Control Missing Authorization to Arbitrary SQL Execution ≤ 3.10.15 CVE-2024-3750 Wordfence
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode ≤ 3.6.5 CVE-2024-4670 Wordfence
8.8 High Email Subscribers by Icegram Express Plugin email-subscribers Broken Access Control Missing Authorization in handle_ajax_request ≤ 5.7.19 CVE-2024-4010 Wordfence
8.8 High WP Prayer Plugin Cross-Site Request Forgery Email Settings Update via CSRF No login needed ≤ 2.0.9 CVE-2024-3406 WPScan
7.6 High WP Prayer Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 2.0.9 CVE-2024-3405 WPScan
8.8 High Alt Text AI – Automatically generate image alt text for SEO and accessibility Plugin alttext-ai SQL Injection Automatically generate image alt text for SEO and accessibility <= 1.4.9 - Authenticated (Subscriber+) SQL Injection ≤ 1.4.9 CVE-2024-4847 Wordfence
8.8 High Leyka Plugin leyka Privilege Escalation ≤ 3.30.2 Fixed in 3.30.3 CVE-2023-33327 Patchstack
7.1 High Propovoice CRM Plugin propovoice Cross-Site Scripting No login needed ≤ 1.7.6.2 CVE-2024-4747 Patchstack
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.5.102 CVE-2024-3055 Wordfence
7.1 High WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery No login needed ≤ 1.33.17 CVE-2024-34818 Patchstack
7.2 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution Authenticated (Admin+) Command Injection ≤ 1.5.102 CVE-2024-2662 Wordfence
8.8 High Spectra Pro Plugin Privilege Escalation Authenticated (Author+) Privilege Escalation ≤ 1.1.5 CVE-2024-3828 Wordfence
8.8 High reCAPTCHA Jetpack Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.2.2 CVE-2024-3940 WPScan
8.1 High VikBooking Plugin Broken Access Control Insecure Direct Object References < 1.6.8 Fixed in 1.6.8 CVE-2024-2441 WPScan
8.8 High Porto Theme - Functionality Plugin Local File Inclusion Functionality <= 3.0.9 - Authenticated (Contributor+) Local File Inclusion via Post Meta ≤ 3.0.9 CVE-2024-3809 Wordfence
8.8 High Porto Theme - Functionality Plugin Local File Inclusion Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.1.0 CVE-2024-3808 Wordfence
7.2 High Advanced Ads – Ad Manager & AdSense Plugin advanced-ads PHP Object Injection Ad Manager & AdSense <= 1.52.1 - Authenticated (Admin+) PHP Object Injection ≤ 1.52.1 CVE-2024-2290 Wordfence
8.8 High LearnPress – WordPress LMS Plugin learnpress Arbitrary File Upload WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload ≤ 4.2.6.5 CVE-2024-4397 Wordfence
8.1 High XML Sitemap & Google News Plugin xml-sitemap-feed Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.4.8 CVE-2024-4441 Wordfence
8.8 High Porto Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Meta ≤ 7.1.0 CVE-2024-3807 Wordfence
8.8 High Ditty – Responsive News Tickers, Sliders, and Lists Plugin ditty-news-ticker PHP Object Injection Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection ≤ 3.1.38 CVE-2024-3954 Wordfence
8.8 High Breakdance Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 1.7.1 CVE-2024-4605 Wordfence
7.5 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control No login needed ≤ 4.0.14 Fixed in 4.0.15 CVE-2024-32712 Patchstack
7.5 High Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy Plugin woo-aliexpress-dropshipping Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-32724 Patchstack
7.5 High Ghost Plugin ghost Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 1.4.0 Fixed in 1.5.0 CVE-2024-34559 Patchstack
8.0 High Timber Plugin timber-library PHP Object Injection Deserialization of untrusted data ≤ 1.23.0 Fixed in 1.23.1 CVE-2024-29800 Patchstack
7.1 High WP etracker Plugin wp-etracker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-34431 Patchstack
7.1 High Add Custom CSS and JS Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.20 CVE-2024-3903 WPScan
7.6 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31270 Patchstack
7.7 High Rolo Slider Plugin rolo-slider Broken Access Control ≤ 1.0.9 CVE-2024-1438 Patchstack
7.1 High Stockholm Core Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-34553 Patchstack
7.1 High Academy LMS Plugin academy Broken Access Control Broken Access Control on Paid Courses ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-33912 Patchstack
8.6 High LeadConnector Plugin leadconnector Broken Access Control No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-34378 Patchstack
7.1 High Webpushr Plugin webpushr-web-push-notifications Cross-Site Scripting Webpushr plugin <= 4.35.0 - Cross Site Scripting (XSS) No login needed ≤ 4.35.0 Fixed in 4.36.0 CVE-2024-34369 Patchstack
7.1 High Popup box Plugin ays-popup-box Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-34367 Patchstack
7.6 High Auto Affiliate Links Plugin wp-auto-affiliate-links SQL Injection ≤ 6.4.3.1 Fixed in 6.4.4 CVE-2024-34386 Patchstack
8.5 High ParcelPanel Plugin parcelpanel SQL Injection Auth. SQL Injection ≤ 3.8.1 Fixed in 3.9.0 CVE-2024-34412 Patchstack
7.5 High GDPR Compliance Plugin gdpr-compliance Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.5 CVE-2024-34388 Patchstack
8.5 High Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Path Traversal Arbitrary File Download and Deletion ≤ 4.0.17 Fixed in 4.0.18 CVE-2024-32807 Patchstack
7.5 High MF Gig Calendar Plugin Cross-Site Request Forgery Arbitrary Event Deletion via CSRF No login needed ≤ 1.2.1 CVE-2024-3756 WPScan
8.8 High ConvertPlug Plugin PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 3.5.25 CVE-2024-3240 Wordfence
7.6 High ShortPixel Critical CSS Plugin shortpixel-critical-css Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-32810 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 4.14.4 CVE-2024-33924 Patchstack
7.1 High CodeBard's Patron Button and Widgets for Patreon Plugin patron-button-and-widgets-by-codebard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-33928 Patchstack
7.1 High WPify Woo Czech Plugin wpify-woo Cross-Site Scripting No login needed ≤ 4.0.10 Fixed in 4.0.11 CVE-2024-33946 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 5.3.2.0 Fixed in 5.3.2.1 CVE-2024-33947 Patchstack
7.2 High WordPress Core Cross-Site Scripting WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the d… No login needed 6.0 – 6.0.7, 6.1 – 6.1.5, 6.2 – 6.2.4, … CVE-2024-4439 Wordfence
7.2 High Cost Calculator Builder Pro Plugin Cross-Site Scripting Unauthenticated Cross-Site Scripting via SVG Upload No login needed ≤ 3.1.67 CVE-2024-4097 Wordfence
8.8 High Click to Chat – HoliThemes Plugin click-to-chat-for-whatsapp Local File Inclusion HoliThemes <= 3.35 - Authenticated (Contributor+) Local File Inclusion ≤ 3.35 CVE-2024-3849 Wordfence
7.5 High Shortcodes and extra features for Phlox Plugin auxin-elements PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer ≤ 2.17.5 CVE-2023-7064 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only