WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,351–8,400 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 168 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload via featured image ≤ 3.6.4 CVE-2024-4033 Wordfence
8.8 High WP ULike – Most Advanced WordPress Marketing Toolkit Plugin SQL Injection Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes ≤ 4.6.9 CVE-2024-1797 Wordfence
8.8 High User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 3.1.5 CVE-2024-2417 Wordfence
7.2 High EleForms – All In One Form Integration including DB for Elementor Plugin Cross-Site Scripting All In One Form Integration including DB for Elementor <= 2.9.9.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.9.9.7 CVE-2024-2082 Wordfence
7.2 High WP Meta SEO Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Referer header No login needed ≤ 4.5.12 CVE-2023-6961 Wordfence
8.8 High ElementsKit Pro Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Price Menu, Hotspot, and Advanced Toggle Widgets ≤ 3.6.0 CVE-2024-3500 Wordfence
7.2 High Database for Contact Form 7, WPforms, Elementor forms Plugin contact-form-entries Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.8 CVE-2024-3715 Wordfence
7.2 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp SQL Injection Authenticated (AccountingManager+) SQL Injection ≤ 1.13.1 CVE-2024-1173 Wordfence
8.2 High Royal Elementor Addons and Templates Plugin royal-elementor-addons Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.3.94 CVE-2024-1567 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Onepage Scroll Module ≤ 3.1.0 CVE-2024-3499 Wordfence
7.5 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Information Disclosure Absolute Addons For Elementor <= 2.4.6 - Sensitive Information Exposure via purchased_products No login needed ≤ 2.4.6 CVE-2023-6214 Wordfence
8.8 High WP Datepicker Plugin wp-datepicker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 2.1.0 CVE-2024-3895 Wordfence
8.8 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.5.4 CVE-2024-2661 Wordfence
7.5 High Grid Gallery – Photo Image Grid Gallery Plugin new-grid-gallery PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode ≤ 1.4.3 CVE-2024-1897 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-3045 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.8.0 CVE-2024-3047 Wordfence
7.5 High Photo Gallery Plugin new-photo-gallery PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode ≤ 1.4.2 CVE-2024-1896 Wordfence
8.8 High Calendar Plugin calendar SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.3.14 CVE-2024-2831 Wordfence
7.1 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion ≤ 1.6.4 CVE-2024-1945 Wordfence
7.6 High School Management Pro Plugin SQL Injection ≤ 10.3.4 CVE-2024-33911 Patchstack
8.8 High Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Menu Deletion via CSRF No login needed < 4.2.1 Fixed in 4.2.1 CVE-2024-3476 WPScan
7.5 High Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Button Deletion via CSRF < 3.2.4 Fixed in 3.2.4 CVE-2024-3475 WPScan
8.8 High Wow Skype Buttons Plugin Cross-Site Request Forgery Button Deletion via CSRF No login needed < 4.0.4 Fixed in 4.0.4 CVE-2024-3474 WPScan
8.1 High Customer Email Verification for WooCommerce Plugin emails-verification-for-woocommerce Authentication Bypass Email Verification and Authentication Bypass due to Insufficient Randomness No login needed ≤ 2.7.4 CVE-2024-4185 Wordfence
8.3 High ZD YouTube FLV Player Plugin zd-youtube-flv-player Server-Side Request Forgery No login needed ≤ 1.2.6 CVE-2024-2663 Wordfence
7.5 High Event Monster Plugin event-monster PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Custom Meta ≤ 1.3.9 CVE-2024-1895 Wordfence
7.5 High Easy Accept Payments Plugin wordpress-easy-paypal-payment-or-donation-accept-plugin Broken Access Control No login needed ≤ 4.9.10 Fixed in 5.0 CVE-2024-33591 Patchstack
7.5 High Leaky Paywall Plugin leaky-paywall Price Manipulation No login needed ≤ 4.20.8 Fixed in 4.20.9 CVE-2024-33594 Patchstack
7.5 High SSU Plugin wp-s3-smart-upload Broken Access Control No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-33597 Patchstack
7.5 High Piotnet Addons For Elementor Pro Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 7.1.17 CVE-2024-33635 Patchstack
7.5 High Solid Affiliate Plugin Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 1.9.1 CVE-2024-33637 Patchstack
7.1 High Regenerate post permalink Plugin regenerate-post-permalinks Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed ≤ 1.0.3 CVE-2024-33681 Patchstack
8.1 High GamiPress Plugin gamipress Broken Access Control < 6.8.9 Fixed in 6.8.9 CVE-2024-2505 WPScan
7.1 High WZone Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 14.0.10 CVE-2024-33548 Patchstack
7.1 High XStore Core Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.5 CVE-2024-33554 Patchstack
7.1 High XStore Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.3.5 CVE-2024-33562 Patchstack
7.1 High VOD Infomaniak Plugin vod-infomaniak Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-33571 Patchstack
7.1 High Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.17 CVE-2024-33633 Patchstack
7.1 High Easy Set Favicon Plugin easy-set-favicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-33645 Patchstack
7.1 High Sticky Anything Plugin toast-stick-anything Broken Access Control Broken Access Control to XSS No login needed ≤ 2.1.5 CVE-2024-33646 Patchstack
7.2 High WP SMTP Plugin SQL Injection The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on the user supplied parameter and… 1.2 – 1.2.6 CVE-2024-1789 Wordfence
8.1 High MM-email2image Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 0.2.5 CVE-2024-3075 WPScan
7.1 High UDesign Theme u-design Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.3 CVE-2024-4077 Patchstack
8.8 High WP Setup Wizard Plugin Information Disclosure Auth. Full Database Download ≤ 1.0.8.1 Fixed in 1.0.8.2 CVE-2024-25917 Patchstack
8.2 High Checkout Mestres WP Plugin checkout-mestres-wp Authentication Bypass Unauthenticated Arbitrary Options Update No login needed ≤ 7.1.9.7 Fixed in 7.1.9.8 CVE-2023-51471 Patchstack
8.2 High BookingPress Plugin bookingpress-appointment-booking Price Manipulation Booking Price Manipulation No login needed ≤ 1.0.74 Fixed in 1.0.75 CVE-2023-51405 Patchstack
7.1 High Slash Admin Plugin slash-admin Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2024-32958 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Other Arbitrary Price Change No login needed ≤ 5.1.9.2 Fixed in 5.1.9.3 CVE-2023-23976 Patchstack
7.1 High The Pack Elementor addons Plugin the-pack-addon Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 2.0.8.3 Fixed in 2.0.8.4 CVE-2024-32785 Patchstack
7.1 High Seers Plugin seers-cookie-consent-banner-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 8.1.0 Fixed in 8.1.1 CVE-2024-32789 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only