WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,401–8,450 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 169 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High ARForms Plugin arforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.4 Fixed in 6.4.1 CVE-2024-32702 Patchstack
7.1 High WP Media Category Management Plugin wp-media-category-management Cross-Site Scripting No login needed ≤ 2.2 Fixed in 2.3.0 CVE-2024-32950 Patchstack
7.1 High Max Addons Pro for Bricks Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32952 Patchstack
8.5 High ARForms Plugin arforms SQL Injection Subscriber+ SQL Injection ≤ 6.4 Fixed in 6.4.1 CVE-2024-32706 Patchstack
8.5 High WP-Recall Plugin wp-recall SQL Injection ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32710 Patchstack
7.5 High Frontend Dashboard Plugin frontend-dashboard Information Disclosure Sensitive Data Exposure on PII No login needed ≤ 2.2.2 Fixed in 2.2.4 CVE-2024-32726 Patchstack
7.5 High Email Customizer for WooCommerce Plugin email-customizer-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32781 Patchstack
7.5 High Post Grid Plugin post-grid Information Disclosure Sensitive Data Exposure via API No login needed ≤ 2.2.78 Fixed in 2.2.79 CVE-2024-32816 Patchstack
7.5 High Simply Static Plugin simply-static Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-32825 Patchstack
7.5 High Newsletters Plugin newsletters-lite Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-32953 Patchstack
7.2 High Forminator Plugin forminator SQL Injection Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain… prior to 1.29.3 CVE-2024-31077 jpcert
8.8 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode ≤ 4.6.18 CVE-2024-3293 Wordfence
7.1 High Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32682 Patchstack
7.6 High Automatic Plugin Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed < 3.93.0 Fixed in 3.93.0 CVE-2024-32693 Patchstack
7.1 High Language Switcher for Transposh Plugin language-switcher-for-transposh Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.9 Fixed in 1.6.0 CVE-2024-32695 Patchstack
7.1 High 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.62 Fixed in 3.63 CVE-2024-32694 Patchstack
7.2 High Poll Maker – Best WordPress Poll Plugin Broken Access Control Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.1.8 CVE-2024-3600 Wordfence
7.6 High CataBlog Plugin catablog Arbitrary File Deletion WordPress CataBlog Plugin <= 1.7.0 is vulnerable to Arbitrary File Deletion ≤ 1.7.0 CVE-2023-47843 Patchstack
7.6 High SP Project & Document Manager Plugin sp-client-document-manager SQL Injection Auth. SQL Injection ≤ 4.71 CVE-2024-32551 Patchstack
7.6 High WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual SQL Injection ≤ 5.3.3.1 Fixed in 5.3.4 CVE-2024-32602 Patchstack
8.3 High Master Slider Plugin master-slider PHP Object Injection No login needed ≤ 3.9.5 Fixed in 3.9.7 CVE-2024-32600 Patchstack
7.1 High Superfly Menu Plugin superfly-menu Cross-Site Scripting Subscriber+ Site-Wide Stored Cross Site Scripting (XSS) ≤ 5.0.25 CVE-2024-32553 Patchstack
7.1 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Scripting No login needed ≤ 3.3.32 Fixed in 3.3.33 CVE-2024-32558 Patchstack
7.1 High WP 404 Auto Redirect to Similar Post Plugin wp-404-auto-redirect-to-similar-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-32559 Patchstack
8.6 High Z Y N I T H Plugin Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 7.4.9 CVE-2024-32562 Patchstack
7.1 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-32563 Patchstack
7.1 High DirectoryPress Plugin directorypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-32567 Patchstack
7.1 High WP 2FA Plugin wp-2fa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-32568 Patchstack
7.1 High Cornerstone Plugin cornerstone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.8.0 Fixed in 0.8.1 CVE-2024-32570 Patchstack
7.1 High WP Simple HTML Sitemap Plugin wp-simple-html-sitemap Cross-Site Scripting No login needed ≤ 2.8 Fixed in 2.9 CVE-2024-32574 Patchstack
7.1 High Slider by 10Web Plugin slider-wd Cross-Site Scripting No login needed ≤ 1.2.54 Fixed in 1.2.55 CVE-2024-32578 Patchstack
7.1 High Debug Log Manager Plugin debug-log-manager Cross-Site Scripting No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-32582 Patchstack
7.1 High Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.21 Fixed in 1.8.22 CVE-2024-32583 Patchstack
7.1 High LearnPress Export Import Plugin learnpress-import-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.3 Fixed in 4.0.4 CVE-2024-32588 Patchstack
7.1 High WP Helper Premium Plugin wp-helper-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.6.0 Fixed in 4.6.0 CVE-2024-32595 Patchstack
8.5 High WooBuddy Plugin wc4bp PHP Object Injection ≤ 3.4.20 Fixed in 3.4.21 CVE-2024-32603 Patchstack
7.7 High JVM rich text icons Plugin jvm-rich-text-icons Arbitrary File Deletion ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-51418 Patchstack
7.7 High Uncode Core Plugin Arbitrary File Deletion ≤ 2.8.8 Fixed in 2.8.9 CVE-2023-51500 Patchstack
8.6 High JS Help Desk – Best Help Desk & Support Plugin js-support-ticket SQL Injection Unauth. SQL Injection No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-47151 Patchstack
7.1 High WP Cost Estimation & Payment Forms Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-32510 Patchstack
7.1 High WP Dynamic Keywords Injector Plugin wp-dynamic-keywords-injector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.18 Fixed in 2.3.22 CVE-2024-32528 Patchstack
7.1 High GuCherry Blog Theme gucherry-blog Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.8 CVE-2024-32531 Patchstack
7.5 High Simple File List Plugin simple-file-list Arbitrary File Deletion WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion No login needed ≤ 6.1.9 Fixed in 6.1.10 CVE-2023-44227 Patchstack
7.1 High LH Add Media From Url Plugin lh-add-media-from-url Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22 Fixed in 1.23 CVE-2024-32533 Patchstack
7.1 High Access Category Password Plugin access-category-password Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2024-32535 Patchstack
7.1 High WP-Cufon Plugin wp-cufon Cross-Site Scripting No login needed ≤ 1.6.10 CVE-2024-32541 Patchstack
7.1 High Bulk Block Converter Plugin bulk-block-converter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-32542 Patchstack
7.1 High MJ Update History Plugin mj-update-history Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-32543 Patchstack
7.1 High Netgsm Plugin netgsm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8 Fixed in 2.9 CVE-2024-32544 Patchstack
7.1 High Canva – Design beautiful blog graphics Plugin canva Cross-Site Scripting Design beautiful blog graphics plugin <= 1.2.4 - Cross Site Scripting (XSS) No login needed ≤ 1.2.4 CVE-2024-32545 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only