WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,451–8,500 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 170 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Scripting No login needed ≤ 2.4.5 CVE-2024-32546 Patchstack
7.1 High BMI Adult & Kid Calculator Plugin bmi-adultkid-calculator Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-32550 Patchstack
7.1 High Related Posts Plugin microkids-related-posts Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.0.3 CVE-2024-32549 Patchstack
8.6 High MoveTo Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.2 CVE-2024-25911 Patchstack
8.2 High LiteSpeed Cache Plugin litespeed-cache Broken Access Control Unauthenticated Broken Access Control on API No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-45000 Patchstack
8.3 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Site Wide Stored XSS No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-40000 Patchstack
7.5 High Citadela Listing Plugin citadela-directory Information Disclosure Unauth. Sensitive Data Exposure No login needed ≤ 5.18.1 CVE-2024-32086 Patchstack
7.2 High WooCommerce Google Feed Manager Plugin wp-product-feed-manager SQL Injection Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting ≤ 2.4.2 CVE-2024-3067 Wordfence
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
7.1 High Social Author Bio Plugin social-autho-bio Cross-Site Scripting Stored XSS via Cross Site Request Forgery (CSRF) No login needed ≤ 2.4 CVE-2024-30545 Patchstack
7.1 High Change default login logo,url and title Plugin change-default-login-logo-url-and-title Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.0 CVE-2024-31086 Patchstack
7.1 High Broken Images Plugin wp-broken-images Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.2 CVE-2024-31093 Patchstack
7.1 High Sync Post With Other Site Plugin sync-post-with-other-site Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.9.1 CVE-2024-32082 Patchstack
7.6 High Product Feed on WooCommerce for Google Plugin purple-xmls-google-product-feed-for-woocommerce SQL Injection Auth. SQL Injection (SQLi) ≤ 3.5.7 CVE-2024-32087 Patchstack
7.6 High Advanced Page Visit Counter Plugin advanced-page-visit-counter SQL Injection Auth. SQL Injection (SQLi) ≤ 8.0.6 CVE-2024-32098 Patchstack
8.5 High BA Book Everything Plugin ba-book-everything SQL Injection Auth. SQL Injection ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-32125 Patchstack
8.5 High Find Duplicates Plugin find-duplicates SQL Injection Auth. SQL Injection ≤ 1.4.6 CVE-2024-32127 Patchstack
7.6 High CBX Bookmark & Favorite Plugin cbxwpbookmark SQL Injection ≤ 1.7.20 CVE-2024-32132 Patchstack
7.6 High Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook Plugin forms-to-zapier SQL Injection Auth. SQL Injection ≤ 1.1.12 CVE-2024-32134 Patchstack
7.6 High Disable Comments | WPZest Plugin disable-comments-wpz SQL Injection ≤ 1.51 CVE-2024-32135 Patchstack
7.6 High BWL Advanced FAQ Manager Plugin bwl-advanced-faq-manager SQL Injection Auth. SQL Injection ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-32136 Patchstack
8.5 High User Activity Log Pro Plugin SQL Injection Auth. SQL Injection ≤ 2.3.4 CVE-2024-32137 Patchstack
8.5 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress SQL Injection ≤ 4.0.12 Fixed in 4.0.14 CVE-2024-32139 Patchstack
7.1 High EZ Form Calculator Plugin ez-form-calculator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.14.0.3 CVE-2024-32133 Patchstack
7.1 High Short URL Plugin shorten-url Cross-Site Scripting No login needed ≤ 1.6.8 CVE-2024-32138 Patchstack
7.1 High WP Google Analytics Events Plugin wp-google-analytics-events Cross-Site Scripting No-Code Custom Event Tracking for Google Analytics plugin <= 2.8.0 - Reflected Cross-Site Scripting No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-32145 Patchstack
7.1 High Jobs Plugin job-postings Cross-Site Scripting No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2024-32149 Patchstack
8.7 High Advance Search Plugin Cross-Site Request Forgery Shortcode Deletion via CSRF ≤ 1.1.6 CVE-2024-2739 WPScan
8.8 High NPS computy Plugin nps-computy Cross-Site Request Forgery Results Deletion via CSRF No login needed ≤ 2.7.5 CVE-2024-1755 WPScan
8.1 High WooCommerce Customers Manager Plugin SQL Injection Subscriber+ SQL Injection < 29.7 Fixed in 29.7 CVE-2024-0399 WPScan
8.8 High Uncode Core Plugin uncode-core Privilege Escalation ≤ 2.8.8 Fixed in 2.8.9 CVE-2023-51515 Patchstack
7.2 High WPvivid Backup & Migration Plugin PHP Object Injection Authenticated (Admin+) PHAR Deserialization ≤ 0.9.99 CVE-2024-3054 Wordfence
8.8 High Shopping Cart & eCommerce Store Plugin wp-easycart SQL Injection Authenticated (Contributor+) SQL Injection ≤ 5.6.3 CVE-2024-3211 Wordfence
7.1 High WordPress Tooltips Plugin wordpress-tooltips Cross-Site Request Forgery No login needed ≤ 9.5.3 Fixed in 9.5.9 CVE-2024-31285 Patchstack
8.8 High Ninja Forms Plugin ninja-forms Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations ma… No login needed prior to 3.4.31 CVE-2024-25572 jpcert
7.2 High Language Translate Widget for WordPress – ConveyThis Plugin Cross-Site Scripting ConveyThis <= 223 - Unauthenticated Stored Cross-Site Scripting via api_key No login needed ≤ 223 CVE-2023-6811 Wordfence
7.1 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31299 Patchstack
8.5 High Slideshow Gallery Plugin slideshow-gallery SQL Injection Auth. SQL Injection ≤ 1.7.8 CVE-2024-31355 Patchstack
7.6 High User Activity Log Plugin user-activity-log SQL Injection Auth. SQL Injection ≤ 1.8 CVE-2024-31356 Patchstack
7.5 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Path Traversal Arbitrary File Download No login needed ≤ 4.10.1 Fixed in 5.0 CVE-2024-31343 Patchstack
7.7 High WP Poll Maker Plugin epoll-wp-voting Arbitrary File Deletion Auth. Arbitrary File Deletion ≤ 3.1 Fixed in 3.4 CVE-2024-31240 Patchstack
7.5 High Wholesale For WooCommerce Plugin Broken Access Control Unauthenticated Arbitrary Post/Page No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2024-31297 Patchstack
7.5 High 5 Stars Rating Funnel Plugin 5-stars-rating-funnel Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.2.67 Fixed in 1.3.02 CVE-2024-31358 Patchstack
7.5 High SearchIQ Plugin searchiq Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 4.5 Fixed in 4.6 CVE-2024-31259 Patchstack
7.2 High Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection ≤ 2.6.3 CVE-2024-3020 Wordfence
7.2 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via id ≤ 1.12.9 CVE-2024-0952 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.6.7.7 CVE-2024-2341 Wordfence
8.8 High Pods Plugin pods Remote Code Execution Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution < 2.7.31, 2.8 – < 2.8.23.2, 3 – < 3.0.10.2 Fixed in 2.7.31 CVE-2023-6999 Wordfence
7.2 High Everest Forms Plugin everest-forms Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via font_url No login needed ≤ 2.0.7 CVE-2024-1812 Wordfence
7.5 High Hubbub Lite – Fast, Reliable Social Network Sharing Buttons Plugin social-pug PHP Object Injection Fast, Reliable Social Network Sharing Buttons <= 1.33.1 - PHP Object Injection ≤ 1.33.1 CVE-2024-2501 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only