WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,501–8,550 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 171 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Avada Theme SQL Injection Authenticated (Admin+) SQL Injection via entry ≤ 7.11.6 CVE-2024-2344 Wordfence
7.5 High CMB2 Plugin cmb2 PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.10.1 CVE-2024-1792 Wordfence
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
8.8 High Easy Property Listings Plugin easy-property-listings SQL Injection Authenticated(Contributor+) SQL Injection via Shortcode ≤ 3.5.2 CVE-2024-1893 Wordfence
7.5 High WP Compress – Image Optimizer Plugin wp-compress-image-optimizer Broken Access Control Image Optimizer <= 6.11.08 - Missing Authorization to Unauthenticated CDN Modification No login needed ≤ 6.11.10 CVE-2024-1934 Wordfence
8.8 High Link Whisper Free Plugin link-whisper PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 0.7.1 CVE-2024-2693 Wordfence
7.5 High WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score Plugin Information Disclosure One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score <= 7.0 - Sensitive Information Exposure via insufficiently protected files No login needed ≤ 7.0 CVE-2023-7046 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 5.3.0.0 CVE-2024-1991 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 5.3.1.0 CVE-2024-1990 Wordfence
8.8 High Classified Listing Plugin classified-listing Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account No login needed ≤ 3.0.4 CVE-2024-1315 Wordfence
7.5 High WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Broken Access Control Missing Authorization to Unauthenticated Permalink Modification No login needed ≤ 1.0.33 CVE-2024-1308 Wordfence
8.8 High WP Activity Log Premium Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.6.4 CVE-2024-2018 Wordfence
8.8 High EnvíaloSimple: Email Marketing y Newsletters Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.3 CVE-2024-2125 Wordfence
7.2 High Forminator Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload No login needed ≤ 1.29.0 CVE-2024-1794 Wordfence
8.8 High Pods Plugin pods SQL Injection Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode < 2.7.31, 2.8 – < 2.8.23.2, 3 – < 3.0.10.2 Fixed in 2.7.31 CVE-2023-6967 Wordfence
8.8 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Path Traversal Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.6 CVE-2024-1974 Wordfence
7.2 High Customily Product Personalizer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.23.3 CVE-2024-1774 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.6.7.7 CVE-2024-2342 Wordfence
7.2 High WP-Members Membership Plugin wp-members Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.4.9.2 CVE-2024-1852 Wordfence
8.5 High AIKit Plugin aikit-wordpress-ai-writing-assistant-using-gpt3 SQL Injection ≤ 4.14.1 CVE-2024-31370 Patchstack
7.1 High Soledad Theme Broken Access Control Authenticated Broken Access Control ≤ 8.4.2 CVE-2024-31367 Patchstack
7.1 High Post Type Builder (PTB) Plugin Broken Access Control Auth. Arbitrary Post/Page Creation ≤ 2.0.8 CVE-2024-31366 Patchstack
7.1 High Post Type Builder (PTB) Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-31365 Patchstack
7.5 High BackWPup Plugin backwpup Other Unauthenticated Backup Download No login needed < 4.0.4 Fixed in 4.0.4 CVE-2023-7164 WPScan
8.5 High Rehub Theme SQL Injection Auth. SQL Injection ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31233 Patchstack
8.5 High REHub Framework Plugin SQL Injection < 19.6.2 Fixed in 19.6.2 CVE-2024-31234 Patchstack
7.6 High LearnPress Export Import Plugin learnpress-import-export SQL Injection Auth. SQL Injection ≤ 4.0.3 Fixed in 4.0.4 CVE-2024-31241 Patchstack
7.6 High Edwiser Bridge Plugin edwiser-bridge SQL Injection ≤ 3.0.2 Fixed in 3.0.4 CVE-2024-31260 Patchstack
7.1 High ELEX WooCommerce Dynamic Pricing and Discounts Plugin elex-woocommerce-dynamic-pricing-and-discounts Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2024-31255 Patchstack
7.1 High WebinarPress Plugin wp-webinarsystem Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.33.10 Fixed in 1.3.11 CVE-2024-31256 Patchstack
7.2 High Import XML and RSS Feeds Plugin import-xml-feed Arbitrary File Upload ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-31292 Patchstack
8.7 High Product Designer Plugin product-designer PHP Object Injection No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2024-31277 Patchstack
7.2 High RapidLoad Power-Up for Autoptimize Plugin unusedcss Server-Side Request Forgery No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-31288 Patchstack
7.1 High WP-Stateless – Google Cloud Storage Plugin wp-stateless Broken Access Control Google Cloud Storage <= 3.4.0 - Missing Authorization to Limited Arbitrary Options Update ≤ 3.4.0 CVE-2024-1385 Wordfence
8.8 High WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.3.0 CVE-2024-3217 Wordfence
8.8 High LearnPress – WordPress LMS Plugin learnpress Cross-Site Request Forgery WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.0.0 CVE-2024-2115 Wordfence
8.8 High Modal Popup Box – Popup Builder, Show Offers And News in Popup Plugin modal-popup-box PHP Object Injection Popup Builder, Show Offers And News in Popup <= 1.5.2 - Authenticated (Contributor+) PHP Object Injection in awl_modal_popup_box_shortcode ≤ 1.5.2 CVE-2024-2008 Wordfence
7.2 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Arbitrary File Upload Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.87 CVE-2024-3022 Wordfence
8.5 High Slivery Extender Plugin slivery-extender Remote Code Execution ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-27191 Patchstack
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2024-31105 Patchstack
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
7.1 High Sticky Anything Plugin toast-stick-anything Cross-Site Scripting No login needed ≤ 2.1.5 CVE-2024-30551 Patchstack
7.1 High Add Shortcodes Actions And Filters Plugin add-actions-and-filters Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.10 CVE-2024-30558 Patchstack
7.1 High Appointment Calendar Plugin appointment-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.6 CVE-2024-30561 Patchstack
7.1 High Weekly Class Schedule Plugin weekly-class-schedule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.19 CVE-2024-31084 Patchstack
7.1 High Post-Plugin Library Plugin post-plugin-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2.1 CVE-2024-31085 Patchstack
7.1 High pageMash > Page Management Plugin pagemash Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2024-31087 Patchstack
7.1 High Hacklog Down As PDF Plugin down-as-pdf Cross-Site Scripting No login needed ≤ 2.3.6 CVE-2024-31090 Patchstack
7.1 High Custom Field Bulk Editor Plugin custom-field-bulk-editor Cross-Site Scripting No login needed ≤ 1.9.1 CVE-2024-31091 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only