WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,551–8,600 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 172 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Backup and Restore Plugin Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 1.45 CVE-2023-7232 WPScan
4.3 Medium Google Maps CP Plugin codepeople-post-map Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.43 Fixed in 1.0.44 CVE-2023-25039 Patchstack
6.5 Medium Advance WordPress Search Plugin th-advance-product-search Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 1.2.1 CVE-2022-38057 Patchstack
5.4 Medium MainWP Wordfence Extension Plugin Broken Access Control Subscriber+ Arbitrary Plugin Activation ≤ 4.0.7 Fixed in 4.0.8 CVE-2023-22699 Patchstack
5.4 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Broken Access Control ≤ 3.1.4 Fixed in 3.1.5 CVE-2022-45851 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45356 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45352 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45351 Patchstack
4.3 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45349 Patchstack
6.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control ≤ 12.1.20 Fixed in 12.1.21 CVE-2022-44626 Patchstack
6.5 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control No login needed ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27608 Patchstack
4.3 Medium Educenter Theme educenter Broken Access Control ≤ 1.5.5 CVE-2023-30480 Patchstack
4.3 Medium RealHomes Theme Broken Access Control ≤ 4.0.2 CVE-2023-37885 Patchstack
5.4 Medium RealHomes Theme Broken Access Control ≤ 4.0.2 CVE-2023-37886 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Broken Access Control ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24835 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 5.4.11 Fixed in 5.4.12 CVE-2024-24840 Patchstack
4.3 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 3.11.10 Fixed in 3.11.11 CVE-2024-24883 Patchstack
5.4 Medium WP Media folder Plugin Broken Access Control Plugin Settings Change ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25907 Patchstack
5.3 Medium Quicksand Post Filter jQuery Plugin quicksand-jquery-post-filter Broken Access Control No login needed ≤ 3.1.1 CVE-2024-24850 Patchstack
6.5 Medium YITH WooCommerce Gift Cards Premium Plugin yith-woocommerce-gift-cards-premium Cross-Site Scripting Unauth. Gift Card Creation Leading to Stored XSS No login needed ≤ 3.23.1 Fixed in 3.24.0 CVE-2022-44633 Patchstack
4.3 Medium AJAX Thumbnail Rebuild Plugin ajax-thumbnail-rebuild Broken Access Control ≤ 1.13 Fixed in 1.14 CVE-2022-47604 Patchstack
4.3 Medium WP Media folder Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Modification ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25908 Patchstack
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-25935 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Settings Change ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27607 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Authentication Bypass Broken Authentication No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2022-44595 Patchstack
6.5 Medium Code Embed Plugin simple-embed-code Denial of Service Denial of Service Attack ≤ 2.3.6 Fixed in 2.3.7 CVE-2023-49837 Patchstack
4.3 Medium Download Media Plugin download-media Broken Access Control ≤ 1.4.2 CVE-2024-27190 Patchstack
5.9 Medium WP Coder Plugin wp-coder Cross-Site Scripting ≤ 3.5 Fixed in 3.5.1 CVE-2024-2578 Patchstack
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting ≤ 2.0.16 Fixed in 2.1.0 CVE-2024-2579 Patchstack
6.5 Medium Automation By Autonami Plugin wp-marketing-automations Cross-Site Scripting ≤ 2.8.2 Fixed in 2.8.3 CVE-2024-2580 Patchstack
6.5 Medium Crisp Plugin crisp Cross-Site Scripting Live Chat and Chatbot plugin <= 0.44 - Cross Site Scripting (XSS) ≤ 0.44 Fixed in 0.45 CVE-2024-27963 Patchstack
5.9 Medium WPFunnels Plugin wpfunnels Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-27965 Patchstack
5.9 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting ≤ 8.2.2 Fixed in 8.2.3 CVE-2024-27966 Patchstack
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
6.5 Medium Free Downloads WooCommerce Plugin download-now-for-woocommerce Cross-Site Scripting ≤ 3.5.8.2 Fixed in 3.5.8.3 CVE-2024-27969 Patchstack
5.4 Medium WP SendFox Plugin wp-sendfox Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-27970 Patchstack
5.4 Medium PropertyHive Plugin propertyhive PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-27985 Patchstack
6.5 Medium WEN Responsive Columns Plugin wen-responsive-columns Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-27988 Patchstack
6.5 Medium WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs Cross-Site Scripting ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-27989 Patchstack
6.5 Medium The Moneytizer Plugin the-moneytizer Cross-Site Scripting ≤ 9.5.20 Fixed in 9.6.1 CVE-2024-27990 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.2.3 Fixed in 3.2.4 CVE-2024-27991 Patchstack
5.9 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting ≤ 4.0.23 Fixed in 4.0.24 CVE-2024-27995 Patchstack
6.5 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control No login needed ≤ 1.0 CVE-2023-52229 Patchstack
6.4 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Cross-Site Scripting Weglot <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 4.2.5 CVE-2024-2124 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-27996 Patchstack
5.9 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.6.0 Fixed in 45.7.0 CVE-2024-27997 Patchstack
6.5 Medium Five Star Restaurant Menu Plugin food-and-drink-menu Cross-Site Scripting ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-29089 Patchstack
4.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.01.3 Fixed in 1.01.4 CVE-2024-29093 Patchstack
5.9 Medium Site Reviews Plugin site-reviews Cross-Site Scripting ≤ 6.11.6 Fixed in 6.11.7 CVE-2024-29095 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only