WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,651–8,700 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 174 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.11 Fixed in 5.7.12 CVE-2024-22300 Patchstack
7.1 High CformsII Plugin cforms2 Cross-Site Scripting No login needed ≤ 15.0.5 CVE-2024-22149 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack
7.1 High WP Editor Plugin wp-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-24700 Patchstack
7.1 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.2.5 Fixed in 13.2.6 CVE-2024-24800 Patchstack
7.1 High Widgets Controller Plugin widgets-controller Cross-Site Scripting No login needed ≤ 1.1 CVE-2024-25926 Patchstack
7.1 High Fusion Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39306 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6.20 Fixed in 1.6.6.24 CVE-2024-22311 Patchstack
8.7 High Knowledge Base for Documentation, FAQs with AI Assistance Plugin echo-knowledge-base PHP Object Injection No login needed ≤ 11.30.2 Fixed in 11.31.0 CVE-2024-24842 Patchstack
8.0 High Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Arbitrary File Upload ≤ 11.0.2 Fixed in 11.1 CVE-2023-48275 Patchstack
8.5 High Avada Theme Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39307 Patchstack
7.1 High Glaze Blog Lite Theme glaze-blog-lite Cross-Site Scripting Reflected Cross-Site Scripting (XSS) vulnerability in multiple WordPress themes No login needed ≤ <= 1.1.4, ≤ 1.0.8, ≤ 2.1.3, … Fixed in 1.1.5 CVE-2023-28687 Patchstack
7.4 High User Registration Plugin user-registration PHP Object Injection Authenticated PHP Object Injection ≤ 2.3.2.1 Fixed in 2.3.3 CVE-2023-27459 Patchstack
7.2 High Types Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4.17 Fixed in 3.4.18 CVE-2023-27440 Patchstack
7.2 High Theme Editor Plugin theme-editor Arbitrary File Upload ≤ 2.7.1 Fixed in 2.8 CVE-2023-6091 Patchstack
7.5 High CF7 Google Sheets Connector Plugin cf7-google-sheets-connector Information Disclosure Sensitive Data Exposure via Debug Log No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-44989 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 9.4.3 Fixed in 9.4.3.1 CVE-2023-23991 Patchstack
7.1 High Front End Users Plugin front-end-only-users Cross-Site Scripting No login needed < 3.2.25 Fixed in 3.2.25 CVE-2023-33322 Patchstack
7.1 High Contact Form With Captcha Plugin contact-form-with-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 CVE-2023-45771 Patchstack
7.1 High Cosmetsy theme (core plugin) Plugin Cross-Site Scripting Reflected Cross-Site Scripting vulnerability in multiple WordPress components by KlbTheme No login needed ≤ 1.3.0, ≤ 1.0.9, ≤ 1.3.3, … CVE-2023-49839 Patchstack
8.1 High Check & Log Email Plugin check-email Remote Code Execution Unauthenticated Hook Injection No login needed ≤ 1.0.9 CVE-2024-0866 Wordfence
7.3 High Youzify - Buddypress Moderation Plugin youzify-moderation Cross-Site Scripting Buddypress Moderation plugin <= 1.2.5 - Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2024-2864 Patchstack
8.8 High CM Download and File Manager Plugin Cross-Site Request Forgery Download Edit via CSRF No login needed < 2.9.1 Fixed in 2.9.1 CVE-2024-1962 WPScan
8.2 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 3.3.9 Fixed in 3.4.0 CVE-2024-24832 Patchstack
8.8 High BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin wc4bp PHP Object Injection Authenticated (Subscriber+) PHP Object Injection in get_simple_request ≤ 3.4.20 CVE-2024-2025 Wordfence
7.5 High FunnelKit Checkout Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 3.10.3 Fixed in 3.11.0 CVE-2023-51672 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
7.1 High wp-mpdf Plugin wp-mpdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.1 Fixed in 3.8 CVE-2024-27962 Patchstack
8.8 High Zippy Plugin zippy Arbitrary File Upload ≤ 1.6.9 Fixed in 1.6.10 CVE-2024-27964 Patchstack
7.1 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.8 Fixed in 0.6.9 CVE-2024-27992 Patchstack
7.1 High Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-27993 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting No login needed ≤ 4.5.0 Fixed in 4.6.0 CVE-2024-27994 Patchstack
8.8 High File Manager Plugin wp-file-manager Cross-Site Request Forgery Cross-Site Request Forgery to Local JS File Inclusion No login needed ≤ 7.2.4 CVE-2024-1538 Wordfence
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
8.2 High Olive One Click Demo Import Plugin olive-one-click-demo-import Broken Access Control No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-2702 Patchstack
8.8 High Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring Plugin wemanage-app-worker Arbitrary File Upload Order notifications, Order management, Lead management, Uptime Monitoring <= 1.2.2 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.2.2 CVE-2024-1205 Wordfence
7.4 High UX Flat Plugin ux-flat Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4 CVE-2024-2459 Wordfence
7.1 High Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Unauthenticated Stored XSS No login needed < 20240223 Fixed in 20240223 CVE-2024-1983 WPScan
8.8 High Booking Calendar Plugin booking Cross-Site Request Forgery CSRF appointment scheduling No login needed < 1.3.83 Fixed in 1.3.83 CVE-2024-0856 WPScan
8.8 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin SQL Injection The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 6.8.6 CVE-2024-1799 Wordfence
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-27998 Patchstack
7.1 High WP Armour – Honeypot Anti Spam Plugin honeypot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2024-29091 Patchstack
7.1 High Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.3 Fixed in 2.4.3.1 CVE-2024-29092 Patchstack
7.1 High HT Easy GA4 ( Google Analytics 4 ) Plugin ht-easy-google-analytics Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-29094 Patchstack
7.1 High Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-29099 Patchstack
7.1 High Extensions For CF7 Plugin extensions-for-cf7 Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29102 Patchstack
7.1 High Database for Contact Form 7 Plugin cf7-database Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29103 Patchstack
7.1 High Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Scripting No login needed ≤ 1.0.27 Fixed in 1.0.28 CVE-2024-29110 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-29113 Patchstack
7.1 High WooThumbs for WooCommerce by Iconic Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-29116 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only