WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 8,701–8,750 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Contact Forms by Cimatti | Cross-Site Scripting Unauthenticated Stored Cross Site Scripting (XSS) No login needed |
≤ 1.7.0 Fixed in 1.8.0 |
CVE-2024-29117 |
Patchstack | |
| 7.1 High | WooCommerce License Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-29121 |
Patchstack | |
| 7.1 High | Link Library | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 7.6 Fixed in 7.6.1 |
CVE-2024-29123 |
Patchstack | |
| 7.1 High | Coupon Affiliates | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.12.7 Fixed in 5.12.8 |
CVE-2024-29125 |
Patchstack | |
| 7.1 High | Specific Content For Mobile – Customize the mobile version without redirections | Cross-Site Scripting No login needed |
≤ 0.1.9.5 Fixed in 0.1.9.6 |
CVE-2024-29126 |
Patchstack | |
| 7.1 High | Advanced Access Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.9.20 Fixed in 6.9.21 |
CVE-2024-29127 |
Patchstack | |
| 7.1 High | POST SMTP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.8.6 Fixed in 2.8.7 |
CVE-2024-29128 |
Patchstack | |
| 7.1 High | OxyExtras | Cross-Site Scripting No login needed |
≤ 1.4.4 Fixed in 1.4.5 |
CVE-2024-29129 |
Patchstack | |
| 7.1 High | Contact Form 7 – PayPal & Stripe Add-on | Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0 Fixed in 2.1 |
CVE-2024-29130 |
Patchstack | |
| 8.5 High | Tourfic | PHP Object Injection |
≤ 2.11.17 Fixed in 2.11.19 |
CVE-2024-29136 |
Patchstack | |
| 7.1 High | Tourfic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.11.7 Fixed in 2.11.8 |
CVE-2024-29137 |
Patchstack | |
| 7.1 High | Restrict User Access – Membership Plugin with Force | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5 Fixed in 2.6 |
CVE-2024-29138 |
Patchstack | |
| 7.1 High | MyCurator Content Curation | Cross-Site Scripting No login needed |
≤ 3.76 Fixed in 3.77 |
CVE-2024-29139 |
Patchstack | |
| 7.1 High | Better Search – Relevant search results | Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed |
≤ 3.3.0 Fixed in 3.3.1 |
CVE-2024-29142 |
Patchstack | |
| 8.8 High | Innovs HR | Cross-Site Request Forgery Employee Creation via CSRF No login needed |
≤ 1.0.3.4 |
CVE-2024-0858 |
WPScan | |
| 8.8 High | Enjoy Social Feed | Cross-Site Request Forgery Unauthenticated Arbitrary Instagram Account Unlinking No login needed |
≤ 6.2.2 |
CVE-2024-0779 |
WPScan | |
| 8.8 High | Enjoy Social Feed | Broken Access Control Subscriber+ Plugin Database Reset |
≤ 6.2.2 |
CVE-2024-0780 |
WPScan | |
| 7.1 High | AntiSpam for Contact Form 7 | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.6.0 Fixed in 0.6.1 |
CVE-2024-27961 |
Patchstack | |
| 7.1 High | Email Subscription Popup | Cross-Site Scripting No login needed |
≤ 1.2.20 Fixed in 1.2.21 |
CVE-2024-27960 |
Patchstack | |
| 7.1 High | WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management | Cross-Site Scripting No login needed |
≤ 4.2.9 Fixed in 4.3 |
CVE-2024-27959 |
Patchstack | |
| 7.1 High | Visualizer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.10.5 Fixed in 3.10.6 |
CVE-2024-27958 |
Patchstack | |
| 8.8 High | Social Media Share Buttons | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 2.1.0 |
CVE-2024-1685 |
Wordfence | |
| 7.1 High | Fontific | Google Fonts | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 0.1.6 |
CVE-2024-27194 |
Patchstack | |
| 7.1 High | Watermark RELOADED | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 1.3.5 Fixed in 1.4.0 |
CVE-2024-27195 |
Patchstack | |
| 7.1 High | BeePress | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 6.9.8 |
CVE-2024-27197 |
Patchstack | |
| 8.8 High | TerraClassifieds | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed |
≤ 2.0.3 |
CVE-2023-51474 |
Patchstack | |
| 7.1 High | Ultimate Reviews | Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed |
≤ 3.2.8 Fixed in 3.2.9 |
CVE-2024-25597 |
Patchstack | |
| 7.1 High | Action Network | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2024-25921 |
Patchstack | |
| 7.1 High | PayU India | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.8.8 Fixed in 3.8.9 |
CVE-2024-27193 |
Patchstack | |
| 7.1 High | postMash – custom post order | Cross-Site Scripting custom post order plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.0 |
CVE-2024-27196 |
Patchstack | |
| 7.1 High | Configure SMTP | Cross-Site Scripting WordPress Configure SMTP Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.1 |
CVE-2024-27192 |
Patchstack | |
| 7.1 High | GiveWP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.3.1 Fixed in 3.4.0 |
CVE-2024-27987 |
Patchstack | |
| 8.8 High | HUSKY – Products Filter for WooCommerce Professional | SQL Injection Products Filter for WooCommerce Professional <= 1.3.5.2 - Authenticated (Contributor+) SQL Injection |
≤ 1.3.5.2 |
CVE-2024-1795 |
Wordfence | |
| 7.1 High | Advanced Sermons | Cross-Site Scripting No login needed |
≤ 3.2 Fixed in 3.3 |
CVE-2024-27952 |
Patchstack | |
| 8.8 High | Tutor LMS – eLearning and online course solution | SQL Injection eLearning and online course solution <= 2.6.1 - Authenticated (Subscriber+) SQL Injection |
≤ 2.6.1 |
CVE-2024-1751 |
Wordfence | |
| 7.2 High | AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber | SQL Injection Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber <= 7.3.14 - Authenticated (Admin+) SQL Injection |
≤ 7.3.14 |
CVE-2024-1793 |
Wordfence | |
| 7.5 High | Product Carousel Slider & Grid Ultimate for WooCommerce | PHP Object Injection Authenticated(Contributor+) PHP Object Injection |
≤ 1.9.7 |
CVE-2024-1950 |
Wordfence | |
| 8.6 High | Hustle | Information Disclosure Sensitive Information Exposure via Exposed Hubspot API Keys No login needed |
≤ 7.8.3 |
CVE-2024-0368 |
Wordfence | |
| 7.2 High | WP Statistics | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 14.5 |
CVE-2024-2194 |
Wordfence | |
| 8.8 High | Brizy – Page Builder | Arbitrary File Upload Page Builder <= 2.4.40 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 2.4.40 |
CVE-2024-1311 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Broken Access Control Missing Authorization No login needed |
≤ 3.0.14 |
CVE-2024-0683 |
Wordfence | |
| 8.8 High | News Announcement Scroll | SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 9.0.0 |
CVE-2023-5663 |
Wordfence | |
| 7.5 High | Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | PHP Object Injection Logo Carousel, Logo Slider & Logo Grid <= 1.3.8 - Authenticated(Contributor+) PHP Object Injection |
≤ 1.3.8 |
CVE-2024-1951 |
Wordfence | |
| 8.8 High | Academy LMS – eLearning and online course solution | Privilege Escalation eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation |
≤ 1.9.19 |
CVE-2024-1505 |
Wordfence | |
| 8.8 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup |
≤ 1.6.7 |
CVE-2024-2006 |
Wordfence | |
| 8.8 High | Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | PHP Object Injection Make Your Blog Posts Accessible With Text to Speech Audio <= 3.6.4 - Authenticated (Contributor+) PHP Object Injection |
≤ 3.6.4 |
CVE-2024-1772 |
Wordfence | |
| 8.8 High | Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce | SQL Injection Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce <= 7.0.7 - Authenticated (Subscriber+) SQL Injection |
≤ 7.0.7 |
CVE-2024-1203 |
Wordfence | |
| 7.2 High | Calculated Fields Form Professional | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 5.1.56 |
CVE-2024-2020 |
Wordfence | |
| 8.1 High | WooCommerce Add to Cart Custom Redirect | Broken Access Control Authenticated(Contributor+) Missing Authorization to Limited Arbitrary Options Update |
≤ 1.2.13 |
CVE-2024-1862 |
Wordfence | |
| 7.2 High | Giveaways and Contests by RafflePress | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.12.5 |
CVE-2024-1935 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.