WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 8,751–8,800 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | Elementor Addon Elements | Path Traversal Directory Traversal to Local File Inclusion |
≤ 1.12.12 |
CVE-2024-1358 |
Wordfence | |
| 7.4 High | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar |
≤ 5.9.9 |
CVE-2024-1536 |
Wordfence | |
| 7.2 High | Ultimate Member | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.8.3 |
CVE-2024-2123 |
Wordfence | |
| 7.5 High | Post Grid Combo – 36+ Gutenberg Blocks | Information Disclosure Information Exposure via get_posts API Endpoint No login needed |
≤ 2.2.68 |
CVE-2023-7072 |
Wordfence | |
| 7.2 High | weForms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Referer No login needed |
≤ 1.6.21 |
CVE-2024-0386 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.0.14 |
CVE-2024-2395 |
Wordfence | |
| 7.2 High | 404 Solution | SQL Injection Admin+ SQL Injection |
< 2.35.8 Fixed in 2.35.8 |
CVE-2024-1068 |
WPScan | |
| 8.8 High | Elite Booster for WooCommerce | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 7.1.7 |
CVE-2024-1986 |
Wordfence | |
| 8.8 High | Digits: WordPress Mobile Number Signup and Login | Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed |
8.4.1 |
CVE-2024-0203 |
Wordfence | |
| 8.8 High | PDF Invoices and Packing Slips For WooCommerce | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.3.7 |
CVE-2024-1773 |
Wordfence | |
| 7.5 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload No login needed |
≤ 2.8.7 |
CVE-2024-1169 |
Wordfence | |
| 8.2 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion No login needed |
≤ 2.8.7 |
CVE-2024-1170 |
Wordfence | |
| 8.8 High | Restaurant Reservations | Path Traversal Directory Traversal to Authenticated (Contributor+) Local File Inclusion |
≤ 1.9 |
CVE-2024-1382 |
Wordfence | |
| 8.8 High | Vimeography: Vimeo Video Gallery | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 2.3.2 |
CVE-2024-0825 |
Wordfence | |
| 8.8 High | Auto Refresh Single Page | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.1 |
CVE-2024-1731 |
Wordfence | |
| 8.8 High | Slider Responsive Slideshow – Image slider, Gallery slideshow | PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection |
≤ 1.3.8 |
CVE-2024-1859 |
Wordfence | |
| 7.1 High | GD Rating System | Cross-Site Scripting WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.5 Fixed in 3.5.1 |
CVE-2024-25093 |
Patchstack | |
| 7.1 High | WP Activity Log | Cross-Site Scripting WordPress WP Activity Log Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.6.1 Fixed in 4.6.2 |
CVE-2023-50905 |
Patchstack | |
| 7.1 High | Ajax Search Lite | Cross-Site Scripting WordPress Ajax Search Lite Plugin <= 4.11.4 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.11.4 Fixed in 4.11.5 |
CVE-2024-21752 |
Patchstack | |
| 7.1 High | Adsmonetizer | Cross-Site Scripting WordPress Adsmonetizer Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2024-1437 |
Patchstack | |
| 8.8 High | Avada | Website Builder For WordPress & WooCommerce | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.11.4 |
CVE-2024-1468 |
Wordfence | |
| 8.5 High | SP Project & Document Manager | SQL Injection WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection |
≤ 4.69 Fixed in 4.70 |
CVE-2024-24868 |
Patchstack | |
| 7.6 High | Malware Scanner | SQL Injection WordPress Malware Scanner Plugin <= 4.7.2 is vulnerable to SQL Injection |
≤ 4.7.2 |
CVE-2024-25902 |
Patchstack | |
| 8.8 High | Conversios | SQL Injection Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory |
≤ 7.0.7 |
CVE-2024-0786 |
Wordfence | |
| 7.5 High | JetBackup | Information Disclosure Directory Listing Exposing Backups No login needed |
< 2.0.9.9 Fixed in 2.0.9.9 |
CVE-2023-7165 |
WPScan | |
| 7.5 High | JobSearch WP Job Board | Authentication Bypass No login needed |
< 2.3.4 Fixed in 2.3.4 |
CVE-2023-6584 |
WPScan | |
| 7.5 High | JobSearch WP Job Board | Arbitrary File Upload Arbitrary File Upload to RCE No login needed |
< 2.3.4 Fixed in 2.3.4 |
CVE-2023-6585 |
WPScan | |
| 7.2 High | Icons Font Loader | Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2024-24714 |
Patchstack | |
| 8.8 High | Addon Library | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload |
≤ 1.3.76 |
CVE-2024-1710 |
Wordfence | |
| 7.1 High | Sitepact | SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed |
≤ 1.0.5 Fixed in 3.0.0 |
CVE-2024-25928 |
Patchstack | |
| 7.2 High | Admin side data storage for Contact Form 7 | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.1.1 |
CVE-2024-1776 |
Wordfence | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 8.8 High | RSS Aggregator by Feedzy | SQL Injection Authenticated(Contributor+) SQL Injection |
≤ 4.4.2 |
CVE-2024-1317 |
Wordfence | |
| 7.3 High | Oliver POS – A WooCommerce Point of Sale (POS) | Broken Access Control A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization No login needed |
≤ 2.4.2.0 |
CVE-2024-0702 |
Wordfence | |
| 8.8 High | WP Recipe Maker | Broken Access Control Missing Authorization to Authenticated (Subscriber+) SQL Injecton |
≤ 9.1.2 |
CVE-2024-1206 |
Wordfence | |
| 7.6 High | Contact Form builder with drag & drop for WordPress – Kali Forms | Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation |
≤ 2.3.41 |
CVE-2024-1217 |
Wordfence | |
| 7.5 High | popup-builder | Server-Side Request Forgery Admin+ SSRF & File Read No login needed |
< 4.2.6 Fixed in 4.2.6 |
CVE-2023-6294 |
WPScan | |
| 7.2 High | Smart Manager | SQL Injection Admin+ SQL Injection |
< 8.28.0 Fixed in 8.28.0 |
CVE-2024-0566 |
WPScan | |
| 8.7 High | ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2024-23512 |
Patchstack | |
| 8.7 High | PropertyHive | PHP Object Injection WordPress PropertyHive Plugin <= 2.0.5 is vulnerable to PHP Object Injection No login needed |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2024-23513 |
Patchstack | |
| 8.2 High | Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – | PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection |
≤ 4.1.1 Fixed in 4.1.2 |
CVE-2024-24796 |
Patchstack | |
| 7.5 High | Brooklyn | Creative Multi-Purpose Responsive | PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection |
≤ 4.9.7.6 |
CVE-2024-24926 |
Patchstack | |
| 7.1 High | Brooklyn | Creative Multi-Purpose Responsive | Cross-Site Scripting WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.9.7.6 |
CVE-2024-24927 |
Patchstack | |
| 7.1 High | VK Poster Group | Cross-Site Scripting WordPress VK Poster Group Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 2.0.3 |
CVE-2024-24932 |
Patchstack | |
| 7.1 High | Honeypot for WP Comment | Cross-Site Scripting WordPress Honeypot for WP Comment Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 2.2.3 |
CVE-2024-24933 |
Patchstack | |
| 7.1 High | Crowdsignal Dashboard – Polls, Surveys & more | Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.0.11 Fixed in 3.1.0 |
CVE-2023-51488 |
Patchstack | |
| 8.8 High | Awesome Support – WordPress HelpDesk & Support | SQL Injection WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection |
≤ 6.1.7 |
CVE-2024-0594 |
Wordfence | |
| 7.5 High | Backuply - Backup, Restore, Migrate and Clone | Denial of Service Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service No login needed |
≤ 1.2.6 |
CVE-2024-0842 |
Wordfence | |
| 7.1 High | Wonder Slider Lite | Cross-Site Scripting WordPress Wonder Slider Lite Plugin <= 13.9 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 13.9 Fixed in 14.0 |
CVE-2024-24877 |
Patchstack | |
| 7.1 High | Portugal CTT Tracking for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1 Fixed in 2.2 |
CVE-2024-24878 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.