WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,751–8,800 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 176 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Path Traversal Directory Traversal to Local File Inclusion ≤ 1.12.12 CVE-2024-1358 Wordfence
7.4 High Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar ≤ 5.9.9 CVE-2024-1536 Wordfence
7.2 High Ultimate Member Plugin ultimate-member Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.8.3 CVE-2024-2123 Wordfence
7.5 High Post Grid Combo – 36+ Gutenberg Blocks Plugin post-grid Information Disclosure Information Exposure via get_posts API Endpoint No login needed ≤ 2.2.68 CVE-2023-7072 Wordfence
7.2 High weForms Plugin weforms Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Referer No login needed ≤ 1.6.21 CVE-2024-0386 Wordfence
7.3 High Bulgarisation for WooCommerce Plugin Cross-Site Request Forgery No login needed ≤ 3.0.14 CVE-2024-2395 Wordfence
7.2 High 404 Solution Plugin 404-solution SQL Injection Admin+ SQL Injection < 2.35.8 Fixed in 2.35.8 CVE-2024-1068 WPScan
8.8 High Elite Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.1.7 CVE-2024-1986 Wordfence
8.8 High Digits: WordPress Mobile Number Signup and Login Plugin Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed 8.4.1 CVE-2024-0203 Wordfence
8.8 High PDF Invoices and Packing Slips For WooCommerce Plugin pdf-invoices-and-packing-slips-for-woocommerce PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.3.7 CVE-2024-1773 Wordfence
7.5 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload No login needed ≤ 2.8.7 CVE-2024-1169 Wordfence
8.2 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion No login needed ≤ 2.8.7 CVE-2024-1170 Wordfence
8.8 High Restaurant Reservations Plugin nd-restaurant-reservations Path Traversal Directory Traversal to Authenticated (Contributor+) Local File Inclusion ≤ 1.9 CVE-2024-1382 Wordfence
8.8 High Vimeography: Vimeo Video Gallery Plugin vimeography PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.3.2 CVE-2024-0825 Wordfence
8.8 High Auto Refresh Single Page Plugin auto-refresh-single-page PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.1 CVE-2024-1731 Wordfence
8.8 High Slider Responsive Slideshow – Image slider, Gallery slideshow Plugin PHP Object Injection Image slider, Gallery slideshow <= 1.3.8 - Authenticated (Contributor+) PHP Object Injection ≤ 1.3.8 CVE-2024-1859 Wordfence
7.1 High GD Rating System Plugin gd-rating-system Cross-Site Scripting WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.5 Fixed in 3.5.1 CVE-2024-25093 Patchstack
7.1 High WP Activity Log Plugin wp-security-audit-log Cross-Site Scripting WordPress WP Activity Log Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2023-50905 Patchstack
7.1 High Ajax Search Lite Plugin ajax-search-lite Cross-Site Scripting WordPress Ajax Search Lite Plugin <= 4.11.4 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.11.4 Fixed in 4.11.5 CVE-2024-21752 Patchstack
7.1 High Adsmonetizer Plugin adsensei-b30 Cross-Site Scripting WordPress Adsmonetizer Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-1437 Patchstack
8.8 High Avada | Website Builder For WordPress & WooCommerce Theme Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 7.11.4 CVE-2024-1468 Wordfence
8.5 High SP Project & Document Manager Plugin sp-client-document-manager SQL Injection WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection ≤ 4.69 Fixed in 4.70 CVE-2024-24868 Patchstack
7.6 High Malware Scanner Plugin miniorange-malware-protection SQL Injection WordPress Malware Scanner Plugin <= 4.7.2 is vulnerable to SQL Injection ≤ 4.7.2 CVE-2024-25902 Patchstack
8.8 High Conversios Plugin enhanced-e-commerce-for-woocommerce-store SQL Injection Authenticated (Subscriber+) SQL Injection via ee_syncProductCategory ≤ 7.0.7 CVE-2024-0786 Wordfence
7.5 High JetBackup Plugin backup Information Disclosure Directory Listing Exposing Backups No login needed < 2.0.9.9 Fixed in 2.0.9.9 CVE-2023-7165 WPScan
7.5 High JobSearch WP Job Board Plugin Authentication Bypass No login needed < 2.3.4 Fixed in 2.3.4 CVE-2023-6584 WPScan
7.5 High JobSearch WP Job Board Plugin Arbitrary File Upload Arbitrary File Upload to RCE No login needed < 2.3.4 Fixed in 2.3.4 CVE-2023-6585 WPScan
7.2 High Icons Font Loader Plugin icons-font-loader Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-24714 Patchstack
8.8 High Addon Library Plugin addon-library Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.3.76 CVE-2024-1710 Wordfence
7.1 High Sitepact Plugin sitepact-klaviyo-contact-form-7 SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed ≤ 1.0.5 Fixed in 3.0.0 CVE-2024-25928 Patchstack
7.2 High Admin side data storage for Contact Form 7 Plugin admin-side-data-storage-for-contact-form-7 SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.1.1 CVE-2024-1776 Wordfence
7.1 High PowerPack Pro for Elementor Plugin Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed < 2.10.8 Fixed in 2.10.8 CVE-2024-24843 Patchstack
8.8 High RSS Aggregator by Feedzy Plugin feedzy-rss-feeds SQL Injection Authenticated(Contributor+) SQL Injection ≤ 4.4.2 CVE-2024-1317 Wordfence
7.3 High Oliver POS – A WooCommerce Point of Sale (POS) Plugin oliver-pos Broken Access Control A WooCommerce Point of Sale (POS) <= 2.4.2.1 - Missing Authorization No login needed ≤ 2.4.2.0 CVE-2024-0702 Wordfence
8.8 High WP Recipe Maker Plugin wp-recipe-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) SQL Injecton ≤ 9.1.2 CVE-2024-1206 Wordfence
7.6 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation ≤ 2.3.41 CVE-2024-1217 Wordfence
7.5 High popup-builder Plugin Server-Side Request Forgery Admin+ SSRF & File Read No login needed < 4.2.6 Fixed in 4.2.6 CVE-2023-6294 WPScan
7.2 High Smart Manager Plugin smart-manager-for-wp-e-commerce SQL Injection Admin+ SQL Injection < 8.28.0 Fixed in 8.28.0 CVE-2024-0566 WPScan
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
8.7 High PropertyHive Plugin propertyhive PHP Object Injection WordPress PropertyHive Plugin <= 2.0.5 is vulnerable to PHP Object Injection No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2024-23513 Patchstack
8.2 High Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – Plugin mage-eventpress PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection ≤ 4.1.1 Fixed in 4.1.2 CVE-2024-24796 Patchstack
7.5 High Brooklyn | Creative Multi-Purpose Responsive Theme PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection ≤ 4.9.7.6 CVE-2024-24926 Patchstack
7.1 High Brooklyn | Creative Multi-Purpose Responsive Theme Cross-Site Scripting WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.9.7.6 CVE-2024-24927 Patchstack
7.1 High VK Poster Group Plugin vk-poster-group Cross-Site Scripting WordPress VK Poster Group Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-24932 Patchstack
7.1 High Honeypot for WP Comment Plugin honeypot-for-wp-comment Cross-Site Scripting WordPress Honeypot for WP Comment Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2024-24933 Patchstack
7.1 High Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51488 Patchstack
8.8 High Awesome Support – WordPress HelpDesk & Support Plugin awesome-support SQL Injection WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection ≤ 6.1.7 CVE-2024-0594 Wordfence
7.5 High Backuply - Backup, Restore, Migrate and Clone Plugin backuply Denial of Service Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service No login needed ≤ 1.2.6 CVE-2024-0842 Wordfence
7.1 High Wonder Slider Lite Plugin wonderplugin-slider-lite Cross-Site Scripting WordPress Wonder Slider Lite Plugin <= 13.9 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 13.9 Fixed in 14.0 CVE-2024-24877 Patchstack
7.1 High Portugal CTT Tracking for WooCommerce Plugin portugal-ctt-tracking-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2024-24878 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only