WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,851–8,900 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 178 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.0 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Arbitrary File Upload WordPress Order Export & Order Import for WooCommerce Plugin <= 2.4.3 is vulnerable to Arbitrary File Upload ≤ 2.4.3 Fixed in 2.4.4 CVE-2024-22135 Patchstack
8.0 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload WordPress Product Import Export for WooCommerce Plugin <= 2.3.7 is vulnerable to Arbitrary File Upload ≤ 2.3.7 Fixed in 2.3.8 CVE-2024-22152 Patchstack
8.7 High Asgaros Forum Plugin asgaros-forum PHP Object Injection WordPress Asgaros Forum Plugin <= 2.7.2 is vulnerable to PHP Object Injection No login needed ≤ 2.7.2 Fixed in 2.8.0 CVE-2024-22284 Patchstack
8.7 High ChatBot with AI Plugin chatbot PHP Object Injection WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2024-22309 Patchstack
7.2 High WP All Import Plugin wp-all-import Arbitrary File Upload Admin+ Arbitrary File Upload to RCE < 3.7.3 Fixed in 3.7.3 CVE-2023-7082 WPScan
7.2 High WPForms Pro Plugin Cross-Site Scripting The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient… No login needed ≤ 1.8.5.3 CVE-2023-7063 Wordfence
8.2 High Montonio for WooCommerce Plugin montonio-for-woocommerce Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability affecting multiple WordPress plugins No login needed ≤ 6.0.1, ≤ 1.5.8, ≤ 4.6.6, … Fixed in 6.0.2 CVE-2022-40700 Patchstack
7.1 High 3D Tag Cloud Plugin cardoza-3d-tag-cloud Cross-Site Request Forgery WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.8 CVE-2022-41990 Patchstack
8.8 High Track The Click Plugin track-the-click SQL Injection Author+ Time-Based Blind SQL Injection < 0.3.12 Fixed in 0.3.12 CVE-2023-5041 WPScan
7.2 High Burst Statistics Really Simple Plugins Plugin burst-statistics SQL Injection Authenticated (Editor+) SQL Injection ≤ 1.5.3 CVE-2024-0405 Wordfence
8.8 High ArtPlacer Widget Plugin artplacer-widget SQL Injection Editor+ SQLi < 2.20.7 Fixed in 2.20.7 CVE-2023-6373 WPScan
7.5 High Royal Elementor Addons and Templates Plugin Broken Access Control Unauthenticated Arbitrary Post Read No login needed < 1.3.81 Fixed in 1.3.81 CVE-2023-5922 WPScan
7.5 High All in One B2B for WooCommerce Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.3 CVE-2023-4703 WPScan
7.2 High Newsletter Lite Plugin Remote Code Execution Admin+ Command Injection < 4.9.3 Fixed in 4.9.3 CVE-2023-4797 WPScan
8.8 High My Account Page Editor Plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload < 1.3.2 Fixed in 1.3.2 CVE-2023-4536 WPScan
7.4 High UserPlus Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 2.0 CVE-2023-0824 WPScan
7.5 High Formidable Forms Plugin formidable PHP Object Injection Unauthenticated PHP Object Injection No login needed < 6.2 Fixed in 6.2 CVE-2023-1405 WPScan
7.2 High Contact Form by WD Plugin SQL Injection Admin+ SQLi ≤ 1.13.23 CVE-2023-2655 WPScan
7.8 High Contact Form Entries Plugin Content Injection CSV Injection No login needed < 1.3.0 Fixed in 1.3.0 CVE-2022-3604 WPScan
8.1 High 3DPrint Plugin Arbitrary File Deletion Arbitrary File and Directory Deletion via CSRF No login needed < 3.5.6.9 Fixed in 3.5.6.9 CVE-2022-3899 WPScan
7.2 High Form Vibes Plugin form-vibes SQL Injection Admin+ SQLi < 1.4.6 Fixed in 1.4.6 CVE-2022-3764 WPScan
7.2 High Theme-Demo-Importer Plugin Arbitrary File Upload Admin+ Arbitrary File Upload < 1.1.1 Fixed in 1.1.1 CVE-2022-1538 WPScan
8.8 High WP Fastest Cache Plugin wp-fastest-cache SQL Injection Subscriber+ SQL Injection < 0.9.5 Fixed in 0.9.5 CVE-2021-24869 WPScan
7.2 High WP Editor Plugin wp-editor SQL Injection Authenticated SQL injection < 1.2.7 Fixed in 1.2.7 CVE-2021-24151 WPScan
8.8 High WooCommerce Currency Switcher Plugin Local File Inclusion Authenticated (Low Privilege) Local File Inclusion < 1.3.7 Fixed in 1.3.7 CVE-2021-24566 WPScan
8.1 High DeMomentSomTres WordPress Export Posts With Images Plugin Broken Access Control Subscriber+ unauthorized data export ≤ 20220825 CVE-2023-5905 WPScan
8.8 High JSM file_get_contents() Shortcode Plugin wp-file-get-contents Server-Side Request Forgery Contributor+ SSRF < 2.7.1 Fixed in 2.7.1 CVE-2023-6991 WPScan
7.2 High Post SMTP Plugin post-smtp SQL Injection Admin+ SQL Injection < 2.8.7 Fixed in 2.8.7 CVE-2023-6620 WPScan
7.5 High EazyDocs Plugin eazydocs Cross-Site Request Forgery Unauthenticated Arbitrary Posts Deletion and Document Management No login needed < 2.3.6 Fixed in 2.3.6 CVE-2023-6029 WPScan
7.1 High Profile Builder Pro Plugin Cross-Site Scripting WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22142 Patchstack
8.7 High BackWPup Plugin backwpup Path Traversal Authenticated (Administrator+) Directory Traversal ≤ 4.0.1 CVE-2023-5504 Wordfence
7.3 High Hostinger Plugin Broken Access Control Missing Authorization to Maintenance Mode Activation No login needed ≤ 1.9.7 CVE-2023-6751 Wordfence
8.1 High Piotnet Forms Plugin piotnetforms Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.28 CVE-2023-6220 Wordfence
7.2 High Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload ≤ 7.6.2 CVE-2023-6636 Wordfence
8.8 High Slick Social Share Buttons Plugin slick-social-share-buttons Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 2.4.11 CVE-2023-6878 Wordfence
7.2 High ARForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url No login needed ≤ 1.5.8 CVE-2023-6828 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload ≤ 2.4.8 CVE-2023-6558 Wordfence
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 5.38.9 CVE-2023-6979 Wordfence
8.1 High LearnPress Plugin learnpress Remote Code Execution Command Injection No login needed ≤ 4.2.5.7 CVE-2023-6634 Wordfence
7.5 High Backup Migration Plugin backup-backup Information Disclosure Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure No login needed ≤ 1.3.6 CVE-2023-6266 Wordfence
8.8 High WP Register Profile With Shortcode Plugin wp-register-profile-with-shortcode Cross-Site Request Forgery Cross-Site Request Forgery to User Password Reset No login needed ≤ 3.5.9 CVE-2023-5448 Wordfence
7.6 High Events Shortcodes For The Events Calendar Plugin template-events-calendar SQL Injection WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-52142 Patchstack
7.1 High CPT Bootstrap Carousel Plugin cpt-bootstrap-carousel Cross-Site Scripting WordPress CPT Bootstrap Carousel Plugin <= 1.12 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2023-52196 Patchstack
7.6 High pTypeConverter Plugin ptypeconverter SQL Injection WordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL Injection ≤ 0.2.8.1 CVE-2023-52201 Patchstack
8.5 High Randomize Plugin randomize SQL Injection WordPress Randomize Plugin <= 1.4.3 is vulnerable to SQL Injection ≤ 1.4.3 CVE-2023-52204 Patchstack
7.7 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection WordPress Page Builder: Live Composer Plugin <= 1.5.25 is vulnerable to PHP Object Injection ≤ 1.5.25 CVE-2023-52206 Patchstack
7.1 High Rate Star Review – AJAX Reviews for Content, with Star Ratings Plugin rate-star-review Cross-Site Scripting WordPress Rate Star Review Plugin <= 1.5.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52213 Patchstack
8.8 High WP Blogs' Planetarium Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0 CVE-2023-6532 WPScan
7.5 High Coupon Referral Program Plugin Information Disclosure WordPress Coupon Referral Program Plugin <= 1.7.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2023-52190 Patchstack
8.8 High CommentTweets Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.6 CVE-2023-6845 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only