WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 851–900 of 985 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Responsive Flickr Gallery | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3.1 |
CVE-2024-51630 |
Patchstack | |
| 7.1 High | Featured Posts Scroll | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.25 |
CVE-2024-51647 |
Patchstack | |
| 7.1 High | WPMobile.App | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 11.48 Fixed in 11.49 |
CVE-2024-43933 |
Patchstack | |
| 7.1 High | Google Docs RSVP | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 2.0.1 |
CVE-2024-49672 |
Patchstack | |
| 7.1 High | GoogleDrive folder list | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 2.2.2 |
CVE-2024-49335 |
Patchstack | |
| 7.1 High | AVChat Video Chat | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.2 |
CVE-2024-49605 |
Patchstack | |
| 7.1 High | Endless Posts Navigation | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.2.7 Fixed in 2.2.8 |
CVE-2024-49629 |
Patchstack | |
| 8.2 High | SafetyForms | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 1.0.0 |
CVE-2024-49615 |
Patchstack | |
| 8.2 High | Back Link Tracker | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 1.0.0 |
CVE-2024-49617 |
Patchstack | |
| 7.1 High | EU/UK VAT Manager for WooCommerce | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 2.12.14 Fixed in 3.0.0 |
CVE-2024-44061 |
Patchstack | |
| 8.2 High | APA Register Newsletter Form | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 1.0.0 |
CVE-2024-49621 |
Patchstack | |
| 8.2 High | Apa Banner Slider | Cross-Site Request Forgery CSRF to SQL Injection No login needed |
≤ 1.0.0 |
CVE-2024-49622 |
Patchstack | |
| 7.1 High | Cookie Scanner | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1 |
CVE-2024-49220 |
Patchstack | |
| 7.1 High | cSlider | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.4.2 |
CVE-2024-49221 |
Patchstack | |
| 7.1 High | CJ Change Howdy | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 3.3.1 |
CVE-2024-49223 |
Patchstack | |
| 7.1 High | Better Author Bio | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 2.7.10.11 |
CVE-2024-49229 |
Patchstack | |
| 7.1 High | Ahmeti Wp Timeline | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 5.1 |
CVE-2024-49237 |
Patchstack | |
| 7.6 High | Surfer | SQL Injection |
≤ 1.5.0.502 Fixed in 1.6.0.523 |
CVE-2024-49299 |
Patchstack | |
| 7.1 High | Wsify Widget | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2024-48048 |
Patchstack | |
| 7.1 High | NiceJob | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 3.6.5 Fixed in 3.6.5 |
CVE-2024-44028 |
Patchstack | |
| 7.1 High | Copyscape Premium | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.3.9 Fixed in 1.4.0 |
CVE-2024-47644 |
Patchstack | |
| 7.5 High | Justified Image Grid | Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed |
≤ 4.6.1 Fixed in 4.7 |
CVE-2024-43989 |
Patchstack | |
| 8.1 High | Favicon Generator | Arbitrary File Upload Arbitrary File Upload via CSRF |
< 2.1 Fixed in 2.1 |
CVE-2024-7863 |
WPScan | |
| 7.1 High | Fonts | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed |
≤ 3.7.7 Fixed in 3.7.8 |
CVE-2024-43301 |
Patchstack | |
| 7.1 High | MyBookTable Bookstore | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 3.3.9 Fixed in 3.5.0 |
CVE-2024-43255 |
Patchstack | |
| 7.1 High | Contact Form 7 Summary and Print | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 1.2.5 Fixed in 1.2.6 |
CVE-2024-38724 |
Patchstack | |
| 7.1 High | WP GoToWebinar | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 15.7 Fixed in 15.8 |
CVE-2024-38776 |
Patchstack | |
| 8.8 High | WordPress Menu Plugin — Superfly Responsive Menu | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed |
≤ 5.0.29 |
CVE-2024-3238 |
Wordfence | |
| 7.1 High | MakeStories (for Google Web Stories) | Path Traversal Arbitrary File Download and SSRF |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2024-38746 |
Patchstack | |
| 8.1 High | WooCommerce Customers Manager | Cross-Site Request Forgery Bulk Action via CSRF No login needed |
< 30.1 Fixed in 30.1 |
CVE-2024-3983 |
WPScan | |
| 7.2 High | BerqWP | Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed |
≤ 1.7.5 Fixed in 1.7.6 |
CVE-2024-37942 |
Patchstack | |
| 7.1 High | Seraphinite Post .DOCX Source | Server-Side Request Forgery No login needed |
≤ 2.16.9 Fixed in 2.16.10 |
CVE-2024-38728 |
Patchstack | |
| 8.8 High | pz-frontend-manager | Cross-Site Request Forgery CSRF change user profile picture No login needed |
< 1.0.6 Fixed in 1.0.6 |
CVE-2024-6244 |
WPScan | |
| 7.1 High | ARForms Form Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.7 Fixed in 1.6.8 |
CVE-2024-37920 |
Patchstack | |
| 7.5 High | ArtPlacer Widget | Cross-Site Scripting Stored XSS via CSRF |
< 2.21.2 Fixed in 2.21.2 |
CVE-2023-7269 |
WPScan | |
| 8.8 High | WP eStore | Cross-Site Request Forgery Coupon Deletion via CSRF No login needed |
< 8.5.5 Fixed in 8.5.5 |
CVE-2024-6075 |
WPScan | |
| 7.1 High | WP Affiliate Platform | Cross-Site Request Forgery Profile Update via CSRF No login needed |
< 6.5.1 Fixed in 6.5.1 |
CVE-2024-5287 |
WPScan | |
| 8.1 High | CM Email Registration Blacklist and Whitelist | Cross-Site Request Forgery Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelist No login needed |
< 1.4.9 Fixed in 1.4.9 |
CVE-2024-5167 |
WPScan | |
| 8.8 High | WP eMember | Cross-Site Request Forgery Bulk Delete via CSRF No login needed |
< 10.6.6 Fixed in 10.6.6 |
CVE-2024-5076 |
WPScan | |
| 8.8 High | SULly | Cross-Site Request Forgery Plugin Reset via CSRF No login needed |
< 4.3.1 Fixed in 4.3.1 |
CVE-2024-5034 |
WPScan | |
| 7.2 High | UserFeedback Lite | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Name Parameter No login needed |
≤ 1.0.15 |
CVE-2024-5902 |
Wordfence | |
| 7.4 High | Seraphinite Accelerator (Full, premium) | Cross-Site Request Forgery CSRF Leading to Arbitrary File Deletion No login needed |
≤ 2.21.13 Fixed in 2.21.13.1 |
CVE-2024-37940 |
Patchstack | |
| 7.1 High | Comment Reply Email | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3 Fixed in 1.5 |
CVE-2024-35773 |
Patchstack | |
| 7.1 High | AliNext | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 3.4.6 Fixed in 3.4.7 |
CVE-2024-37213 |
Patchstack | |
| 8.8 High | ContentLock | Cross-Site Request Forgery Groups/Emails Deletion via CSRF No login needed |
≤ 1.0.3 |
CVE-2024-6024 |
WPScan | |
| 8.8 High | ContentLock | Cross-Site Request Forgery Email Adding via CSRF No login needed |
≤ 1.0.3 |
CVE-2024-6023 |
WPScan | |
| 8.8 High | ContentLock | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 1.0.3 |
CVE-2024-6022 |
WPScan | |
| 7.2 High | Foxiz | Server-Side Request Forgery No login needed |
≤ 2.3.5 Fixed in 2.3.6 |
CVE-2024-37260 |
Patchstack | |
| 8.8 High | WPQA | Cross-Site Request Forgery Arbitrary Category and Tag Follow/Unfollow via CSRF No login needed |
< 6.1.1 Fixed in 6.1.1 |
CVE-2024-2376 |
WPScan | |
| 8.8 High | Sitetweet | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 0.2 |
CVE-2024-5767 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.