WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 851–900 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 18 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.25 CVE-2024-51647 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 11.48 Fixed in 11.49 CVE-2024-43933 Patchstack
7.1 High Google Docs RSVP Plugin google-docs-rsvp-guestlist Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-49672 Patchstack
7.1 High GoogleDrive folder list Plugin googledrive-folder-list Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49335 Patchstack
7.1 High AVChat Video Chat Plugin avchat-3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2 CVE-2024-49605 Patchstack
7.1 High Endless Posts Navigation Plugin endless-posts-navigation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-49629 Patchstack
8.2 High SafetyForms Plugin safetymails-forms Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49615 Patchstack
8.2 High Back Link Tracker Plugin back-link-tracker Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49617 Patchstack
7.1 High EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.12.14 Fixed in 3.0.0 CVE-2024-44061 Patchstack
8.2 High APA Register Newsletter Form Plugin apa-register-newsletter-form Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49621 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
7.1 High Cookie Scanner Plugin cookie-scanner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-49220 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.1 High CJ Change Howdy Plugin cj-change-howdy Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.1 CVE-2024-49223 Patchstack
7.1 High Better Author Bio Plugin better-author-bio Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.7.10.11 CVE-2024-49229 Patchstack
7.1 High Ahmeti Wp Timeline Plugin ahmeti-wp-timeline Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.1 CVE-2024-49237 Patchstack
7.6 High Surfer Plugin surferseo SQL Injection ≤ 1.5.0.502 Fixed in 1.6.0.523 CVE-2024-49299 Patchstack
7.1 High Wsify Widget Plugin wsify-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-48048 Patchstack
7.1 High NiceJob Plugin nicejob Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.6.5 Fixed in 3.6.5 CVE-2024-44028 Patchstack
7.1 High Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-47644 Patchstack
7.5 High Justified Image Grid Plugin justified-image-grid Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 4.6.1 Fixed in 4.7 CVE-2024-43989 Patchstack
8.1 High Favicon Generator Plugin Arbitrary File Upload Arbitrary File Upload via CSRF < 2.1 Fixed in 2.1 CVE-2024-7863 WPScan
7.1 High Fonts Plugin olympus-google-fonts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43301 Patchstack
7.1 High MyBookTable Bookstore Plugin mybooktable Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.3.9 Fixed in 3.5.0 CVE-2024-43255 Patchstack
7.1 High Contact Form 7 Summary and Print Plugin cf7-summary-and-print Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-38724 Patchstack
7.1 High WP GoToWebinar Plugin wp-gotowebinar Cross-Site Request Forgery CSRF to XSS No login needed ≤ 15.7 Fixed in 15.8 CVE-2024-38776 Patchstack
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
7.1 High MakeStories (for Google Web Stories) Plugin makestories-helper Path Traversal Arbitrary File Download and SSRF ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-38746 Patchstack
8.1 High WooCommerce Customers Manager Plugin Cross-Site Request Forgery Bulk Action via CSRF No login needed < 30.1 Fixed in 30.1 CVE-2024-3983 WPScan
7.2 High BerqWP Plugin searchpro Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-37942 Patchstack
7.1 High Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Server-Side Request Forgery No login needed ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38728 Patchstack
8.8 High pz-frontend-manager Plugin Cross-Site Request Forgery CSRF change user profile picture No login needed < 1.0.6 Fixed in 1.0.6 CVE-2024-6244 WPScan
7.1 High ARForms Form Builder Plugin arforms-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-37920 Patchstack
7.5 High ArtPlacer Widget Plugin artplacer-widget Cross-Site Scripting Stored XSS via CSRF < 2.21.2 Fixed in 2.21.2 CVE-2023-7269 WPScan
8.8 High WP eStore Plugin Cross-Site Request Forgery Coupon Deletion via CSRF No login needed < 8.5.5 Fixed in 8.5.5 CVE-2024-6075 WPScan
7.1 High WP Affiliate Platform Plugin Cross-Site Request Forgery Profile Update via CSRF No login needed < 6.5.1 Fixed in 6.5.1 CVE-2024-5287 WPScan
8.1 High CM Email Registration Blacklist and Whitelist Plugin Cross-Site Request Forgery Add/Delete Emails via CSRF Add and delete any item from blacklist/whitelist No login needed < 1.4.9 Fixed in 1.4.9 CVE-2024-5167 WPScan
8.8 High WP eMember Plugin Cross-Site Request Forgery Bulk Delete via CSRF No login needed < 10.6.6 Fixed in 10.6.6 CVE-2024-5076 WPScan
8.8 High SULly Plugin sully Cross-Site Request Forgery Plugin Reset via CSRF No login needed < 4.3.1 Fixed in 4.3.1 CVE-2024-5034 WPScan
7.2 High UserFeedback Lite Plugin userfeedback-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Name Parameter No login needed ≤ 1.0.15 CVE-2024-5902 Wordfence
7.4 High Seraphinite Accelerator (Full, premium) Plugin Cross-Site Request Forgery CSRF Leading to Arbitrary File Deletion No login needed ≤ 2.21.13 Fixed in 2.21.13.1 CVE-2024-37940 Patchstack
7.1 High Comment Reply Email Plugin comment-reply-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 Fixed in 1.5 CVE-2024-35773 Patchstack
7.1 High AliNext Plugin ali2woo-lite Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-37213 Patchstack
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Groups/Emails Deletion via CSRF No login needed ≤ 1.0.3 CVE-2024-6024 WPScan
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Email Adding via CSRF No login needed ≤ 1.0.3 CVE-2024-6023 WPScan
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0.3 CVE-2024-6022 WPScan
7.2 High Foxiz Theme Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-37260 Patchstack
8.8 High WPQA Plugin Cross-Site Request Forgery Arbitrary Category and Tag Follow/Unfollow via CSRF No login needed < 6.1.1 Fixed in 6.1.1 CVE-2024-2376 WPScan
8.8 High Sitetweet Plugin sitetweet-tweets-user-behaviors-on-your-site-on-twitter Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.2 CVE-2024-5767 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only