WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 901–950 of 985 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.6 High | Muslim Prayer Time BD | Cross-Site Request Forgery Settings Reset via CSRF No login needed |
≤ 2.4 |
CVE-2024-4758 |
WPScan | |
| 8.1 High | Logo Manager For Enamad | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 0.7.0 |
CVE-2024-4757 |
WPScan | |
| 8.3 High | Ali2Woo Lite | Cross-Site Request Forgery CSRF to PHP Object Injection No login needed |
≤ 3.3.5 |
CVE-2024-37212 |
Patchstack | |
| 7.7 High | ARForms | Arbitrary File Deletion Subscriber+ Arbitrary File Deletion |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32703 |
Patchstack | |
| 7.1 High | ARForms | Broken Access Control Subscriber+ Arbitrary WordPress Options Removal |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32704 |
Patchstack | |
| 7.1 High | ARForms | Broken Access Control Subscriber+ Arbitrary Plugin Activation/Deactivation |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32705 |
Patchstack | |
| 7.5 High | Migration Backup Restore | Server-Side Request Forgery Admin+ SSRF No login needed |
< 3.5.0 Fixed in 3.5.0 |
CVE-2024-4469 |
WPScan | |
| 8.8 High | KKProgressbar2 Free | Cross-Site Request Forgery Progress Bar Deletion via CSRF No login needed |
≤ 1.1.4.2 |
CVE-2024-4535 |
WPScan | |
| 7.1 High | Business Card | Cross-Site Request Forgery Card Edit via CSRF No login needed |
≤ 1.0.0 |
CVE-2024-4531 |
WPScan | |
| 8.6 High | BuddyForms | Path Traversal WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF No login needed |
≤ 2.8.8 Fixed in 2.8.9 |
CVE-2024-32830 |
Patchstack | |
| 8.8 High | Automatic | Cross-Site Request Forgery CSRF to Privilege Escalation No login needed |
≤ 3.92.0 Fixed in 3.92.1 |
CVE-2024-27955 |
Patchstack | |
| 8.2 High | ICS Calendar | Server-Side Request Forgery SSRF and Arbitrary File Read No login needed |
≤ 10.12.0.3 Fixed in 10.12.0.4 |
CVE-2023-46784 |
Patchstack | |
| 7.1 High | Events Rich Snippets for Google | Cross-Site Request Forgery CSRF Leading to Privilege Escalation No login needed |
≤ 1.8 |
CVE-2023-44478 |
Patchstack | |
| 8.8 High | Newsletter Popup | Cross-Site Request Forgery List Deletion via CSRF No login needed |
≤ 1.2 |
CVE-2024-3643 |
WPScan | |
| 8.8 High | WP Prayer | Cross-Site Request Forgery Email Settings Update via CSRF No login needed |
≤ 2.0.9 |
CVE-2024-3406 |
WPScan | |
| 7.6 High | WP Prayer | Cross-Site Request Forgery Settings Update via CSRF |
≤ 2.0.9 |
CVE-2024-3405 |
WPScan | |
| 7.1 High | WebinarPress | Cross-Site Request Forgery No login needed |
≤ 1.33.17 |
CVE-2024-34818 |
Patchstack | |
| 8.8 High | reCAPTCHA Jetpack | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.2.2 |
CVE-2024-3940 |
WPScan | |
| 7.1 High | Add Custom CSS and JS | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 1.20 |
CVE-2024-3903 |
WPScan | |
| 7.6 High | ARForms Form Builder | Broken Access Control No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-31270 |
Patchstack | |
| 7.1 High | Popup box | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 4.1.2 Fixed in 4.1.3 |
CVE-2024-34367 |
Patchstack | |
| 7.5 High | MF Gig Calendar | Cross-Site Request Forgery Arbitrary Event Deletion via CSRF No login needed |
≤ 1.2.1 |
CVE-2024-3756 |
WPScan | |
| 7.1 High | ARForms Form Builder | Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion |
≤ 1.6.4 |
CVE-2024-1945 |
Wordfence | |
| 8.8 High | Side Menu Lite | Cross-Site Request Forgery Menu Deletion via CSRF No login needed |
< 4.2.1 Fixed in 4.2.1 |
CVE-2024-3476 |
WPScan | |
| 7.5 High | Sticky Buttons | Cross-Site Request Forgery Button Deletion via CSRF |
< 3.2.4 Fixed in 3.2.4 |
CVE-2024-3475 |
WPScan | |
| 8.8 High | Wow Skype Buttons | Cross-Site Request Forgery Button Deletion via CSRF No login needed |
< 4.0.4 Fixed in 4.0.4 |
CVE-2024-3474 |
WPScan | |
| 7.1 High | Regenerate post permalink | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed |
≤ 1.0.3 |
CVE-2024-33681 |
Patchstack | |
| 7.1 High | Slash Admin | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 3.8.1 Fixed in 3.8.2 |
CVE-2024-32958 |
Patchstack | |
| 7.1 High | The Pack Elementor addons | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 2.0.8.3 Fixed in 2.0.8.4 |
CVE-2024-32785 |
Patchstack | |
| 7.1 High | Seers | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 8.1.0 Fixed in 8.1.1 |
CVE-2024-32789 |
Patchstack | |
| 7.1 High | ARForms | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32702 |
Patchstack | |
| 8.5 High | ARForms | SQL Injection Subscriber+ SQL Injection |
≤ 6.4 Fixed in 6.4.1 |
CVE-2024-32706 |
Patchstack | |
| 7.6 High | Automatic | Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed |
< 3.93.0 Fixed in 3.93.0 |
CVE-2024-32693 |
Patchstack | |
| 7.1 High | Superfly Menu | Cross-Site Scripting Subscriber+ Site-Wide Stored Cross Site Scripting (XSS) |
≤ 5.0.25 |
CVE-2024-32553 |
Patchstack | |
| 7.1 High | BMI Adult & Kid Calculator | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 1.2.1 Fixed in 1.2.2 |
CVE-2024-32550 |
Patchstack | |
| 7.1 High | Related Posts | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 4.0.3 |
CVE-2024-32549 |
Patchstack | |
| 8.8 High | Login with phone number | Cross-Site Request Forgery No login needed |
≤ 1.6.93 Fixed in 1.6.94 |
CVE-2024-31424 |
Patchstack | |
| 7.1 High | Social Author Bio | Cross-Site Scripting Stored XSS via Cross Site Request Forgery (CSRF) No login needed |
≤ 2.4 |
CVE-2024-30545 |
Patchstack | |
| 7.1 High | Change default login logo,url and title | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 2.0 |
CVE-2024-31086 |
Patchstack | |
| 7.1 High | Broken Images | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 0.2 |
CVE-2024-31093 |
Patchstack | |
| 7.1 High | Sync Post With Other Site | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 1.9.1 |
CVE-2024-32082 |
Patchstack | |
| 8.7 High | Advance Search | Cross-Site Request Forgery Shortcode Deletion via CSRF |
≤ 1.1.6 |
CVE-2024-2739 |
WPScan | |
| 8.8 High | NPS computy | Cross-Site Request Forgery Results Deletion via CSRF No login needed |
≤ 2.7.5 |
CVE-2024-1755 |
WPScan | |
| 7.1 High | WordPress Tooltips | Cross-Site Request Forgery No login needed |
≤ 9.5.3 Fixed in 9.5.9 |
CVE-2024-31285 |
Patchstack | |
| 8.8 High | Ninja Forms | Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations ma… No login needed |
prior to 3.4.31 |
CVE-2024-25572 |
jpcert | |
| 7.1 High | ReDi Restaurant Reservation | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed |
≤ 24.0128 Fixed in 24.0303 |
CVE-2024-31299 |
Patchstack | |
| 8.5 High | Gutenberg Blocks by Kadence Blocks – Page Builder Features | Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) |
≤ 3.1.26 |
CVE-2023-6964 |
Wordfence | |
| 7.2 High | RapidLoad Power-Up for Autoptimize | Server-Side Request Forgery No login needed |
≤ 2.2.11 Fixed in 2.2.12 |
CVE-2024-31288 |
Patchstack | |
| 7.1 High | Tax Rate Upload | Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed |
≤ 2.4.5 |
CVE-2024-31105 |
Patchstack | |
| 7.1 High | Woocommerce Social Media Share Buttons | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 1.3.0 |
CVE-2024-31109 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.