WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 901–950 of 985 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 19 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Muslim Prayer Time BD Plugin muslim-prayer-time-bd Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 2.4 CVE-2024-4758 WPScan
8.1 High Logo Manager For Enamad Plugin logo-manager-for-enamad Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.7.0 CVE-2024-4757 WPScan
8.3 High Ali2Woo Lite Plugin ali2woo-lite Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 3.3.5 CVE-2024-37212 Patchstack
7.7 High ARForms Plugin arforms Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 6.4 Fixed in 6.4.1 CVE-2024-32703 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary WordPress Options Removal ≤ 6.4 Fixed in 6.4.1 CVE-2024-32704 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary Plugin Activation/Deactivation ≤ 6.4 Fixed in 6.4.1 CVE-2024-32705 Patchstack
7.5 High Migration Backup Restore Plugin Server-Side Request Forgery Admin+ SSRF No login needed < 3.5.0 Fixed in 3.5.0 CVE-2024-4469 WPScan
8.8 High KKProgressbar2 Free Plugin kkprogressbar Cross-Site Request Forgery Progress Bar Deletion via CSRF No login needed ≤ 1.1.4.2 CVE-2024-4535 WPScan
7.1 High Business Card Plugin Cross-Site Request Forgery Card Edit via CSRF No login needed ≤ 1.0.0 CVE-2024-4531 WPScan
8.6 High BuddyForms Plugin buddyforms Path Traversal WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF No login needed ≤ 2.8.8 Fixed in 2.8.9 CVE-2024-32830 Patchstack
8.8 High Automatic Plugin wp-automatic Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27955 Patchstack
8.2 High ICS Calendar Plugin ics-calendar Server-Side Request Forgery SSRF and Arbitrary File Read No login needed ≤ 10.12.0.3 Fixed in 10.12.0.4 CVE-2023-46784 Patchstack
7.1 High Events Rich Snippets for Google Plugin rich-snippets-vevents Cross-Site Request Forgery CSRF Leading to Privilege Escalation No login needed ≤ 1.8 CVE-2023-44478 Patchstack
8.8 High Newsletter Popup Plugin Cross-Site Request Forgery List Deletion via CSRF No login needed ≤ 1.2 CVE-2024-3643 WPScan
8.8 High WP Prayer Plugin Cross-Site Request Forgery Email Settings Update via CSRF No login needed ≤ 2.0.9 CVE-2024-3406 WPScan
7.6 High WP Prayer Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 2.0.9 CVE-2024-3405 WPScan
7.1 High WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery No login needed ≤ 1.33.17 CVE-2024-34818 Patchstack
8.8 High reCAPTCHA Jetpack Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.2.2 CVE-2024-3940 WPScan
7.1 High Add Custom CSS and JS Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.20 CVE-2024-3903 WPScan
7.6 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31270 Patchstack
7.1 High Popup box Plugin ays-popup-box Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-34367 Patchstack
7.5 High MF Gig Calendar Plugin Cross-Site Request Forgery Arbitrary Event Deletion via CSRF No login needed ≤ 1.2.1 CVE-2024-3756 WPScan
7.1 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion ≤ 1.6.4 CVE-2024-1945 Wordfence
8.8 High Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Menu Deletion via CSRF No login needed < 4.2.1 Fixed in 4.2.1 CVE-2024-3476 WPScan
7.5 High Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Button Deletion via CSRF < 3.2.4 Fixed in 3.2.4 CVE-2024-3475 WPScan
8.8 High Wow Skype Buttons Plugin Cross-Site Request Forgery Button Deletion via CSRF No login needed < 4.0.4 Fixed in 4.0.4 CVE-2024-3474 WPScan
7.1 High Regenerate post permalink Plugin regenerate-post-permalinks Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed ≤ 1.0.3 CVE-2024-33681 Patchstack
7.1 High Slash Admin Plugin slash-admin Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2024-32958 Patchstack
7.1 High The Pack Elementor addons Plugin the-pack-addon Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 2.0.8.3 Fixed in 2.0.8.4 CVE-2024-32785 Patchstack
7.1 High Seers Plugin seers-cookie-consent-banner-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 8.1.0 Fixed in 8.1.1 CVE-2024-32789 Patchstack
7.1 High ARForms Plugin arforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.4 Fixed in 6.4.1 CVE-2024-32702 Patchstack
8.5 High ARForms Plugin arforms SQL Injection Subscriber+ SQL Injection ≤ 6.4 Fixed in 6.4.1 CVE-2024-32706 Patchstack
7.6 High Automatic Plugin Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed < 3.93.0 Fixed in 3.93.0 CVE-2024-32693 Patchstack
7.1 High Superfly Menu Plugin superfly-menu Cross-Site Scripting Subscriber+ Site-Wide Stored Cross Site Scripting (XSS) ≤ 5.0.25 CVE-2024-32553 Patchstack
7.1 High BMI Adult & Kid Calculator Plugin bmi-adultkid-calculator Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-32550 Patchstack
7.1 High Related Posts Plugin microkids-related-posts Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.0.3 CVE-2024-32549 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
7.1 High Social Author Bio Plugin social-autho-bio Cross-Site Scripting Stored XSS via Cross Site Request Forgery (CSRF) No login needed ≤ 2.4 CVE-2024-30545 Patchstack
7.1 High Change default login logo,url and title Plugin change-default-login-logo-url-and-title Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.0 CVE-2024-31086 Patchstack
7.1 High Broken Images Plugin wp-broken-images Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.2 CVE-2024-31093 Patchstack
7.1 High Sync Post With Other Site Plugin sync-post-with-other-site Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.9.1 CVE-2024-32082 Patchstack
8.7 High Advance Search Plugin Cross-Site Request Forgery Shortcode Deletion via CSRF ≤ 1.1.6 CVE-2024-2739 WPScan
8.8 High NPS computy Plugin nps-computy Cross-Site Request Forgery Results Deletion via CSRF No login needed ≤ 2.7.5 CVE-2024-1755 WPScan
7.1 High WordPress Tooltips Plugin wordpress-tooltips Cross-Site Request Forgery No login needed ≤ 9.5.3 Fixed in 9.5.9 CVE-2024-31285 Patchstack
8.8 High Ninja Forms Plugin ninja-forms Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations ma… No login needed prior to 3.4.31 CVE-2024-25572 jpcert
7.1 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31299 Patchstack
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
7.2 High RapidLoad Power-Up for Autoptimize Plugin unusedcss Server-Side Request Forgery No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-31288 Patchstack
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2024-31105 Patchstack
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only