WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–79 of 79 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
6.1 Medium WP – Bulk SMS – by SMS.to Plugin wp-bulk-sms Cross-Site Scripting Bulk SMS – by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting No login needed ≤ 1.0.12 CVE-2024-11434 Wordfence
5.4 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Broken Access Control ≤ 1.5 Fixed in 1.51 CVE-2023-41688 Patchstack
6.1 Medium Seraphinite Bulk Discounts for WooCommerce Plugin seraphinite-discount-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-12160 Wordfence
4.3 Medium Bulk Edit Post Titles Plugin bulk-edit-post-titles Broken Access Control ≤ 5.0.0 CVE-2023-49754 Patchstack
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
6.1 Medium BulkPress Plugin bulkpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.3.5 CVE-2024-9615 Wordfence
4.9 Medium WOLF Plugin bulk-editor Path Traversal CSV Limited Path Traversal ≤ 1.0.8.3 Fixed in 1.0.8.4 CVE-2024-52396 Patchstack
4.3 Medium Bulk images optimizer: Resize, optimize, convert to webp, rename ... Plugin bulk-image-resizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Options Update ≤ 2.0.1 CVE-2024-9361 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
6.1 Medium Quantity Dynamic Pricing & Bulk Discounts for WooCommerce Plugin wholesale-pricing-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.8.0 CVE-2024-9384 Wordfence
6.1 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.15 CVE-2024-8803 Wordfence
6.5 Medium HTML Forms – Simple WordPress Forms Plugin Cross-Site Request Forgery Simple WordPress Forms Plugin < 1.3.34 - Bulk Delete via CSRF No login needed < 1.3.34 Fixed in 1.3.34 CVE-2024-6412 WPScan
5.4 Medium Astra Bulk Edit Plugin astra-bulk-edit Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2023-44148 Patchstack
5.4 Medium BulkGate SMS Plugin for WooCommerce Plugin woosms-sms-module-for-woocommerce Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2023-51679 Patchstack
4.3 Medium Bulk Posts Editing Plugin Cross-Site Request Forgery No login needed ≤ 4.2.3 CVE-2024-4204 Wordfence
4.3 Medium Bulk Posts Editing Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization ≤ 4.2.3 CVE-2024-4199 Wordfence
5.9 Medium WOLF Plugin bulk-editor Cross-Site Scripting ≤ 1.0.8.2 Fixed in 1.0.8.3 CVE-2024-34558 Patchstack
4.3 Medium 5280 Bootstrap Modal Contact Form Plugin 5280-bootstrap-modal-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Delete Messages No login needed ≤ 1.0 CVE-2024-0847 Wordfence
4.3 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in realmag777 BEAR and WOLF WordPress plugins No login needed ≤ 1.0.8.1, ≤ 1.1.4.1 Fixed in 1.0.8.2 CVE-2024-31430 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Broken Access Control ≤ 1.1.4.3 Fixed in 1.1.4.4 CVE-2024-30463 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Broken Access Control ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24835 Patchstack
4.3 Medium Bulk Edit Post Titles Plugin bulk-edit-post-titles Broken Access Control Missing Authorization via bulkUpdatePostTitles ≤ 5.0.0 CVE-2024-0369 Wordfence
4.3 Medium MainWP Dashboard Plugin mainwp Cross-Site Request Forgery Cross-Site Request Forgery via posting_bulk No login needed ≤ 4.6.0.1 CVE-2024-1642 Wordfence
5.4 Medium Master Slider - Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed ≤ 3.9.10 CVE-2023-6326 Wordfence
5.9 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Scripting WordPress BEAR Plugin <= 1.1.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24834 Patchstack
6.6 Medium Advanced Database Cleaner Plugin advanced-database-cleaner PHP Object Injection Authenticated(Administrator+) PHP Object Injection via process_bulk_action ≤ 3.1.3 CVE-2024-0668 Wordfence
5.4 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Cross-Site Request Forgery WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery No login needed ≤ 1.0.8.1 CVE-2024-0790 Wordfence
4.3 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Broken Access Control WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Missing Authorization ≤ 1.0.8.1 CVE-2024-0791 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only