WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–90 of 90 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Mixcloud Embed Plugin mixcloud-embed Cross-Site Scripting ≤ 2.2.0 CVE-2025-46501 Patchstack
4.3 Medium Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) Plugin Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure ≤ 4.1 CVE-2025-1284 Wordfence
7.1 High Cart66 Cloud Plugin cart66-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.7 CVE-2025-32653 Patchstack
5.3 Medium Cart66 Cloud Plugin cart66-cloud Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.3.7 CVE-2025-2841 Wordfence
4.3 Medium Printus Plugin printus-cloud-printing-for-woocommerce Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-31830 Patchstack
4.3 Medium pCloud Backup Plugin pcloud-backup Broken Access Control ≤ 1.0.1 CVE-2025-31755 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
7.1 High WooCommerce Fattureincloud Plugin woo-fattureincloud Cross-Site Scripting No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-30837 Patchstack
7.1 High WP Colorful Tag Cloud Plugin wp-colorful-tag-cloud Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-28865 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
6.5 Medium List Mixcloud Plugin list-mixcloud Cross-Site Scripting ≤ 1.4 CVE-2025-28930 Patchstack
6.5 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting ≤ 2.8.0.1 Fixed in 2.8.1 CVE-2025-26878 Patchstack
6.4 Medium Autoship Cloud for WooCommerce Subscription Products Plugin autoship-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2024-13461 Wordfence
7.5 High WP Cloud Plugin cloud Arbitrary File Deletion No login needed ≤ 1.4.3 CVE-2025-23819 Patchstack
7.1 High CloudFlare(R) Cache Purge Plugin cloudflare-cache-purge Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-22332 Patchstack
7.1 High WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Cross-Site Scripting Tag Groups plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-22735 Patchstack
4.3 Medium Soundcloud Is Gold Plugin soundcloud-is-gold Broken Access Control ≤ 2.5.1 CVE-2023-32586 Patchstack
5.4 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) ≤ 4.16.4 CVE-2024-12042 Wordfence
4.3 Medium Child Theme Creator by Orbisius Plugin orbisius-child-theme-creator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete ≤ 1.5.5 CVE-2024-12263 Wordfence
5.4 Medium tencentcloud-cos Plugin tencentcloud-cos Broken Access Control ≤ 1.0.7 CVE-2023-29433 Patchstack
4.3 Medium Dollie Hub – Build Your Own WordPress Cloud Platform Plugin Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure ≤ 6.2.0 CVE-2024-12099 Wordfence
6.4 Medium LegalWeb Cloud Plugin legalweb-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.2 CVE-2024-11761 Wordfence
7.5 High Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup Information Disclosure WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log No login needed ≤ 2.2.13 CVE-2024-10028 Wordfence
6.1 Medium 2D Tag Cloud Plugin 2d-tag-cloud-widget-by-sujin Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 6.0.2 CVE-2024-9670 Wordfence
5.3 Medium WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-43237 Patchstack
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload ≤ 4.15.3 CVE-2024-8242 Wordfence
7.3 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed ≤ 4.15.3 CVE-2024-8269 Wordfence
8.1 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed ≤ 4.15.2 CVE-2024-7628 Wordfence
9.8 Critical MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass No login needed ≤ 4.14.7 CVE-2024-6328 Wordfence
6.4 Medium Ultimate Post Kit Addons for Elementor Plugin ultimate-post-kit Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget ≤ 3.11.7 CVE-2024-5662 Wordfence
7.5 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control No login needed ≤ 4.3.39 Fixed in 4.5.4 CVE-2024-32777 Patchstack
7.1 High WP-Stateless – Google Cloud Storage Plugin wp-stateless Broken Access Control Google Cloud Storage <= 3.4.0 - Missing Authorization to Limited Arbitrary Options Update ≤ 3.4.0 CVE-2024-1385 Wordfence
7.1 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.5.5 Fixed in 4.5.6 CVE-2024-29773 Patchstack
6.5 Medium Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more Plugin ilab-media-tools Cross-Site Scripting ≤ 4.5.24 Fixed in 4.5.25 CVE-2024-29795 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
6.5 Medium SoundCloud Shortcode Plugin soundcloud-shortcode Cross-Site Scripting ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-25936 Patchstack
3.0 Low TablePress Plugin tablepress Server-Side Request Forgery TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts < 2.2.5 CVE-2024-23825 GitHub_M
8.1 High Cloudflare Plugin cloudflare Information Disclosure Cloudflare WordPress plugin enables information disclosure of Cloudflare API (for low privileged users) ≤ 4.12.2 Fixed in 4.12.3 CVE-2024-0212 cloudflare
7.1 High 3D Tag Cloud Plugin cardoza-3d-tag-cloud Cross-Site Request Forgery WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.8 CVE-2022-41990 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only