WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–100 of 101 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 3.4.24 CVE-2024-13358 Wordfence
7.1 High Bricksbuilder Theme Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave ≤ 1.9.6.1 CVE-2024-2297 Wordfence
6.1 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6.6 CVE-2025-0864 Wordfence
4.3 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.10 Fixed in 3.4.11 CVE-2025-24603 Patchstack
6.5 Medium Create with Code Plugin create-with-code Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2025-24638 Patchstack
6.4 Medium Quill Forms | Conversational Multi Step Forms, Surveys & quizzes Plugin quillforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.0 CVE-2024-11826 Wordfence
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
7.1 High Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-56024 Patchstack
8.8 High WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Plugin wte-elementor-widgets Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion ≤ 1.3.7 CVE-2024-12272 Wordfence
5.4 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) ≤ 4.16.4 CVE-2024-12042 Wordfence
6.4 Medium FAQ And Answers – Create Frequently Asked Questions Area on WP Sites Plugin Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11882 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
6.1 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.136 CVE-2024-11276 Wordfence
6.5 Medium Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2024-51860 Patchstack
5.3 Medium Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Plugin ays-popup-box Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed ≤ 4.9.7 CVE-2024-10861 Wordfence
4.3 Medium Content Slider Block – Create fully functional slider with Gutenberg block Plugin content-slider-block Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure ≤ 3.1.5 CVE-2024-10667 Wordfence
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
8.1 High App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 5.3.7 CVE-2024-9302 Wordfence
9.9 Critical Creates 3D Flipbook, PDF Flipbook Plugin create-flipbook-from-pdf Arbitrary File Upload ≤ 1.2 CVE-2024-48034 Patchstack
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_profile' ≤ 4.3.7 CVE-2023-7294 Wordfence
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_account' ≤ 4.3.7 CVE-2023-7291 Wordfence
4.7 Medium Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons Plugin woo-discount-rules Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2024-8541 Wordfence
5.1 Medium Create Plugin create Cross-Site Scripting ≤ 2.9.1 Fixed in 2.9.2 CVE-2024-47356 Patchstack
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload ≤ 4.15.3 CVE-2024-8242 Wordfence
7.3 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed ≤ 4.15.3 CVE-2024-8269 Wordfence
5.3 Medium Create by Mediavine Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.8 Fixed in 1.9.9 CVE-2024-43264 Patchstack
5.6 Medium App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder SQL Injection Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search No login needed ≤ 4.3.3 CVE-2024-7651 Wordfence
6.5 Medium Modal Window Plugin modal-window Cross-Site Scripting create popup modal window plugin <= 6.0.3 - Cross Site Scripting (XSS) ≤ 6.0.3 Fixed in 6.0.4 CVE-2024-43346 Patchstack
8.1 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed ≤ 4.15.2 CVE-2024-7628 Wordfence
4.3 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update ≤ 3.4.6 CVE-2024-6836 Wordfence
6.5 Medium Create by Mediavine Plugin mediavine-create Cross-Site Scripting ≤ 1.9.7 Fixed in 1.9.8 CVE-2024-37495 Patchstack
6.5 Medium Caxton – Create Pro page layouts in Gutenberg Plugin caxton Cross-Site Scripting Create Pro page layouts in Gutenberg plugin <= 1.30.1 - Cross Site Scripting (XSS) ≤ 1.30.1 CVE-2024-37948 Patchstack
9.8 Critical MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass No login needed ≤ 4.14.7 CVE-2024-6328 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
6.4 Medium Create by Mediavine Plugin mediavine-create Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Schema Meta Shortcode ≤ 1.9.7 CVE-2024-5601 Wordfence
6.4 Medium WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce Plugin cartflows Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.7 CVE-2024-4632 Wordfence
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
6.4 Medium Modal Window – create popup modal window Plugin modal-window Cross-Site Scripting create popup modal window <= 5.3.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.3.8 CVE-2024-2457 Wordfence
8.8 High BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin wc4bp PHP Object Injection Authenticated (Subscriber+) PHP Object Injection in get_simple_request ≤ 3.4.20 CVE-2024-2025 Wordfence
9.8 Critical Create by Mediavine Plugin mediavine-create SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 1.9.4 CVE-2024-1711 Wordfence
5.3 Medium Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates Plugin Broken Access Control Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.6.6 CVE-2024-1857 Wordfence
5.4 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.101 Fixed in 1.2.102 CVE-2023-51486 Patchstack
6.3 Medium affiliate-toolkit – WordPress Affiliate Plugin affiliate-toolkit-starter Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list ≤ 3.5.4 CVE-2024-1851 Wordfence
5.4 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin Cross-Site Scripting Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.13 CVE-2024-0903 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via create_view ≤ 3.2.2 CVE-2024-0371 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Cross-Site Request Forgery Cross-Site Request Forgery via create_view No login needed ≤ 3.2.2 CVE-2024-0374 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only