WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 51–100 of 101 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update |
≤ 3.4.25 |
CVE-2025-1780 |
Wordfence | |
| 4.3 Medium | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update |
≤ 3.4.24 |
CVE-2024-13358 |
Wordfence | |
| 7.1 High | Bricksbuilder | Privilege Escalation Authenticated (Contributor+) Privilege Escalation via create_autosave |
≤ 1.9.6.1 |
CVE-2024-2297 |
Wordfence | |
| 6.1 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6.6 |
CVE-2025-0864 |
Wordfence | |
| 4.3 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.10 Fixed in 3.4.11 |
CVE-2025-24603 |
Patchstack | |
| 6.5 Medium | Create with Code | Cross-Site Scripting |
≤ 1.4 Fixed in 1.5 |
CVE-2025-24638 |
Patchstack | |
| 6.4 Medium | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.10.0 |
CVE-2024-11826 |
Wordfence | |
| 9.8 Critical | Themes Coder – Create Android & iOS Apps For Your Woocommerce Site | Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed |
≤ 1.3.4 |
CVE-2024-12402 |
Wordfence | |
| 7.1 High | Custom Dashboard Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.0 |
CVE-2024-56024 |
Patchstack | |
| 8.8 High | WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor | Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.3.7 |
CVE-2024-12272 |
Wordfence | |
| 5.4 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) |
≤ 4.16.4 |
CVE-2024-12042 |
Wordfence | |
| 6.4 Medium | FAQ And Answers – Create Frequently Asked Questions Area on WP Sites | Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11882 |
Wordfence | |
| 7.3 High | Active Products Tables for WooCommerce. Use constructor to create tables | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed |
≤ 1.0.6.5 |
CVE-2024-10959 |
Wordfence | |
| 6.1 Medium | PDF Builder for WooCommerce. Create invoices,packing slips and more | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.136 |
CVE-2024-11276 |
Wordfence | |
| 6.5 Medium | Custom Dashboard Widget | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2024-51860 |
Patchstack | |
| 5.3 Medium | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed |
≤ 4.9.7 |
CVE-2024-10861 |
Wordfence | |
| 4.3 Medium | Content Slider Block – Create fully functional slider with Gutenberg block | Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure |
≤ 3.1.5 |
CVE-2024-10667 |
Wordfence | |
| 6.4 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode |
≤ 1.0.6.4 |
CVE-2024-10168 |
Wordfence | |
| 6.5 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.9 Fixed in 3.4.10 |
CVE-2024-43310 |
Patchstack | |
| 8.1 High | App Builder – Create Native Android & iOS Apps On The Flight | Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP No login needed |
≤ 5.3.7 |
CVE-2024-9302 |
Wordfence | |
| 9.9 Critical | Creates 3D Flipbook, PDF Flipbook | Arbitrary File Upload |
≤ 1.2 |
CVE-2024-48034 |
Patchstack | |
| 7.1 High | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'create_mollie_profile' |
≤ 4.3.7 |
CVE-2023-7294 |
Wordfence | |
| 7.1 High | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'create_mollie_account' |
≤ 4.3.7 |
CVE-2023-7291 |
Wordfence | |
| 4.7 Medium | Discount Rules for WooCommerce – Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons | Cross-Site Scripting Create Smart WooCommerce Coupons & Discounts, Bulk Discount, BOGO Coupons <= 2.6.5 - Reflected Cross-Site Scripting No login needed |
≤ 2.6.5 |
CVE-2024-8541 |
Wordfence | |
| 5.1 Medium | Create | Cross-Site Scripting |
≤ 2.9.1 Fixed in 2.9.2 |
CVE-2024-47356 |
Patchstack | |
| 4.3 Medium | MStore API – Create Native Android & iOS Apps On The Cloud | Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload |
≤ 4.15.3 |
CVE-2024-8242 |
Wordfence | |
| 7.3 High | MStore API – Create Native Android & iOS Apps On The Cloud | Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed |
≤ 4.15.3 |
CVE-2024-8269 |
Wordfence | |
| 5.3 Medium | Create by Mediavine | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2024-43264 |
Patchstack | |
| 5.6 Medium | App Builder – Create Native Android & iOS Apps On The Flight | SQL Injection Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search No login needed |
≤ 4.3.3 |
CVE-2024-7651 |
Wordfence | |
| 6.5 Medium | Modal Window | Cross-Site Scripting create popup modal window plugin <= 6.0.3 - Cross Site Scripting (XSS) |
≤ 6.0.3 Fixed in 6.0.4 |
CVE-2024-43346 |
Patchstack | |
| 8.1 High | MStore API – Create Native Android & iOS Apps On The Cloud | Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed |
≤ 4.15.2 |
CVE-2024-7628 |
Wordfence | |
| 4.3 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update |
≤ 3.4.6 |
CVE-2024-6836 |
Wordfence | |
| 6.5 Medium | Create by Mediavine | Cross-Site Scripting |
≤ 1.9.7 Fixed in 1.9.8 |
CVE-2024-37495 |
Patchstack | |
| 6.5 Medium | Caxton – Create Pro page layouts in Gutenberg | Cross-Site Scripting Create Pro page layouts in Gutenberg plugin <= 1.30.1 - Cross Site Scripting (XSS) |
≤ 1.30.1 |
CVE-2024-37948 |
Patchstack | |
| 9.8 Critical | MStore API – Create Native Android & iOS Apps On The Cloud | Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass No login needed |
≤ 4.14.7 |
CVE-2024-6328 |
Wordfence | |
| 6.4 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload |
≤ 3.3.1 |
CVE-2024-5192 |
Wordfence | |
| 6.4 Medium | Create by Mediavine | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Schema Meta Shortcode |
≤ 1.9.7 |
CVE-2024-5601 |
Wordfence | |
| 6.4 Medium | WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce | Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.7 |
CVE-2024-4632 |
Wordfence | |
| 8.1 High | Popup Builder – Create highly converting, mobile friendly marketing popups | Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure |
≤ 4.3.1 |
CVE-2023-6696 |
Wordfence | |
| 6.4 Medium | Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce | Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates |
≤ 3.4.6 |
CVE-2024-1679 |
Wordfence | |
| 6.3 Medium | Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce | Broken Access Control Improper Authorization |
≤ 3.4.6 |
CVE-2024-1677 |
Wordfence | |
| 6.4 Medium | Modal Window – create popup modal window | Cross-Site Scripting create popup modal window <= 5.3.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 5.3.8 |
CVE-2024-2457 |
Wordfence | |
| 8.8 High | BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection in get_simple_request |
≤ 3.4.20 |
CVE-2024-2025 |
Wordfence | |
| 9.8 Critical | Create by Mediavine | SQL Injection Unauthenticated SQL Injection via 'id' No login needed |
≤ 1.9.4 |
CVE-2024-1711 |
Wordfence | |
| 5.3 Medium | Ultimate Gift Cards for WooCommerce – Create, Redeem & Manage Digital Gift Certificates with Personalized Templates | Broken Access Control Create, Redeem & Manage Digital Gift Certificates with Personalized Templates <= 2.6.6 - Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 2.6.6 |
CVE-2024-1857 |
Wordfence | |
| 5.4 Medium | WooCommerce PDF Invoice Builder | Cross-Site Request Forgery No login needed |
≤ 1.2.101 Fixed in 1.2.102 |
CVE-2023-51486 |
Patchstack | |
| 6.3 Medium | affiliate-toolkit – WordPress Affiliate | Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list |
≤ 3.5.4 |
CVE-2024-1851 |
Wordfence | |
| 5.4 Medium | User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | Cross-Site Scripting Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.0.13 |
CVE-2024-0903 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Broken Access Control Missing Authorization via create_view |
≤ 3.2.2 |
CVE-2024-0371 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Cross-Site Request Forgery Cross-Site Request Forgery via create_view No login needed |
≤ 3.2.2 |
CVE-2024-0374 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.