WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 51–98 of 98 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 3.22.1 - Authenticated (Subscriber+) Sensitive Information Exposure No login needed ≤ 3.22.1 CVE-2025-2331 Wordfence
6.5 Medium Give Plugin give Broken Access Control Missing Authorization to Unauthenticated Arbitrary Earning Reports Disclosure via give_reports_earnings Function ≤ 3.22.0 CVE-2025-2025 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.4 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.4 CVE-2025-0912 Wordfence
5.8 Medium Give – Divi Donation Modules Plugin give-donation-modules-for-divi Information Disclosure Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-22633 Patchstack
6.5 Medium WPExperts Square For GiveWP Plugin wpexperts-square-for-give SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.3.1 CVE-2024-13713 Wordfence
5.3 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Broken Access Control Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation No login needed ≤ 2.8.0 CVE-2024-13316 Wordfence
6.5 Medium Giveaways and Contests by PromoSimple Plugin giveaways-contests-by-promosimple Cross-Site Scripting ≤ 1.24 CVE-2025-23934 Patchstack
9.8 Critical GiveWP Plugin give PHP Object Injection No login needed ≤ 3.19.3 Fixed in 3.19.4 CVE-2025-22777 Patchstack
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.2 CVE-2024-12877 Wordfence
6.4 Medium SweepWidget Contests, Giveaways, Photo Contests, Competitions Plugin sweepwidget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-11756 Wordfence
5.4 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Cross-Site Request Forgery Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation Function No login needed ≤ 2.7.1 CVE-2024-12545 Wordfence
5.4 Medium GiveWP Plugin give Broken Access Control Arbitrary Content Deletion ≤ 2.25.1 Fixed in 2.25.2 CVE-2023-23672 Patchstack
5.3 Medium GiveWP Plugin give Broken Access Control No login needed ≤ 2.33.1 Fixed in 2.33.2 CVE-2023-47183 Patchstack
4.8 Medium Give Plugin paystack-for-give Cross-Site Scripting Reflected XSS < 3.19.0 Fixed in 3.19.0 CVE-2024-11921 WPScan
5.3 Medium Simple Giveaways Plugin giveasap Broken Access Control No login needed ≤ 2.48.0 Fixed in 2.48.1 CVE-2023-23893 Patchstack
6.4 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Cross-Site Scripting Giveaways and Contests <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.9 CVE-2024-11898 Wordfence
6.1 Medium Run Contests, Raffles, and Giveaways with ContestsWP Plugin contest-code-checker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.3 CVE-2024-11456 Wordfence
9.8 Critical Giveaway Boost Plugin giveaway-boost PHP Object Injection No login needed ≤ 2.1.4 CVE-2024-49332 Patchstack
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 3.16.3 CVE-2024-9634 Wordfence
8.5 High WPExperts Square For GiveWP Plugin wpexperts-square-for-give SQL Injection ≤ 1.3 Fixed in 1.3.2 CVE-2024-47338 Patchstack
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.16.1 CVE-2024-8353 Wordfence
7.2 High GiveWP – Donation Plugin and Fundraising Platform Plugin give SQL Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Authenticated (GiveWP Manager+) SQL Injection via order Parameter ≤ 3.16.1 CVE-2024-9130 Wordfence
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
4.8 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Scripting Editor+ Stored XSS < 1.12.16 Fixed in 1.12.16 CVE-2024-6887 WPScan
5.3 Medium GiveWP Plugin give Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.15.1 CVE-2024-6551 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed ≤ 3.13.0 CVE-2024-5940 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure No login needed ≤ 3.13.0 CVE-2024-5939 Wordfence
10.0 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 3.14.1 CVE-2024-5932 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion ≤ 3.14.1 CVE-2024-5941 Wordfence
10.0 Critical GiveWP Plugin give PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.1 Fixed in 3.14.2 CVE-2024-37099 Patchstack
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions ≤ 3.13.0 CVE-2024-5977 Wordfence
4.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Broken Access Control ≤ 1.12.4 Fixed in 1.12.5 CVE-2024-4745 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.12.0 Fixed in 3.12.1 CVE-2024-35679 Patchstack
6.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.0 CVE-2024-3714 Wordfence
5.3 Medium Giveaways and Contests Plugin rafflepress Authentication Bypass IP Restriction Bypass No login needed ≤ 1.12.7 Fixed in 1.12.11 CVE-2024-32827 Patchstack
8.8 High GiveWP Plugin give Privilege Escalation GiveWP Manager+ Privilege Escalation ≤ 2.33.0 Fixed in 2.33.1 CVE-2023-41665 Patchstack
6.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 3.6.1 -- Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.6.1 CVE-2024-1957 Wordfence
5.9 Medium GiveWP Plugin give Cross-Site Scripting Cross Site Scripting (XSS) via render_dropdown ≤ 2.25.1 Fixed in 2.25.2 CVE-2022-40211 Patchstack
6.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.5.1 CVE-2024-1424 Wordfence
8.0 High GiveWP Plugin give PHP Object Injection ≤ 3.4.2 Fixed in 3.5.0 CVE-2024-30229 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-27987 Patchstack
7.2 High Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.12.5 CVE-2024-1935 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS) ≤ 3.2.2 Fixed in 3.3.0 CVE-2023-51415 Patchstack
9.8 Critical GiveWP Plugin give SQL Injection Unauthenticated SQLi No login needed < 2.24.1 Fixed in 2.24.1 CVE-2023-0224 WPScan
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Cross-Site Request Forgery to plugin deactivation No login needed ≤ 2.33.3 CVE-2023-4247 Wordfence
4.3 Medium GiveWP Plugin give Cross-Site Request Forgery Cross-Site Request Forgery to plugin installation No login needed ≤ 2.33.3 CVE-2023-4246 Wordfence
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Integration Deletion No login needed ≤ 2.33.3 CVE-2023-4248 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only