WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 51–86 of 86 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs | Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion |
≤ 1.3.2 |
CVE-2024-12113 |
Wordfence | |
| 5.9 Medium | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 4.7.1 Fixed in 4.7.2 |
CVE-2025-24644 |
Patchstack | |
| 5.3 Medium | Visual Website Collaboration, Feedback & Project Management – Atarim | Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed |
≤ 4.0.9 |
CVE-2024-12104 |
Wordfence | |
| 6.4 Medium | Page Builder by SiteOrigin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter |
≤ 2.31.0 |
CVE-2024-12240 |
Wordfence | |
| 6.1 Medium | Deliver via Shipos for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed |
≤ 2.1.7 |
CVE-2024-12222 |
Wordfence | |
| 5.4 Medium | WP iCal Availability | Broken Access Control No login needed |
≤ 1.0.3 |
CVE-2023-46607 |
Patchstack | |
| 6.1 Medium | Branda – White Label & Branding, Custom Login Page Customizer | Cross-Site Scripting White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scripting No login needed |
≤ 3.4.21 |
CVE-2024-9371 |
Wordfence | |
| 6.5 Medium | Atarim | Broken Access Control No login needed |
≤ 4.0 Fixed in 4.0.1 |
CVE-2024-38771 |
Patchstack | |
| 5.3 Medium | Atarim | Broken Access Control No login needed |
≤ 4.0.1 Fixed in 4.0.2 |
CVE-2024-43290 |
Patchstack | |
| 6.5 Medium | Print Barcode Labels for your WooCommerce products/orders | Broken Access Control |
≤ 3.4.9 Fixed in 3.4.10 |
CVE-2024-43310 |
Patchstack | |
| 6.5 Medium | Custom Add to Cart Button Label and Link | Cross-Site Scripting |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-49296 |
Patchstack | |
| 6.5 Medium | Advanced Woo Labels | Cross-Site Scripting |
≤ 2.01 Fixed in 2.02 |
CVE-2024-47622 |
Patchstack | |
| 6.4 Medium | WordPress Infinite Scroll - Ajax Load More | Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter |
≤ 7.1.2 |
CVE-2024-8505 |
Wordfence | |
| 5.4 Medium | Visual Website Collaboration, Feedback & Project Management – Atarim | Broken Access Control Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 4.0.2 |
CVE-2024-7621 |
Wordfence | |
| 5.9 Medium | Branda | Cross-Site Scripting |
≤ 3.4.17 Fixed in 3.4.18 |
CVE-2024-37239 |
Patchstack | |
| 5.9 Medium | Atarim | Cross-Site Scripting Authenticated Cross Site Scripting (XSS) |
≤ 3.31 Fixed in 3.32 |
CVE-2024-37434 |
Patchstack | |
| 5.3 Medium | Branda – White Label WordPress, Custom Login Page Customizer | Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed |
≤ 3.4.18 |
CVE-2024-6554 |
Wordfence | |
| 6.4 Medium | Branda – White Label WordPress, Custom Login Page Customizer | Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload |
≤ 3.4.17 |
CVE-2024-5191 |
Wordfence | |
| 6.5 Medium | SKU Label Changer For WooCommerce | Broken Access Control No login needed |
≤ 3.0 Fixed in 3.0.1 |
CVE-2023-29174 |
Patchstack | |
| 6.5 Medium | Advanced Woo Labels | Cross-Site Scripting |
≤ 1.93 Fixed in 1.94 |
CVE-2024-35675 |
Patchstack | |
| 5.3 Medium | Branda | Authentication Bypass IP Restriction Bypass No login needed |
≤ 3.4.14 Fixed in 3.4.15 |
CVE-2023-51542 |
Patchstack | |
| 5.3 Medium | White Label CMS | Broken Access Control Missing Authorization to Plugin Settings Reset No login needed |
≤ 2.7.3 |
CVE-2024-4280 |
Wordfence | |
| 6.4 Medium | Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce | Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates |
≤ 3.4.6 |
CVE-2024-1679 |
Wordfence | |
| 6.3 Medium | Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce | Broken Access Control Improper Authorization |
≤ 3.4.6 |
CVE-2024-1677 |
Wordfence | |
| 5.9 Medium | WooCommerce Shipping Label | Cross-Site Scripting |
≤ 2.3.8 Fixed in 2.3.9 |
CVE-2024-32834 |
Patchstack | |
| 6.5 Medium | Knight Lab Timeline | Cross-Site Scripting |
≤ 3.9.3.4 |
CVE-2024-32554 |
Patchstack | |
| 6.1 Medium | Ninja Forms | Cross-Site Scripting Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on th… No login needed |
prior to 3.8.1 |
CVE-2024-29220 |
jpcert | |
| 6.4 Medium | Knight Lab Timeline | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.9.3.3 |
CVE-2024-2287 |
Wordfence | |
| 5.9 Medium | Easy Login Styler – White Label Admin Login Page | Cross-Site Scripting |
≤ 1.0.6 |
CVE-2024-31344 |
Patchstack | |
| 5.3 Medium | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed |
≤ 4.4.2 |
CVE-2024-3216 |
Wordfence | |
| 6.5 Medium | Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more | Cross-Site Scripting |
≤ 4.5.24 Fixed in 4.5.25 |
CVE-2024-29795 |
Patchstack | |
| 6.1 Medium | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 4.4.1 |
CVE-2024-0957 |
Wordfence | |
| 5.4 Medium | Scalable Vector Graphics (SVG) | Cross-Site Scripting Author+ Stored XSS via SVG |
≤ 3.4 |
CVE-2023-7085 |
WPScan | |
| 5.9 Medium | Product Labels For Woocommerce (Sale Badges) | Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-24886 |
Patchstack | |
| 4.3 Medium | White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard | Cross-Site Request Forgery WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.9.0 Fixed in 2.9.1 |
CVE-2023-52128 |
Patchstack | |
| 4.3 Medium | WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels | Broken Access Control Missing Authorization to Order Export |
≤ 4.3.0 |
CVE-2023-7068 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.