WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 51–86 of 86 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
5.9 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.7.1 Fixed in 4.7.2 CVE-2025-24644 Patchstack
5.3 Medium Visual Website Collaboration, Feedback & Project Management – Atarim Plugin Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed ≤ 4.0.9 CVE-2024-12104 Wordfence
6.4 Medium Page Builder by SiteOrigin Plugin siteorigin-panels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Row Label Parameter ≤ 2.31.0 CVE-2024-12240 Wordfence
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
5.4 Medium WP iCal Availability Plugin wp-ical-availability Broken Access Control No login needed ≤ 1.0.3 CVE-2023-46607 Patchstack
6.1 Medium Branda – White Label & Branding, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scripting No login needed ≤ 3.4.21 CVE-2024-9371 Wordfence
6.5 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2024-38771 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-43290 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.01 Fixed in 2.02 CVE-2024-47622 Patchstack
6.4 Medium WordPress Infinite Scroll - Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter ≤ 7.1.2 CVE-2024-8505 Wordfence
5.4 Medium Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Broken Access Control Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 4.0.2 CVE-2024-7621 Wordfence
5.9 Medium Branda Plugin branda-white-labeling Cross-Site Scripting ≤ 3.4.17 Fixed in 3.4.18 CVE-2024-37239 Patchstack
5.9 Medium Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Authenticated Cross Site Scripting (XSS) ≤ 3.31 Fixed in 3.32 CVE-2024-37434 Patchstack
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence
6.4 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.4.17 CVE-2024-5191 Wordfence
6.5 Medium SKU Label Changer For WooCommerce Plugin woo-sku-label-changer Broken Access Control No login needed ≤ 3.0 Fixed in 3.0.1 CVE-2023-29174 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 1.93 Fixed in 1.94 CVE-2024-35675 Patchstack
5.3 Medium Branda Plugin branda-white-labeling Authentication Bypass IP Restriction Bypass No login needed ≤ 3.4.14 Fixed in 3.4.15 CVE-2023-51542 Patchstack
5.3 Medium White Label CMS Plugin white-label-cms Broken Access Control Missing Authorization to Plugin Settings Reset No login needed ≤ 2.7.3 CVE-2024-4280 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
5.9 Medium WooCommerce Shipping Label Plugin shipping-labels-for-woo Cross-Site Scripting ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-32834 Patchstack
6.5 Medium Knight Lab Timeline Plugin knight-lab-timelinejs Cross-Site Scripting ≤ 3.9.3.4 CVE-2024-32554 Patchstack
6.1 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on th… No login needed prior to 3.8.1 CVE-2024-29220 jpcert
6.4 Medium Knight Lab Timeline Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.3.3 CVE-2024-2287 Wordfence
5.9 Medium Easy Login Styler – White Label Admin Login Page Plugin easy-login-styler Cross-Site Scripting ≤ 1.0.6 CVE-2024-31344 Patchstack
5.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 4.4.2 CVE-2024-3216 Wordfence
6.5 Medium Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more Plugin ilab-media-tools Cross-Site Scripting ≤ 4.5.24 Fixed in 4.5.25 CVE-2024-29795 Patchstack
6.1 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.1 CVE-2024-0957 Wordfence
5.4 Medium Scalable Vector Graphics (SVG) Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 3.4 CVE-2023-7085 WPScan
5.9 Medium Product Labels For Woocommerce (Sale Badges) Plugin aco-product-labels-for-woocommerce Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-24886 Patchstack
4.3 Medium White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Plugin white-label Cross-Site Request Forgery WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-52128 Patchstack
4.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin Broken Access Control Missing Authorization to Order Export ≤ 4.3.0 CVE-2023-7068 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only