WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 51–89 of 89 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Newsletter Subscriptions | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2024-11683 |
Wordfence | |
| 4.3 Medium | BlossomThemes Email Newsletter | Broken Access Control |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2023-47849 |
Patchstack | |
| 4.3 Medium | Smart Marketing SMS and Newsletters Forms | Broken Access Control |
≤ 5.0.4 Fixed in 5.0.5 |
CVE-2024-53784 |
Patchstack | |
| 5.3 Medium | Noptin | Broken Access Control Noptin plugin <= 3.4.2 - Broken Access Control No login needed |
≤ 3.4.2 Fixed in 3.4.3 |
CVE-2024-37456 |
Patchstack | |
| 5.3 Medium | Newspack Newsletters | Broken Access Control No login needed |
≤ 2.13.2 Fixed in 2.13.3 |
CVE-2024-37475 |
Patchstack | |
| 6.4 Medium | Newsletters | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode |
≤ 4.9.9.4 |
CVE-2024-10181 |
Wordfence | |
| 4.3 Medium | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) | Cross-Site Request Forgery No login needed |
≤ 3.1.87 |
CVE-2024-8477 |
Wordfence | |
| 5.4 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 5.7.34 |
CVE-2024-8254 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 5.7.34 |
CVE-2024-8771 |
Wordfence | |
| 5.4 Medium | Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin | Cross-Site Scripting MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.70.3 |
CVE-2024-8628 |
Wordfence | |
| 4.3 Medium | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.6.18 Fixed in 2.6.19 |
CVE-2024-39657 |
Patchstack | |
| 4.3 Medium | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue | Cross-Site Request Forgery No login needed |
≤ 3.1.82 Fixed in 3.1.83 |
CVE-2024-43287 |
Patchstack | |
| 5.3 Medium | Newsletters | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 4.9.9 |
CVE-2024-7411 |
Wordfence | |
| 4.3 Medium | Icegram Express - Email Subscribers, Newsletters and Marketing Automation | Broken Access Control Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization |
≤ 5.7.26 |
CVE-2024-5703 |
Wordfence | |
| 4.4 Medium | BlossomThemes Email Newsletter | Server-Side Request Forgery |
≤ 2.2.6 Fixed in 2.2.7 |
CVE-2024-37098 |
Patchstack | |
| 4.3 Medium | Newsletters | Cross-Site Request Forgery No login needed |
≤ 4.9.7 Fixed in 4.9.8 |
CVE-2024-37227 |
Patchstack | |
| 5.3 Medium | SendPress Newsletters | Broken Access Control No login needed |
≤ 1.23.11.6 |
CVE-2023-35040 |
Patchstack | |
| 6.5 Medium | Newsletter - API v1 and v2 addon for Newsletter | Broken Access Control API v1 and v2 addon for Newsletter <= 2.4.5 - Missing Authorization to Email Subscribers Management No login needed |
≤ 2.4.5 |
CVE-2024-5674 |
Wordfence | |
| 5.3 Medium | Email Subscribers & Newsletters | Broken Access Control No login needed |
≤ 5.7.13 Fixed in 5.7.14 |
CVE-2024-31352 |
Patchstack | |
| 6.4 Medium | Newsletter | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via np1 |
≤ 8.3.4 |
CVE-2024-5317 |
Wordfence | |
| 6.4 Medium | Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation | Cross-Site Scripting WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.16.1 |
CVE-2024-4045 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization |
≤ 5.7.17 |
CVE-2024-3626 |
Wordfence | |
| 5.3 Medium | Newsletter | Authentication Bypass IP Blacklist Bypass No login needed |
≤ 8.2.0 Fixed in 8.2.1 |
CVE-2024-30522 |
Patchstack | |
| 4.8 Medium | Newsletter Popup | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.2 |
CVE-2024-3644 |
WPScan | |
| 6.9 Medium | Newsletter Popup | Cross-Site Request Forgery Subscriber Deletion via CSRF |
≤ 1.2 |
CVE-2024-3642 |
WPScan | |
| 6.1 Medium | Newsletter Popup | Cross-Site Scripting Unauthenticated Stored XSS No login needed |
≤ 1.2 |
CVE-2024-3641 |
WPScan | |
| 4.3 Medium | Arigato Autoresponder and Newsletter | Cross-Site Request Forgery No login needed |
≤ 2.7.2.3 Fixed in 2.7.2.4 |
CVE-2024-34823 |
Patchstack | |
| 5.9 Medium | LetterPress | Cross-Site Scripting |
≤ 1.2.1 |
CVE-2024-34568 |
Patchstack | |
| 6.5 Medium | WooCommerce AWeber Newsletter Subscription | Broken Access Control Unauthenticated Access Token Change/Reset No login needed |
≤ 4.0.2 Fixed in 4.0.3 |
CVE-2024-33944 |
Patchstack | |
| 4.5 Medium | ENL Newsletter | SQL Injection Admin+ SQL Injection |
≤ 1.0.1 |
CVE-2024-3060 |
WPScan | |
| 5.7 Medium | ENL Newsletter | Cross-Site Request Forgery Campaign Deletion via CSRF |
≤ 1.0.1 |
CVE-2024-3059 |
WPScan | |
| 5.4 Medium | ENL Newsletter | Cross-Site Scripting Stored XSS via CSRF |
≤ 1.0.1 |
CVE-2024-3058 |
WPScan | |
| 5.8 Medium | EnvÃaloSimple | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2 Fixed in 2.3 |
CVE-2024-32587 |
Patchstack | |
| 5.4 Medium | Newsletter | Cross-Site Request Forgery No login needed |
≤ 8.0.6 Fixed in 8.0.7 |
CVE-2024-31434 |
Patchstack | |
| 6.1 Medium | SendPress Newsletters | Cross-Site Scripting Admin+ Stored XSS via Form Settings No login needed |
≤ 1.23.11.6 |
CVE-2024-1589 |
WPScan | |
| 6.8 Medium | SendPress Newsletters | Cross-Site Scripting Admin+ Stored XSS via Settings |
≤ 1.23.11.6 |
CVE-2024-1588 |
WPScan | |
| 6.5 Medium | EnvÃaloSimple | Cross-Site Request Forgery No login needed |
≤ 2.2 Fixed in 2.3 |
CVE-2023-51416 |
Patchstack | |
| 6.5 Medium | Automation By Autonami | Cross-Site Scripting |
≤ 2.8.2 Fixed in 2.8.3 |
CVE-2024-2580 |
Patchstack | |
| 6.4 Medium | Newsletter2Go | Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via style |
≤ 4.0.14 |
CVE-2024-1328 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.