WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 951–1,000 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Shipping for Nova Poshta Plugin nova-poshta-ttn SQL Injection No login needed ≤ 1.19.6 Fixed in 1.19.7 CVE-2025-24612 Patchstack
9.8 Critical FundPress Plugin fundpress PHP Object Injection No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24601 Patchstack
9.1 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.15.3 Fixed in 2.15.4 CVE-2025-24650 Patchstack
9.8 Critical Muzaara Google Ads Report Plugin muzaara-adwords-optimize-dashboard PHP Object Injection No login needed ≤ 3.1 CVE-2025-23914 Patchstack
10.0 Critical user files Plugin user-files Arbitrary File Upload No login needed ≤ 2.4.2 CVE-2025-23953 Patchstack
9.1 Critical WP Load Gallery Plugin wp-load-gallery Arbitrary File Upload ≤ 2.1.6 CVE-2025-23942 Patchstack
9.8 Critical Quick Count Plugin quick-count PHP Object Injection No login needed ≤ 3.00 CVE-2025-23932 Patchstack
9.3 Critical WordPress Local SEO Plugin dh-local-seo SQL Injection No login needed ≤ 2.3 CVE-2025-23931 Patchstack
9.0 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Arbitrary File Upload No login needed ≤ 1.1.3 Fixed in 1.1.5 CVE-2025-23921 Patchstack
9.9 Critical Smallerik File Browser Plugin smallerik-file-browser Arbitrary File Upload ≤ 1.1 CVE-2025-23918 Patchstack
9.8 Critical WPBot Pro Wordpress Chatbot Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 13.5.4 CVE-2024-13091 Wordfence
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Arbitrary File Upload ≤ 1.6.7 Fixed in 1.7.0 CVE-2025-22723 Patchstack
9.8 Critical Easy Real Estate Plugin easy-real-estate Privilege Escalation No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-32555 Patchstack
9.3 Critical Multiple Carousel Plugin multicarousel SQL Injection No login needed ≤ 2.0 CVE-2025-22553 Patchstack
9.0 Critical Fancy Product Designer Plugin fancy-product-designer Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51919 Patchstack
9.8 Critical Homey Login Register Plugin homey-login-register Privilege Escalation No login needed ≤ 2.4.0 CVE-2024-51888 Patchstack
9.3 Critical Fancy Product Designer Plugin fancy-product-designer SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51818 Patchstack
9.8 Critical ARPrice Plugin arprice PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49688 Patchstack
9.3 Critical ARPrice Plugin arprice SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49655 Patchstack
10.0 Critical iSpring Embedder Plugin embed-ispring Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.0 CVE-2025-23922 Patchstack
9.8 Critical WP Options Editor Plugin wp-options-editor Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.1 CVE-2025-23797 Patchstack
9.9 Critical WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Remote Code Execution ≤ 1.0.8 CVE-2025-22782 Patchstack
9.3 Critical Course Booking System Plugin course-booking-system SQL Injection No login needed ≤ 6.0.6 Fixed in 6.0.7 CVE-2025-22785 Patchstack
9.8 Critical GiveWP Plugin give PHP Object Injection No login needed ≤ 3.19.3 Fixed in 3.19.4 CVE-2025-22777 Patchstack
10.0 Critical 4ECPS Web Forms Plugin 4ecps-webforms Arbitrary File Upload No login needed ≤ 0.2.18 CVE-2025-22504 Patchstack
9.3 Critical Emailing Subscription Plugin email-suscripcion SQL Injection No login needed ≤ 1.4.1 CVE-2025-22540 Patchstack
9.3 Critical Virtual Bot Plugin virtual-bot SQL Injection No login needed ≤ 1.0.0 CVE-2025-22542 Patchstack
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unuathenticated Remote Code Execution No login needed ≤ 4.24.12 CVE-2024-11635 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion No login needed ≤ 4.24.15 CVE-2024-11613 Wordfence
10.0 Critical JobBoard Job listing Plugin job-board-light Arbitrary File Upload No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-43243 Patchstack
9.8 Critical WPGuppy Plugin wpguppy-lite PHP Object Injection No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-49222 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2024-49649 Patchstack
9.1 Critical WP Ultimate Exporter Plugin wp-ultimate-exporter Remote Code Execution ≤ 2.9.1 Fixed in 2.9.2 CVE-2024-56278 Patchstack
9.3 Critical SSL Wireless SMS Notification Plugin ssl-wireless-sms-notification SQL Injection No login needed ≤ 3.5.0 Fixed in 3.6.0 CVE-2024-56284 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2 Fixed in 1.3 CVE-2024-56290 Patchstack
9.8 Critical WordPress Auction Plugin SQL Injection Editor+ SQL Injection No login needed ≤ 3.7 CVE-2024-8855 WPScan
9.1 Critical WPMasterToolKit Plugin wpmastertoolkit Arbitrary File Upload ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56249 Patchstack
9.8 Critical Agency Toolkit Plugin agency-toolkit Privilege Escalation No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-56066 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56045 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Authentication Bypass Unauthenticated Arbitrary User Token Generation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56044 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56043 Patchstack
9.8 Critical VibeBP Plugin vibebp Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9.4.1 Fixed in 1.9.9.5 CVE-2024-56040 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56042 Patchstack
9.3 Critical VibeBP Plugin vibebp SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.7.7 Fixed in 1.9.9.7.7 CVE-2024-56039 Patchstack
10.0 Critical WP SuperBackup Plugin indeed-wp-superbackup Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56064 Patchstack
10.0 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56046 Patchstack
9.8 Critical Simple Dashboard Plugin simple-dashboard Privilege Escalation No login needed ≤ 2.0 CVE-2024-56071 Patchstack
9.8 Critical AI Magic Plugin newsletter-page-redirects Privilege Escalation SEO Content Generator & Article Writer plugin <= 1.0.4 - Privilege Escalation No login needed ≤ 1.0.4 Fixed in 1.0.6 CVE-2024-56205 Patchstack
9.8 Critical SSL Wireless SMS Notification Plugin ssl-wireless-sms-notification Privilege Escalation No login needed ≤ 3.6.0 Fixed in 3.7.0 CVE-2024-56220 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56050 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only