WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,001–1,050 of 1,492 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 21 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.3 Medium W3SPEEDSTER Plugin w3speedster-wp Cross-Site Request Forgery No login needed ≤ 7.25 Fixed in 7.27 CVE-2024-52392 Patchstack
5.4 Medium ARMember Plugin armember-membership Cross-Site Request Forgery No login needed ≤ 4.0.5, < 6.7.1 Fixed in 4.0.6 CVE-2022-47424 Patchstack
4.3 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-43338 Patchstack
4.3 Medium Manage User Columns Plugin manage-user-columns Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51686 Patchstack
4.3 Medium Disable Admin Notices individually Plugin disable-admin-notices Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-52420 Patchstack
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
4.1 Medium Post From Frontend Plugin Cross-Site Request Forgery Post Deletion via CSRF ≤ 1.0.0 CVE-2024-9689 WPScan
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Broken Access Control + CSRF ≤ 4.24.7 Fixed in 4.24.8 CVE-2024-39639 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43118 Patchstack
5.4 Medium Clearfy Cache Plugin clearfy Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2024-43260 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
4.3 Medium DarkMySite – Advanced Dark Mode Plugin darkmysite Cross-Site Request Forgery Advanced Dark Mode Plugin for WordPress plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.8 CVE-2024-50466 Patchstack
6.1 Medium PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip Plugin 3d-flipbook-dflip-lite Cross-Site Scripting DearFlip <= 2.3.32 - Reflected Cross-Site Scripting No login needed ≤ 2.3.32 CVE-2024-8717 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
6.4 Medium RSS Feed Widget Plugin rss-feed-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via rfw-youtube-videos Shortcode ≤ 2.9.9 CVE-2024-10057 Wordfence
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
6.5 Medium Featured Posts with Multiple Custom Groups (FPMCG) Plugin featured-posts-with-multiple-custom-groups-fpmcg Cross-Site Request Forgery No login needed ≤ 4.0 CVE-2024-48031 Patchstack
5.4 Medium Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery CSRF No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-48037 Patchstack
4.3 Medium wp-Monalisa Plugin wp-monalisa Cross-Site Request Forgery No login needed ≤ 6.4 Fixed in 6.5 CVE-2024-48038 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
5.4 Medium TinyPNG Plugin tiny-compress-images Cross-Site Request Forgery No login needed ≤ 3.4.3 Fixed in 3.4.4 CVE-2024-47635 Patchstack
6.4 Medium Memberful – Membership Plugin memberful-wp Cross-Site Scripting Membership Plugin <= 1.73.7 - Authenticated (contributor+) Stored Cross-Site Scripting ≤ 1.73.7 CVE-2024-9242 Wordfence
4.3 Medium Use Any Font Plugin use-any-font Cross-Site Request Forgery No login needed ≤ 6.3.08 Fixed in 6.3.09 CVE-2024-47305 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
4.3 Medium adstxt Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0.0 CVE-2024-7892 WPScan
4.8 Medium Posts reminder Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 0.20 CVE-2024-8093 WPScan
5.4 Medium Accordion Image Menu Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 3.1.3 CVE-2024-8092 WPScan
4.8 Medium Enhanced Search Box Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 0.6.1 CVE-2024-8091 WPScan
4.8 Medium Review Ratings Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.6 CVE-2024-8052 WPScan
5.7 Medium Special Feed Items Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.0.1 CVE-2024-8051 WPScan
5.7 Medium Visual Sound (old) Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 1.06 CVE-2024-8047 WPScan
5.7 Medium infolinks Ad Wrap Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 1.0.2 CVE-2024-8044 WPScan
5.7 Medium Vikinghammer Tweet Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 0.2.4 CVE-2024-8043 WPScan
6.5 Medium Favicon Generator Plugin Arbitrary File Deletion Arbitrary File Deletion via CSRF No login needed < 2.1 Fixed in 2.1 CVE-2024-7864 WPScan
6.1 Medium MM-Breaking News Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.7.9 CVE-2024-8054 WPScan
4.3 Medium Blog Introduction Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.3.0 CVE-2024-7862 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only