WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,101–1,150 of 1,401 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | WordPress User Extra Fields | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 16.6 |
CVE-2024-11150 |
Wordfence | |
| 10.0 Critical | The Novel Design Store Directory | Arbitrary File Upload No login needed |
≤ 4.3.0 |
CVE-2024-51788 |
Patchstack | |
| 10.0 Critical | Image Classify | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-51789 |
Patchstack | |
| 10.0 Critical | HB AUDIO GALLERY | Arbitrary File Upload No login needed |
≤ 3.0 |
CVE-2024-51790 |
Patchstack | |
| 10.0 Critical | Forms | Arbitrary File Upload No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2024-51791 |
Patchstack | |
| 10.0 Critical | Audio Record | Arbitrary File Upload No login needed |
≤ 1.0 |
CVE-2024-51792 |
Patchstack | |
| 10.0 Critical | RepairBuddy | Arbitrary File Upload No login needed |
≤ 3.8115 Fixed in 3.8116 |
CVE-2024-51793 |
Patchstack | |
| 9.8 Critical | WordPress User Extra Fields | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 16.5 |
CVE-2024-10801 |
Wordfence | |
| 9.8 Critical | WPLMS Learning Management System | Path Traversal Unauthenticated Arbitrary File Read and Deletion No login needed |
≤ 4.962 |
CVE-2024-10470 |
Wordfence | |
| 10.0 Critical | All Post Contact Form | Arbitrary File Upload No login needed |
≤ 1.8.2 |
CVE-2024-50523 |
Patchstack | |
| 10.0 Critical | Helloprint | Arbitrary File Upload No login needed |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2024-50525 |
Patchstack | |
| 10.0 Critical | Multi Purpose Mail Form | Arbitrary File Upload No login needed |
≤ 1.0.2 |
CVE-2024-50526 |
Patchstack | |
| 10.0 Critical | Stacks Mobile App Builder | Arbitrary File Upload No login needed |
≤ 5.2.3 |
CVE-2024-50527 |
Patchstack | |
| 9.9 Critical | Training – Courses | Arbitrary File Upload Courses plugin <= 2.0.1 - Arbitrary File Upload |
≤ 2.0.1 |
CVE-2024-50529 |
Patchstack | |
| 9.9 Critical | Stars SMTP Mailer | Arbitrary File Upload |
≤ 2.2.1 |
CVE-2024-50530 |
Patchstack | |
| 10.0 Critical | RSVPMaker for Toastmasters | Arbitrary File Upload No login needed |
≤ 6.2.4 Fixed in 6.2.5 |
CVE-2024-50531 |
Patchstack | |
| 9.1 Critical | Media LIbrary Assistant | Remote Code Execution |
≤ 3.19 Fixed in 3.20 |
CVE-2024-51661 |
Patchstack | |
| 9.6 Critical | Podlove Podcast Publisher | Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed |
≤ 4.1.13 Fixed in 4.1.14 |
CVE-2024-43984 |
Patchstack | |
| 9.6 Critical | EKC Tournament Manager | Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed |
≤ 2.2.1 Fixed in 2.2.2 |
CVE-2024-49674 |
Patchstack | |
| 10.0 Critical | AR For Woocommerce | Arbitrary File Upload No login needed |
≤ 6.3 Fixed in 7.0 |
CVE-2024-50510 |
Patchstack | |
| 9.9 Critical | WP donimedia carousel | Arbitrary File Upload |
≤ 1.0.1 |
CVE-2024-50511 |
Patchstack | |
| 9.8 Critical | DS.DownloadList | PHP Object Injection No login needed |
≤ 1.3 |
CVE-2024-50507 |
Patchstack | |
| 9.8 Critical | User Toolkit | Privilege Escalation Account Takeover No login needed |
≤ 1.2.3 Fixed in 1.2.4 |
CVE-2024-50503 |
Patchstack | |
| 9.8 Critical | Signup Page | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0 |
CVE-2024-50475 |
Patchstack | |
| 9.8 Critical | GRÜN spendino Spendenformular | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0.1 |
CVE-2024-50476 |
Patchstack | |
| 9.8 Critical | Exam Matrix | Privilege Escalation No login needed |
≤ 1.5 |
CVE-2024-50485 |
Patchstack | |
| 9.8 Critical | PegaPoll | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0.2 |
CVE-2024-50490 |
Patchstack | |
| 10.0 Critical | aDirectory | Arbitrary File Upload No login needed |
≤ 1.3 Fixed in 1.3.1 |
CVE-2024-50420 |
Patchstack | |
| 9.9 Critical | SurveyJS | Arbitrary File Upload |
≤ 1.9.136 Fixed in 1.12.4 |
CVE-2024-50427 |
Patchstack | |
| 10.0 Critical | Ajar in5 Embed | Arbitrary File Upload No login needed |
≤ 3.1.3 Fixed in 3.1.4 |
CVE-2024-50473 |
Patchstack | |
| 9.9 Critical | Marketing Automation by AZEXO | Arbitrary File Upload |
≤ 1.27.80 |
CVE-2024-50480 |
Patchstack | |
| 10.0 Critical | Woocommerce Product Design | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-50482 |
Patchstack | |
| 10.0 Critical | Multi Purpose Mail Form | Arbitrary File Upload No login needed |
≤ 1.0.2 |
CVE-2024-50484 |
Patchstack | |
| 10.0 Critical | Automatic Translation | Arbitrary File Upload No login needed |
≤ 1.0.4 |
CVE-2024-50493 |
Patchstack | |
| 10.0 Critical | Sudan Payment Gateway for WooCommerce | Arbitrary File Upload No login needed |
≤ 1.2.2 |
CVE-2024-50494 |
Patchstack | |
| 10.0 Critical | Plugin Propagator | Arbitrary File Upload No login needed |
≤ 0.1 |
CVE-2024-50495 |
Patchstack | |
| 10.0 Critical | AR | Arbitrary File Upload No login needed |
≤ 6.6 Fixed in 7.0 |
CVE-2024-50496 |
Patchstack | |
| 9.3 Critical | Woocommerce Quote Calculator | SQL Injection No login needed |
≤ 1.1 |
CVE-2024-50479 |
Patchstack | |
| 9.3 Critical | RSVP ME | SQL Injection No login needed |
≤ 1.9.9 |
CVE-2024-50491 |
Patchstack | |
| 9.8 Critical | 1-Click Login: Passwordless Authentication | Authentication Bypass Broken Authentication No login needed |
1.4.5 |
CVE-2024-50478 |
Patchstack | |
| 9.8 Critical | Meetup | Authentication Bypass Broken Authentication No login needed |
≤ 0.1 |
CVE-2024-50483 |
Patchstack | |
| 10.0 Critical | WP Query Console | Remote Code Execution No login needed |
≤ 1.0 |
CVE-2024-50498 |
Patchstack | |
| 9.8 Critical | Stacks Mobile App Builder | Privilege Escalation Account Takeover No login needed |
≤ 5.2.3 |
CVE-2024-50477 |
Patchstack | |
| 9.8 Critical | Acnoo Flutter API | Privilege Escalation Account Takeover No login needed |
≤ 1.0.5 |
CVE-2024-50486 |
Patchstack | |
| 9.8 Critical | MaanStore API | Privilege Escalation Account Takeover No login needed |
≤ 1.0.1 |
CVE-2024-50487 |
Patchstack | |
| 9.8 Critical | Realty Workstation | Privilege Escalation Account Takeover No login needed |
≤ 1.0.45 |
CVE-2024-50489 |
Patchstack | |
| 9.8 Critical | Wp Social Login and Register Social Counter | Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed |
≤ 3.0.7 |
CVE-2024-9501 |
Wordfence | |
| 9.8 Critical | Comments – wpDiscuz | Authentication Bypass wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider No login needed |
≤ 7.6.24 |
CVE-2024-9488 |
Wordfence | |
| 9.3 Critical | WP Sessions Time Monitoring Full Automatic | SQL Injection No login needed |
≤ 1.0.9 Fixed in 1.1.0 |
CVE-2024-49681 |
Patchstack | |
| 9.9 Critical | 3D Work In Progress | Arbitrary File Upload |
≤ 1.0.3 |
CVE-2024-49652 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.