WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,651–11,700 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 234 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control ≤ 7.6.3 Fixed in 7.6.4 CVE-2023-45760 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2023-45649 Patchstack
5.4 Medium WordPress Backup & Migration Plugin wp-migration-duplicator Broken Access Control ≤ 1.4.1 Fixed in 1.4.2 CVE-2023-45636 Patchstack
4.3 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2023-45631 Patchstack
6.5 Medium Kali Forms Plugin kali-forms Broken Access Control ≤ 2.3.28 Fixed in 2.3.29 CVE-2023-45275 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control No login needed ≤ 2.7.8 Fixed in 3.0.0 CVE-2023-45271 Patchstack
4.3 Medium Bold Timeline Lite Plugin bold-timeline-lite Broken Access Control ≤ 1.1.9 Fixed in 1.2.0 CVE-2023-45110 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control ≤ 5.36.0 Fixed in 5.36.1 CVE-2023-45101 Patchstack
5.3 Medium WP Job Openings Plugin wp-job-openings Broken Access Control No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2023-45061 Patchstack
5.4 Medium WP Custom Widget area Plugin wp-custom-widget-area Broken Access Control ≤ 1.2.5 CVE-2023-45045 Patchstack
4.3 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control ≤ 3.6.8 Fixed in 3.6.9 CVE-2023-45002 Patchstack
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.32 Fixed in 7.33 CVE-2023-44988 Patchstack
5.3 Medium Schema App Structured Data Plugin schema-app-structured-data-for-schemaorg Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.23.1 Fixed in 1.23.2 CVE-2023-44258 Patchstack
6.5 Medium Inline Footnotes Plugin inline-footnotes Cross-Site Scripting ≤ 2.3.0 CVE-2024-56019 Patchstack
4.7 Medium AHAthat Plugin Cross-Site Scripting Reflected XSS via REQUEST_URI No login needed ≤ 1.6 CVE-2024-12595 WPScan
5.9 Medium Goodlayers Core Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.0.10 Fixed in 2.0.10 CVE-2024-11357 WPScan
4.8 Medium WP Enabled SVG Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 0.7 CVE-2024-11184 WPScan
6.5 Medium SvegliaT Buttons Plugin svegliat-buttons Cross-Site Scripting ≤ 1.3.0 CVE-2024-56020 Patchstack
6.5 Medium Category Post Shortcode Plugin category-post-shortcode Cross-Site Scripting ≤ 2.4 CVE-2024-56021 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.987 Fixed in 1.7.1 CVE-2024-56062 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
5.4 Medium Landing Page Cat Plugin landing-page-cat Broken Access Control ≤ 1.7.4 Fixed in 1.7.5 CVE-2024-49686 Patchstack
4.3 Medium Smart Manager Plugin smart-manager-for-wp-e-commerce Broken Access Control ≤ 8.45.0 Fixed in 8.46.0 CVE-2024-49687 Patchstack
5.3 Medium My Wp Brand Plugin my-wp-brand Broken Access Control Hide menu & Hide Plugin plugin <= 1.1.2 - Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-49694 Patchstack
4.3 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-49698 Patchstack
4.3 Medium Paytium Plugin paytium Broken Access Control ≤ 4.4.10 Fixed in 4.4.11 CVE-2024-51667 Patchstack
6.5 Medium Torod Plugin torod Broken Access Control Settings Change No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-55995 Patchstack
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Broken Access Control MightyForms plugin <= 1.3.9 - Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2024-56002 Patchstack
6.5 Medium WP-CRM System Plugin wp-crm-system Broken Access Control WP-CRM System plugin <= 3.2.9.1 - Broken Access Control No login needed ≤ 3.2.9.1 Fixed in 3.4.0 CVE-2024-55991 Patchstack
6.5 Medium Smart Shopify Product Plugin smart-shopify-product Broken Access Control Arbitrary Content Deletion ≤ 1.0.2 CVE-2024-56031 Patchstack
5.3 Medium WP Cleanfix Plugin wp-cleanfix Broken Access Control No login needed ≤ 5.6.2 Fixed in 5.7.0 CVE-2023-48775 Patchstack
4.3 Medium WooCommerce Subscriptions Plugin woocommerce-subscriptions Broken Access Control < 5.8.0 Fixed in 5.8.0 CVE-2023-50850 Patchstack
6.5 Medium WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-56221 Patchstack
6.5 Medium Ledenbeheer Plugin ledenbeheer-external-connection Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-56224 Patchstack
6.5 Medium SaasPricing Plugin saaspricing Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-56231 Patchstack
5.4 Medium VW Automobile Lite Plugin vw-automobile-lite Broken Access Control ≤ 2.1 CVE-2024-56234 Patchstack
4.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56227 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control ≤ 4.0.6.1 Fixed in 4.0.8 CVE-2024-56219 Patchstack
4.3 Medium Download Manager Plugin download-manager Broken Access Control ≤ 3.3.03 Fixed in 3.3.04 CVE-2024-56217 Patchstack
4.3 Medium Member Directory and Contact Form Plugin pta-member-directory Broken Access Control ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-56215 Patchstack
6.5 Medium Coupon Plugin coupon-lite Cross-Site Scripting ≤ 1.2.2 CVE-2024-56235 Patchstack
5.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Cross-Site Scripting ≤ 2.3.1 Fixed in 2.4.0 CVE-2024-56256 Patchstack
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Request Forgery Dynamic Text Extension plugin <= 5.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.0.1 Fixed in 5.0.2 CVE-2024-56218 Patchstack
5.4 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56222 Patchstack
4.3 Medium SearchIQ Plugin searchiq Cross-Site Request Forgery No login needed ≤ 4.6 Fixed in 4.7 CVE-2024-56229 Patchstack
6.5 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 4.0.7 Fixed in 4.0.9 CVE-2024-56213 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Local File Inclusion ≤ 7.6.3 Fixed in 7.6.5 CVE-2024-56216 Patchstack
6.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Arbitrary Shortcode Execution The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.8.22 CVE-2024-12238 Wordfence
4.8 Medium Give Plugin paystack-for-give Cross-Site Scripting Reflected XSS < 3.19.0 Fixed in 3.19.0 CVE-2024-11921 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only