WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 11,901–11,950 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 239 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium GiveWP Plugin give Broken Access Control Arbitrary Content Deletion ≤ 2.25.1 Fixed in 2.25.2 CVE-2023-23672 Patchstack
5.4 Medium WoodMart Theme woodmart Broken Access Control ≤ 7.2.1 Fixed in 7.2.2 CVE-2023-32240 Patchstack
4.3 Medium ARMember Premium Plugin armember Broken Access Control ≤ 5.9.2 Fixed in 5.9.3 CVE-2023-39994 Patchstack
6.5 Medium Analytify Plugin wp-analytify Privilege Escalation Google Analytics Dashboard plugin <= 4.2.3 - Privilege Escalation No login needed ≤ 4.2.3 Fixed in 4.3.0 CVE-2022-45830 Patchstack
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
5.4 Medium 10Web Map Builder for Google Maps Plugin wd-google-maps Broken Access Control Notice Dismissal ≤ 1.0.73 Fixed in 1.0.74 CVE-2023-45272 Patchstack
6.5 Medium IMPress Listings Plugin wp-listings Broken Access Control No login needed ≤ 2.6.2 CVE-2023-45633 Patchstack
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
4.3 Medium Subscribe to Category Plugin subscribe-to-category Broken Access Control WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to Broken Access Control ≤ 2.7.4 CVE-2022-43476 Patchstack
4.3 Medium LuckyWP Scripts Control Plugin luckywp-scripts-control Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2023-47778 Patchstack
4.3 Medium 10WebAnalytics Plugin wd-google-analytics Broken Access Control ≤ 1.2.12 CVE-2023-47807 Patchstack
5.3 Medium Porto Theme - Functionality Plugin porto-functionality Broken Access Control No login needed ≤ 2.12.1 Fixed in 2.12.1 CVE-2023-48739 Patchstack
7.1 High JetEngine Plugin jet-engine Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-48758 Patchstack
4.3 Medium FS Poster Plugin fs-poster Cross-Site Request Forgery No login needed ≤ 6.5.8 Fixed in 6.5.9 CVE-2024-37237 Patchstack
4.3 Medium WP Job Manager - Resume Manager Plugin wp-job-manager-resumes Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-37241 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Request Forgery No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37438 Patchstack
4.3 Medium Schema Lite Theme schema-lite Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2024-37452 Patchstack
5.4 Medium BuddyBoss Theme buddyboss-theme Cross-Site Request Forgery No login needed ≤ 2.4.61 Fixed in 2.5.01 CVE-2024-37925 Patchstack
4.3 Medium Point Theme point Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-37931 Patchstack
4.3 Medium i-amaze Theme i-amaze Cross-Site Request Forgery No login needed ≤ 1.3.7 CVE-2024-38731 Patchstack
4.3 Medium Patricia Blog Theme patricia-blog Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2024-38732 Patchstack
4.3 Medium i-transform Theme i-transform Cross-Site Request Forgery No login needed ≤ 3.0.9 CVE-2024-38764 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.69.234 Fixed in 1.70.236 CVE-2024-38778 Patchstack
8.8 High ListingPro Theme listingpro Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39623 Patchstack
7.1 High Olivia Theme olivia Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.5 CVE-2024-56014 Patchstack
6.5 Medium Coins MarketCap Plugin coins-marketcap Cross-Site Scripting ≤ 5.5.8 Fixed in 5.5.9 CVE-2024-56257 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56302 Patchstack
7.1 High Interactive UK Map Plugin interactive-uk-map Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2024-56267 Patchstack
6.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.8 Fixed in 5.9 CVE-2024-56266 Patchstack
6.6 Medium ACF City Selector Plugin acf-city-selector Arbitrary File Upload ≤ 1.14.0 Fixed in 1.15.0 CVE-2024-56264 Patchstack
6.5 Medium GS Shots for Dribbble Plugin gs-dribbble-portfolio Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-56263 Patchstack
6.5 Medium GS Coaches Plugin gs-coach Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56262 Patchstack
6.5 Medium Project Showcase Plugin gs-projects Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56261 Patchstack
6.5 Medium ShopElement Plugin shopelement Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-56260 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.84 Fixed in 2.3.85 CVE-2024-56259 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.20 Fixed in 1.3.21 CVE-2024-56258 Patchstack
4.3 Medium AyeCode Connect Plugin ayecode-connect Broken Access Control ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-56255 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
5.4 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.36 Fixed in 1.10.37 CVE-2024-56253 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-56252 Patchstack
4.3 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Cross-Site Request Forgery No login needed ≤ 5.0.28.decaf Fixed in 5.0.31.decaf CVE-2024-56251 Patchstack
7.6 High Just Writing Statistics Plugin just-writing-statistics SQL Injection ≤ 4.7 Fixed in 4.8 CVE-2024-56250 Patchstack
9.1 Critical WPMasterToolKit Plugin wpmastertoolkit Arbitrary File Upload ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56249 Patchstack
4.9 Medium WPMasterToolKit Plugin wpmastertoolkit Path Traversal Arbitrary File Download ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56248 Patchstack
7.6 High WP Post Author Plugin wp-post-author SQL Injection ≤ 3.8.2 Fixed in 3.8.3 CVE-2024-56247 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2024-56246 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
5.4 Medium Ashe Extra Plugin ashe-extra Broken Access Control ≤ 1.2.92 Fixed in 1.3 CVE-2024-56244 Patchstack
4.3 Medium WPSSO Core Plugin wpsso Broken Access Control ≤ 18.18.1 Fixed in 18.18.2 CVE-2024-56243 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only