WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,901–11,950 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 239 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Quran Phrases About Most People Shortcodes Plugin quran-phrases-about-most-people-shortcodes Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2024-54334 Patchstack
6.5 Medium GEO my Plugin geo-my-wp Broken Access Control ≤ 4.5.0.4 Fixed in 4.5.1 CVE-2024-54326 Patchstack
5.4 Medium New User Approve Plugin new-user-approve Broken Access Control ≤ 2.6.2 Fixed in 2.6.4 CVE-2024-54323 Patchstack
4.3 Medium Hive Support Plugin hive-support Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-54321 Patchstack
6.5 Medium NiceJob Plugin nicejob Cross-Site Scripting ≤ 3.6.5 Fixed in 3.7.2 CVE-2024-54318 Patchstack
6.5 Medium Web Stories Plugin web-stories Cross-Site Scripting ≤ 1.37.0 Fixed in 1.38.0 CVE-2024-54317 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54316 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-54315 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.2 CVE-2024-54314 Patchstack
6.5 Medium FULL Customer Plugin full-customer Local File Inclusion Cliente plugin <= 3.1.25 - Local File Inclusion ≤ 3.1.25 Fixed in 3.1.26 CVE-2024-54313 Patchstack
5.4 Medium Mark New Posts Plugin mark-new-posts Broken Access Control ≤ 7.5.1 Fixed in 7.6 CVE-2024-54311 Patchstack
5.3 Medium Gou Manage My Account Menu Plugin gou-wc-account-tabs Broken Access Control No login needed ≤ 1.0.1.8 Fixed in 1.0.1.9 CVE-2024-54310 Patchstack
6.5 Medium PostBox Plugin postbox-email-logs Information Disclosure Sensitive Data Exposure ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-54309 Patchstack
5.9 Medium Cryptocurrency Price Widget Plugin cryptocurrency-price-widget Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-54308 Patchstack
4.3 Medium AIcomments Plugin aicomments Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-54307 Patchstack
4.3 Medium AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot Plugin ai-seo-translator Cross-Site Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-54306 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Cross-Site Request Forgery No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-54300 Patchstack
4.3 Medium Car Dealer Plugin cardealer Broken Access Control ≤ 4.46 Fixed in 4.48 CVE-2024-54298 Patchstack
6.5 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-54289 Patchstack
6.5 Medium Advanced Blog Post Block Plugin advanced-blog-post-block Cross-Site Scripting ≤ 1.0.4 CVE-2024-54287 Patchstack
6.5 Medium Smaily for WP Plugin smaily-for-wp Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2024-54286 Patchstack
4.3 Medium News Ticker for Elementor Plugin news-ticker-for-elementor Broken Access Control ≤ 2.1.3 CVE-2024-54278 Patchstack
6.5 Medium Nias course Plugin nias-course Cross-Site Scripting ≤ 1.2.10 CVE-2024-54277 Patchstack
6.5 Medium Poll Builder Plugin poll-builder Cross-Site Scripting ≤ 1.3.5 CVE-2024-54276 Patchstack
6.5 Medium Radius Blocks Plugin radius-blocks Cross-Site Scripting ≤ 2.1.2 Fixed in 2.2.0 CVE-2024-54272 Patchstack
5.4 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Settings Change ≤ 8.0.2 CVE-2024-54271 Patchstack
4.3 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Broken Access Control ≤ 1.64.0 Fixed in 1.64.1 CVE-2024-54268 Patchstack
4.3 Medium CM Answers Plugin cm-answers Broken Access Control ≤ 3.2.6 Fixed in 3.2.7 CVE-2024-54267 Patchstack
6.5 Medium DELUCKS SEO Plugin delucks-seo Path Traversal Arbitrary File Download ≤ 2.7.0 CVE-2024-54259 Patchstack
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Cross-Site Scripting ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-54250 Patchstack
6.5 Medium FAQs Plugin faqs Cross-Site Scripting ≤ 1.0.2 CVE-2024-54246 Patchstack
6.5 Medium Clients Plugin clients Cross-Site Scripting ≤ 1.1.4 CVE-2024-54245 Patchstack
6.5 Medium Easy Replace Plugin easy-replace Cross-Site Scripting ≤ 1.3 CVE-2024-54244 Patchstack
6.5 Medium Echoza Plugin echoza Cross-Site Scripting ≤ 0.1.1 CVE-2024-54243 Patchstack
6.5 Medium Simple Notification Plugin simple-notification Broken Access Control ≤ 1.3 CVE-2024-54242 Patchstack
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium Comment Blacklist Updater Plugin comment-blacklist-updater Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.2.0 CVE-2023-44147 Patchstack
5.4 Medium Inactive Logout Plugin inactive-logout Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2023-44142 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.3 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control ≤ 4.6.14 Fixed in 4.6.15 CVE-2023-41951 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-41875 Patchstack
4.3 Medium SAML SP Single Sign On Plugin miniorange-saml-20-single-sign-on Broken Access Control SSO Login plugin <= 5.0.4 - Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2023-41873 Patchstack
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2023-41870 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.4 Fixed in 0.6.2.5 CVE-2023-41869 Patchstack
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Slider Pro Plugin sliderpro Broken Access Control ≤ 4.8.6 Fixed in 4.8.7 CVE-2023-41865 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.0 Fixed in 14.1 CVE-2023-41862 Patchstack
5.4 Medium Click To Tweet Plugin click-to-tweet Broken Access Control No login needed ≤ 2.0.14 CVE-2023-41857 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only