WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 12,051–12,100 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 242 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
6.4 Medium WordPress Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.7 CVE-2024-12622 Wordfence
6.1 Medium Bitcoin Lightning Publisher Plugin bitcoin-lightning-publisher Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.1 CVE-2024-12100 Wordfence
8.8 High eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Request Forgery Cross-Site Request Forgery to Password Reset No login needed ≤ 3.3.43 CVE-2024-12771 Wordfence
6.4 Medium NACC Plugin nacc-wordpress-plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.0 CVE-2024-12506 Wordfence
6.4 Medium Sell Tickets Online – TicketSource Ticket Shop Plugin ticketsource-events Cross-Site Scripting TicketSource Ticket Shop for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.0.2 CVE-2024-11784 Wordfence
5.3 Medium Page Restriction WordPress (WP) – Protect WP Pages/Post Plugin page-and-post-restriction Information Disclosure Protect WP Pages/Post <= 1.3.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.3.6 CVE-2024-11297 Wordfence
6.5 Medium Fusion Plugin fusion Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37962 Patchstack
8.5 High WPLMS Plugin wplms_plugin SQL Injection Subscriber+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56047 Patchstack
7.6 High WPLMS Plugin wplms_plugin SQL Injection Instructor+ SQL Injection ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56053 Patchstack
8.8 High WPLMS Plugin wplms_plugin Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56048 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Subscriber+ Arbitrary File Upload ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56050 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Student+ Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56052 Patchstack
9.1 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Instructor+ Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56054 Patchstack
9.9 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56057 Patchstack
7.1 High Advance Menu Manager Plugin advance-menu-manager Broken Access Control Settings Change ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-54381 Patchstack
9.8 Critical WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Authentication Bypass PDF Vouchers plugin < 4.9.9 - Broken Authentication No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-54383 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56049 Patchstack
8.5 High WPLMS Plugin wplms_plugin Arbitrary File Deletion Arbitrary Directory Deletion ≤ 1.9.9.5.2 Fixed in 1.9.9.5.2 CVE-2024-56055 Patchstack
8.5 High WPLMS Plugin wplms_plugin Remote Code Execution Student+ Remote Code Execution (RCE) ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56051 Patchstack
6.5 Medium WP Menu Image Plugin wp-menu-image Broken Access Control No login needed ≤ 2.2 Fixed in 2.3 CVE-2024-52485 Patchstack
6.5 Medium Order Delivery & Pickup Location Date Time Plugin order-delivery-pickup-location-date-time-free-version Broken Access Control Settings Change No login needed ≤ 1.1.0 CVE-2024-55997 Patchstack
7.1 High Saoshyant Element Plugin saoshyant-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-51646 Patchstack
7.1 High Bootstrap Buttons Plugin bootstrap-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49677 Patchstack
7.1 High Device Detector Plugin device-detector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2024-56010 Patchstack
7.1 High hmd Plugin hmd Cross-Site Scripting No login needed ≤ 2.0 Fixed in 2.2 CVE-2024-54350 Patchstack
7.1 High Image Mapper Plugin image-mapper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.5.3 CVE-2024-56016 Patchstack
8.5 High Dr Affiliate Plugin dr-affiliate SQL Injection ≤ 1.2.3 CVE-2024-55975 Patchstack
8.5 High Saksh Escrow System Plugin saksh-escrow-system SQL Injection ≤ 2.4 CVE-2024-55984 Patchstack
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack
8.5 High YDS Support Ticket System Plugin yds-support-ticket-system SQL Injection ≤ 1.0 CVE-2024-55985 Patchstack
9.8 Critical VRPConnector Plugin vrpconnector PHP Object Injection No login needed ≤ 2.0.1 CVE-2024-56058 Patchstack
8.1 High Axeptio Plugin axeptio-sdk-integration Local File Inclusion No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-54270 Patchstack
9.8 Critical Partners Plugin partners PHP Object Injection No login needed ≤ 0.2.0 CVE-2024-56059 Patchstack
7.5 High Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56008 Patchstack
8.8 High CRM WordPress Plugin – RepairBuddy Plugin Broken Access Control RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation ≤ 3.8120 CVE-2024-12259 Wordfence
6.1 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via 'number' No login needed ≤ 1.4.7 CVE-2024-12395 Wordfence
6.1 Medium Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS Plugin sikshya Cross-Site Scripting Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter No login needed ≤ 0.0.21 CVE-2024-12127 Wordfence
6.4 Medium CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Plugin support-x Cross-Site Scripting WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.6 CVE-2024-12443 Wordfence
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.23 Fixed in 1.24 CVE-2024-56017 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed ≤ 7.11.10 Fixed in 7.11.11 CVE-2024-54357 Patchstack
7.5 High EazyDocs Plugin eazydocs Local File Inclusion ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-54376 Patchstack
4.3 Medium Caldera SMTP Mailer Plugin caldera-smtp-mailer Broken Access Control ≤ 1.0.1 CVE-2024-56003 Patchstack
5.3 Medium XML Multilanguage Sitemap Generator Plugin xml-multilanguage-sitemap-generator Broken Access Control No login needed ≤ 2.0.6 CVE-2024-55999 Patchstack
6.5 Medium Brand Plugin brand Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-54348 Patchstack
9.1 Critical SeedProd Pro Plugin seedprod-coming-soon-pro-5 Remote Code Execution ≤ 6.18.10 CVE-2024-54285 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54284 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54283 Patchstack
9.3 Critical WPBookit Plugin wpbookit SQL Injection No login needed ≤ 1.6.0 CVE-2024-54280 Patchstack
7.5 High WP-NERD Toolkit Plugin wp-nerd-toolkit Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-54279 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only