WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 12,301–12,350 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 247 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Alt Manager Plugin alt-manager Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2023-50373 Patchstack
4.3 Medium Product Filter by WBW Plugin woo-product-filter Broken Access Control ≤ 2.5.0 Fixed in 2.5.1 CVE-2023-50877 Patchstack
5.3 Medium Google Language Translator Plugin google-language-translator Broken Access Control Google Language Translator plugin <= 6.0.19 - Broken Access Control No login needed ≤ 6.0.19 Fixed in 6.0.20 CVE-2023-50375 Patchstack
4.3 Medium Molongui Plugin molongui-authorship Broken Access Control ≤ 4.7.3 Fixed in 4.7.4 CVE-2023-50876 Patchstack
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.2 Fixed in 4.13.3 CVE-2023-50882 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2023-50884 Patchstack
5.3 Medium User Feedback Plugin userfeedback-lite Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2023-50887 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Broken Access Control No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2023-50904 Patchstack
5.3 Medium Metform Plugin metform Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2023-50903 Patchstack
5.3 Medium Popup by Supsystic Plugin popup-by-supsystic Broken Access Control No login needed ≤ 1.10.19 Fixed in 1.10.20 CVE-2023-51353 Patchstack
5.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control No login needed ≤ 6.5.0 Fixed in 6.5.1 CVE-2023-51357 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control Multiple Subscriber+ Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-51360 Patchstack
5.4 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control Multiple Contributor+ Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-51359 Patchstack
5.3 Medium My Sticky Elements Plugin mystickyelements Broken Access Control No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2023-51362 Patchstack
5.3 Medium Redirects Plugin redirects Broken Access Control No login needed ≤ 1.2.1 CVE-2023-49845 Patchstack
6.1 Medium Contact Form Plugin by Fluent Forms Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 5.2.1 Fixed in 5.2.1 CVE-2024-9651 WPScan
6.1 Medium Feedpress Generator – External RSS Frontend Customizer Plugin feedpress-generator Cross-Site Scripting External RSS Frontend Customizer <= 1.2.1 - Reflected Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2024-11457 Wordfence
6.4 Medium Mini Program API Plugin wp-mini-program Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.5 CVE-2024-11380 Wordfence
6.1 Medium Easy Code Snippets Plugin easy-code-snippets Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.2 CVE-2024-11464 Wordfence
6.1 Medium Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal Plugin simple-e-commerce-shopping-cart Cross-Site Scripting Reflected Cross-Site Scripting via monthly_sales_current_year Parameter No login needed ≤ 3.1.2 CVE-2024-12128 Wordfence
6.1 Medium Smoove connector for Elementor forms Plugin smoove-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.0 CVE-2024-11367 Wordfence
6.1 Medium TWChat – Send or receive messages from users Plugin twchat Cross-Site Scripting Send or receive messages from users <= 4.0.4 - Reflected Cross-Site Scripting No login needed ≤ 4.0.4 CVE-2024-11374 Wordfence
5.4 Medium Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal Plugin simple-e-commerce-shopping-cart Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update / Data Access ≤ 3.1.2 CVE-2024-12253 Wordfence
4.8 Medium Simple Side Tab Plugin simple-side-tab Cross-Site Scripting Admin+ Stored XSS < 2.2.0 Fixed in 2.2.0 CVE-2024-11183 WPScan
6.8 Medium Library Management System Plugin library-management-system SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.1 CVE-2024-8679 Wordfence
5.3 Medium If Menu Plugin if-menu Broken Access Control Missing Authorization to License Key Update No login needed ≤ 0.19.1 CVE-2024-7894 Wordfence
6.1 Medium Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross-Site Scripting via _wpnonce No login needed ≤ 2.2.0 CVE-2024-12167 Wordfence
4.3 Medium Poll Maker Plugin poll-maker Cross-Site Request Forgery Cross-Site Request Forgery to Poll Duplication No login needed ≤ 5.5.4 CVE-2024-12115 Wordfence
6.1 Medium CardGate Payments for WooCommerce Plugin cardgate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12257 Wordfence
6.1 Medium Mollie for Contact Form 7 Plugin cf7-mollie Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.0.0 CVE-2024-12165 Wordfence
4.3 Medium SMS for Lead Capture Forms Plugin clicksend-lead-capture-form Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Message Deletion ≤ 1.1.0 CVE-2024-11353 Wordfence
6.1 Medium Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed ≤ 2.2.0 CVE-2024-12166 Wordfence
4.3 Medium Message Filter for Contact Form 7 Plugin cf7-message-filter Broken Access Control Missing Authorization to Authenticated (Subscriber+) New Filter Creation ≤ 1.6.3 CVE-2024-12026 Wordfence
6.4 Medium 코드엠샵 소셜톡 Plugin mshop-naver-talktalk Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.0 CVE-2024-11904 Wordfence
6.1 Medium 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 Plugin pgall-for-woocommerce Cross-Site Scripting 우커머스 결제 플러그인 <= 5.2.2 - Reflected Cross-Site Scripting via add_query_arg Function No login needed ≤ 5.2.2 CVE-2024-11943 Wordfence
6.4 Medium Zooom Plugin zooom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11451 Wordfence
6.1 Medium Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.19 CVE-2024-11436 Wordfence
6.1 Medium افزونه پیامک ووکامرس Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.5 CVE-2024-10046 Wordfence
6.1 Medium Comfino Payment Gateway Plugin comfino-payment-gateway Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.1 CVE-2024-11329 Wordfence
6.4 Medium Depicter — Popup & Slider Builder Plugin depicter Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.2.1 CVE-2024-4633 Wordfence
5.3 Medium WPCasa Plugin wpcasa Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.13 Fixed in 1.3.0 CVE-2024-53826 Patchstack
5.3 Medium Church Admin Plugin church-admin Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2024-53795 Patchstack
6.5 Medium WP Mailster Plugin wp-mailster Broken Access Control ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53803 Patchstack
4.3 Medium FloristPress Plugin bakkbone-florist-companion Broken Access Control ≤ 7.3.0 Fixed in 7.4.0 CVE-2024-53799 Patchstack
6.5 Medium WP Travel Plugin wp-travel Broken Access Control No login needed ≤ 9.6.0 Fixed in 9.7.0 CVE-2024-53813 Patchstack
4.7 Medium Filebird Plugin filebird Broken Access Control ≤ 6.3.2 Fixed in 6.3.4 CVE-2024-53825 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-53796 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.27.0 Fixed in 2.27.1 CVE-2024-53794 Patchstack
6.5 Medium Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting ≤ 2.8.4.3 Fixed in 2.8.4.4 CVE-2024-53797 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only