WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 12,401–12,450 of 17,051 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 249 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Settings Change ≤ 8.0.2 CVE-2024-54271 Patchstack
4.3 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Broken Access Control ≤ 1.64.0 Fixed in 1.64.1 CVE-2024-54268 Patchstack
4.3 Medium CM Answers Plugin cm-answers Broken Access Control ≤ 3.2.6 Fixed in 3.2.7 CVE-2024-54267 Patchstack
7.1 High ImageRecycle pdf & image compression Plugin imagerecycle-pdf-image-compression Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-54266 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-54265 Patchstack
7.1 High Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-54264 Patchstack
9.9 Critical Import Export For WooCommerce Plugin import-export-for-woocommerce Arbitrary File Upload ≤ 1.6.2 CVE-2024-54262 Patchstack
10.0 Critical TAX SERVICE Electronic HDM Plugin virtual-hdm-for-taxservice-am SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-54261 Patchstack
6.5 Medium DELUCKS SEO Plugin delucks-seo Path Traversal Arbitrary File Download ≤ 2.7.0 CVE-2024-54259 Patchstack
8.5 High Ni CRM Lead Plugin ni-crm-lead SQL Injection ≤ 1.3.0 CVE-2024-54258 Patchstack
7.1 High Easy Blocks pro Plugin easy-blocks-pro Broken Access Control ≤ 1.0.21 CVE-2024-54256 Patchstack
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Cross-Site Scripting ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-54250 Patchstack
8.8 High eewee admin custom Plugin eewee-admincustom Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.8.2.4 CVE-2024-54248 Patchstack
6.5 Medium FAQs Plugin faqs Cross-Site Scripting ≤ 1.0.2 CVE-2024-54246 Patchstack
6.5 Medium Clients Plugin clients Cross-Site Scripting ≤ 1.1.4 CVE-2024-54245 Patchstack
6.5 Medium Easy Replace Plugin easy-replace Cross-Site Scripting ≤ 1.3 CVE-2024-54244 Patchstack
6.5 Medium Echoza Plugin echoza Cross-Site Scripting ≤ 0.1.1 CVE-2024-54243 Patchstack
6.5 Medium Simple Notification Plugin simple-notification Broken Access Control ≤ 1.3 CVE-2024-54242 Patchstack
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
7.1 High Blaze Online eParcel for WooCommerce Plugin blaze-online-eparcel-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2024-54240 Patchstack
9.8 Critical Eyewear prescription form Plugin eyewear-prescription-form Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 4.0.18 Fixed in 4.0.19 CVE-2024-54239 Patchstack
7.1 High Board Document Manager from CHUHPL Plugin board-document-manager-from-chuhpl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2024-54238 Patchstack
7.1 High Ni CRM Lead Plugin ni-crm-lead Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-54237 Patchstack
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack
7.1 High Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.86 CVE-2024-54235 Patchstack
9.3 Critical Limit Login Attempts Plugin wp-limit-failed-login-attempts SQL Injection No login needed ≤ 5.5 Fixed in 5.6 CVE-2024-54234 Patchstack
7.1 High Advanced Control Manager for WordPress by ItalyStrap Plugin advanced-control-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16.0 CVE-2024-54233 Patchstack
7.1 High Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 CVE-2024-54231 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium Comment Blacklist Updater Plugin comment-blacklist-updater Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.2.0 CVE-2023-44147 Patchstack
5.4 Medium Inactive Logout Plugin inactive-logout Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2023-44142 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.3 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control ≤ 4.6.14 Fixed in 4.6.15 CVE-2023-41951 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-41875 Patchstack
4.3 Medium SAML SP Single Sign On Plugin miniorange-saml-20-single-sign-on Broken Access Control SSO Login plugin <= 5.0.4 - Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2023-41873 Patchstack
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2023-41870 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.4 Fixed in 0.6.2.5 CVE-2023-41869 Patchstack
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Slider Pro Plugin sliderpro Broken Access Control ≤ 4.8.6 Fixed in 4.8.7 CVE-2023-41865 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.0 Fixed in 14.1 CVE-2023-41862 Patchstack
5.4 Medium Click To Tweet Plugin click-to-tweet Broken Access Control No login needed ≤ 2.0.14 CVE-2023-41857 Patchstack
5.3 Medium Posts Like Dislike Plugin posts-like-dislike Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2023-41849 Patchstack
5.3 Medium Carousel Slider Plugin carousel-slider Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-41848 Patchstack
5.3 Medium BitPay Checkout for WooCommerce Plugin bitpay-checkout-for-woocommerce Broken Access Control No login needed ≤ 4.1.0 Fixed in 5.0.0 CVE-2023-41803 Patchstack
4.3 Medium Super Socializer Plugin super-socializer Broken Access Control ≤ 7.13.54 Fixed in 7.13.55 CVE-2023-41802 Patchstack
3.5 Low Analytify Plugin wp-analytify Broken Access Control ≤ 5.1.0 Fixed in 5.1.1 CVE-2023-41695 Patchstack
5.3 Medium WiserNotify Social Proof Plugin wiser-notify Broken Access Control No login needed ≤ 2.5 Fixed in 2.6 CVE-2023-41690 Patchstack
4.3 Medium Post to Google My Business (Google Business Profile) Plugin post-to-google-my-business Broken Access Control ≤ 3.1.14 Fixed in 3.1.15 CVE-2023-41689 Patchstack
5.4 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Broken Access Control ≤ 1.5 Fixed in 1.51 CVE-2023-41688 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only