WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,201–1,250 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 2.5.9 Fixed in 2.6.1 CVE-2024-47636 Patchstack
9.3 Critical YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search SQL Injection No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-47350 Patchstack
9.6 Critical Vmax Project Manager Plugin vmax-project-manager Local File Inclusion Local File Inclusion to RCE No login needed ≤ 1.0 CVE-2024-44014 Patchstack
9.8 Critical WordPress & WooCommerce Affiliate Program Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 8.4.1 CVE-2024-9289 Wordfence
9.1 Critical WordPress Simple HTML Sitemap Plugin wp-simple-html-sitemap SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.1 CVE-2024-7385 Wordfence
9.9 Critical WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection ≤ 4.8.5 CVE-2024-8436 Wordfence
9.8 Critical Donation Forms by Charitable – Donations Plugin & Fundraising Platform Plugin charitable Broken Access Control Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation No login needed ≤ 1.8.1.14 CVE-2024-8791 Wordfence
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 6.9.7 Fixed in 6.9.8 CVE-2024-43976 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 6.9.8 Fixed in 6.9.8 CVE-2024-43978 Patchstack
9.3 Critical WPCargo Track & Trace Plugin wpcargo SQL Injection No login needed < 8.0.4 Fixed in 8.0.4 CVE-2024-44004 Patchstack
10.0 Critical LearnPress – WordPress LMS Plugin SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed ≤ 4.2.7 CVE-2024-8529 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed ≤ 4.2.7 CVE-2024-8522 Wordfence
10.0 Critical Droip Plugin Path Traversal Unauthenticated Arbitrary File Download/Deletion No login needed ≤ 1.1.1 CVE-2024-43955 Patchstack
9.3 Critical Propovoice Pro Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.7.0.3 CVE-2024-43941 Patchstack
9.8 Critical JobSearch Plugin PHP Object Injection No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-43931 Patchstack
10.0 Critical WBW Product Table PRO Plugin SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2024-43918 Patchstack
9.3 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection No login needed ≤ 2.8.2 CVE-2024-43917 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.15 Fixed in 3.2.16 CVE-2024-43144 Patchstack
9.3 Critical Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin SQL Injection Unauthenticated SQL Injection No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43132 Patchstack
9.3 Critical VikRentCar Plugin vikrentcar SQL Injection No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-39653 Patchstack
9.3 Critical ListingPro Theme listingpro SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39622 Patchstack
9.3 Critical ListingPro Plugin listingpro-plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-38795 Patchstack
9.3 Critical Easy Digital Downloads Plugin easy-digital-downloads SQL Injection No login needed ≤ 3.2.12 Fixed in 3.3.1 CVE-2024-5057 Patchstack
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 6.3.0.1 Fixed in 6.4 CVE-2024-28000 Patchstack
9.8 Critical myCred Plugin mycred PHP Object Injection No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43354 Patchstack
9.8 Critical Login As Users Plugin login-as-users Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-43311 Patchstack
9.6 Critical Compute Links Plugin compute-links Local File Inclusion Remote File Inclusion No login needed ≤ 1.2.1 CVE-2024-43261 Patchstack
9.0 Critical Crew HRM Plugin hr-management PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-43252 Patchstack
9.9 Critical Bit Form Pro Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 2.6.4 CVE-2024-43249 Patchstack
9.8 Critical JobSearch Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 2.3.4 CVE-2024-43245 Patchstack
9.0 Critical Ultimate Membership Pro Plugin indeed-membership-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43242 Patchstack
9.4 Critical Ultimate Membership Pro Plugin indeed-membership-pro Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43240 Patchstack
10.0 Critical GiveWP Plugin give PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.1 Fixed in 3.14.2 CVE-2024-37099 Patchstack
9.8 Critical GEO my Plugin Remote Code Execution Unauthenticated RCE via LFI No login needed < 4.5.0.2 Fixed in 4.5.0.2 CVE-2024-6330 WPScan
10.0 Critical BerqWP Plugin searchpro Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2024-43160 Patchstack
9.8 Critical Woffice Plugin woffice Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 5.4.10 Fixed in 5.4.12 CVE-2024-43153 Patchstack
9.8 Critical Participants Database Plugin participants-database PHP Object Injection No login needed ≤ 2.5.9.2 Fixed in 2.5.9.3 CVE-2024-43141 Patchstack
9.1 Critical HUSKY Plugin woocommerce-products-filter Privilege Escalation ≤ 1.3.6.1 Fixed in 1.3.6.2 CVE-2024-43121 Patchstack
9.8 Critical Backup and Staging by WP Time Capsule Plugin wp-time-capsule Authentication Bypass Authentication Bypass and Privilege Escalation No login needed ≤ 1.22.20 Fixed in 1.22.21 CVE-2024-38770 Patchstack
9.0 Critical ListingPro Plugin listingpro-plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39619 Patchstack
9.3 Critical FormLift for Infusionsoft Web Forms Plugin formlift SQL Injection Unauthenticated Blind SQL Injection No login needed ≤ 7.5.17 Fixed in 7.5.18 CVE-2024-38773 Patchstack
9.1 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Arbitrary File Upload ≤ 4.14.13 CVE-2024-38736 Patchstack
9.1 Critical Import Spreadsheets from Microsoft Excel Plugin import-spreadsheets-from-microsoft-excel Arbitrary File Upload ≤ 10.1.4 CVE-2024-38734 Patchstack
9.8 Critical Jobmonster Theme noo-jobmonster Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-37927 Patchstack
9.3 Critical Woocommerce OpenPos Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.4 CVE-2024-37933 Patchstack
9.8 Critical WishList Member X Plugin Information Disclosure Unauthenticated Database Backup Download No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37113 Patchstack
9.9 Critical Newspack Blocks Plugin Arbitrary File Upload ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37424 Patchstack
9.9 Critical Zita Elementor Site Library Plugin zita-site-library Remote Code Execution Arbitrary Code Execution ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37420 Patchstack
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.4.6 Fixed in 4.4.7 CVE-2024-37418 Patchstack
10.0 Critical WishList Member X Plugin SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37112 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only