WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,201–1,250 of 1,401 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | JobSearch | PHP Object Injection No login needed |
≤ 2.5.9 Fixed in 2.6.1 |
CVE-2024-47636 |
Patchstack | |
| 9.3 Critical | YITH WooCommerce Ajax Search | SQL Injection No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2024-47350 |
Patchstack | |
| 9.6 Critical | Vmax Project Manager | Local File Inclusion Local File Inclusion to RCE No login needed |
≤ 1.0 |
CVE-2024-44014 |
Patchstack | |
| 9.8 Critical | WordPress & WooCommerce Affiliate Program | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 8.4.1 |
CVE-2024-9289 |
Wordfence | |
| 9.1 Critical | WordPress Simple HTML Sitemap | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 3.1 |
CVE-2024-7385 |
Wordfence | |
| 9.9 Critical | WP Easy Gallery – WordPress Gallery | SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection |
≤ 4.8.5 |
CVE-2024-8436 |
Wordfence | |
| 9.8 Critical | Donation Forms by Charitable – Donations Plugin & Fundraising Platform | Broken Access Control Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation No login needed |
≤ 1.8.1.14 |
CVE-2024-8791 |
Wordfence | |
| 9.3 Critical | Super Store Finder | SQL Injection No login needed |
≤ 6.9.7 Fixed in 6.9.8 |
CVE-2024-43976 |
Patchstack | |
| 9.3 Critical | Super Store Finder | SQL Injection No login needed |
≤ 6.9.8 Fixed in 6.9.8 |
CVE-2024-43978 |
Patchstack | |
| 9.3 Critical | WPCargo Track & Trace | SQL Injection No login needed |
< 8.0.4 Fixed in 8.0.4 |
CVE-2024-44004 |
Patchstack | |
| 10.0 Critical | LearnPress – WordPress LMS | SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed |
≤ 4.2.7 |
CVE-2024-8529 |
Wordfence | |
| 10.0 Critical | LearnPress – WordPress LMS | SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed |
≤ 4.2.7 |
CVE-2024-8522 |
Wordfence | |
| 10.0 Critical | Droip | Path Traversal Unauthenticated Arbitrary File Download/Deletion No login needed |
≤ 1.1.1 |
CVE-2024-43955 |
Patchstack | |
| 9.3 Critical | Propovoice Pro | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.7.0.3 |
CVE-2024-43941 |
Patchstack | |
| 9.8 Critical | JobSearch | PHP Object Injection No login needed |
≤ 2.5.3 Fixed in 2.5.4 |
CVE-2024-43931 |
Patchstack | |
| 10.0 Critical | WBW Product Table PRO | SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed |
≤ 1.9.4 Fixed in 1.9.5 |
CVE-2024-43918 |
Patchstack | |
| 9.3 Critical | TI WooCommerce Wishlist | SQL Injection No login needed |
≤ 2.8.2 |
CVE-2024-43917 |
Patchstack | |
| 9.3 Critical | Cost Calculator Builder | SQL Injection No login needed |
≤ 3.2.15 Fixed in 3.2.16 |
CVE-2024-43144 |
Patchstack | |
| 9.3 Critical | Docket (WooCommerce Collections / Wishlist / Watchlist) | SQL Injection Unauthenticated SQL Injection No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-43132 |
Patchstack | |
| 9.3 Critical | VikRentCar | SQL Injection No login needed |
≤ 1.4.0 Fixed in 1.4.1 |
CVE-2024-39653 |
Patchstack | |
| 9.3 Critical | ListingPro | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.9.4 Fixed in 2.9.5 |
CVE-2024-39622 |
Patchstack | |
| 9.3 Critical | ListingPro | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.9.4 Fixed in 2.9.5 |
CVE-2024-38795 |
Patchstack | |
| 9.3 Critical | Easy Digital Downloads | SQL Injection No login needed |
≤ 3.2.12 Fixed in 3.3.1 |
CVE-2024-5057 |
Patchstack | |
| 9.8 Critical | LiteSpeed Cache | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 6.3.0.1 Fixed in 6.4 |
CVE-2024-28000 |
Patchstack | |
| 9.8 Critical | myCred | PHP Object Injection No login needed |
≤ 2.7.2 Fixed in 2.7.3 |
CVE-2024-43354 |
Patchstack | |
| 9.8 Critical | Login As Users | Authentication Bypass Broken Authentication No login needed |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2024-43311 |
Patchstack | |
| 9.6 Critical | Compute Links | Local File Inclusion Remote File Inclusion No login needed |
≤ 1.2.1 |
CVE-2024-43261 |
Patchstack | |
| 9.0 Critical | Crew HRM | PHP Object Injection No login needed |
≤ 1.1.1 Fixed in 1.1.2 |
CVE-2024-43252 |
Patchstack | |
| 9.9 Critical | Bit Form Pro | Arbitrary File Upload Authenticated Arbitrary File Upload |
≤ 2.6.4 |
CVE-2024-43249 |
Patchstack | |
| 9.8 Critical | JobSearch | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 2.3.4 |
CVE-2024-43245 |
Patchstack | |
| 9.0 Critical | Ultimate Membership Pro | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 12.7 Fixed in 12.8 |
CVE-2024-43242 |
Patchstack | |
| 9.4 Critical | Ultimate Membership Pro | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 12.7 Fixed in 12.8 |
CVE-2024-43240 |
Patchstack | |
| 10.0 Critical | GiveWP | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 3.14.1 Fixed in 3.14.2 |
CVE-2024-37099 |
Patchstack | |
| 9.8 Critical | GEO my | Remote Code Execution Unauthenticated RCE via LFI No login needed |
< 4.5.0.2 Fixed in 4.5.0.2 |
CVE-2024-6330 |
WPScan | |
| 10.0 Critical | BerqWP | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2024-43160 |
Patchstack | |
| 9.8 Critical | Woffice | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 5.4.10 Fixed in 5.4.12 |
CVE-2024-43153 |
Patchstack | |
| 9.8 Critical | Participants Database | PHP Object Injection No login needed |
≤ 2.5.9.2 Fixed in 2.5.9.3 |
CVE-2024-43141 |
Patchstack | |
| 9.1 Critical | HUSKY | Privilege Escalation |
≤ 1.3.6.1 Fixed in 1.3.6.2 |
CVE-2024-43121 |
Patchstack | |
| 9.8 Critical | Backup and Staging by WP Time Capsule | Authentication Bypass Authentication Bypass and Privilege Escalation No login needed |
≤ 1.22.20 Fixed in 1.22.21 |
CVE-2024-38770 |
Patchstack | |
| 9.0 Critical | ListingPro | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 2.9.4 Fixed in 2.9.5 |
CVE-2024-39619 |
Patchstack | |
| 9.3 Critical | FormLift for Infusionsoft Web Forms | SQL Injection Unauthenticated Blind SQL Injection No login needed |
≤ 7.5.17 Fixed in 7.5.18 |
CVE-2024-38773 |
Patchstack | |
| 9.1 Critical | Realtyna Organic IDX | Arbitrary File Upload |
≤ 4.14.13 |
CVE-2024-38736 |
Patchstack | |
| 9.1 Critical | Import Spreadsheets from Microsoft Excel | Arbitrary File Upload |
≤ 10.1.4 |
CVE-2024-38734 |
Patchstack | |
| 9.8 Critical | Jobmonster | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 4.7.5 Fixed in 4.7.6 |
CVE-2024-37927 |
Patchstack | |
| 9.3 Critical | Woocommerce OpenPos | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.4.4 |
CVE-2024-37933 |
Patchstack | |
| 9.8 Critical | WishList Member X | Information Disclosure Unauthenticated Database Backup Download No login needed |
< 3.26.7 Fixed in 3.26.7 |
CVE-2024-37113 |
Patchstack | |
| 9.9 Critical | Newspack Blocks | Arbitrary File Upload |
≤ 3.0.8 Fixed in 3.0.9 |
CVE-2024-37424 |
Patchstack | |
| 9.9 Critical | Zita Elementor Site Library | Remote Code Execution Arbitrary Code Execution |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-37420 |
Patchstack | |
| 9.9 Critical | Church Admin | Arbitrary File Upload |
≤ 4.4.6 Fixed in 4.4.7 |
CVE-2024-37418 |
Patchstack | |
| 10.0 Critical | WishList Member X | SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed |
< 3.26.7 Fixed in 3.26.7 |
CVE-2024-37112 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.