WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 12,551–12,600 of 16,945 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Stamped.io Product Reviews & UGC for WooCommerce | Broken Access Control No login needed |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2023-30479 |
Patchstack | |
| 4.3 Medium | Blogger Buzz | Broken Access Control |
≤ 1.2.2 |
CVE-2023-30476 |
Patchstack | |
| 4.3 Medium | Square | Broken Access Control |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2023-30486 |
Patchstack | |
| 5.3 Medium | Featured Post Creative | Broken Access Control No login needed |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2023-30488 |
Patchstack | |
| 4.3 Medium | Easy Appointments | Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) No login needed |
≤ 3.10.7 Fixed in 3.11.1 |
CVE-2023-30748 |
Patchstack | |
| 6.5 Medium | Sharkdropship for AliExpress Dropship and Affiliate | Broken Access Control Multiple Broken Access Control vulnerabilities No login needed |
≤ 2.2.3 Fixed in 2.2.5 |
CVE-2023-30870 |
Patchstack | |
| 4.3 Medium | Smart WooCommerce Search | Broken Access Control |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2023-30783 |
Patchstack | |
| 5.4 Medium | WP Docs | Broken Access Control |
≤ 1.9.8 Fixed in 1.9.9 |
CVE-2023-30873 |
Patchstack | |
| 4.3 Medium | Display custom fields in the frontend – Post and User Profile Fields | Broken Access Control |
≤ 1.2.0 Fixed in 1.2.1 |
CVE-2023-31073 |
Patchstack | |
| 5.4 Medium | WP Quick Post Duplicator | Broken Access Control |
≤ 2.0 Fixed in 2.1 |
CVE-2023-31214 |
Patchstack | |
| 5.4 Medium | Extended Post Status | Broken Access Control |
≤ 1.0.19 Fixed in 1.0.20 |
CVE-2023-32094 |
Patchstack | |
| 9.8 Critical | Integrate Google Drive | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 1.1.99 Fixed in 1.2.0 |
CVE-2023-32117 |
Patchstack | |
| 5.3 Medium | WRC Pricing Tables | Broken Access Control No login needed |
≤ 2.3.7 Fixed in 2.3.8 |
CVE-2023-32293 |
Patchstack | |
| 4.3 Medium | SALERT | Broken Access Control |
≤ 1.2.1 Fixed in 1.2.2 |
CVE-2023-32126 |
Patchstack | |
| 6.5 Medium | Ni WooCommerce Sales Report | Broken Access Control |
≤ 3.7.3 Fixed in 3.7.4 |
CVE-2023-32299 |
Patchstack | |
| 5.4 Medium | Mini Cart Drawer For WooCommerce | Broken Access Control No login needed |
≤ 4.0.0 Fixed in 4.0.1 |
CVE-2023-47694 |
Patchstack | |
| 8.6 High | Japanized For WooCommerce | Broken Access Control Multiple Broken Access Control No login needed |
≤ 2.6.4 Fixed in 2.6.5 |
CVE-2023-47698 |
Patchstack | |
| 4.3 Medium | Welcome Email Editor | Broken Access Control |
≤ 5.0.6 Fixed in 5.0.7 |
CVE-2023-47756 |
Patchstack | |
| 4.3 Medium | Essential Blocks for Gutenberg | Broken Access Control |
≤ 4.2.0 Fixed in 4.2.1 |
CVE-2023-47760 |
Patchstack | |
| 4.3 Medium | Simple 301 Redirects by BetterLinks | Broken Access Control |
≤ 2.0.7 Fixed in 2.0.8 |
CVE-2023-47761 |
Patchstack | |
| 4.3 Medium | WP Custom Admin Interface | Broken Access Control |
≤ 7.31 Fixed in 7.32 |
CVE-2023-47763 |
Patchstack | |
| 4.3 Medium | BetterDocs | Broken Access Control |
≤ 2.5.2 Fixed in 2.5.3 |
CVE-2023-47762 |
Patchstack | |
| 6.5 Medium | Ditty | Broken Access Control No login needed |
≤ 3.1.24 Fixed in 3.1.25 |
CVE-2023-47764 |
Patchstack | |
| 4.3 Medium | miniorange otp verification | Broken Access Control |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2023-47776 |
Patchstack | |
| 4.3 Medium | EasyAzon | Broken Access Control Amazon Associates Affiliate Plugin plugin <= 5.1.0 - Broken Access Control |
≤ 5.1.0 Fixed in 5.1.1 |
CVE-2023-47780 |
Patchstack | |
| 4.3 Medium | Acme Fix Images | Broken Access Control |
≤ 1.0.0 Fixed in 2.0.0 |
CVE-2023-47793 |
Patchstack | |
| 5.3 Medium | WPCafe | Broken Access Control No login needed |
≤ 2.2.22 Fixed in 2.2.23 |
CVE-2023-47805 |
Patchstack | |
| 4.3 Medium | WP Like Button | Broken Access Control |
≤ 1.7.0 |
CVE-2023-47820 |
Patchstack | |
| 5.4 Medium | MP3 Audio Player for Music, Radio & Podcast by Sonaar | Broken Access Control |
≤ 4.10 Fixed in 4.10.1 |
CVE-2023-47822 |
Patchstack | |
| 5.3 Medium | FormCraft | Broken Access Control Contact Form Builder for WordPress plugin <= 1.2.7 - Broken Access Control No login needed |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2023-47823 |
Patchstack | |
| 6.5 Medium | Restaurant & Cafe Addon for Elementor | Broken Access Control No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2023-47826 |
Patchstack | |
| 5.4 Medium | Live Preview for Contact Form 7 | Broken Access Control |
≤ 1.2.0 |
CVE-2023-47830 |
Patchstack | |
| 5.4 Medium | WP Meta and Date Remover | Broken Access Control |
≤ 2.3.0 Fixed in 2.3.1 |
CVE-2023-47836 |
Patchstack | |
| 5.3 Medium | SearchIQ | Broken Access Control No login needed |
≤ 4.4 Fixed in 4.5 |
CVE-2023-47832 |
Patchstack | |
| 4.3 Medium | Conditional Fields for Contact Form 7 | Broken Access Control |
≤ 2.4.1 Fixed in 2.4.2 |
CVE-2023-47838 |
Patchstack | |
| 4.3 Medium | Analytify | Broken Access Control |
≤ 5.1.1 Fixed in 5.2.0 |
CVE-2023-47841 |
Patchstack | |
| 5.3 Medium | PayTR Taksit Tablosu | Broken Access Control No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2023-47847 |
Patchstack | |
| 4.3 Medium | wpForo Forum | Broken Access Control Broken Access Control + CSRF |
≤ 2.2.5 Fixed in 2.2.6 |
CVE-2023-47869 |
Patchstack | |
| 4.3 Medium | BlossomThemes Email Newsletter | Broken Access Control |
≤ 2.2.4 Fixed in 2.2.5 |
CVE-2023-47849 |
Patchstack | |
| 4.3 Medium | Contact Form to Any API | Broken Access Control |
≤ 1.1.6 Fixed in 1.1.7 |
CVE-2023-47871 |
Patchstack | |
| 6.5 Medium | WCMultiShipping | Broken Access Control |
≤ 2.3.5 Fixed in 2.3.6 |
CVE-2023-48274 |
Patchstack | |
| 8.2 High | Stripe Payments | Broken Access Control No login needed |
≤ 2.0.79 Fixed in 2.0.80 |
CVE-2023-48286 |
Patchstack | |
| 5.4 Medium | Awesome Support | Broken Access Control |
≤ 6.1.4 Fixed in 6.1.5 |
CVE-2023-48324 |
Patchstack | |
| 5.4 Medium | TextMe SMS | Broken Access Control |
≤ 1.9.0 Fixed in 1.9.1 |
CVE-2023-48287 |
Patchstack | |
| 4.3 Medium | Mail Bank - #1 Mail SMTP | Broken Access Control #1 Mail SMTP Plugin for WordPress plugin <= 4.0.14 - Broken Access Control |
≤ 4.0.14 |
CVE-2023-48332 |
Patchstack | |
| 4.3 Medium | Easy Social Feed | Broken Access Control |
≤ 6.5.1 Fixed in 6.5.2 |
CVE-2023-48740 |
Patchstack | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Broken Access Control No login needed |
≤ 2.1.10 Fixed in 2.2 |
CVE-2023-48750 |
Patchstack | |
| 5.4 Medium | IdeaPush | Broken Access Control |
< 8.58 Fixed in 8.58 |
CVE-2023-48774 |
Patchstack | |
| 5.4 Medium | canvasio3D Light | Broken Access Control |
≤ 2.5.0 |
CVE-2023-48776 |
Patchstack | |
| 6.5 Medium | 360 Javascript Viewer | Broken Access Control No login needed |
≤ 1.7.11 Fixed in 1.7.12 |
CVE-2023-48779 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.