WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,251–1,300 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 26 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.6 Critical Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery CSRF to Arbitrary File Upload ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-37555 Patchstack
9.8 Critical Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed ≤ 5.7.25 CVE-2024-6172 Wordfence
9.8 Critical UsersWP – Front-end login form, User Registration, User Profile & Members Directory Plugin userswp SQL Injection Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' No login needed ≤ 1.2.10 CVE-2024-6265 Wordfence
9.3 Critical Email Subscribers & Newsletters Plugin email-subscribers SQL Injection No login needed ≤ 5.7.25 Fixed in 5.7.26 CVE-2024-37252 Patchstack
10.0 Critical Several WordPress.org Plugins <= Various Versions Plugin social-warfare Other Injected Backdoor No login needed 4.4.6.4 – 4.4.7.1, 1.0.4 – 1.0.5, 1.2.1 – 1.2.2, … CVE-2024-6297 Wordfence
10.0 Critical InstaWP Connect Plugin instawp-connect Arbitrary File Upload No login needed ≤ 0.1.0.38 Fixed in 0.1.0.39 CVE-2024-37228 Patchstack
9.9 Critical WishList Member X Plugin Remote Code Execution Authenticated Arbitrary PHP Code Execution < 3.26.7 Fixed in 3.26.7 CVE-2024-37109 Patchstack
9.9 Critical Consulting Elementor Widgets Plugin Remote Code Execution ≤ 1.3.0, ≤ 1.2.2 Fixed in 1.3.1 CVE-2024-37091 Patchstack
9.0 Critical Consulting Elementor Widgets Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37089 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.4 Fixed in 1.4.1 CVE-2024-35767 Patchstack
9.8 Critical JupiterX Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.3.8 Fixed in 3.4.3 CVE-2023-38389 Patchstack
9.1 Critical Avada Theme Broken Access Control Auth. Unrestricted Zip Extraction ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39312 Patchstack
9.3 Critical WordPress Picture / Portfolio / Media Gallery Plugin nimble-portfolio Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.0.1 CVE-2024-5021 Wordfence
10.0 Critical BuddyPress Cover Plugin bp-cover Arbitrary File Upload No login needed ≤ 2.1.4.2 CVE-2024-35746 Patchstack
9.0 Critical MegaMenu Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.3.12 Fixed in 2.3.13 CVE-2024-35677 Patchstack
9.9 Critical Advanced Custom Fields PRO Plugin Local File Inclusion Contributor+ Local File Inclusion < 6.2.10 Fixed in 6.2.10 CVE-2024-34762 Patchstack
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33565 Patchstack
9.8 Critical Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31244 Patchstack
9.9 Critical Quiz And Survey Master – Best Quiz, Exam and Survey Plugin quiz-master-next SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection ≤ 9.0.1 CVE-2024-3592 Wordfence
9.8 Critical Userpro Plugin userpro Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.1.8 Fixed in 5.1.9 CVE-2024-35700 Patchstack
9.6 Critical Easy Digital Downloads – Recent Purchases Plugin edd-recent-purchases Local File Inclusion Recent Purchases plugin <= 1.0.2 - Remote File Inclusion No login needed ≤ 1.0.2 CVE-2024-35629 Patchstack
9.1 Critical Dextaz Ping Plugin dextaz-ping Remote Code Execution ≤ 0.65 CVE-2024-34792 Patchstack
9.0 Critical Stockholm Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 9.6 Fixed in 9.7 CVE-2024-34551 Patchstack
9.0 Critical XStore Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33560 Patchstack
10.0 Critical Bricks Builder Theme Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.9.6 Fixed in 1.9.6.1 CVE-2024-25600 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
9.1 Critical WP STAGING WordPress Backup Plugin – Migration Backup Restore Plugin wp-staging Arbitrary File Upload Migration Backup Restore <= 3.4.3 - Authenticated (Admin+) Arbitrary File Upload ≤ 3.4.3 CVE-2024-3412 Wordfence
9.8 Critical Business Directory Plugin – Easy Listing Directories Plugin business-directory-plugin SQL Injection Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter No login needed ≤ 6.4.2 CVE-2024-4443 Wordfence
10.0 Critical ActiveDEMAND Plugin activedemand Arbitrary File Upload No login needed ≤ 0.2.41 Fixed in 0.2.42 CVE-2024-32809 Patchstack
9.8 Critical Simple Registration for WooCommerce Plugin woocommerce-simple-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.6 CVE-2024-32511 Patchstack
9.8 Critical Demo My Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.9.1 Fixed in 1.1.0 CVE-2024-31290 Patchstack
9.0 Critical Rehub Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31231 Patchstack
9.8 Critical WholesaleX Plugin wholesalex Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-30542 Patchstack
9.3 Critical Automatic Plugin Path Traversal Unauthenticated Arbitrary File Download and SSRF No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27954 Patchstack
9.8 Critical Masteriyo - LMS Plugin learning-management-system Privilege Escalation No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-24882 Patchstack
9.8 Critical SalesKing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22157 Patchstack
9.8 Critical WP Frontend Profile Plugin wp-front-end-profile Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-51483 Patchstack
9.8 Critical Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-51481 Patchstack
9.8 Critical WP MLM Unilevel Plugin wp-mlm Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 4.0 CVE-2023-51476 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.05.0 Fixed in 3.05.1 CVE-2023-51424 Patchstack
9.8 Critical XStore Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33552 Patchstack
9.8 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33567 Patchstack
9.9 Critical Customify Site Library Plugin customify-sites Remote Code Execution ≤ 0.0.9 CVE-2024-33644 Patchstack
9.8 Critical HT Mega Plugin ht-mega-for-elementor Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-37999 Patchstack
9.0 Critical LWS Affiliation Plugin lws-affiliation Local File Inclusion No login needed ≤ 2.2.6 Fixed in 2.3 CVE-2023-32297 Patchstack
9.8 Critical Woodmart Core Plugin Privilege Escalation No login needed ≤ 1.0.36 Fixed in 1.0.37 CVE-2023-32244 Patchstack
9.8 Critical Houzez Theme Privilege Escalation No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2023-26540 Patchstack
9.8 Critical Houzez Login Register Plugin Privilege Escalation No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2023-26009 Patchstack
9.8 Critical WatchTowerHQ Plugin watchtowerhq Privilege Escalation No login needed ≤ 3.6.16 Fixed in 3.6.17 CVE-2023-25701 Patchstack
9.1 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Arbitrary File Upload Best Help Desk & Support Plugin plugin <= 2.7.7 - Arbitrary File Upload ≤ 2.7.7 Fixed in 2.7.8 CVE-2023-25444 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only