WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,301–13,350 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 267 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Cross-Site Scripting Drag & Drop Contact Form Builder for WordPress <= 1.9.244 - Reflected Cross-Site Scripting via URL No login needed ≤ 1.9.244 CVE-2024-10647 Wordfence
7.5 High Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin everest-backup Information Disclosure WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.2.13 - Sensitive Invormation Disclosure via procstat Log No login needed ≤ 2.2.13 CVE-2024-10028 Wordfence
7.3 High Tickera – WordPress Event Ticketing Plugin tickera-event-ticketing-system Arbitrary Shortcode Execution WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.5.4.4 CVE-2024-10263 Wordfence
8.1 High Social Login - WordPress / WooCommerce Plugin Authentication Bypass WordPress / WooCommerce Plugin <= 2.7.7 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 2.7.7 CVE-2024-10114 Wordfence
8.1 High Loginizer Security and Loginizer Plugin loginizer Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 1.9.2 CVE-2024-10097 Wordfence
6.5 Medium Knowledge Base Plugin knowledgebase Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-51677 Patchstack
6.5 Medium Elo Rating Shortcode Plugin elo-rating-shortcode Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51678 Patchstack
6.5 Medium Cresta Addons for Elementor Plugin cresta-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-51680 Patchstack
6.5 Medium WP Pocket URLs Plugin wp-pocket-urls Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51681 Patchstack
6.5 Medium HT Builder – WordPress Theme Builder for Elementor Plugin ht-builder Cross-Site Scripting WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-51682 Patchstack
6.5 Medium Custom post type templates for Elementor Plugin custom-post-type-templates-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.1 Fixed in 1.1.12 CVE-2024-51683 Patchstack
5.9 Medium Accordion title for Elementor Plugin accordion-title-for-elementor Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-51685 Patchstack
8.5 High Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection ≤ 1.1 CVE-2024-51626 Patchstack
7.6 High BetterLinks Plugin betterlinks SQL Injection ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-51672 Patchstack
7.5 High Stacks Mobile App Builder Plugin stacks-mobile-app-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.3 CVE-2024-50528 Patchstack
10.0 Critical All Post Contact Form Plugin allpost-contactform Arbitrary File Upload No login needed ≤ 1.8.2 CVE-2024-50523 Patchstack
10.0 Critical Helloprint Plugin helloprint Arbitrary File Upload No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-50525 Patchstack
10.0 Critical Multi Purpose Mail Form Plugin multi-purpose-mail-form Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-50526 Patchstack
10.0 Critical Stacks Mobile App Builder Plugin stacks-mobile-app-builder Arbitrary File Upload No login needed ≤ 5.2.3 CVE-2024-50527 Patchstack
9.9 Critical Training – Courses Plugin training Arbitrary File Upload Courses plugin <= 2.0.1 - Arbitrary File Upload ≤ 2.0.1 CVE-2024-50529 Patchstack
9.9 Critical Stars SMTP Mailer Plugin stars-smtp-mailer Arbitrary File Upload ≤ 2.2.1 CVE-2024-50530 Patchstack
10.0 Critical RSVPMaker for Toastmasters Plugin rsvpmaker-for-toastmasters Arbitrary File Upload No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2024-50531 Patchstack
7.5 High WP Hotel Booking Plugin wp-hotel-booking Local File Inclusion ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-51582 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
9.1 Critical Media LIbrary Assistant Plugin media-library-assistant Remote Code Execution ≤ 3.19 Fixed in 3.20 CVE-2024-51661 Patchstack
6.1 Medium ReCaptcha Integration Plugin wp-recaptcha-integration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-8739 Wordfence
6.5 Medium User Rights Access Manager Plugin user-rights-access-manager Broken Access Control ≤ 1.1.2 CVE-2024-37209 Patchstack
6.5 Medium Htaccess File Editor Plugin htaccess-file-editor Broken Access Control ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-49256 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control ≤ 3.12.3 Fixed in 3.12.4 CVE-2024-48045 Patchstack
5.4 Medium ShortPixel Image Optimizer Plugin shortpixel-image-optimiser Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-48044 Patchstack
4.3 Medium CubeWP Plugin cubewp-framework Broken Access Control ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-48039 Patchstack
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-47314 Patchstack
5.3 Medium Wheel of Life Plugin wheel-of-life Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-47311 Patchstack
5.3 Medium Fluent Support Plugin fluent-support Broken Access Control Broken Access Control on Email Verification No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47302 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-44038 Patchstack
5.4 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Broken Access Control Subscriber+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37250 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin Broken Access Control Contributor+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37249 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium Popup box Plugin ays-popup-box Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2024-37096 Patchstack
7.7 High WishList Member X Plugin Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37108 Patchstack
8.2 High WishList Member X Plugin Cross-Site Scripting Unautenticated Plugin Settings Change Leading to Stored XSS No login needed ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37106 Patchstack
5.3 Medium Ibtana Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder plugin <= 1.2.3.3 - Broken Access Control No login needed ≤ 1.2.3.3 Fixed in 1.2.3.4 CVE-2024-37123 Patchstack
5.3 Medium Uncanny Automator Pro Plugin uncanny-automator-pro Broken Access Control Unauthenticated License Settings Reset No login needed ≤ 5.3.0.0 Fixed in 5.3.0.1 CVE-2024-37119 Patchstack
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-37204 Patchstack
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
5.4 Medium Demo Awesome Plugin demo-awesome Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-37207 Patchstack
6.5 Medium Ali2Woo Lite Plugin ali2woo-lite Broken Access Control Broken Access Control to XSS ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37214 Patchstack
5.3 Medium Optinly Plugin optinly Broken Access Control No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-37220 Patchstack
4.3 Medium Page Builder Sandwich – Front-End Page Builder Plugin page-builder-sandwich Broken Access Control ≤ 5.1.0 CVE-2024-37218 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only