WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,301–1,350 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 27 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical MainWP Code Snippets Extension Plugin Remote Code Execution Subscriber+ Arbitrary PHP Code Injection/Execution ≤ 4.0.2 Fixed in 4.0.3 CVE-2023-23645 Patchstack
10.0 Critical Copymatic – AI Content Writer & Generator Plugin copymatic Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6 Fixed in 1.7 CVE-2024-31351 Patchstack
10.0 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 8.7.01.001 Fixed in 8.7.01.002 CVE-2024-31377 Patchstack
9.9 Critical canvasio3D Light Plugin canvasio3d-light Arbitrary File Upload ≤ 2.5.0 CVE-2024-34411 Patchstack
9.1 Critical Pk Favicon Manager Plugin phpsword-favicon-manager Arbitrary File Upload ≤ 2.1 CVE-2024-34416 Patchstack
9.1 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload Auth. Arbitrary File Upload ≤ 2.2.63 Fixed in 2.2.70 CVE-2024-34440 Patchstack
9.1 Critical Z-Downloads Plugin z-downloads Arbitrary File Upload Auth. Arbitrary File Upload No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2024-34555 Patchstack
10.0 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-32700 Patchstack
9.8 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function No login needed ≤ 1.9.9 CVE-2024-4560 Wordfence
9.8 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.6.5 CVE-2024-4434 Wordfence
9.6 Critical Xserver Migrator Plugin xserver-migrator Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.6.1 CVE-2024-33913 Patchstack
10.0 Critical OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Arbitrary File Upload Unauthenticated API Access to Arbitrary File Upload No login needed ≤ 12.4 Fixed in 12.5 CVE-2024-33566 Patchstack
9.0 Critical XStore Core Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 5.3.5 CVE-2024-33553 Patchstack
9.3 Critical WZone Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 14.0.10 CVE-2024-33544 Patchstack
9.6 Critical WZone Plugin SQL Injection Arbitrary SQL Update Execution ≤ 14.0.10 CVE-2024-33546 Patchstack
9.3 Critical XStore Core Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.3.5 CVE-2024-33551 Patchstack
9.3 Critical XStore Theme SQL Injection Unauthenticated SQL Injection No login needed ≤ 9.3.5 CVE-2024-33559 Patchstack
9.1 Critical Advanced Order Export For WooCommerce Plugin woo-order-export-lite Remote Code Execution ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-31266 Patchstack
9.6 Critical DX-Watermark Plugin dx-watermark Cross-Site Request Forgery CSRF to Arbitrary File Upload and XSS No login needed ≤ 1.0.4 CVE-2024-30560 Patchstack
9.0 Critical Anti-Malware Security and Brute-Force Firewall Plugin gotmls Remote Code Execution Unauthenticated Predictable Nonce Brute-Force Leading to RCE No login needed ≤ 4.21.96 Fixed in 4.23.56 CVE-2024-22144 Patchstack
9.8 Critical Login as User or Customer (User Switching) Plugin login-as-customer-or-user Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.8 CVE-2023-51484 Patchstack
9.9 Critical Eazy Plugin Manager Plugin plugins-on-steroids Remote Code Execution Auth. Arbitrary Options Update lead to RCE ≤ 4.1.2 Fixed in 4.1.3 CVE-2023-51482 Patchstack
9.8 Critical Build App Online Plugin build-app-online Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.19 CVE-2023-51478 Patchstack
9.8 Critical BuddyBoss Theme Authentication Bypass Unauth. Arbitrary WordPress Settings Change No login needed ≤ 2.4.60 Fixed in 2.4.61 CVE-2023-51477 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 7.1.9.7 Fixed in 7.1.9.8 CVE-2023-51472 Patchstack
9.8 Critical Rencontre – Dating Site Plugin rencontre Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.10.1 Fixed in 3.11 CVE-2023-51425 Patchstack
9.9 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.60 Fixed in 1.5.61 CVE-2023-31090 Patchstack
9.1 Critical Newsletters Plugin newsletters-lite Arbitrary File Upload ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-32954 Patchstack
9.3 Critical WP-Recall Plugin wp-recall SQL Injection No login needed ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32709 Patchstack
9.1 Critical WP-Lister Lite for eBay Plugin wp-lister-for-ebay Arbitrary File Upload ≤ 3.5.11 Fixed in 3.6.0 CVE-2024-32836 Patchstack
9.1 Critical ARMember Plugin armember-membership Broken Access Control Membership Plugin plugin <= 4.0.28 - Broken Access Control No login needed ≤ 4.0.28 Fixed in 4.0.29 CVE-2024-32948 Patchstack
10.0 Critical WP Dummy Content Generator Plugin wp-dummy-content-generator Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.2.1 Fixed in 3.3.0 CVE-2024-32599 Patchstack
9.9 Critical Support Genix Plugin support-genix-lite Broken Access Control Broken Access Control lead to Arbitrary File Upload ≤ 1.2.3 Fixed in 1.2.4 CVE-2023-49742 Patchstack
9.9 Critical WP Poll Maker Plugin epoll-wp-voting Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4 CVE-2024-32514 Patchstack
9.3 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.14.4 CVE-2024-32128 Patchstack
10.0 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.98 Fixed in 1.9.99 CVE-2023-51409 Patchstack
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.1.5 Fixed in 4.1.6 CVE-2024-31280 Patchstack
9.9 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload < 8.6.03.005 Fixed in 8.6.03.005 CVE-2024-31286 Patchstack
9.1 Critical Auto Poster Plugin auto-poster Arbitrary File Upload ≤ 1.2 CVE-2024-31345 Patchstack
9.0 Critical VideoWhisper Live Streaming Integration Plugin videowhisper-live-streaming-integration Remote Code Execution No login needed ≤ 5.5.15 Fixed in 5.5.16 CVE-2023-25699 Patchstack
9.9 Critical Cwicly Plugin Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 1.4.0.2 Fixed in 1.4.0.3 CVE-2024-24707 Patchstack
10.0 Critical Canto Plugin canto Remote Code Execution Unauth. Remote Code Execution (RCE) No login needed ≤ 3.0.7 CVE-2024-25096 Patchstack
9.9 Critical InstaWP Connect Plugin instawp-connect Remote Code Execution ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-25918 Patchstack
9.1 Critical Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-27951 Patchstack
9.9 Critical WP Fusion Lite Plugin wp-fusion-lite Remote Code Execution ≤ 3.41.24 Fixed in 3.42.10 CVE-2024-27972 Patchstack
9.9 Critical Oxygen Builder Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 4.9 CVE-2024-31380 Patchstack
9.9 Critical Breakdance Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 1.7.2 CVE-2024-31390 Patchstack
9.8 Critical LayerSlider Plugin SQL Injection The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user suppl… No login needed 7.9.11 – 7.10.0 CVE-2024-2879 Wordfence
9.1 Critical Shortcode Addons Plugin shortcode-addons Arbitrary File Upload ≤ 3.2.5 CVE-2024-31114 Patchstack
10.0 Critical Chauffeur Taxi Booking System Plugin Arbitrary File Upload No login needed ≤ 7.2 Fixed in 7.3 CVE-2024-31115 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only