WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,451–13,500 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 270 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2024-43297 Patchstack
4.3 Medium Fonts Plugin olympus-google-fonts Broken Access Control ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43302 Patchstack
5.4 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.1.9 Fixed in 7.2.0 CVE-2024-43312 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
4.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control ≤ 1.3.9.3 Fixed in 1.3.9.4 CVE-2024-43314 Patchstack
4.3 Medium Photo Engine Plugin wplr-sync Broken Access Control ≤ 6.4.0 Fixed in 6.4.1 CVE-2024-43332 Patchstack
5.3 Medium ReviewX Plugin reviewx Broken Access Control No login needed ≤ 1.6.28 Fixed in 1.6.29 CVE-2024-43323 Patchstack
4.3 Medium Order Tracking Plugin order-tracking Broken Access Control WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control ≤ 3.3.12 Fixed in 3.3.13 CVE-2024-43343 Patchstack
6.5 Medium Hello Agency Theme hello-agency Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-43341 Patchstack
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control ≤ 5.3.0 Fixed in 5.5.7 CVE-2024-43355 Patchstack
5.3 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-43923 Patchstack
5.3 Medium YARPP Plugin yet-another-related-posts-plugin Broken Access Control No login needed ≤ 5.30.10 CVE-2024-43919 Patchstack
5.4 Medium JobSearch Plugin wp-jobsearch Broken Access Control ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43928 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control ≤ 1.8.14 Fixed in 1.8.15 CVE-2024-43925 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Broken Access Control ≤ 5.6.2 Fixed in 5.6.3 CVE-2024-43932 Patchstack
6.5 Medium JobSearch Plugin Broken Access Control No login needed ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43929 Patchstack
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Settings Change ≤ 2.1.10 Fixed in 2.1.11 CVE-2024-43937 Patchstack
5.4 Medium LWS Affiliation Plugin lws-affiliation Broken Access Control ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43962 Patchstack
6.5 Medium Memberpress Plugin Broken Access Control No login needed ≤ 1.11.34 Fixed in 1.11.35 CVE-2024-43956 Patchstack
4.3 Medium Newspack Plugin newspack-plugin Broken Access Control ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-43968 Patchstack
6.5 Medium ReviveNews Theme revivenews Broken Access Control No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-43974 Patchstack
4.3 Medium GetPaid Plugin invoicing Broken Access Control ≤ 2.8.11 Fixed in 2.8.12 CVE-2024-43973 Patchstack
6.5 Medium Fota WP Theme fotawp Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-43980 Patchstack
6.5 Medium Blockbooster Theme blockbooster Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-43979 Patchstack
4.3 Medium GeoDirectory Plugin geodirectory Broken Access Control ≤ 2.3.70 Fixed in 2.3.71 CVE-2024-43981 Patchstack
6.5 Medium Blogpoet Theme blogpoet Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-43998 Patchstack
8.8 High Login As Users Plugin login-as-users Broken Access Control Broken Access Control to Account Takeover ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-43982 Patchstack
4.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.6 Fixed in 5.3.7 CVE-2024-44006 Patchstack
4.3 Medium WP Free SSL – Free SSL Certificate for WordPress and force HTTPS Plugin wp-free-ssl Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-44020 Patchstack
5.3 Medium Contact Form 7 Campaign Monitor Extension Plugin contact-form-7-campaign-monitor-extension Arbitrary File Deletion No login needed ≤ 0.4.67 CVE-2024-44019 Patchstack
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-44031 Patchstack
5.4 Medium Truepush Plugin truepush-free-web-push-notifications Broken Access Control ≤ 1.0.8 CVE-2024-44021 Patchstack
4.3 Medium HelloAsso Plugin helloasso Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2024-44052 Patchstack
4.3 Medium Ads by WPQuads Plugin quick-adsense-reloaded Broken Access Control ≤ 2.0.84 Fixed in 2.0.85 CVE-2024-47317 Patchstack
6.5 Medium Templately Plugin templately Broken Access Control No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-47308 Patchstack
4.3 Medium PWA for WP & AMP Plugin pwa-for-wp Broken Access Control No login needed ≤ 1.7.72 Fixed in 1.7.73 CVE-2024-47318 Patchstack
5.3 Medium Popup Maker Plugin popup-maker Broken Access Control No login needed ≤ 1.19.2 Fixed in 1.20.0 CVE-2024-47358 Patchstack
6.5 Medium WP Datepicker Plugin wp-datepicker Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-47321 Patchstack
5.3 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 3.2.2 Fixed in 3.5.0 CVE-2024-47359 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Broken Access Control ≤ 1.13.6 Fixed in 1.13.7 CVE-2024-47361 Patchstack
4.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-47362 Patchstack
8.2 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.2.12 Fixed in 3.2.13 CVE-2024-37094 Patchstack
4.3 Medium JobSearch Plugin wp-jobsearch Broken Access Control No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-43930 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 11.48 Fixed in 11.49 CVE-2024-43933 Patchstack
9.6 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43984 Patchstack
9.6 Critical EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-49674 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
5.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 9.7 Fixed in 9.8 CVE-2024-50419 Patchstack
8.8 High Bulk Change Role Plugin bulk-role-change Privilege Escalation ≤ 1.1 CVE-2024-50504 Patchstack
8.8 High Marketing Automation by AZEXO Plugin marketing-automation-by-azexo Privilege Escalation ≤ 1.27.80 CVE-2024-50506 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only