WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,651–13,700 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 274 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Portfolleo Plugin portfolleo Arbitrary File Upload ≤ 1.2 CVE-2024-49653 Patchstack
9.9 Critical Woocommerce Custom Profile Picture Plugin woo-custom-profile-picture Arbitrary File Upload ≤ 1.0 CVE-2024-49658 Patchstack
10.0 Critical Verbalize WP Plugin verbalize-wp Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49668 Patchstack
9.9 Critical INK Official Plugin ink-official Arbitrary File Upload ≤ 4.1.2 CVE-2024-49669 Patchstack
9.9 Critical AI Image Generator for Your Content & Featured Images – AI Postpix Plugin ai-postpix Arbitrary File Upload ≤ 1.1.8 Fixed in 1.1.8.1 CVE-2024-49671 Patchstack
6.6 Medium Custom Icons for Elementor Plugin custom-icons-for-elementor Arbitrary File Upload ≤ 0.3.3 Fixed in 0.3.4 CVE-2024-49676 Patchstack
7.5 High Qi Blocks Plugin qi-blocks Local File Inclusion ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-49690 Patchstack
7.5 High Mags Plugin mags Local File Inclusion No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-49701 Patchstack
7.2 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule PHP Object Injection ≤ 1.22.21 Fixed in 1.22.22 CVE-2024-49684 Patchstack
7.7 High 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Deletion ≤ 1.0.3 CVE-2024-49657 Patchstack
8.8 High iBryl Switch User Plugin ibryl-switch-user Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2024-49675 Patchstack
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
8.1 High ProfilePress - Pro Plugin Authentication Bypass Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 4.11.1 CVE-2024-9947 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
4.3 Medium WP VR Plugin wpvr Broken Access Control ≤ 8.5.4 Fixed in 8.5.5 CVE-2024-49293 Patchstack
4.3 Medium Simple Custom Post Order Plugin simple-custom-post-order Broken Access Control ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-49321 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
7.6 High FunnelKit Automations Plugin wp-marketing-automations SQL Injection ≤ 3.1.2 Fixed in 3.2.0 CVE-2024-47328 Patchstack
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Account Takeover via Cookie Leak No login needed ≤ 6.5.0.1 Fixed in 6.5.0.1 CVE-2024-44000 Patchstack
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
7.1 High GoogleDrive folder list Plugin googledrive-folder-list Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49335 Patchstack
7.1 High AVChat Video Chat Plugin avchat-3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2 CVE-2024-49605 Patchstack
7.1 High Endless Posts Navigation Plugin endless-posts-navigation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-49629 Patchstack
8.5 High MPG Plugin multiple-pages-generator-by-porthas SQL Injection MPG plugin <= 3.4.7 - SQL Injection ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-47325 Patchstack
8.5 High Author Discussion Plugin author-discussion SQL Injection ≤ 0.2.2 CVE-2024-49609 Patchstack
8.5 High SW Contact Form Plugin sw-contact-form SQL Injection ≤ 1.0 CVE-2024-49612 Patchstack
8.5 High Simple Code Insert Shortcode Plugin simple-code-insert-shortcode SQL Injection ≤ 1.0 CVE-2024-49613 Patchstack
8.5 High SermonAudio Widgets Plugin sermonaudio-widgets SQL Injection ≤ 1.9.3 CVE-2024-49614 Patchstack
8.2 High SafetyForms Plugin safetymails-forms Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49615 Patchstack
8.5 High Rate Own Post Plugin rate-own-post SQL Injection ≤ 1.0 CVE-2024-49616 Patchstack
8.2 High Back Link Tracker Plugin back-link-tracker Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49617 Patchstack
8.5 High MyTweetLinks Plugin mytweetlinks SQL Injection ≤ 1.1.1 CVE-2024-49618 Patchstack
8.5 High Social Link Groups Plugin social-link-groups SQL Injection ≤ 1.1.0 CVE-2024-49619 Patchstack
8.5 High FERMA.ru.net Plugin ferma-ru-net-checkout SQL Injection ≤ 1.3.3 CVE-2024-49620 Patchstack
7.1 High EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.12.14 Fixed in 3.0.0 CVE-2024-44061 Patchstack
8.2 High APA Register Newsletter Form Plugin apa-register-newsletter-form Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49621 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
8.5 High Duplicate Title Validate Plugin duplicate-title-validate SQL Injection ≤ 1.0 Fixed in 1.4 CVE-2024-49623 Patchstack
8.8 High GERRYWORKS Post by Mail Plugin gerryworks-post-by-mail Privilege Escalation ≤ 1.0 CVE-2024-49608 Patchstack
10.0 Critical Sovratec Case Management Plugin sovratec-case-management Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49324 Patchstack
10.0 Critical Affiliator Plugin affiliator-lite Arbitrary File Upload No login needed ≤ 2.1.3 CVE-2024-49326 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only