WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,351–1,400 of 1,401 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical WP Travel Engine Plugin wp-travel-engine SQL Injection Unauth. Blind SQL Injection No login needed ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-30502 Patchstack
9.3 Critical CRM Perks Forms Plugin crm-perks-forms SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-30498 Patchstack
9.3 Critical ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection No login needed ≤ 5.7.8 Fixed in 5.7.9 CVE-2024-30490 Patchstack
10.0 Critical Salon booking system Plugin salon-booking-system Arbitrary File Upload No login needed ≤ 9.5 Fixed in 9.5.1 CVE-2024-30510 Patchstack
9.9 Critical CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Arbitrary File Upload ≤ 1.1.12 Fixed in 1.1.13 CVE-2024-30500 Patchstack
9.1 Critical Tumult Hype Animations Plugin tumult-hype-animations Arbitrary File Upload ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-2890 Patchstack
9.1 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload ≤ 2.1.4 Fixed in 2.1.5 CVE-2024-29100 Patchstack
9.0 Critical ARMember Plugin armember-membership PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30223 Patchstack
10.0 Critical WholesaleX Plugin wholesalex PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-30224 Patchstack
10.0 Critical WP Migrate Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.6.10 Fixed in 2.6.11 CVE-2024-30225 Patchstack
9.0 Critical BetterDocs Plugin betterdocs PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2024-30226 Patchstack
9.0 Critical Geo Controller Plugin cf-geoplugin PHP Object Injection No login needed ≤ 8.6.4 Fixed in 8.6.5 CVE-2024-30227 Patchstack
9.9 Critical Hercules Core Plugin PHP Object Injection Auth. PHP Object Injection ≤ 6.4 Fixed in 6.5 CVE-2024-30228 Patchstack
10.0 Critical WappPress Plugin wapppress-builds-android-app-for-website Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.3 Fixed in 6.0.0 CVE-2023-49815 Patchstack
9.9 Critical Elementor Website Builder Plugin elementor Arbitrary File Upload 3.3.0 – 3.18.1 Fixed in 3.18.2 CVE-2023-48777 Patchstack
9.0 Critical JupiterX Core Plugin Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 3.3.5 Fixed in 3.3.8 CVE-2023-38388 Patchstack
9.1 Critical WP Child Theme Generator Plugin wp-child-theme-generator Arbitrary File Upload ≤ 1.0.9 CVE-2023-47873 Patchstack
9.1 Critical WP Githuber MD Plugin wp-githuber-md Arbitrary File Upload ≤ 1.16.2 Fixed in 1.16.3 CVE-2023-47846 Patchstack
9.1 Critical CataBlog Plugin catablog Arbitrary File Upload ≤ 1.7.0 CVE-2023-47842 Patchstack
9.1 Critical Manager for Icomoon Plugin manager-for-icomoon Arbitrary File Upload ≤ 2.0 Fixed in 2.1 CVE-2023-29386 Patchstack
9.3 Critical Quiz And Survey Master Plugin quiz-master-next SQL Injection Unauthenticated SQL Injection No login needed ≤ 8.1.4 Fixed in 8.1.5 CVE-2023-28787 Patchstack
10.0 Critical MainWP File Uploader Extension Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.1 Fixed in 4.1.1 CVE-2023-23656 Patchstack
9.1 Critical Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-30231 Patchstack
9.8 Critical MoveTo Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 6.2 CVE-2024-25912 Patchstack
9.9 Critical Automatic Plugin SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27956 Patchstack
9.9 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.11.15 Fixed in 2.11.16 CVE-2024-29135 Patchstack
10.0 Critical Pie Register Plugin pie-register Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.8.3.1 CVE-2024-27957 Patchstack
9.8 Critical Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member SQL Injection User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sor… No login needed 2.1.3 – 2.8.2 CVE-2024-1071 Wordfence
9.8 Critical Migration, Backup, Staging – WPvivid Plugin wpvivid-backuprestore SQL Injection WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the… No login needed 0.9.68 CVE-2024-1981 Wordfence
9.1 Critical Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Arbitrary File Upload WordPress Mollie Payments for WooCommerce Plugin <= 7.3.11 is vulnerable to Arbitrary File Upload ≤ 7.3.11 Fixed in 7.3.12 CVE-2023-6090 Patchstack
9.8 Critical MoveTo Plugin SQL Injection WordPress MoveTo Plugin <= 6.2 is vulnerable to SQL Injection No login needed ≤ 6.2 CVE-2024-25910 Patchstack
9.3 Critical postMash – custom post order Plugin postmash SQL Injection custom post order Plugin <= 1.2.0 is vulnerable to SQL Injection No login needed ≤ 1.2.0 CVE-2024-25927 Patchstack
9.9 Critical WP Media folder Plugin Arbitrary File Upload WordPress WP Media folder Plugin <= 5.7.2 is vulnerable to Arbitrary File Upload ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25909 Patchstack
10.0 Critical MoveTo Plugin Arbitrary File Upload WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload No login needed ≤ 6.2 CVE-2024-25913 Patchstack
10.0 Critical WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin Arbitrary File Upload WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload No login needed ≤ 3.5.12 Fixed in 3.5.13 CVE-2024-25925 Patchstack
9.8 Critical MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system SQL Injection for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection No login needed ≤ 3.2.5 CVE-2024-1512 Wordfence
9.8 Critical ERE Recently Viewed – Essential Real Estate Add-On Plugin ere-recently-viewed PHP Object Injection WordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object Injection No login needed ≤ 1.3 CVE-2024-24797 Patchstack
10.0 Critical Coupon Referral Program Plugin coupon-referral-program PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.8.4 Fixed in 1.8.4 CVE-2024-25100 Patchstack
9.8 Critical Cryptocurrency Widgets – Price Ticker & Coins List Plugin cryptocurrency-price-ticker-widget SQL Injection Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficie… No login needed 2.0 – 2.6.5 CVE-2024-0709 Wordfence
10.0 Critical Barcode Scanner and Inventory manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Arbitrary File Upload WordPress Barcode Scanner with Inventory & Order Manager Plugin <= 1.5.1 is vulnerable to Arbitrary File Upload No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52221 Patchstack
9.8 Critical WordPress Database Administrator Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.3 CVE-2023-3211 WPScan
9.8 Critical POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp Broken Access Control Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API No login needed ≤ 2.8.7 CVE-2023-6875 Wordfence
9.1 Critical HTML5 MP3 Player with Folder Feedburner Playlist Free Plugin html5-mp3-player-with-mp3-folder-feedburner-playlist PHP Object Injection WordPress HTML5 MP3 Player with Folder Feedburner Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52202 Patchstack
9.6 Critical ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Request Forgery WordPress ARMember Plugin <= 4.0.22 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object Injection No login needed ≤ 4.0.22 Fixed in 4.0.23 CVE-2023-52200 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack
9.1 Critical HTML5 MP3 Player with Playlist Free Plugin html5-mp3-player-with-playlist PHP Object Injection WordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object Injection ≤ 3.0.0 CVE-2023-52207 Patchstack
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack
9.9 Critical Gecka Terms Thumbnails Plugin gecka-terms-thumbnails PHP Object Injection WordPress Gecka Terms Thumbnails Plugin <= 1.1 is vulnerable to PHP Object Injection ≤ 1.1 CVE-2023-52219 Patchstack
10.0 Critical Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics Plugin taggbox-widget PHP Object Injection WordPress Taggbox Plugin <= 3.1 is vulnerable to PHP Object Injection No login needed ≤ 3.1 CVE-2023-52225 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only