WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1,351–1,400 of 1,491 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium WooCommerce Cart Abandonment Recovery Plugin Cross-Site Request Forgery Templates/Abandoned Orders Deletion via CSRF < 1.2.27 Fixed in 1.2.27 CVE-2024-2322 WPScan
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-30531 Patchstack
4.9 Medium Builderall Builder Plugin builderall-cheetah-for-wp Server-Side Request Forgery ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-30532 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.25 Fixed in 3.2.26 CVE-2024-24888 Patchstack
4.7 Medium WooCommerce Product Filter Plugin Cross-Site Request Forgery Filter Deletion via CSRF No login needed < 1.4.4 Fixed in 1.4.4 CVE-2024-2262 WPScan
4.3 Medium Easy Social Feed Plugin easy-facebook-likebox Cross-Site Request Forgery Social Photos Gallery – Post Feed – Like Box plugin <= 6.5.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 6.5.6 CVE-2024-30526 Patchstack
4.3 Medium Slugs Manager Plugin remove-old-slugspermalinks Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.7.0 CVE-2024-30536 Patchstack
4.3 Medium LWS Optimize Plugin lws-optimize Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 2.0 CVE-2024-30541 Patchstack
4.3 Medium Nictitate Theme nictitate Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-31096 Patchstack
5.4 Medium Popup Cart Lite for WooCommerce Plugin woocommerce-woocart-popup-lite Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-31100 Patchstack
5.4 Medium Brave Popup Builder Plugin brave-popup-builder Server-Side Request Forgery No login needed ≤ 0.6.5 Fixed in 0.6.6 CVE-2024-30453 Patchstack
4.3 Medium GamiPress Plugin gamipress Cross-Site Request Forgery No login needed ≤ 6.8.5 Fixed in 6.8.6 CVE-2024-30455 Patchstack
4.3 Medium Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30460 Patchstack
4.3 Medium WP SMS Plugin wp-sms Cross-Site Request Forgery No login needed ≤ 6.6.2 Fixed in 6.6.3 CVE-2024-30454 Patchstack
4.3 Medium HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin woocommerce-products-filter Cross-Site Request Forgery No login needed ≤ 1.3.5.1 Fixed in 1.3.5.2 CVE-2024-30462 Patchstack
4.3 Medium All In One WP Security & Firewall Plugin all-in-one-wp-security-and-firewall Cross-Site Request Forgery Security and Firewall plugin <= 5.2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.2.6 Fixed in 5.2.7 CVE-2024-30468 Patchstack
4.3 Medium Simple Revisions Delete Plugin simple-revisions-delete Cross-Site Request Forgery No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-30482 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-30518 Patchstack
5.4 Medium Landingi Landing Pages Plugin landingi-landing-pages Cross-Site Request Forgery No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-30521 Patchstack
4.3 Medium Church Admin Plugin church-admin Cross-Site Request Forgery No login needed ≤ 4.1.7 Fixed in 4.1.8 CVE-2024-30493 Patchstack
4.3 Medium WPCS Plugin currency-switcher Cross-Site Request Forgery WordPress Currency Switcher Professional plugin <=1.2.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.0.1 Fixed in 1.2.0.2 CVE-2024-30456 Patchstack
4.3 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Request Forgery No login needed ≤ 1.3.3.1 Fixed in 1.3.3.2 CVE-2024-30457 Patchstack
4.3 Medium WOOCS – WooCommerce Currency Switcher Plugin woocommerce-currency-switcher Cross-Site Request Forgery Currency Switcher Professional for WooCommerce plugin <= 1.4.1.7 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.4.1.7 Fixed in 1.4.1.8 CVE-2024-30458 Patchstack
4.3 Medium Events Manager Plugin events-manager Cross-Site Request Forgery No login needed ≤ 6.4.7.1 Fixed in 6.4.7.2 CVE-2024-30421 Patchstack
6.1 Medium Image Map Pro Plugin Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) leading to Stored Cross-Site Scripting (XSS) No login needed < 5.6.9 Fixed in 5.6.9 CVE-2022-45850 Patchstack
5.5 Medium CMP – Coming Soon & Maintenance Plugin cmp-coming-soon-maintenance Server-Side Request Forgery Coming Soon & Maintenance Plugin by NiteoThemes plugin <= 4.1.10 - Server Side Request Forgery (SSRF) ≤ 4.1.10 Fixed in 4.1.11 CVE-2023-50374 Patchstack
6.8 Medium AI Engine: ChatGPT Chatbot Plugin ai-engine Server-Side Request Forgery ≤ 2.1.4 Fixed in 2.1.5 CVE-2024-29090 Patchstack
5.1 Medium Pz-LinkCard Plugin pz-linkcard Server-Side Request Forgery Contributor+ SSRF ≤ 2.5.1 CVE-2024-0677 WPScan
6.1 Medium WordPress Countdown Widget Plugin wordpress-countdown-widget Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) leading to Cross-Site Scripting (XSS) No login needed ≤ 3.1.9.1 Fixed in 3.1.9.3 CVE-2022-45847 Patchstack
4.3 Medium Don't Muck My Markup Plugin dont-muck-my-markup Cross-Site Request Forgery No login needed ≤ 1.8 CVE-2024-23510 Patchstack
5.4 Medium Post Video Players Plugin video-playlist-and-gallery-plugin Cross-Site Request Forgery No login needed ≤ 1.159 Fixed in 1.160 CVE-2024-23515 Patchstack
5.4 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Cross-Site Request Forgery No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2023-44999 Patchstack
6.5 Medium DearFlip Plugin 3d-flipbook-dflip-lite Cross-Site Scripting ≤ 2.2.26 Fixed in 2.2.27 CVE-2024-29807 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
4.3 Medium Calliope Theme calliope Cross-Site Request Forgery No login needed ≤ 1.0.33 Fixed in 1.0.35 CVE-2024-2904 Patchstack
4.3 Medium Clotya Theme Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in multiple themes by KlbTheme No login needed ≤ 1.1.6, ≤ 1.7.7, ≤ 1.2.2, … CVE-2023-49838 Patchstack
6.5 Medium EnvíaloSimple Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2023-51416 Patchstack
4.8 Medium CM Download Manager Plugin cm-download-manager Cross-Site Request Forgery Download Deletion via CSRF < 2.9.0 Fixed in 2.9.0 CVE-2024-1232 WPScan
6.8 Medium CM Download and File Manager Plugin Cross-Site Request Forgery Download Unpublish via CSRF < 2.9.0 Fixed in 2.9.0 CVE-2024-1231 WPScan
6.1 Medium easy-popup-show Plugin easy-popup-show Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to p… No login needed all versions CVE-2024-29009 jpcert
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
4.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.01.3 Fixed in 1.01.4 CVE-2024-29093 Patchstack
6.5 Medium Tourfic Plugin tourfic Cross-Site Scripting ≤ 2.11.8 Fixed in 2.11.9 CVE-2024-29134 Patchstack
5.4 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.101 Fixed in 1.2.102 CVE-2023-51486 Patchstack
5.4 Medium ARI Stream Quiz Plugin ari-stream-quiz Cross-Site Request Forgery WordPress Quizzes Builder plugin <= 1.2.32 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.32 Fixed in 1.3.0 CVE-2023-51487 Patchstack
5.4 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51489 Patchstack
5.4 Medium Depicter Slider Plugin depicter Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-51491 Patchstack
4.3 Medium Export Media URLs Plugin export-media-urls Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 2.0 CVE-2023-51510 Patchstack
4.3 Medium Product Table by WBW Plugin woo-product-tables Cross-Site Request Forgery No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2023-51512 Patchstack
5.4 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Request Forgery No login needed ≤ 8.1.18 Fixed in 8.1.19 CVE-2023-51521 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only