WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,401–1,450 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 29 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium WP Revisions Manager Plugin wp-revisions-manager Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2024-53761 Patchstack
4.3 Medium DancePress (TRWA) Plugin dancepress-trwa Cross-Site Request Forgery No login needed ≤ 3.1.11 CVE-2024-53775 Patchstack
4.4 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery ≤ 1.3.9.8 Fixed in 1.3.9.9 CVE-2024-53738 Patchstack
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
6.1 Medium Skt NURCaptcha Plugin skt-nurcaptcha Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.5.0 CVE-2024-11342 Wordfence
6.1 Medium WIP Incoming Lite Plugin wip-incoming-lite Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2024-11416 Wordfence
6.1 Medium Friendly Functions for Welcart Plugin friendly-functions-for-welcart Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.2.4 CVE-2024-10726 Wordfence
4.3 Medium Dynamic Widgets Plugin dynamic-widgets Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-51669 Patchstack
6.3 Medium W3SPEEDSTER Plugin w3speedster-wp Cross-Site Request Forgery No login needed ≤ 7.25 Fixed in 7.27 CVE-2024-52392 Patchstack
5.4 Medium ARMember Plugin armember-membership Cross-Site Request Forgery No login needed ≤ 4.0.5, < 6.7.1 Fixed in 4.0.6 CVE-2022-47424 Patchstack
4.3 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-43338 Patchstack
4.3 Medium Manage User Columns Plugin manage-user-columns Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51686 Patchstack
4.3 Medium Disable Admin Notices individually Plugin disable-admin-notices Cross-Site Request Forgery No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-52420 Patchstack
4.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Cross-Site Request Forgery All In One Form Integration including DB for Elementor <= 2.9.9.9 - Cross-Site Request Forgery No login needed ≤ 2.9.9.9 CVE-2024-6628 Wordfence
5.3 Medium 404 Error Monitor Plugin 404-error-monitor Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update via updatePluginSettings Function No login needed ≤ 1.1 CVE-2024-11118 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed ≤ 2.1.8 CVE-2024-11143 Wordfence
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
6.4 Medium Code Embed Plugin simple-embed-code Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.5 CVE-2024-10814 Wordfence
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
6.1 Medium WPGlobus Translate Options Plugin wpglobus-translate-options Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-9434 Wordfence
4.3 Medium DarkMySite – Advanced Dark Mode Plugin darkmysite Cross-Site Request Forgery Advanced Dark Mode Plugin for WordPress plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.8 CVE-2024-50466 Patchstack
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
4.3 Medium Transients Manager Plugin transients-manager Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2024-10045 Wordfence
5.4 Medium Category and Taxonomy Meta Fields Plugin wp-custom-taxonomy-meta Cross-Site Request Forgery Cross-Site Request Forgery to Taxonomy Meta Add/Delete No login needed ≤ 1.0.0 CVE-2024-9588 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
5.3 Medium Infinite-Scroll Plugin infinite-scroll Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.6.2 CVE-2024-10040 Wordfence
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
6.5 Medium Featured Posts with Multiple Custom Groups (FPMCG) Plugin featured-posts-with-multiple-custom-groups-fpmcg Cross-Site Request Forgery No login needed ≤ 4.0 CVE-2024-48031 Patchstack
4.3 Medium wp-Monalisa Plugin wp-monalisa Cross-Site Request Forgery No login needed ≤ 6.4 Fixed in 6.5 CVE-2024-48038 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation No login needed ≤ 1.35.1 CVE-2024-9351 Wordfence
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation No login needed ≤ 1.35.1 CVE-2024-9352 Wordfence
4.3 Medium WP ULike Plugin wp-ulike Cross-Site Request Forgery Cross-Site Request Forgery to Statistic Deletion No login needed ≤ 4.7.4 CVE-2024-9649 Wordfence
4.3 Medium ImagePress – Image Gallery Plugin image-gallery Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.2.2 CVE-2024-9778 Wordfence
6.1 Medium Easy PayPal Gift Certificate Plugin paypal-gift-certificate Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options No login needed ≤ 1.2.3 CVE-2024-9592 Wordfence
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.87 CVE-2024-8477 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only