WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 1,401–1,450 of 1,491 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Split Test For Elementor | Cross-Site Request Forgery No login needed |
≤ 1.6.9 Fixed in 1.7.0 |
CVE-2023-51407 |
Patchstack | |
| 4.3 Medium | Paid Member Subscriptions | Cross-Site Request Forgery No login needed |
≤ 2.10.4 Fixed in 2.10.5 |
CVE-2023-51522 |
Patchstack | |
| 4.3 Medium | Customize My Account for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 1.8.3 Fixed in 1.8.4 |
CVE-2023-51369 |
Patchstack | |
| 4.3 Medium | Legal Pages | Cross-Site Request Forgery CSRF + Broken Access Control |
≤ 1.3.7 Fixed in 1.3.8 |
CVE-2023-50886 |
Patchstack | |
| 4.3 Medium | WP Simple Booking Calendar | Cross-Site Request Forgery No login needed |
≤ 2.0.8.4 Fixed in 2.0.8.5 |
CVE-2023-51525 |
Patchstack | |
| 4.3 Medium | HUSKY – Products Filter for WooCommerce (formerly WOOF) | Cross-Site Request Forgery No login needed |
≤ 1.3.4.3 Fixed in 1.3.4.4 |
CVE-2023-50861 |
Patchstack | |
| 5.4 Medium | Sirv | Server-Side Request Forgery |
≤ 7.2.0 Fixed in 7.2.1 |
CVE-2024-27949 |
Patchstack | |
| 5.4 Medium | Perfmatters | Broken Access Control WordPress Perfmatters Plugin <= 2.1.6 is vulnerable to Broken Access Control |
≤ 2.1.6 Fixed in 2.1.7 |
CVE-2023-47874 |
Patchstack | |
| 5.4 Medium | Thrive Automator | Cross-Site Request Forgery WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.17 Fixed in 1.17.1 |
CVE-2023-51531 |
Patchstack | |
| 4.3 Medium | Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation | Cross-Site Request Forgery WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2023-51530 |
Patchstack | |
| 4.3 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Request Forgery WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.3.3 Fixed in 2.3.4 |
CVE-2023-51529 |
Patchstack | |
| 4.3 Medium | AI Power: Complete AI Pack – Powered by GPT-4 | Cross-Site Request Forgery WordPress GPT3 AI Content Writer Plugin <= 1.8.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.8.12 Fixed in 1.8.13 |
CVE-2023-51528 |
Patchstack | |
| 4.3 Medium | Spam protection, Anti-Spam, FireWall by CleanTalk | Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.20 Fixed in 6.21 |
CVE-2023-51696 |
Patchstack | |
| 5.4 Medium | Ecwid Ecommerce Shopping Cart | Cross-Site Request Forgery WordPress Ecwid Shopping Cart Plugin <= 6.12.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.12.4 Fixed in 6.12.5 |
CVE-2023-51533 |
Patchstack | |
| 5.4 Medium | Atahualpa | Cross-Site Request Forgery WordPress Atahualpa Theme <= 3.7.24 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.7.24 |
CVE-2024-27948 |
Patchstack | |
| 5.4 Medium | Easy PayPal & Stripe Buy Now Button | Cross-Site Request Forgery WordPress Easy PayPal Buy Now Button Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.8.1 Fixed in 1.8.2 |
CVE-2023-51683 |
Patchstack | |
| 6.5 Medium | Duplicator – WordPress Migration & Backup | Cross-Site Request Forgery WordPress Duplicator Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.7 Fixed in 1.5.7.1 |
CVE-2023-51681 |
Patchstack | |
| 5.4 Medium | MailerLite – WooCommerce integration | Cross-Site Request Forgery WooCommerce integration Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2023-52223 |
Patchstack | |
| 4.3 Medium | Advanced Flamingo | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2023-52226 |
Patchstack | |
| 5.4 Medium | 1 click disable all | Cross-Site Request Forgery WordPress 1 click disable all Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.1 |
CVE-2024-21749 |
Patchstack | |
| 4.3 Medium | Email Before Download | Cross-Site Request Forgery WordPress Email Before Download Plugin <= 6.9.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.9.7 Fixed in 6.9.8 |
CVE-2024-23519 |
Patchstack | |
| 4.3 Medium | A no-code page builder for beautiful performance-based content | Cross-Site Request Forgery WordPress Setka Editor Plugin <= 2.1.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.1.20 |
CVE-2024-24701 |
Patchstack | |
| 4.3 Medium | Page Restrict | Cross-Site Request Forgery WordPress Page Restrict Plugin <= 2.5.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.5.5 |
CVE-2024-24702 |
Patchstack | |
| 5.4 Medium | Accessibility | Cross-Site Request Forgery WordPress Accessibility Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.6 |
CVE-2024-24705 |
Patchstack | |
| 4.3 Medium | W3SPEEDSTER | Cross-Site Request Forgery WordPress W3SPEEDSTER Plugin <= 7.19 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.19 |
CVE-2024-24708 |
Patchstack | |
| 4.3 Medium | Custom Order Statuses for WooCommerce | Cross-Site Request Forgery WordPress Custom Order Statuses for WooCommerce Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.2 |
CVE-2024-25930 |
Patchstack | |
| 4.3 Medium | Heureka | Cross-Site Request Forgery WordPress Heureka Plugin <= 1.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.8 |
CVE-2024-25931 |
Patchstack | |
| 4.3 Medium | Change Table Prefix | Cross-Site Request Forgery No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2024-25932 |
Patchstack | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_set_default_card No login needed |
≤ 20221130 |
CVE-2024-0431 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_delete_card No login needed |
≤ 20221130 |
CVE-2024-0432 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_unset_default_card No login needed |
≤ 20221130 |
CVE-2024-0433 |
Wordfence | |
| 5.4 Medium | SuperFaktura WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.40.3 |
CVE-2024-1758 |
Wordfence | |
| 4.9 Medium | Pexels: Free Stock Photos | Server-Side Request Forgery WordPress Pexels: Free Stock Photos Plugin <= 1.2.2 is vulnerable to Server Side Request Forgery (SSRF) |
≤ 1.2.2 |
CVE-2024-25915 |
Patchstack | |
| 4.3 Medium | Debug | Cross-Site Request Forgery WordPress Debug Plugin <= 1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.10 |
CVE-2024-24798 |
Patchstack | |
| 4.3 Medium | JTRT Responsive Tables | Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 4.1.9 |
CVE-2024-24802 |
Patchstack | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 4.3 Medium | Quicksand Post Filter jQuery | Cross-Site Request Forgery WordPress Quicksand Post Filter jQuery Plugin Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.1 |
CVE-2024-24849 |
Patchstack | |
| 4.3 Medium | Themify Builder | Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.0.5 Fixed in 7.0.6 |
CVE-2024-24872 |
Patchstack | |
| 4.3 Medium | Admin Menu Editor | Cross-Site Request Forgery WordPress Admin Menu Editor Plugin <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.12 Fixed in 1.12.1 |
CVE-2024-24876 |
Patchstack | |
| 4.3 Medium | TinyMCE and TinyMCE Advanced Professsional Formats and Styles | Cross-Site Request Forgery WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.1.2 |
CVE-2024-25904 |
Patchstack | |
| 5.4 Medium | Multi Step Form | Cross-Site Request Forgery WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.18 |
CVE-2024-25905 |
Patchstack | |
| 4.3 Medium | SMTP Mail | Cross-Site Request Forgery WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3.20 |
CVE-2024-25914 |
Patchstack | |
| 5.4 Medium | lasTunes | Cross-Site Request Forgery Settings Update via CSRF |
≤ 3.6.1 |
CVE-2023-6499 |
WPScan | |
| 4.3 Medium | Splashscreen | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.20 |
CVE-2023-6501 |
WPScan | |
| 4.3 Medium | Link Library | Cross-Site Request Forgery WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.5.13 Fixed in 7.6 |
CVE-2024-24875 |
Patchstack | |
| 4.3 Medium | Contact Form 7 Connector | Cross-Site Request Forgery WordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2024-24884 |
Patchstack | |
| 5.4 Medium | Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting | Cross-Site Request Forgery WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 21.2.8.4 Fixed in 21.2.9 |
CVE-2024-24887 |
Patchstack | |
| 4.3 Medium | WP Contact Form | Cross-Site Request Forgery WordPress WP Contact Form Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.6 |
CVE-2024-24929 |
Patchstack | |
| 4.3 Medium | Basic Log Viewer | Cross-Site Request Forgery WordPress Basic Log Viewer Plugin <= 1.0.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.4 |
CVE-2024-24935 |
Patchstack | |
| 5.4 Medium | WP-CFM | Cross-Site Request Forgery WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2024-24706 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.