WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,551–14,600 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 292 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Jobmonster Theme noo-jobmonster Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-37927 Patchstack
8.0 High WP User Switch Plugin wp-user-switch Privilege Escalation ≤ 1.1.0 CVE-2024-37560 Patchstack
4.3 Medium SociallyViral Theme sociallyviral Cross-Site Request Forgery No login needed ≤ 1.0.10 CVE-2024-37938 Patchstack
4.3 Medium Patricia Lite Theme patricia-lite Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2024-37939 Patchstack
7.4 High Seraphinite Accelerator (Full, premium) Plugin Cross-Site Request Forgery CSRF Leading to Arbitrary File Deletion No login needed ≤ 2.21.13 Fixed in 2.21.13.1 CVE-2024-37940 Patchstack
4.3 Medium Internal Link Juicer: SEO Auto Linker Plugin internal-links Cross-Site Request Forgery No login needed ≤ 2.24.3 Fixed in 2.24.4 CVE-2024-37941 Patchstack
7.1 High Comment Reply Email Plugin comment-reply-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 Fixed in 1.5 CVE-2024-35773 Patchstack
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack
7.1 High AliNext Plugin ali2woo-lite Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-37213 Patchstack
4.3 Medium Get Better Reviews for WooCommerce Plugin more-better-reviews-for-woocommerce Broken Access Control ≤ 4.0.6 CVE-2024-37544 Patchstack
8.5 High PayPlus Payment Gateway Plugin payplus-payment-gateway SQL Injection ≤ 7.0.7 Fixed in 7.0.8 CVE-2024-37564 Patchstack
9.3 Critical Woocommerce OpenPos Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.4 CVE-2024-37933 Patchstack
5.3 Medium WP Popups – WordPress Popup builder Plugin wp-popups-lite Information Disclosure WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure No login needed ≤ 2.2.0.1 CVE-2024-6555 Wordfence
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence
7.5 High WishList Member X Plugin Information Disclosure Unauthenticated Settings & Users Data Dump No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37110 Patchstack
9.8 Critical WishList Member X Plugin Information Disclosure Unauthenticated Database Backup Download No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37113 Patchstack
7.5 High Newspack Blocks Plugin Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37115 Patchstack
5.3 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-37205 Patchstack
5.3 Medium TrustedLogin Vendor Plugin Information Disclosure Sensitive Data Exposure No login needed < 1.1.1 Fixed in 1.1.1 CVE-2024-37270 Patchstack
5.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure via API No login needed ≤ 1.0.33 Fixed in 1.0.34 CVE-2024-37498 Patchstack
5.3 Medium FileBird Document Library Plugin filebird-document-library Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.6 Fixed in 2.0.8.1 CVE-2024-37504 Patchstack
5.3 Medium SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer Plugin Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.10.8 CVE-2024-6556 Wordfence
8.8 High BookYourTravel Theme Privilege Escalation Subscriber+ Privilege Escalation ≤ 8.18.17 Fixed in 8.18.19 CVE-2024-37952 Patchstack
5.4 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution ≤ 3.8.4 Fixed in 3.8.5 CVE-2024-37934 Patchstack
6.5 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Local File Inclusion Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-37520 Patchstack
8.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.27 Fixed in 2.2.28 CVE-2024-37513 Patchstack
8.5 High Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Local File Inclusion ≤ 3.1.3 Fixed in 3.2.1 CVE-2024-37501 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Local File Inclusion ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37499 Patchstack
7.7 High JetThemeCore Plugin jet-theme-core Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 2.2.1 Fixed in 2.2.1 CVE-2024-37497 Patchstack
8.8 High Zephyr Project Manager Plugin zephyr-project-manager Privilege Escalation ≤ 3.3.97 Fixed in 3.3.99 CVE-2024-37484 Patchstack
4.9 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Local File Inclusion ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-37464 Patchstack
8.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-37462 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.31 Fixed in 1.36.32 CVE-2024-37455 Patchstack
6.5 Medium AWSM Team Plugin awsm-team Local File Inclusion Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-37454 Patchstack
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
5.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Arbitrary SVG File Download ≤ 3.22.1 Fixed in 3.22.2 CVE-2024-37437 Patchstack
5.3 Medium Patreon Plugin patreon-connect Authentication Bypass Image Protection Bypass No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2024-37430 Patchstack
9.9 Critical Newspack Blocks Plugin Arbitrary File Upload ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37424 Patchstack
9.9 Critical Zita Elementor Site Library Plugin zita-site-library Remote Code Execution Arbitrary Code Execution ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37420 Patchstack
7.5 High Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Local File Inclusion Elementor Addons plugin <= 1.1.1 - Local File Inclusion No login needed ≤ 1.1.1 Fixed in 1.2.0 CVE-2024-37419 Patchstack
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.4.6 Fixed in 4.4.7 CVE-2024-37418 Patchstack
4.9 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Local File Inclusion ≤ 1.3.0.3 Fixed in 1.3.0.4 CVE-2024-37410 Patchstack
8.5 High Striking Theme Local File Inclusion ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-37268 Patchstack
4.9 Medium Tutor LMS Plugin tutor Path Traversal ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37266 Patchstack
2.7 Low WP Directory Kit Plugin wpdirectorykit Content Injection HTML Injection ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-37253 Patchstack
7.5 High SP Project & Document Manager Plugin sp-client-document-manager Path Traversal Directory Traversal No login needed ≤ 4.71 CVE-2024-37224 Patchstack
3.5 Low WooCommerce Plugin woocommerce Content Injection ≤ 8.9.2 Fixed in 9.0.0 CVE-2024-35777 Patchstack
10.0 Critical WishList Member X Plugin SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37112 Patchstack
8.5 High Zoho Marketing Automation Plugin zoho-marketinghub SQL Injection ≤ 1.2.7 CVE-2024-37225 Patchstack
7.6 High Tutor LMS Plugin tutor SQL Injection ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37256 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only