WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,601–14,650 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 293 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Paid Memberships Pro Plugin paid-memberships-pro SQL Injection Authenticated SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-37486 Patchstack
8.5 High Youzify Plugin youzify SQL Injection ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-37494 Patchstack
5.4 Medium WooCommerce Social Login Plugin woo-social-login PHP Object Injection No login needed ≤ 2.6.3 Fixed in 2.7.0 CVE-2024-37502 Patchstack
5.4 Medium Cliengo – Chatbot Plugin cliengo Cross-Site Request Forgery Chatbot plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37923 Patchstack
9.6 Critical Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery CSRF to Arbitrary File Upload ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-37555 Patchstack
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting ≤ 2.0.2 CVE-2024-37554 Patchstack
6.5 Medium Testimonials Widget Plugin testimonials-widget Cross-Site Scripting ≤ 4.0.4 CVE-2024-37553 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Local File Inclusion ≤ 8.4.0 Fixed in 8.4.1 CVE-2024-37547 Patchstack
6.5 Medium Image Hover Effects - Caption Hover with Carousel Plugin image-hover-effects-with-carousel Cross-Site Scripting ≤ 3.0.2 CVE-2024-37546 Patchstack
5.4 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2024-37542 Patchstack
6.5 Medium Elementor Addons, Widgets and Enhancements – Stax Plugin stax-addons-for-elementor Cross-Site Scripting Stax plugin <= 1.5.0 - Cross Site Scripting (XSS) ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-37541 Patchstack
6.5 Medium WP To Do Plugin wp-todo Cross-Site Scripting ≤ 1.3.0 CVE-2024-37539 Patchstack
3.5 Low Academy LMS Plugin academy Open Redirect ≤ 2.0.4 CVE-2024-37234 Patchstack
4.9 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery ≤ 5.7 Fixed in 5.8 CVE-2024-37208 Patchstack
7.2 High Foxiz Theme Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-37260 Patchstack
7.1 High Woffice Core Plugin Cross-Site Scripting Site Wide Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8 Fixed in 5.4.9 CVE-2024-37471 Patchstack
7.1 High Woffice Plugin woffice Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.8 Fixed in 5.4.9 CVE-2024-37472 Patchstack
6.5 Medium Newspack Ads Plugin Cross-Site Scripting ≤ 1.47.1 Fixed in 1.47.2 CVE-2024-37474 Patchstack
6.5 Medium Newspack Campaigns Plugin Cross-Site Scripting ≤ 2.31.1 Fixed in 2.31.2 CVE-2024-37476 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Other WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration No login needed ≤ 4.2.6.8.1 CVE-2024-6099 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass No login needed ≤ 4.2.6.8.1 CVE-2024-6088 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 3.1.9 CVE-2024-4268 Wordfence
8.5 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Contributor+ Local File Inclusion ≤ 1.3.8.1 Fixed in 1.3.9 CVE-2024-37479 Patchstack
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via title tag attribute ≤ 3.1.9 CVE-2024-3513 Wordfence
9.8 Critical Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed ≤ 5.7.25 CVE-2024-6172 Wordfence
5.4 Medium Basil Theme Cross-Site Scripting WordPress Basil Theme Authenticated (Contributor+) Persistent Cross-Site Scripting < 2.0.5 CVE-2024-39310 GitHub_M
8.8 High WordPress Plugin for Google Maps – WP MAPS Plugin wp-google-map-plugin SQL Injection WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection ≤ 4.6.1 CVE-2024-2386 Wordfence
9.8 Critical UsersWP – Front-end login form, User Registration, User Profile & Members Directory Plugin userswp SQL Injection Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' No login needed ≤ 1.2.10 CVE-2024-6265 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
6.5 Medium jQuery T(-) Countdown Widget Plugin jquery-t-countdown-widget Cross-Site Scripting ≤ 2.3.25 CVE-2024-37247 Patchstack
6.5 Medium Anima Theme anima Cross-Site Scripting ≤ 1.4.1 CVE-2024-37248 Patchstack
4.4 Medium BlossomThemes Email Newsletter Plugin blossomthemes-email-newsletter Server-Side Request Forgery ≤ 2.2.6 Fixed in 2.2.7 CVE-2024-37098 Patchstack
9.3 Critical Email Subscribers & Newsletters Plugin email-subscribers SQL Injection No login needed ≤ 5.7.25 Fixed in 5.7.26 CVE-2024-37252 Patchstack
6.4 Medium The7 — Website and eCommerce Builder Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute ≤ 11.13.0 CVE-2024-5451 Wordfence
5.0 Medium WordPress Core Path Traversal Auth. Arbitrary .html File Read (Windows Only) 6.5 – 6.5.4, 6.4 – 6.4.4, 6.3 – 6.3.4, … Fixed in 6.5.5 CVE-2024-32111 Patchstack
6.5 Medium WordPress Core Cross-Site Scripting 6.5 – 6.5.4, 6.4 – 6.4.4, 6.3 – 6.3.4, … Fixed in 6.5.5 CVE-2024-31111 Patchstack
6.4 Medium WordPress Core Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, … CVE-2024-6307 Wordfence
10.0 Critical Several WordPress.org Plugins <= Various Versions Plugin social-warfare Other Injected Backdoor No login needed 4.4.6.4 – 4.4.7.1, 1.0.4 – 1.0.5, 1.2.1 – 1.2.2, … CVE-2024-6297 Wordfence
4.3 Medium Play.ht Plugin play-ht Broken Access Control ≤ 3.6.4 CVE-2024-37233 Patchstack
8.6 High Salon booking system Plugin salon-booking-system Arbitrary File Deletion No login needed ≤ 9.9 Fixed in 10.0 CVE-2024-37231 Patchstack
10.0 Critical InstaWP Connect Plugin instawp-connect Arbitrary File Upload No login needed ≤ 0.1.0.38 Fixed in 0.1.0.39 CVE-2024-37228 Patchstack
7.5 High WishList Member X Plugin Denial of Service Unauthenticated Denial of Service Attack No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37111 Patchstack
9.9 Critical WishList Member X Plugin Remote Code Execution Authenticated Arbitrary PHP Code Execution < 3.26.7 Fixed in 3.26.7 CVE-2024-37109 Patchstack
8.8 High WishList Member X Plugin Privilege Escalation Authenticated Privilege Escalation < 3.26.7 Fixed in 3.26.7 CVE-2024-37107 Patchstack
8.5 High Consulting Elementor Widgets Plugin Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37092 Patchstack
9.9 Critical Consulting Elementor Widgets Plugin Remote Code Execution ≤ 1.3.0, ≤ 1.2.2 Fixed in 1.3.1 CVE-2024-37091 Patchstack
9.0 Critical Consulting Elementor Widgets Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37089 Patchstack
6.5 Medium Word Balloon Plugin word-balloon Local File Inclusion ≤ 4.21.1 Fixed in 4.22.0 CVE-2024-35781 Patchstack
6.5 Medium Slideshow SE Plugin slideshow-se Local File Inclusion Auth. Limited Local File Inclusion ≤ 2.5.17 Fixed in 2.5.18 CVE-2024-35778 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.4 Fixed in 1.4.1 CVE-2024-35767 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only