WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,651–14,700 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 294 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical JupiterX Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.3.8 Fixed in 3.4.3 CVE-2023-38389 Patchstack
3.7 Low Solid Security Plugin better-wp-security Denial of Service IP Spoofing Leading to Denial of Service No login needed ≤ 9.3.1 Fixed in 9.3.2 CVE-2022-44593 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2022-44587 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Content Injection Auth. HTML Injection ≤ 2.0.9 Fixed in 2.1.0 CVE-2022-38055 Patchstack
5.4 Medium Uncanny Automator Pro Plugin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Leading to License Settings Reset No login needed ≤ 5.3 CVE-2024-37118 Patchstack
4.3 Medium Digital Newspaper Theme digital-newspaper Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-37198 Patchstack
8.3 High Ali2Woo Lite Plugin ali2woo-lite Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 3.3.5 CVE-2024-37212 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.9.7 Fixed in 4.9.8 CVE-2024-37227 Patchstack
4.3 Medium Book Landing Page Theme book-landing-page Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-37230 Patchstack
4.3 Medium EmbedPress Plugin embedpress Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2023-51375 Patchstack
6.5 Medium WordPress Form Builder Plugin – Gutenberg Forms Plugin forms-gutenberg Broken Access Control Auth. Broken Access Control ≤ 2.2.8.3 Fixed in 2.2.9 CVE-2022-45803 Patchstack
8.8 High WP Tools Plugin wptools Broken Access Control Auth. Broken Access Control ≤ 3.41 Fixed in 3.43 CVE-2022-43453 Patchstack
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
4.3 Medium Customizr Theme customizr Cross-Site Request Forgery No login needed ≤ 4.4.21 Fixed in 4.4.22 CVE-2024-35771 Patchstack
4.3 Medium Hueman Theme hueman Cross-Site Request Forgery No login needed ≤ 3.7.24 Fixed in 3.7.25 CVE-2024-35772 Patchstack
5.3 Medium phpinfo() WP Plugin phpinfo-wp Information Disclosure Unauthenticated Data Exposure No login needed ≤ 5.0 CVE-2024-35776 Patchstack
5.3 Medium Event Management Tickets Booking Plugin event-monster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.0 CVE-2024-5059 Patchstack
5.9 Medium Easy Age Verify Plugin easy-age-verify Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-35757 Patchstack
6.5 Medium Interface Theme interface Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-35758 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35759 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35760 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-35761 Patchstack
6.5 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-35762 Patchstack
6.5 Medium Excellent Theme excellent Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-35763 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.4.4 Fixed in 4.4.5 CVE-2024-35764 Patchstack
7.1 High WPPizza Plugin wppizza Cross-Site Scripting A Restaurant Plugin plugin <= 3.18.13 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.18.13 Fixed in 3.18.14 CVE-2024-35766 Patchstack
5.9 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting ≤ 2.1.22 CVE-2024-35768 Patchstack
5.9 Medium Slideshow SE Plugin slideshow-se Cross-Site Scripting ≤ 2.5.17 CVE-2024-35769 Patchstack
6.5 Medium DImage 360 Plugin dimage-360 Cross-Site Scripting ≤ 2.0 CVE-2024-35774 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting Contributor+ Shortcode Cross Site Scripting (XSS) ≤ 1.5.42 CVE-2024-35779 Patchstack
6.5 Medium Typing Text Plugin typing-text Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-5058 Patchstack
6.4 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.4.17 CVE-2024-5191 Wordfence
7.1 High Master Slider Plugin master-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.5 CVE-2024-37222 Patchstack
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify SQL Injection BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection ≤ 1.2.5 CVE-2024-4742 Wordfence
7.1 High Slider Revolution Plugin Broken Access Control Unauthenticated Broken Access Control No login needed < 6.7.0 Fixed in 6.7.0 CVE-2024-34444 Patchstack
5.9 Medium Slider Revolution Plugin Cross-Site Scripting < 6.7.11 Fixed in 6.7.11 CVE-2024-34443 Patchstack
5.4 Medium GamiPress Plugin gamipress Cross-Site Request Forgery CSRF Leading to Settings Change No login needed ≤ 2.5.6 Fixed in 2.5.7 CVE-2023-25697 Patchstack
6.5 Medium Attorney Theme attorney Broken Access Control Unauth. Arbitrary Content Deletion No login needed ≤ 3 CVE-2022-45832 Patchstack
9.1 Critical Avada Theme Broken Access Control Auth. Unrestricted Zip Extraction ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39312 Patchstack
7.3 High LearnPress Plugin learnpress Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 4.2.3 Fixed in 4.2.3.1 CVE-2023-36515 Patchstack
7.6 High LearnPress Plugin learnpress Broken Access Control Authenticated Broken Access Control ≤ 4.2.3 Fixed in 4.2.3.1 CVE-2023-36516 Patchstack
7.6 High Ninja Forms Plugin ninja-forms Broken Access Control Subscriber+ Broken Access Control ≤ 3.6.25 Fixed in 3.6.26 CVE-2023-38393 Patchstack
5.4 Medium JupiterX Core Plugin Broken Access Control Multiple Auth. Broken Access Control 3.0.0 – 3.3.0 Fixed in 3.3.5 CVE-2023-38394 Patchstack
5.4 Medium Fusion Builder Plugin Broken Access Control Authenticated Broken Access Control ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39310 Patchstack
5.4 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.6.6 Fixed in 2.6.7 CVE-2023-36676 Patchstack
6.5 Medium Schema Pro Plugin Broken Access Control No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2023-36683 Patchstack
7.1 High Convert Pro Plugin Broken Access Control No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2023-36684 Patchstack
6.5 Medium Premium Addons PRO Plugin Broken Access Control ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-37869 Patchstack
6.5 Medium WooCommerce Ship to Multiple Addresses Plugin Broken Access Control ≤ 3.8.5 Fixed in 3.8.6 CVE-2023-37872 Patchstack
7.6 High Ninja Forms Plugin ninja-forms Broken Access Control Contributor+ Broken Access Control ≤ 3.6.25 Fixed in 3.6.26 CVE-2023-38386 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only