WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,901–14,950 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 299 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Bosa Elementor Addons and Templates for WooCommerce Plugin bosa-elementor-for-woocommerce Broken Access Control ≤ 1.0.12 Fixed in 1.0.13 CVE-2024-35724 Patchstack
4.3 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Broken Access Control ≤ 1.3.6 Fixed in 1.3.7.4 CVE-2024-35725 Patchstack
4.3 Medium WooBuddy Plugin wc4bp Broken Access Control ≤ 3.4.19 Fixed in 3.4.20 CVE-2024-35726 Patchstack
4.3 Medium Extra Product Options for WooCommerce Plugin extra-product-options-for-woocommerce Broken Access Control ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-35727 Patchstack
5.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control No login needed ≤ 3.5.2.6 Fixed in 3.5.2.7 CVE-2024-35729 Patchstack
5.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2024-35735 Patchstack
4.3 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.1.7 Fixed in 6.1.8 CVE-2024-35741 Patchstack
5.3 Medium Easy Forms for Mailchimp Plugin yikes-inc-easy-mailchimp-extender Broken Access Control No login needed ≤ 6.9.0 CVE-2024-35742 Patchstack
5.3 Medium WooCommerce Dropshipping Plugin Broken Access Control Unauthenticated Arbitrary Email Sending No login needed ≤ 5.0.4 CVE-2024-35748 Patchstack
4.3 Medium Filter Custom Fields & Taxonomies Light Plugin filter-custom-fields-taxonomies-light Broken Access Control ≤ 1.05 CVE-2024-32081 Patchstack
5.3 Medium AdFoxly – Ad Manager, AdSense Ads & Ads.txt Plugin adfoxly Broken Access Control No login needed ≤ 1.8.5 CVE-2024-34802 Patchstack
5.3 Medium Upload Fields for WPForms Plugin upload-fields-for-wpforms Broken Access Control No login needed ≤ 1.0.2 CVE-2024-35661 Patchstack
5.4 Medium Simple COD Fees for WooCommerce Plugin simple-cod-fee-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-35662 Patchstack
5.3 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Broken Access Control No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-31276 Patchstack
6.5 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.8 Fixed in 3.9.9 CVE-2024-31284 Patchstack
6.3 Medium Easy Social Share Buttons Plugin Broken Access Control Multiple Broken Access Control ≤ 9.4 Fixed in 9.5 CVE-2024-31307 Patchstack
4.3 Medium Tracking Code Manager Plugin tracking-code-manager Broken Access Control ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-31347 Patchstack
4.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control ≤ 4.3.1 Fixed in 4.3.2 CVE-2024-31350 Patchstack
5.3 Medium Email Subscribers & Newsletters Plugin email-subscribers Broken Access Control No login needed ≤ 5.7.13 Fixed in 5.7.14 CVE-2024-31352 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
4.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control ≤ 0.1.0.24 Fixed in 0.1.0.25 CVE-2024-32701 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.5 Fixed in 0.6.2.6 CVE-2024-31423 Patchstack
5.4 Medium AI Post Generator | AutoWriter Plugin ai-post-generator Broken Access Control ≤ 3.3 Fixed in 3.4 CVE-2024-32713 Patchstack
4.3 Medium Academy LMS Plugin academy Broken Access Control ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-32714 Patchstack
5.3 Medium 5 Stars Rating Funnel Plugin 5-stars-rating-funnel Broken Access Control No login needed ≤ 1.2.67 Fixed in 1.3.02 CVE-2024-32725 Patchstack
5.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-32727 Patchstack
5.3 Medium Vision Interactive Plugin vision Broken Access Control Image Map Builder plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-32779 Patchstack
4.3 Medium Advanced Testimonial Carousel for Elementor Plugin advanced-testimonial-carousel-for-elementor Broken Access Control ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-32783 Patchstack
4.3 Medium CookieHub Plugin cookiehub Broken Access Control ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-32784 Patchstack
4.3 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Broken Access Control ≤ 3.7.1 Fixed in 3.7.2 CVE-2024-32787 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.7.3 Fixed in 3.7.4 CVE-2024-32792 Patchstack
5.4 Medium WP LinkedIn Auto Publish Plugin wp-linkedin-auto-publish Broken Access Control ≤ 8.11 Fixed in 8.12 CVE-2024-32797 Patchstack
5.3 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2024-32799 Patchstack
4.3 Medium WP GoToWebinar Plugin wp-gotowebinar Broken Access Control ≤ 14.46 Fixed in 15.1 CVE-2024-32804 Patchstack
6.5 Medium Social Snap Plugin socialsnap Broken Access Control No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-32805 Patchstack
5.3 Medium USPS Shipping for WooCommerce – Live Rates Plugin flexible-shipping-usps Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed ≤ 1.9.4 Fixed in 1.10.0 CVE-2024-32811 Patchstack
5.3 Medium Integrate Google Drive Plugin integrate-google-drive Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.3.91 CVE-2024-32813 Patchstack
5.3 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32814 Patchstack
4.3 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Broken Access Control Meta Data and Taxonomies Filter plugin <= 1.3.3 - Broken Access Control ≤ 1.3.3 Fixed in 1.3.3.1 CVE-2024-32818 Patchstack
5.3 Medium Social Share Icons & Social Share Buttons Plugin ultimate-social-media-plus Broken Access Control Broken Access Control lead to Notice Dismissal No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2024-32820 Patchstack
4.3 Medium Total Poll Lite Plugin totalpoll-lite Broken Access Control ≤ 4.9.9 Fixed in 4.10.0 CVE-2024-32821 Patchstack
5.4 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-32824 Patchstack
5.3 Medium WZone Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 14.0.10 CVE-2024-33545 Patchstack
4.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Broken Access Control ≤ 3.2.5 Fixed in 3.2.6 CVE-2024-33572 Patchstack
4.3 Medium Aiomatic Plugin Broken Access Control ≤ 1.9.3 Fixed in 1.9.4 CVE-2024-34435 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on API No login needed ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-35660 Patchstack
4.3 Medium Debug Log Manager Plugin debug-log-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-35669 Patchstack
5.3 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.11 Fixed in 3.9.12 CVE-2024-31274 Patchstack
5.3 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control No login needed ≤ 2.8.3 Fixed in 2.8.4 CVE-2024-31273 Patchstack
4.3 Medium Flexible Checkout Fields for WooCommerce Plugin flexible-checkout-fields Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-31267 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only