WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 151 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Simple Dashboard Plugin simple-dashboard Privilege Escalation No login needed ≤ 2.0 CVE-2024-56071 Patchstack
6.5 Medium Uncanny Toolkit for LearnDash Plugin uncanny-learndash-toolkit Broken Access Control No login needed ≤ 3.6.4.3 Fixed in 3.6.4.4 CVE-2023-34019 Patchstack
6.1 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.8.15 Fixed in 2.8.15 CVE-2024-11107 WPScan
4.9 Medium System Dashboard Plugin system-dashboard Path Traversal Admin+ Path Traversal < 2.8.15 Fixed in 2.8.15 CVE-2024-10708 WPScan
4.3 Medium WPDash Notes Plugin wpdash-notes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 1.3.5 CVE-2024-9223 Wordfence
4.3 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-43338 Patchstack
6.5 Medium Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2024-51860 Patchstack
7.1 High Dashing Memberships Plugin dashing-memberships Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51760 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Duplication ≤ 4.1.4.0 Fixed in 4.1.4.1 CVE-2024-37439 Patchstack
6.4 Medium WP Adminify – Best WordPress Custom Dashboard Plugin adminify Cross-Site Scripting Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0.1.6 CVE-2024-8959 Wordfence
7.2 High MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin Cross-Site Scripting The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting No login needed < 3.1.3 Fixed in 3.1.3 CVE-2016-15041 Wordfence
6.1 Medium Download Plugins and Themes in ZIP from Dashboard Plugin download-plugins-dashboard Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.9.1 CVE-2024-9232 Wordfence
2.7 Low Uncanny Groups for LearnDash Plugin Broken Access Control Missing Authorization to Authenticated (Group Leader+) User Group Add ≤ 6.1.0.1 CVE-2024-8350 Wordfence
7.2 High Uncanny Groups for LearnDash Plugin Privilege Escalation Authenticated (Group Leader+) Privilege Escalation ≤ 6.1.0.1 CVE-2024-8349 Wordfence
8.8 High Frontend Dashboard Plugin frontend-dashboard Broken Access Control Authenticated (Subscriber+) Arbitrary Function Call ≤ 2.2.4 CVE-2024-8268 Wordfence
4.3 Medium Dark Mode for WP Dashboard Plugin dark-mode-for-wp-dashboard Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-43325 Patchstack
4.2 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery No login needed ≤ 1.8.7 CVE-2024-7501 Wordfence
6.5 Medium WP Dashboard Notes Plugin wp-dashboard-notes Cross-Site Scripting ≤ 1.0.11 CVE-2024-43226 Patchstack
7.1 High Tin Canny Reporting for LearnDash Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.0.7 Fixed in 4.3.0.8 CVE-2024-39656 Patchstack
7.1 High Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37436 Patchstack
5.9 Medium Admin Dashboard RSS Feed Plugin admin-dashboard-rss-feed Cross-Site Scripting ≤ 3.1 CVE-2024-38725 Patchstack
5.4 Medium LearnDash LMS - Reports Free Plugin wisdm-reports-for-learndash Broken Access Control Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update ≤ 1.8.2.1 CVE-2024-5648 Wordfence
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Broken Access Control Missing Authorization to Authenticated(Contributor+) Plugin Settings Modification ≤ 1.3 CVE-2024-1955 Wordfence
6.1 Medium Dashboard Widgets Suite Plugin dashboard-widgets-suite Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.4.3 CVE-2024-0979 Wordfence
4.3 Medium Dashboard To-Do List Plugin dashboard-to-do-list Broken Access Control ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-35723 Patchstack
4.4 Medium Custom Dash Plugin custom-dash Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2024-4942 Wordfence
3.7 Low Ultimate Dashboard Plugin ultimate-dashboard Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 3.7.10 Fixed in 3.7.11 CVE-2023-49822 Patchstack
6.5 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Path Traversal Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with… prior to 1.8.6 CVE-2024-35162 jpcert
6.1 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Scripting Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting No login needed ≤ 1.9.0 CVE-2024-4104 Wordfence
4.3 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Request Forgery Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery No login needed ≤ 1.9.0 CVE-2024-4103 Wordfence
5.4 Medium Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) Plugin Broken Access Control Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization ≤ 5.2.3 CVE-2024-1809 Wordfence
5.3 Medium Client Dash Plugin client-dash Broken Access Control No login needed ≤ 2.2.1 CVE-2024-33652 Patchstack
4.4 Medium Absolutely Glamorous Custom Admin Plugin ag-custom-admin Server-Side Request Forgery Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) ≤ 7.2.2 CVE-2024-33627 Patchstack
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.3 CVE-2024-33683 Patchstack
6.8 Medium AGCA – Custom Dashboard & Login Page Plugin ag-custom-admin Cross-Site Scripting Custom Dashboard & Login Page < 7.2.2 - Admin+ Stored XSS via Image URL < 7.2.2 Fixed in 7.2.2 CVE-2024-2907 WPScan
7.5 High Frontend Dashboard Plugin frontend-dashboard Information Disclosure Sensitive Data Exposure on PII No login needed ≤ 2.2.2 Fixed in 2.2.4 CVE-2024-32726 Patchstack
4.3 Medium Dashboard To-Do List Plugin dashboard-to-do-list Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-31376 Patchstack
4.4 Medium Announce from the Dashboard Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.5.2 CVE-2024-3030 Wordfence
4.7 Medium Uncanny Toolkit for LearnDash Plugin uncanny-learndash-toolkit Open Redirect No login needed ≤ 3.6.4.3 Fixed in 3.6.4.4 CVE-2023-34020 Patchstack
6.5 Medium Frontend Dashboard Plugin frontend-dashboard Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-29775 Patchstack
5.4 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Broken Access Control ≤ 3.1.4 Fixed in 3.1.5 CVE-2022-45851 Patchstack
5.4 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting XSS via Header Injection No login needed < 2.8.10 Fixed in 2.8.10 CVE-2023-7246 WPScan
5.4 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51489 Patchstack
4.3 Medium MainWP Dashboard Plugin mainwp Cross-Site Request Forgery Cross-Site Request Forgery via posting_bulk No login needed ≤ 4.6.0.1 CVE-2024-1642 Wordfence
4.3 Medium WPDashboardNotes Plugin Broken Access Control Unauthorised Deletion of Private Notes < 1.0.11 Fixed in 1.0.11 CVE-2023-7198 WPScan
7.1 High Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51488 Patchstack
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via API No login needed ≤ 4.10.2 CVE-2024-1208 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via assignments No login needed ≤ 4.10.1 CVE-2024-1209 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via API No login needed ≤ 4.10.1 CVE-2024-1210 Wordfence
7.1 High Custom Dashboard Widgets Plugin custom-dashboard-widgets Cross-Site Request Forgery WordPress Custom Dashboard Widgets Plugin <= 1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.1 CVE-2024-22290 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only