WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 152 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Age Gate Plugin age-gate Broken Access Control No login needed ≤ 3.5.4 Fixed in 3.6.0 CVE-2025-31012 Patchstack
5.3 Medium GreenPay(tm) by Green.Money Plugin green-money-payment-gateway Information Disclosure Unauthenticated Information Exposure No login needed 3.0.0 – 3.0.9 CVE-2025-2882 Wordfence
6.5 Medium Better Section Navigation Widget Plugin better-section-navigation Cross-Site Scripting ≤ 1.6.1 Fixed in 1.7.0 CVE-2025-31465 Patchstack
5.9 Medium Mobile Navigation Plugin mobile-navigation Cross-Site Scripting WordPress Mobile Navigation plugin <= - 1.5 Cross Site Scripting (XSS) ≤ 1.5 CVE-2025-30574 Patchstack
6.5 Medium Magic the Gathering Card Tooltips Plugin magic-the-gathering-card-tooltips Cross-Site Scripting ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-24704 Patchstack
6.5 Medium Navigation Du Lapin Blanc Plugin navigation-du-lapin-blanc Cross-Site Scripting ≤ 1.1.1 CVE-2025-22745 Patchstack
6.4 Medium GatorMail SmartForms Plugin gatormail-smart-forms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11386 Wordfence
6.1 Medium PayGreen Payment Gateway Plugin paygreen-payment-gateway Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.26 CVE-2024-11810 Wordfence
6.1 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting Reflected Cross-Site Scripting via Navigate Parameter No login needed ≤ 1.3.0.5 CVE-2024-12239 Wordfence
6.1 Medium Dreamfox Media Payment gateway per Product for Woocommerce Plugin woocommerce-product-payments Broken Access Control No login needed ≤ 3.5.6 Fixed in 3.5.9 CVE-2024-55996 Patchstack
6.1 Medium CardGate Payments for WooCommerce Plugin cardgate Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2.1 CVE-2024-12257 Wordfence
6.1 Medium Comfino Payment Gateway Plugin comfino-payment-gateway Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.1 CVE-2024-11329 Wordfence
5.4 Medium Yaad Sarig Payment Gateway For WC Plugin yaad-sarig-payment-gateway-for-wc Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Read/Deletion ≤ 2.2.4 CVE-2024-10665 Wordfence
6.5 Medium Pay With Stripe Plugin payments-stripe-gateway Cross-Site Scripting ≤ 1.2.1 CVE-2024-51918 Patchstack
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.10.1 CVE-2024-9868 Wordfence
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
4.3 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Broken Access Control RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization ≤ 4.23.12 CVE-2024-9583 Wordfence
4.7 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Open Redirect No login needed ≤ 2.6.1 Fixed in 2.6.2 CVE-2024-47646 Patchstack
6.4 Medium Aggregator Advanced Settings Plugin aggregator-advanced-settings Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.1 CVE-2024-9368 Wordfence
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed ≤ 4.17.3 CVE-2024-8678 Wordfence
5.3 Medium Admin Post Navigation Plugin admin-post-navigation Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 2.1 CVE-2024-6549 Wordfence
5.8 Medium YITH WooCommerce Ajax Product Filter Plugin yith-woocommerce-ajax-navigation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.0 Fixed in 5.2.0 CVE-2024-37943 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
4.3 Medium WP RSS Aggregator Plugin wp-rss-aggregator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feed State Update ≤ 4.23.11 CVE-2024-6621 Wordfence
5.3 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Broken Access Control Missing Authorization to Order Status Update No login needed ≤ 2.5.0 CVE-2024-0619 Wordfence
4.6 Medium SVGator Plugin svgator Cross-Site Scripting Stored XSS via SVG Upload ≤ 1.2.6 CVE-2024-4271 WPScan
5.4 Medium BulkGate SMS Plugin for WooCommerce Plugin woosms-sms-module-for-woocommerce Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2023-51679 Patchstack
4.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control ≤ 4.9.7 Fixed in 4.9.8 CVE-2023-52224 Patchstack
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget ≤ 3.10.9 CVE-2024-5347 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box ≤ 5.5.4 CVE-2024-3718 Wordfence
5.4 Medium WordPress RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GE… No login needed < 4.23.9 Fixed in 4.23.9 CVE-2024-4860 tenable
4.3 Medium Arigato Autoresponder and Newsletter Plugin bft-autoresponder Cross-Site Request Forgery No login needed ≤ 2.7.2.3 Fixed in 2.7.2.4 CVE-2024-34823 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.4.2 CVE-2024-2785 Wordfence
5.3 Medium 2Checkout Payment Gateway for WooCommerce Plugin woocommerce-2checkout-payment Broken Access Control Missing Authorization via sniff_ins No login needed ≤ 6.2 CVE-2024-0629 Wordfence
4.3 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-33585 Patchstack
5.9 Medium Navigation menu as Dropdown Widget Plugin navigation-menu-as-dropdown-widget Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-32126 Patchstack
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) ≤ 4.4.7 CVE-2023-6805 Wordfence
4.3 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Request Forgery No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2024-31371 Patchstack
5.3 Medium WooCommerce Clover Payment Gateway Plugin woo-clover-gateway-by-zaytech Broken Access Control Missing Authorization via callback_handler No login needed ≤ 1.3.1 CVE-2024-0626 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message ≤ 4.3.3 CVE-2023-6877 Wordfence
5.3 Medium Paid Memberships Pro – Payfast Gateway Add On Plugin pmpro-payfast Information Disclosure Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-30514 Patchstack
5.4 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Cross-Site Request Forgery No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2023-44999 Patchstack
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation ≤ 3.20.1 CVE-2024-2120 Wordfence
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
5.3 Medium Duitku Payment Gateway Plugin duitku-social-payment-gateway Broken Access Control Missing Authorization via check_duitku_response No login needed ≤ 2.11.6 CVE-2024-0631 Wordfence
6.5 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Missing Authorization to Arbitrary Page Creation and Publication ≤ 4.4.2 CVE-2024-1318 Wordfence
4.3 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization ≤ 4.4.1 CVE-2024-1092 Wordfence
4.4 Medium WP RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source ≤ 4.23.4 CVE-2024-0630 Wordfence
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only