WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 101–131 of 131 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.01 Fixed in 2.02 CVE-2024-47622 Patchstack
6.4 Medium WordPress Infinite Scroll - Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter ≤ 7.1.2 CVE-2024-8505 Wordfence
7.1 High White Label CMS Plugin white-label-cms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2024-43303 Patchstack
5.4 Medium Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Broken Access Control Atarim <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 4.0.2 CVE-2024-7621 Wordfence
5.9 Medium Branda Plugin branda-white-labeling Cross-Site Scripting ≤ 3.4.17 Fixed in 3.4.18 CVE-2024-37239 Patchstack
5.9 Medium Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Authenticated Cross Site Scripting (XSS) ≤ 3.31 Fixed in 3.32 CVE-2024-37434 Patchstack
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence
6.4 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.4.17 CVE-2024-5191 Wordfence
6.5 Medium SKU Label Changer For WooCommerce Plugin woo-sku-label-changer Broken Access Control No login needed ≤ 3.0 Fixed in 3.0.1 CVE-2023-29174 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 1.93 Fixed in 1.94 CVE-2024-35675 Patchstack
5.3 Medium Branda Plugin branda-white-labeling Authentication Bypass IP Restriction Bypass No login needed ≤ 3.4.14 Fixed in 3.4.15 CVE-2023-51542 Patchstack
7.2 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.30 CVE-2024-2793 Wordfence
7.5 High Visual Website Collaboration, Feedback & Project Management – Atarim Plugin atarim-visual-collaboration Broken Access Control Atarim <= 3.22.6 - Hardcoded Credentials No login needed ≤ 3.22.6 CVE-2024-2038 Wordfence
7.2 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Privilege Escalation ≤ 4.2.1 Fixed in 4.3.0 CVE-2023-51546 Patchstack
5.3 Medium White Label CMS Plugin white-label-cms Broken Access Control Missing Authorization to Plugin Settings Reset No login needed ≤ 2.7.3 CVE-2024-4280 Wordfence
6.4 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via Templates ≤ 3.4.6 CVE-2024-1679 Wordfence
6.3 Medium Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce Plugin a4-barcode-generator Broken Access Control Improper Authorization ≤ 3.4.6 CVE-2024-1677 Wordfence
5.9 Medium WooCommerce Shipping Label Plugin shipping-labels-for-woo Cross-Site Scripting ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-32834 Patchstack
6.5 Medium Knight Lab Timeline Plugin knight-lab-timelinejs Cross-Site Scripting ≤ 3.9.3.4 CVE-2024-32554 Patchstack
6.1 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting Ninja Forms prior to 3.8.1 contains a cross-site scripting vulnerability in custom fields for labels. If this vulnerability is exploited, an arbitrary script may be executed on th… No login needed prior to 3.8.1 CVE-2024-29220 jpcert
6.4 Medium Knight Lab Timeline Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.3.3 CVE-2024-2287 Wordfence
5.9 Medium Easy Login Styler – White Label Admin Login Page Plugin easy-login-styler Cross-Site Scripting ≤ 1.0.6 CVE-2024-31344 Patchstack
5.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 4.4.2 CVE-2024-3216 Wordfence
6.5 Medium Media Cloud for Amazon S3, Imgix, Google Cloud Storage, DigitalOcean Spaces and more Plugin ilab-media-tools Cross-Site Scripting ≤ 4.5.24 Fixed in 4.5.25 CVE-2024-29795 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack
6.1 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.1 CVE-2024-0957 Wordfence
5.4 Medium Scalable Vector Graphics (SVG) Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 3.4 CVE-2023-7085 WPScan
5.9 Medium Product Labels For Woocommerce (Sale Badges) Plugin aco-product-labels-for-woocommerce Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-24886 Patchstack
4.3 Medium White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Plugin white-label Cross-Site Request Forgery WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-52128 Patchstack
4.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin Broken Access Control Missing Authorization to Order Export ≤ 4.3.0 CVE-2023-7068 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only