WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 101–146 of 146 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Frontend Content Forms for User Submissions (UGC) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'buddyforms_nav' Shortcode |
≤ 2.8.15 |
CVE-2024-12038 |
Wordfence | |
| 5.3 Medium | WordPress Contact Forms by Cimatti | Broken Access Control Missing Authorization to Unauthenticated Form Submission Download No login needed |
≤ 1.9.4 |
CVE-2024-12184 |
Wordfence | |
| 6.4 Medium | Frontend Content Forms for User Submissions (UGC) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.13 |
CVE-2024-12037 |
Wordfence | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.0.3.3 Fixed in 6.0.3.4 |
CVE-2025-24686 |
Patchstack | |
| 4.3 Medium | Ni Sales Commission For WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Commission Update |
≤ 1.2.4 |
CVE-2024-13424 |
Wordfence | |
| 4.3 Medium | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure |
≤ 2.17.3 |
CVE-2024-12190 |
Wordfence | |
| 5.2 Medium | JobBoardWP – Job Board Listings and Submissions | Broken Access Control Job Board Listings and Submissions plugin <= 1.2.2 - IDOR Leading To Job Removal |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2023-23715 |
Patchstack | |
| 7.5 High | RegistrationMagic | Broken Access Control No login needed |
≤ 5.2.3.0 Fixed in 5.2.3.1 |
CVE-2023-49831 |
Patchstack | |
| 4.3 Medium | Eleblog – Elementor Blog And Magazine Addons | Broken Access Control Elementor Blog And Magazine Addons <= 1.8 - Missing Authorization to Authenticated (Subscriber+) Deactivation Submission |
≤ 1.8 |
CVE-2024-10663 |
Wordfence | |
| 5.3 Medium | Hustle – Email Marketing, Lead Generation, Optins, Popups | Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission No login needed |
≤ 7.8.5 |
CVE-2024-10580 |
Wordfence | |
| 6.1 Medium | JobBoardWP – Job Board Listings and Submissions | Cross-Site Scripting Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.0 |
CVE-2024-10880 |
Wordfence | |
| 6.1 Medium | SimpleForm Contact Form Submissions | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.0 |
CVE-2024-10884 |
Wordfence | |
| 9.8 Critical | RegistrationMagic – User Registration Plugin with Custom Registration Forms | Privilege Escalation User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery No login needed |
≤ 6.0.2.6 |
CVE-2024-10508 |
Wordfence | |
| 5.3 Medium | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.36.0 - Insecure Direct Object Reference to Submission Manipulation No login needed |
≤ 1.36.0 |
CVE-2024-9700 |
Wordfence | |
| 8.8 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Privilege Escalation Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation |
≤ 2.8.11 |
CVE-2024-8246 |
Wordfence | |
| 4.3 Medium | Frontend Post Submission Manager Lite – Frontend Posting | Broken Access Control Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.2.2 |
CVE-2024-8427 |
Wordfence | |
| 4.3 Medium | RegistrationMagic | Cross-Site Scripting No login needed |
≤ 6.0.1.0 Fixed in 6.0.1.1 |
CVE-2024-43317 |
Patchstack | |
| 6.1 Medium | Admission AppManager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2023-4507 |
Wordfence | |
| 5.8 Medium | RegistrationMagic | Cross-Site Scripting No login needed |
≤ 6.0.0.1 Fixed in 6.0.0.2 |
CVE-2024-39643 |
Patchstack | |
| 5.3 Medium | RegistrationMagic | Other Form Submission Limit Bypass No login needed |
≤ 5.2.5.0 Fixed in 5.2.5.1 |
CVE-2023-51544 |
Patchstack | |
| 5.3 Medium | RegistrationMagic | Authentication Bypass IP Limit Bypass No login needed |
≤ 5.2.5.0 Fixed in 5.2.5.1 |
CVE-2023-51543 |
Patchstack | |
| 4.3 Medium | Contact Form Email | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.3.31 Fixed in 1.3.32 |
CVE-2023-28494 |
Patchstack | |
| 4.3 Medium | CP Multi View Event Calendar | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.4.10 Fixed in 1.4.11 |
CVE-2023-28492 |
Patchstack | |
| 4.3 Medium | CP Contact Form with Paypal | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.3.34 Fixed in 1.3.35 |
CVE-2023-27460 |
Patchstack | |
| 4.3 Medium | Calculated Fields Form | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.1.120 Fixed in 1.1.121 |
CVE-2023-26523 |
Patchstack | |
| 4.3 Medium | Search in Place | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.0.104 Fixed in 1.0.105 |
CVE-2023-26521 |
Patchstack | |
| 6.4 Medium | Opal Estate Pro – Property Management and Submission | Cross-Site Scripting Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.6 |
CVE-2024-3666 |
Wordfence | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Other Form Submission Admin Email Bypass No login needed |
≤ 5.6.3 |
CVE-2024-3927 |
Wordfence | |
| 5.3 Medium | weForms | Other Form Submission Restriction Bypass No login needed |
≤ 1.6.20 Fixed in 1.6.21 |
CVE-2024-32512 |
Patchstack | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting No login needed |
≤ 5.3.2.0 Fixed in 5.3.2.1 |
CVE-2024-33947 |
Patchstack | |
| 5.3 Medium | GP Unique ID | Other Unauthenticated Form Submission Unique ID Modification No login needed |
≤ 1.5.5 |
CVE-2024-0710 |
Wordfence | |
| 5.3 Medium | RegistrationMagic | Content Injection No login needed |
≤ 5.1.9.2 Fixed in 5.1.9.3 |
CVE-2023-23989 |
Patchstack | |
| 7.5 High | RegistrationMagic | Other Arbitrary Price Change No login needed |
≤ 5.1.9.2 Fixed in 5.1.9.3 |
CVE-2023-23976 |
Patchstack | |
| 8.8 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation |
≤ 5.3.0.0 |
CVE-2024-1991 |
Wordfence | |
| 8.8 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 5.3.1.0 |
CVE-2024-1990 |
Wordfence | |
| 4.3 Medium | Ninja Forms Contact Form – The Drag and Drop Form Builder | Cross-Site Request Forgery The Drag and Drop Form Builder for WordPress <= 3.8.0 - Cross-Site Request Forgery to Publicly Accessible Form Submission Export No login needed |
≤ 3.8.0 |
CVE-2024-2113 |
Wordfence | |
| 4.3 Medium | RegistrationMagic | Cross-Site Request Forgery No login needed |
≤ 5.3.0.0 Fixed in 5.3.1.0 |
CVE-2024-2951 |
Patchstack | |
| 4.3 Medium | Google Maps CP | Broken Access Control Missing Authorization Leading To Feedback Submission |
≤ 1.0.43 Fixed in 1.0.44 |
CVE-2023-25039 |
Patchstack | |
| 4.3 Medium | RegistrationMagic | Broken Access Control |
≤ 5.2.5.9 Fixed in 5.2.6.0 |
CVE-2024-25935 |
Patchstack | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.2.5.9 Fixed in 5.2.6.0 |
CVE-2024-29113 |
Patchstack | |
| 5.3 Medium | Contact Form Builder Plugin: Multi Step Contact Form, Payment Form, Custom Contact Form Plugin by Bit Form | Broken Access Control Unauthenticated Insecure Direct Object Reference to Form Submission Alteration No login needed |
≤ 2.10.1 |
CVE-2024-1640 |
Wordfence | |
| 4.3 Medium | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization |
≤ 2.8.7 |
CVE-2024-1158 |
Wordfence | |
| 7.5 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload No login needed |
≤ 2.8.7 |
CVE-2024-1169 |
Wordfence | |
| 8.2 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion No login needed |
≤ 2.8.7 |
CVE-2024-1170 |
Wordfence | |
| 7.1 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Cross-Site Scripting WordPress RegistrationMagic Plugin <= 5.2.4.1 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 5.2.4.1 Fixed in 5.2.4.2 |
CVE-2023-51509 |
Patchstack | |
| 7.2 High | WPForms Pro | Cross-Site Scripting The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission parameters in all versions up to, and including, 1.8.5.3 due to insufficient… No login needed |
≤ 1.8.5.3 |
CVE-2023-7063 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.