WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 101–150 of 150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 5.7.34 |
CVE-2024-8254 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 5.7.34 |
CVE-2024-8771 |
Wordfence | |
| 5.4 Medium | Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin | Cross-Site Scripting MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.70.3 |
CVE-2024-8628 |
Wordfence | |
| 8.8 High | Newsletters | Privilege Escalation Authenticated Privilege Escalation |
≤ 4.9.9.2 |
CVE-2024-8247 |
Wordfence | |
| 4.3 Medium | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 2.6.18 Fixed in 2.6.19 |
CVE-2024-39657 |
Patchstack | |
| 4.3 Medium | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue | Cross-Site Request Forgery No login needed |
≤ 3.1.82 Fixed in 3.1.83 |
CVE-2024-43287 |
Patchstack | |
| 7.1 High | Newsletters | Cross-Site Scripting No login needed |
≤ 4.9.8 Fixed in 4.9.9 |
CVE-2024-43279 |
Patchstack | |
| 5.3 Medium | Newsletters | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 4.9.9 |
CVE-2024-7411 |
Wordfence | |
| 7.1 High | Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce | Cross-Site Scripting Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.6.14 - Cross Site Scripting (XSS) No login needed |
≤ 2.6.14 Fixed in 2.6.16 |
CVE-2024-43126 |
Patchstack | |
| 4.3 Medium | Icegram Express - Email Subscribers, Newsletters and Marketing Automation | Broken Access Control Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization |
≤ 5.7.26 |
CVE-2024-5703 |
Wordfence | |
| 9.8 Critical | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed |
≤ 5.7.25 |
CVE-2024-6172 |
Wordfence | |
| 4.4 Medium | BlossomThemes Email Newsletter | Server-Side Request Forgery |
≤ 2.2.6 Fixed in 2.2.7 |
CVE-2024-37098 |
Patchstack | |
| 9.3 Critical | Email Subscribers & Newsletters | SQL Injection No login needed |
≤ 5.7.25 Fixed in 5.7.26 |
CVE-2024-37252 |
Patchstack | |
| 4.3 Medium | Newsletters | Cross-Site Request Forgery No login needed |
≤ 4.9.7 Fixed in 4.9.8 |
CVE-2024-37227 |
Patchstack | |
| 9.8 Critical | Icegram Express - Email Subscribers, Newsletters and Marketing Automation | SQL Injection Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin No login needed |
≤ 5.7.23 |
CVE-2024-5756 |
Wordfence | |
| 5.3 Medium | SendPress Newsletters | Broken Access Control No login needed |
≤ 1.23.11.6 |
CVE-2023-35040 |
Patchstack | |
| 6.5 Medium | Newsletter - API v1 and v2 addon for Newsletter | Broken Access Control API v1 and v2 addon for Newsletter <= 2.4.5 - Missing Authorization to Email Subscribers Management No login needed |
≤ 2.4.5 |
CVE-2024-5674 |
Wordfence | |
| 5.3 Medium | Email Subscribers & Newsletters | Broken Access Control No login needed |
≤ 5.7.13 Fixed in 5.7.14 |
CVE-2024-31352 |
Patchstack | |
| 7.1 High | Newsletters | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.9.5 Fixed in 4.9.6 |
CVE-2024-35718 |
Patchstack | |
| 6.4 Medium | Newsletter | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via np1 |
≤ 8.3.4 |
CVE-2024-5317 |
Wordfence | |
| 7.1 High | Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.1.77 Fixed in 3.1.78 |
CVE-2024-35668 |
Patchstack | |
| 6.4 Medium | Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation | Cross-Site Scripting WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.16.1 |
CVE-2024-4045 |
Wordfence | |
| 4.3 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization |
≤ 5.7.17 |
CVE-2024-3626 |
Wordfence | |
| 5.3 Medium | Newsletter | Authentication Bypass IP Blacklist Bypass No login needed |
≤ 8.2.0 Fixed in 8.2.1 |
CVE-2024-30522 |
Patchstack | |
| 4.8 Medium | Newsletter Popup | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.2 |
CVE-2024-3644 |
WPScan | |
| 8.8 High | Newsletter Popup | Cross-Site Request Forgery List Deletion via CSRF No login needed |
≤ 1.2 |
CVE-2024-3643 |
WPScan | |
| 6.9 Medium | Newsletter Popup | Cross-Site Request Forgery Subscriber Deletion via CSRF |
≤ 1.2 |
CVE-2024-3642 |
WPScan | |
| 6.1 Medium | Newsletter Popup | Cross-Site Scripting Unauthenticated Stored XSS No login needed |
≤ 1.2 |
CVE-2024-3641 |
WPScan | |
| 4.3 Medium | Arigato Autoresponder and Newsletter | Cross-Site Request Forgery No login needed |
≤ 2.7.2.3 Fixed in 2.7.2.4 |
CVE-2024-34823 |
Patchstack | |
| 5.9 Medium | LetterPress | Cross-Site Scripting |
≤ 1.2.1 |
CVE-2024-34568 |
Patchstack | |
| 8.5 High | Sendinblue for WooCommerce | Path Traversal Arbitrary File Download and Deletion |
≤ 4.0.17 Fixed in 4.0.18 |
CVE-2024-32807 |
Patchstack | |
| 9.8 Critical | Icegram Express - Email Subscribers, Newsletters and Marketing Automation | SQL Injection Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection No login needed |
≤ 5.7.14 |
CVE-2024-2876 |
Wordfence | |
| 6.5 Medium | WooCommerce AWeber Newsletter Subscription | Broken Access Control Unauthenticated Access Token Change/Reset No login needed |
≤ 4.0.2 Fixed in 4.0.3 |
CVE-2024-33944 |
Patchstack | |
| 4.5 Medium | ENL Newsletter | SQL Injection Admin+ SQL Injection |
≤ 1.0.1 |
CVE-2024-3060 |
WPScan | |
| 5.7 Medium | ENL Newsletter | Cross-Site Request Forgery Campaign Deletion via CSRF |
≤ 1.0.1 |
CVE-2024-3059 |
WPScan | |
| 5.4 Medium | ENL Newsletter | Cross-Site Scripting Stored XSS via CSRF |
≤ 1.0.1 |
CVE-2024-3058 |
WPScan | |
| 9.1 Critical | Newsletters | Arbitrary File Upload |
≤ 4.9.5 Fixed in 4.9.6 |
CVE-2024-32954 |
Patchstack | |
| 7.5 High | Newsletters | Information Disclosure Sensitive Data Exposure No login needed |
≤ 4.9.5 Fixed in 4.9.6 |
CVE-2024-32953 |
Patchstack | |
| 5.8 Medium | EnvÃaloSimple | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2 Fixed in 2.3 |
CVE-2024-32587 |
Patchstack | |
| 5.4 Medium | Newsletter | Cross-Site Request Forgery No login needed |
≤ 8.0.6 Fixed in 8.0.7 |
CVE-2024-31434 |
Patchstack | |
| 8.8 High | EnvÃaloSimple: Email Marketing y Newsletters | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed |
≤ 2.3 |
CVE-2024-2125 |
Wordfence | |
| 6.1 Medium | SendPress Newsletters | Cross-Site Scripting Admin+ Stored XSS via Form Settings No login needed |
≤ 1.23.11.6 |
CVE-2024-1589 |
WPScan | |
| 6.8 Medium | SendPress Newsletters | Cross-Site Scripting Admin+ Stored XSS via Settings |
≤ 1.23.11.6 |
CVE-2024-1588 |
WPScan | |
| 7.1 High | Contact Form 7 Newsletter | Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2024-31110 |
Patchstack | |
| 7.1 High | Email Subscribers & Newsletters | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.7.11 Fixed in 5.7.12 |
CVE-2024-22300 |
Patchstack | |
| 6.5 Medium | EnvÃaloSimple | Cross-Site Request Forgery No login needed |
≤ 2.2 Fixed in 2.3 |
CVE-2023-51416 |
Patchstack | |
| 6.5 Medium | Automation By Autonami | Cross-Site Scripting |
≤ 2.8.2 Fixed in 2.8.3 |
CVE-2024-2580 |
Patchstack | |
| 7.2 High | AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber | SQL Injection Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber <= 7.3.14 - Authenticated (Admin+) SQL Injection |
≤ 7.3.14 |
CVE-2024-1793 |
Wordfence | |
| 6.4 Medium | Newsletter2Go | Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via style |
≤ 4.0.14 |
CVE-2024-1328 |
Wordfence | |
| 7.2 High | Newsletter Lite | Remote Code Execution Admin+ Command Injection |
< 4.9.3 Fixed in 4.9.3 |
CVE-2023-4797 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.