WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 101–150 of 166 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High amr shortcodes Plugin amr-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2024-52464 Patchstack
7.1 High Custom Shortcode Sidebars Plugin custom-shortcode-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53736 Patchstack
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
7.3 High WooCommerce Product Table Lite Plugin wc-product-table-lite Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed ≤ 3.8.6 CVE-2024-10899 Wordfence
7.1 High Awesome Shortcodes For Genesis Plugin awesome-shortcodes-for-genesis Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2024-51638 Patchstack
7.3 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin gamipress Arbitrary Shortcode Execution The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings No login needed ≤ 7.1.5 CVE-2024-11036 Wordfence
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
7.3 High Uix Slideshow Plugin uix-slideshow Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.5 CVE-2024-9839 Wordfence
7.3 High WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay No login needed ≤ 8.8.08.007 CVE-2024-10958 Wordfence
7.3 High Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Arbitrary Shortcode Execution Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.13.0 CVE-2024-10261 Wordfence
7.3 High The FOX – Currency Switcher Professional for WooCommerce Plugin Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.2 CVE-2024-10640 Wordfence
8.5 High Quran Shortcode Plugin quran-shortcode SQL Injection ≤ 1.5 CVE-2024-51625 Patchstack
7.3 High Tickera – WordPress Event Ticketing Plugin tickera-event-ticketing-system Arbitrary Shortcode Execution WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.5.4.4 CVE-2024-10263 Wordfence
7.2 High WPAdverts – Classifieds Plugin wpadverts Cross-Site Scripting Classifieds Plugin <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via adverts_add Shortcode No login needed ≤ 2.1.6 CVE-2024-10108 Wordfence
7.3 High Enable Shortcodes inside Widgets,Comments and Experts Plugin enable-shortcodes-inside-widgetscomments-and-experts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0.0 CVE-2024-9846 Wordfence
7.3 High Uix Shortcodes – Compatible with Gutenberg Plugin uix-shortcodes Arbitrary Shortcode Execution Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.9.9 CVE-2024-9772 Wordfence
8.5 High Simple Code Insert Shortcode Plugin simple-code-insert-shortcode SQL Injection ≤ 1.0 CVE-2024-49613 Patchstack
7.3 High WP Popup Builder – Popup Forms and Marketing Lead Generation Plugin wp-popup-builder Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed ≤ 1.3.5 CVE-2024-9061 Wordfence
7.3 High AADMY – Add Auto Date Month Year Into Posts Plugin auto-date-year-month Arbitrary Shortcode Execution Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.1 CVE-2024-9837 Wordfence
7.3 High Shortcodes AnyWhere Plugin shortcodes-anywhere Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0.1 CVE-2024-9581 Wordfence
7.3 High Special Text Boxes Plugin tags Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 6.2.4 CVE-2024-8481 Wordfence
7.3 High MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter Arbitrary Shortcode Execution Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.3.3.3 CVE-2024-8623 Wordfence
7.3 High Simple Spoiler Plugin simple-spoiler Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed 1.2 – 1.3 CVE-2024-8479 Wordfence
7.3 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.1 CVE-2024-8271 Wordfence
7.3 High Affiliate Super Assistent Plugin amazonsimpleadmin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.5.3 CVE-2024-8478 Wordfence
8.8 High Horizontal scrolling announcements Plugin horizontal-scrolling-announcements SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 2.4 CVE-2023-5000 Wordfence
7.1 High Shortcodes by United Themes Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.0.5 Fixed in 5.0.5 CVE-2024-37097 Patchstack
8.8 High Advanced File Manager Shortcodes Plugin Path Traversal Authenticated (Contributor+) Directory Traversal ≤ 2.4 CVE-2023-7062 Wordfence
8.8 High Advanced File Manager Shortcode Plugin Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 2.5.3 CVE-2023-7061 Wordfence
8.8 High WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce Plugin wp-cafe Local File Inclusion Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode ≤ 2.2.25 CVE-2024-5431 Wordfence
8.8 High tagDiv Composer Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 4.8 CVE-2024-3813 Wordfence
8.8 High LifterLMS – WordPress LMS Plugin for eLearning Plugin SQL Injection WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 7.6.2 CVE-2024-4743 Wordfence
8.8 High Content Blocks (Custom Post Widget) Plugin custom-post-widget Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.3.0 CVE-2024-3564 Wordfence
8.5 High MemberPress Plugin Server-Side Request Forgery Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode ≤ 1.11.29 CVE-2024-5031 Wordfence
8.8 High Media Library Assistant Plugin media-library-assistant SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 3.15 CVE-2024-3518 Wordfence
7.5 High Salient Core Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 2.0.7 CVE-2024-3812 Wordfence
8.8 High Salient Shortcodes Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 1.5.3 CVE-2024-3810 Wordfence
7.6 High Shortcodes and extra features for Phlox Plugin auxin-elements Local File Inclusion Unauthenticated Local File Inclusion ≤ 2.14.0 Fixed in 2.15.0 CVE-2023-37888 Patchstack
7.1 High Shortcodes Ultimate Plugin shortcodes-ultimate Path Traversal Arbitrary File Download ≤ 5.12.6 Fixed in 5.12.7 CVE-2023-25050 Patchstack
8.8 High All-in-One Video Gallery Plugin all-in-one-video-gallery Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode ≤ 3.6.5 CVE-2024-4670 Wordfence
8.8 High Porto Theme - Functionality Plugin Local File Inclusion Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 3.1.0 CVE-2024-3808 Wordfence
7.5 High Shortcodes and extra features for Phlox Plugin auxin-elements PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer ≤ 2.17.5 CVE-2023-7064 Wordfence
8.8 High WP ULike – Most Advanced WordPress Marketing Toolkit Plugin SQL Injection Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes ≤ 4.6.9 CVE-2024-1797 Wordfence
7.5 High Grid Gallery – Photo Image Grid Gallery Plugin new-grid-gallery PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode ≤ 1.4.3 CVE-2024-1897 Wordfence
7.5 High Photo Gallery Plugin new-photo-gallery PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode ≤ 1.4.2 CVE-2024-1896 Wordfence
8.8 High Calendar Plugin calendar SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.3.14 CVE-2024-2831 Wordfence
8.8 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode ≤ 4.6.18 CVE-2024-3293 Wordfence
8.7 High Advance Search Plugin Cross-Site Request Forgery Shortcode Deletion via CSRF ≤ 1.1.6 CVE-2024-2739 WPScan
8.8 High Easy Property Listings Plugin easy-property-listings SQL Injection Authenticated(Contributor+) SQL Injection via Shortcode ≤ 3.5.2 CVE-2024-1893 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 5.3.1.0 CVE-2024-1990 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only