WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 101–150 of 166 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | amr shortcodes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.7 |
CVE-2024-52464 |
Patchstack | |
| 7.1 High | Custom Shortcode Sidebars | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.2 |
CVE-2024-53736 |
Patchstack | |
| 7.3 High | Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation | Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed |
≤ 1.4 |
CVE-2024-11034 |
Wordfence | |
| 7.3 High | WooCommerce Product Table Lite | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site Scripting No login needed |
≤ 3.8.6 |
CVE-2024-10899 |
Wordfence | |
| 7.1 High | Awesome Shortcodes For Genesis | Cross-Site Scripting No login needed |
≤ 1.1.8 |
CVE-2024-51638 |
Patchstack | |
| 7.3 High | GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in | Arbitrary Shortcode Execution The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings No login needed |
≤ 7.1.5 |
CVE-2024-11036 |
Wordfence | |
| 7.3 High | WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup | Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed |
≤ 1.7.5 |
CVE-2024-11038 |
Wordfence | |
| 7.3 High | Uix Slideshow | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.6.5 |
CVE-2024-9839 |
Wordfence | |
| 7.3 High | WP Photo Album Plus | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay No login needed |
≤ 8.8.08.007 |
CVE-2024-10958 |
Wordfence | |
| 7.3 High | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | Arbitrary Shortcode Execution Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.0 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.13.0 |
CVE-2024-10261 |
Wordfence | |
| 7.3 High | The FOX – Currency Switcher Professional for WooCommerce | Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.2 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.4.2.2 |
CVE-2024-10640 |
Wordfence | |
| 8.5 High | Quran Shortcode | SQL Injection |
≤ 1.5 |
CVE-2024-51625 |
Patchstack | |
| 7.3 High | Tickera – WordPress Event Ticketing | Arbitrary Shortcode Execution WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.5.4.4 |
CVE-2024-10263 |
Wordfence | |
| 7.2 High | WPAdverts – Classifieds | Cross-Site Scripting Classifieds Plugin <= 2.1.6 - Unauthenticated Stored Cross-Site Scripting via adverts_add Shortcode No login needed |
≤ 2.1.6 |
CVE-2024-10108 |
Wordfence | |
| 7.3 High | Enable Shortcodes inside Widgets,Comments and Experts | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.0.0 |
CVE-2024-9846 |
Wordfence | |
| 7.3 High | Uix Shortcodes – Compatible with Gutenberg | Arbitrary Shortcode Execution Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.9.9 |
CVE-2024-9772 |
Wordfence | |
| 8.5 High | Simple Code Insert Shortcode | SQL Injection |
≤ 1.0 |
CVE-2024-49613 |
Patchstack | |
| 7.3 High | WP Popup Builder – Popup Forms and Marketing Lead Generation | Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed |
≤ 1.3.5 |
CVE-2024-9061 |
Wordfence | |
| 7.3 High | AADMY – Add Auto Date Month Year Into Posts | Arbitrary Shortcode Execution Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 2.0.1 |
CVE-2024-9837 |
Wordfence | |
| 7.3 High | Shortcodes AnyWhere | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.0.1 |
CVE-2024-9581 |
Wordfence | |
| 7.3 High | Special Text Boxes | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 6.2.4 |
CVE-2024-8481 |
Wordfence | |
| 7.3 High | MDTF – Meta Data and Taxonomies Filter | Arbitrary Shortcode Execution Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.3.3.3 |
CVE-2024-8623 |
Wordfence | |
| 7.3 High | Simple Spoiler | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
1.2 – 1.3 |
CVE-2024-8479 |
Wordfence | |
| 7.3 High | FOX – Currency Switcher Professional for WooCommerce | Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.4.2.1 |
CVE-2024-8271 |
Wordfence | |
| 7.3 High | Affiliate Super Assistent | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.5.3 |
CVE-2024-8478 |
Wordfence | |
| 8.8 High | Horizontal scrolling announcements | SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 2.4 |
CVE-2023-5000 |
Wordfence | |
| 7.1 High | Shortcodes by United Themes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 5.0.5 Fixed in 5.0.5 |
CVE-2024-37097 |
Patchstack | |
| 8.8 High | Advanced File Manager Shortcodes | Path Traversal Authenticated (Contributor+) Directory Traversal |
≤ 2.4 |
CVE-2023-7062 |
Wordfence | |
| 8.8 High | Advanced File Manager Shortcode | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 2.5.3 |
CVE-2023-7061 |
Wordfence | |
| 8.8 High | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | Local File Inclusion Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode |
≤ 2.2.25 |
CVE-2024-5431 |
Wordfence | |
| 8.8 High | tagDiv Composer | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 4.8 |
CVE-2024-3813 |
Wordfence | |
| 8.8 High | LifterLMS – WordPress LMS Plugin for eLearning | SQL Injection WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 7.6.2 |
CVE-2024-4743 |
Wordfence | |
| 8.8 High | Content Blocks (Custom Post Widget) | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 3.3.0 |
CVE-2024-3564 |
Wordfence | |
| 8.5 High | MemberPress | Server-Side Request Forgery Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode |
≤ 1.11.29 |
CVE-2024-5031 |
Wordfence | |
| 8.8 High | Media Library Assistant | SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 3.15 |
CVE-2024-3518 |
Wordfence | |
| 7.5 High | Salient Core | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 2.0.7 |
CVE-2024-3812 |
Wordfence | |
| 8.8 High | Salient Shortcodes | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 1.5.3 |
CVE-2024-3810 |
Wordfence | |
| 7.6 High | Shortcodes and extra features for Phlox | Local File Inclusion Unauthenticated Local File Inclusion |
≤ 2.14.0 Fixed in 2.15.0 |
CVE-2023-37888 |
Patchstack | |
| 7.1 High | Shortcodes Ultimate | Path Traversal Arbitrary File Download |
≤ 5.12.6 Fixed in 5.12.7 |
CVE-2023-25050 |
Patchstack | |
| 8.8 High | All-in-One Video Gallery | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode |
≤ 3.6.5 |
CVE-2024-4670 |
Wordfence | |
| 8.8 High | Porto Theme - Functionality | Local File Inclusion Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 3.1.0 |
CVE-2024-3808 |
Wordfence | |
| 7.5 High | Shortcodes and extra features for Phlox | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via auxin_template_control_importer |
≤ 2.17.5 |
CVE-2023-7064 |
Wordfence | |
| 8.8 High | WP ULike – Most Advanced WordPress Marketing Toolkit | SQL Injection Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes |
≤ 4.6.9 |
CVE-2024-1797 |
Wordfence | |
| 7.5 High | Grid Gallery – Photo Image Grid Gallery | PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode |
≤ 1.4.3 |
CVE-2024-1897 |
Wordfence | |
| 7.5 High | Photo Gallery | PHP Object Injection Authenticated(Contributor+) PHP Object Injection via Shortcode |
≤ 1.4.2 |
CVE-2024-1896 |
Wordfence | |
| 8.8 High | Calendar | SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 1.3.14 |
CVE-2024-2831 |
Wordfence | |
| 8.8 High | rtMedia for WordPress, BuddyPress and bbPress | SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode |
≤ 4.6.18 |
CVE-2024-3293 |
Wordfence | |
| 8.7 High | Advance Search | Cross-Site Request Forgery Shortcode Deletion via CSRF |
≤ 1.1.6 |
CVE-2024-2739 |
WPScan | |
| 8.8 High | Easy Property Listings | SQL Injection Authenticated(Contributor+) SQL Injection via Shortcode |
≤ 3.5.2 |
CVE-2024-1893 |
Wordfence | |
| 8.8 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 5.3.1.0 |
CVE-2024-1990 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.