WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,451–1,500 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 30 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium TinyPNG Plugin tiny-compress-images Cross-Site Request Forgery No login needed ≤ 3.4.3 Fixed in 3.4.4 CVE-2024-47635 Patchstack
5.3 Medium Ultimate Member Plugin ultimate-member Cross-Site Request Forgery Cross-Site Request Forgery to Membership Status Change No login needed ≤ 2.8.6 CVE-2024-8520 Wordfence
4.3 Medium Use Any Font Plugin use-any-font Cross-Site Request Forgery No login needed ≤ 6.3.08 Fixed in 6.3.09 CVE-2024-47305 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2024-8476 Wordfence
4.3 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Cross-Site Request Forgery Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery No login needed ≤ 5.9.1 CVE-2024-7386 Wordfence
6.1 Medium amCharts: Charts and Maps Plugin amcharts-charts-and-maps Cross-Site Scripting Reflected Cross-Site Scripting via Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-8622 Wordfence
4.3 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery Cross-Site Request Forgery via 'addon_enable_disable' No login needed ≤ 2.7.4 CVE-2023-2919 Wordfence
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
4.3 Medium Tourfic Plugin tourfic Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 2.11.20 CVE-2024-8319 Wordfence
5.4 Medium WP Armour Extended Plugin Cross-Site Request Forgery No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43947 Patchstack
4.3 Medium Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Plugin reviews-feed Cross-Site Request Forgery Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-8200 Wordfence
5.4 Medium Ninja Forms Plugin ninja-forms Cross-Site Request Forgery No login needed ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-39628 Patchstack
4.3 Medium LearnPress Plugin learnpress Cross-Site Request Forgery No login needed ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39641 Patchstack
5.4 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-39645 Patchstack
4.3 Medium Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Request Forgery No login needed ≤ 2.6.18 Fixed in 2.6.19 CVE-2024-39657 Patchstack
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Cross-Site Request Forgery No login needed ≤ 2.7.10 Fixed in 2.7.11 CVE-2024-43116 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Cross-Site Request Forgery No login needed ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43117 Patchstack
4.3 Medium Backup and Restore Plugin wp-backitup Cross-Site Request Forgery No login needed ≤ 1.50 CVE-2024-43269 Patchstack
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.82 Fixed in 3.1.83 CVE-2024-43287 Patchstack
4.3 Medium WP Data Access Plugin wp-data-access Cross-Site Request Forgery No login needed ≤ 5.5.7 Fixed in 5.5.9 CVE-2024-43295 Patchstack
5.4 Medium SpeedyCache Plugin speedycache Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-43299 Patchstack
4.3 Medium Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43316 Patchstack
4.3 Medium Dark Mode for WP Dashboard Plugin dark-mode-for-wp-dashboard Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-43325 Patchstack
4.3 Medium WP User Manager Plugin wp-user-manager Cross-Site Request Forgery User Profile Builder & Membership plugin <= 2.9.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.10 Fixed in 2.9.11 CVE-2024-43336 Patchstack
4.3 Medium Brave Popup Builder Plugin brave-popup-builder Cross-Site Request Forgery No login needed ≤ 0.7.0 Fixed in 0.7.1 CVE-2024-43337 Patchstack
4.3 Medium Advanced Form Integration Plugin advanced-form-integration Cross-Site Request Forgery The Easiest Integration Plugin plugin <= 1.89.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.89.4 Fixed in 1.89.6 CVE-2024-43340 Patchstack
5.4 Medium WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery WebinarPress plugin <= 1.33.20 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.33.20 Fixed in 1.33.21 CVE-2024-43339 Patchstack
6.1 Medium OTA Sync Booking Engine Widget Plugin ota-sync-booking-engine-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2024-7647 Wordfence
6.1 Medium BP Profile Search Plugin bp-profile-search Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 5.7.5 CVE-2024-7850 Wordfence
4.3 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed ≤ 1.8.1 CVE-2023-3408 Wordfence
5.4 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed ≤ 1.8.1 CVE-2023-3409 Wordfence
4.7 Medium Short URL Plugin shorten-url Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed ≤ 1.6.8 CVE-2023-1604 Wordfence
4.2 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery No login needed ≤ 1.8.7 CVE-2024-7501 Wordfence
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 7.1.7 CVE-2024-7422 Wordfence
5.8 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed ≤ 1.3.6 CVE-2024-7420 Wordfence
6.1 Medium Christmasify! Plugin christmasify Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.5 CVE-2024-7574 Wordfence
4.3 Medium Brizy – Page Builder Plugin brizy Cross-Site Request Forgery Page Builder <= 2.5.1 - Cross-Site Request Forgery No login needed ≤ 2.5.1 CVE-2024-6254 Wordfence
5.4 Medium Edubin Plugin edubin Server-Side Request Forgery No login needed ≤ 9.2.0 CVE-2024-39637 Patchstack
4.9 Medium AI Engine: ChatGPT Chatbot Plugin ai-engine Server-Side Request Forgery ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-38791 Patchstack
6.4 Medium Remote Content Shortcode Plugin remote-content-shortcode Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 1.5 CVE-2024-2090 Wordfence
6.1 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.2.0.1 CVE-2024-3246 Wordfence
6.3 Medium Social Auto Poster Plugin Cross-Site Request Forgery Cross-Site Request Forgery via Multiple Functions No login needed ≤ 5.3.14 CVE-2024-6751 Wordfence
6.4 Medium JSON Content Importer Plugin json-content-importer Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) ≤ 1.5.6 Fixed in 1.6.0 CVE-2024-38723 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38730 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack
4.3 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Setting Reset No login needed ≤ 2.4.13 CVE-2024-5804 Wordfence
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Apply Template to All Recipes No login needed < 1.8.0 CVE-2024-39681 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Default Recipe Template Save No login needed < 1.8.0 CVE-2024-39680 GitHub_M

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only