WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,051–15,100 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 302 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Booster Elite for WooCommerce Plugin Authentication Bypass Authenticated Production Creation/Modification < 7.1.3 Fixed in 7.1.3 CVE-2023-51511 Patchstack
6.5 Medium Responsive Slick Slider Plugin responsive-slick-slider Content Injection No login needed ≤ 1.4 CVE-2023-49852 Patchstack
3.7 Low Ultimate Dashboard Plugin ultimate-dashboard Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 3.7.10 Fixed in 3.7.11 CVE-2023-49822 Patchstack
5.3 Medium WP Photo Album Plus Plugin wp-photo-album-plus Information Disclosure IP Bypass No login needed ≤ 8.5.02.005 Fixed in 8.6.01.005 CVE-2023-49774 Patchstack
3.7 Low WPS Hide Login Plugin wps-hide-login Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2023-49748 Patchstack
3.7 Low Coming soon and Maintenance mode Plugin coming-soon-page Authentication Bypass IP Filtering Bypass No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2023-49741 Patchstack
5.3 Medium Restricted Site Access Plugin restricted-site-access Authentication Bypass IP Restriction Bypass No login needed ≤ 7.4.1 Fixed in 7.5.0 CVE-2023-48753 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Authentication Bypass Authenticated Production Creation/Modification ≤ 7.1.2 Fixed in 7.1.3 CVE-2023-48747 Patchstack
5.3 Medium Captcha Code Plugin captcha-code-authentication Authentication Bypass Captcha Bypass No login needed ≤ 2.9 Fixed in 3.0 CVE-2023-48745 Patchstack
3.7 Low Hide login page Plugin hide-login-page Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 1.1.9 CVE-2023-48335 Patchstack
5.3 Medium Contact Form Email Plugin contact-form-to-email Authentication Bypass Captcha Bypass No login needed ≤ 1.3.41 Fixed in 1.3.42 CVE-2023-48318 Patchstack
5.3 Medium Form Maker by 10Web Plugin form-maker Authentication Bypass Captcha Bypass Vulnerability No login needed ≤ 1.15.20 Fixed in 1.15.21 CVE-2023-48290 Patchstack
5.3 Medium Stripe Payments Plugin stripe-payments Content Injection No login needed ≤ 2.0.79 Fixed in 2.0.80 CVE-2023-48285 Patchstack
5.3 Medium WP Forms Puzzle Captcha Plugin wp-forms-puzzle-captcha Authentication Bypass Captcha Bypass No login needed ≤ 4.1 CVE-2023-48276 Patchstack
5.3 Medium Maspik – Spam blacklist Plugin contact-forms-anti-spam Authentication Bypass Spam Blacklist plugin <= 0.10.3 - IP Filtering Bypass No login needed ≤ 0.10.3 Fixed in 0.10.4 CVE-2023-48271 Patchstack
8.3 High ARMember Plugin armember-membership Privilege Escalation Membership Plan Bypass ≤ 4.0.10 Fixed in 4.0.11 CVE-2023-47837 Patchstack
3.7 Low LWS Hide Login Plugin lws-hide-login Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2023-47818 Patchstack
3.7 Low WP Maintenance Plugin wp-maintenance Authentication Bypass IP Filtering Bypass No login needed ≤ 6.1.3 Fixed in 6.1.4 CVE-2023-47769 Patchstack
5.4 Medium ARI Stream Quiz Plugin ari-stream-quiz Content Injection WordPress Quizzes Builder plugin <= 1.3.2 - Content Injection ≤ 1.3.2 Fixed in 1.3.3 CVE-2023-47513 Patchstack
5.3 Medium Defender Security Plugin defender-security Authentication Bypass Masked Login Area View Bypass No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-47189 Patchstack
7.5 High Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Password Protected View Bypass Vulnerability No login needed ≤ 5.7.1 Fixed in 5.8.0 CVE-2023-46630 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Content Injection No login needed ≤ 7.6.10 Fixed in 7.6.11 CVE-2023-46310 Patchstack
5.4 Medium Responsive Tabs Plugin responsive-tabs Content Injection HTML Content Injection < 4.0.6 Fixed in 4.0.6 CVE-2023-45635 Patchstack
4.3 Medium WP Content Pilot – Autoblogging & Affiliate Marketing Plugin wp-content-pilot Content Injection HTML Injection ≤ 1.3.3 Fixed in 1.3.4 CVE-2023-45053 Patchstack
5.3 Medium Captcha/Honeypot for Contact Form 7 Plugin captcha-for-contact-form-7 Other Capcha Bypass No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2023-45009 Patchstack
5.3 Medium WP Captcha Plugin wp-captcha Authentication Bypass Captcha Bypass No login needed ≤ 2.0.0 CVE-2023-44235 Patchstack
5.3 Medium Antispam Bee Plugin antispam-bee Authentication Bypass Country IP Restriction Bypass No login needed ≤ 2.11.3 Fixed in 2.11.4 CVE-2023-41134 Patchstack
6.5 Medium Cartpauj Register Captcha Plugin cartpauj-register-captcha Authentication Bypass Captcha Bypass No login needed ≤ 1.0.02 Fixed in 2.0.0 CVE-2023-40673 Patchstack
5.4 Medium Tabs & Accordion Plugin tabs Content Injection ≤ 1.3.10 CVE-2023-40557 Patchstack
5.3 Medium WP-PostRatings Plugin wp-postratings Other Rating limit Bypass No login needed ≤ 1.91 Fixed in 1.91.1 CVE-2023-40332 Patchstack
5.4 Medium Discussion Board Plugin wp-discussion-board Content Injection ≤ 2.4.8 Fixed in 2.4.9 CVE-2023-39161 Patchstack
6.5 Medium Pinpoint Booking System Plugin booking-system Other Parameter Tampering No login needed ≤ 2.9.9.3.4 Fixed in 2.9.9.3.5 CVE-2023-38520 Patchstack
5.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Authentication Bypass IP Bypass Vulnerability No login needed ≤ 2.29.1 Fixed in 2.29.2 CVE-2023-37865 Patchstack
5.3 Medium Hide My WP Ghost Plugin hide-my-wp Authentication Bypass Security Plugin plugin <= 5.0.25 - Captcha Bypass No login needed ≤ 5.0.25 Fixed in 5.0.26 CVE-2023-34001 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
4.3 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.31 Fixed in 1.3.32 CVE-2023-28494 Patchstack
5.4 Medium Insert or Embed Articulate Content into Plugin Remote Code Execution Author+ Upload to RCE ≤ 4.3000000023 CVE-2024-0757 WPScan
4.3 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.4.10 Fixed in 1.4.11 CVE-2023-28492 Patchstack
4.3 Medium CP Contact Form with Paypal Plugin cp-contact-form-with-paypal Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.34 Fixed in 1.3.35 CVE-2023-27460 Patchstack
3.7 Low Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Bypass No login needed ≤ 4.10.44.decaf Fixed in 4.10.45.decaf CVE-2023-27437 Patchstack
4.3 Medium Calculated Fields Form Plugin calculated-fields-form Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.1.120 Fixed in 1.1.121 CVE-2023-26523 Patchstack
4.3 Medium Search in Place Plugin search-in-place Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.104 Fixed in 1.0.105 CVE-2023-26521 Patchstack
3.7 Low Booking calendar, Appointment Booking System Plugin booking-calendar Other Bypass No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24373 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email Spoofing No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23738 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23735 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Authentication Bypass WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23730 Patchstack
4.3 Medium Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-35632 Patchstack
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.5 Medium ChaosTheory Theme chaostheory Cross-Site Scripting ≤ 1.3 Fixed in 1.3.2 CVE-2024-34766 Patchstack
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-34767 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only