WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,151–15,200 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 304 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Flo Forms Plugin flo-forms Broken Access Control No login needed ≤ 1.0.42 CVE-2024-35174 Patchstack
4.3 Medium Integration for Contact Form 7 and Salesforce Plugin cf7-salesforce Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34755 Patchstack
4.3 Medium Integration for Contact Form 7 HubSpot Plugin cf7-hubspot Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-34756 Patchstack
4.3 Medium Clearfy Cache Plugin clearfy Cross-Site Request Forgery ≤ 2.2.1 CVE-2024-34806 Patchstack
4.3 Medium Fast Custom Social Share by CodeBard Plugin fast-custom-social-share-by-codebard Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-34807 Patchstack
4.3 Medium EmpowerWP Theme empowerwp Cross-Site Request Forgery No login needed ≤ 1.0.21 Fixed in 1.0.22 CVE-2024-34809 Patchstack
8.8 High Booking Ultra Pro Plugin booking-ultra-pro Privilege Escalation ≤ 1.1.12 Fixed in 1.1.13 CVE-2024-32960 Patchstack
8.8 High Sirv Plugin sirv Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 7.2.2 Fixed in 7.2.3 CVE-2024-32959 Patchstack
8.6 High BuddyForms Plugin buddyforms Path Traversal WordPress buddyforms plugin <= 2.8.8- Arbitrary File Read and SSRF No login needed ≤ 2.8.8 Fixed in 2.8.9 CVE-2024-32830 Patchstack
5.3 Medium Giveaways and Contests Plugin rafflepress Authentication Bypass IP Restriction Bypass No login needed ≤ 1.12.7 Fixed in 1.12.11 CVE-2024-32827 Patchstack
10.0 Critical ActiveDEMAND Plugin activedemand Arbitrary File Upload No login needed ≤ 0.2.41 Fixed in 0.2.42 CVE-2024-32809 Patchstack
5.3 Medium BP Better Messages Plugin bp-better-messages Authentication Bypass Broken Authentication No login needed ≤ 2.4.32 Fixed in 2.4.33 CVE-2024-32802 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Authentication Bypass IP Bypass No login needed ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-32786 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Other Group Members Limit Bypass ≤ 5.8.2 Fixed in 5.8.3 CVE-2024-32774 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Authentication Bypass Captcha Bypass No login needed ≤ 1.4.56 Fixed in 1.4.57 CVE-2024-32720 Patchstack
3.7 Low Maintenance Mode Plugin hkdev-maintenance-mode Authentication Bypass IP Bypass No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2024-32708 Patchstack
8.2 High Chauffeur Taxi Booking System Plugin Authentication Bypass Broken Authentication No login needed ≤ 6.9 Fixed in 7.0 CVE-2024-32692 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Other Review Score Manipulation No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32685 Patchstack
8.8 High HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin woocommerce-products-filter Remote Code Execution ≤ 1.3.5.2 Fixed in 1.3.5.3 CVE-2024-32680 Patchstack
8.1 High Mailster Plugin mailster Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2024-32523 Patchstack
5.3 Medium Zero Spam Plugin zero-spam Other Bypass Spam Protection No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2024-32521 Patchstack
5.3 Medium weForms Plugin weforms Other Form Submission Restriction Bypass No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-32512 Patchstack
9.8 Critical Simple Registration for WooCommerce Plugin woocommerce-simple-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.6 CVE-2024-32511 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Privilege Escalation ≤ 1.7.16 Fixed in 1.7.17 CVE-2024-32507 Patchstack
8.5 High Easy Social Share Buttons Plugin Local File Inclusion ≤ 9.4 Fixed in 9.5 CVE-2024-31300 Patchstack
9.8 Critical Demo My Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.9.1 Fixed in 1.1.0 CVE-2024-31290 Patchstack
6.3 Medium Church Admin Plugin church-admin Broken Access Control ≤ 4.1.6 Fixed in 4.1.7 CVE-2024-31281 Patchstack
7.5 High s2Member Pro Plugin s2member Privilege Escalation No login needed ≤ 240315 Fixed in 240325 CVE-2024-31237 Patchstack
8.0 High Rehub Theme Local File Inclusion ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31232 Patchstack
9.0 Critical Rehub Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31231 Patchstack
9.8 Critical WholesaleX Plugin wholesalex Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-30542 Patchstack
6.5 Medium SellKit Plugin sellkit Path Traversal Arbitrary File Download ≤ 1.8.1 Fixed in 1.8.3 CVE-2024-30509 Patchstack
8.3 High Premmerce Permalink Manager for WooCommerce Plugin woo-permalink-manager Local File Inclusion No login needed ≤ 2.3.10 Fixed in 2.3.11 CVE-2024-27971 Patchstack
8.8 High Automatic Plugin wp-automatic Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27955 Patchstack
9.3 Critical Automatic Plugin Path Traversal Unauthenticated Arbitrary File Download and SSRF No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27954 Patchstack
8.5 High Elementor Website Builder Plugin elementor Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization ≤ 3.19.0 Fixed in 3.19.1 CVE-2024-24934 Patchstack
9.8 Critical Masteriyo - LMS Plugin learning-management-system Privilege Escalation No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-24882 Patchstack
7.5 High Total Upkeep Plugin boldgrid-backup Path Traversal Arbitrary File Download No login needed ≤ 1.15.8 Fixed in 1.15.9 CVE-2024-24869 Patchstack
6.5 Medium BookIt Plugin bookit Other Price Bypass Vulnerability No login needed ≤ 2.4.0 Fixed in 2.4.2 CVE-2024-24715 Patchstack
5.3 Medium Formidable Forms Plugin formidable Content Injection No login needed ≤ 6.7 Fixed in 6.7.1 CVE-2024-23522 Patchstack
9.8 Critical SalesKing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22157 Patchstack
8.8 High InstaWP Connect Plugin instawp-connect Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-22145 Patchstack
3.7 Low WordPress Manutenção Plugin wp-manutencao Authentication Bypass No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-22139 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Authentication Bypass IP limit Bypass No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2024-21746 Patchstack
2.7 Low Car Dealer Plugin cardealer Content Injection ≤ 4.15 Fixed in 4.16 CVE-2024-4214 Patchstack
7.2 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Privilege Escalation ≤ 4.2.1 Fixed in 4.3.0 CVE-2023-51546 Patchstack
9.8 Critical WP Frontend Profile Plugin wp-front-end-profile Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-51483 Patchstack
9.8 Critical Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-51481 Patchstack
8.8 High Build App Online Plugin build-app-online Privilege Escalation Authenticated Privilege Escalation ≤ 1.0.19 CVE-2023-51479 Patchstack
9.8 Critical WP MLM Unilevel Plugin wp-mlm Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 4.0 CVE-2023-51476 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only