WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,151–15,200 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 304 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Authentication Bypass IP Bypass Vulnerability No login needed ≤ 2.29.1 Fixed in 2.29.2 CVE-2023-37865 Patchstack
5.3 Medium Hide My WP Ghost Plugin hide-my-wp Authentication Bypass Security Plugin plugin <= 5.0.25 - Captcha Bypass No login needed ≤ 5.0.25 Fixed in 5.0.26 CVE-2023-34001 Patchstack
4.3 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.31 Fixed in 1.3.32 CVE-2023-28494 Patchstack
6.4 Medium SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! Plugin suretriggers Cross-Site Scripting Connect All Your Plugins, Apps, Tools & Automate Everything! <= 1.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trigger Link Shortcode ≤ 1.0.47 CVE-2024-5485 Wordfence
6.1 Medium FS Product Inquiry Plugin fs-product-inquiry Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.1.1 CVE-2024-4857 WPScan
5.3 Medium BuddyBoss Platform Plugin Broken Access Control Insecure Direct Object Reference on Like Comment No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-4750 WPScan
6.1 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed < 3.2.37 Fixed in 3.2.37 CVE-2024-4057 WPScan
5.4 Medium Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Admin+ Stored XSS < 20240412 Fixed in 20240412 CVE-2024-2470 WPScan
5.4 Medium Insert or Embed Articulate Content into Plugin Remote Code Execution Author+ Upload to RCE ≤ 4.3000000023 CVE-2024-0757 WPScan
5.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Broken Access Control Missing Authorization No login needed ≤ 3.43 CVE-2024-4997 Wordfence
4.4 Medium Nafeza Prayer Time Plugin nafeza-prayer-time Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.2.9 CVE-2024-4462 Wordfence
6.4 Medium Cowidgets – Elementor Addons Plugin Cross-Site Scripting Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via heading_tag Parameter ≤ 1.1.2 CVE-2024-4697 Wordfence
6.4 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.2 CVE-2024-4273 Wordfence
4.3 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control Insecure Direct Object Reference to Arbitrary Attachment Deletion ≤ 4.4.4 CVE-2024-4274 Wordfence
6.4 Medium Download Attachments Plugin download-attachments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-3230 Wordfence
4.4 Medium Fluid Notification Bar Plugin fluid-notification-bar Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.2.3 CVE-2024-3031 Wordfence
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
5.3 Medium Claudio Sanches – Checkout Cielo for WooCommerce Plugin woocommerce-checkout-cielo Broken Access Control Checkout Cielo for WooCommerce <= 1.1.0 - Insufficient Verification of Data Authenticity to Order Payment Status Update No login needed ≤ 1.1.0 CVE-2024-1718 Wordfence
4.3 Medium Admin Notices Manager Plugin admin-notices-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Retrieval ≤ 1.4.0 CVE-2024-1717 Wordfence
6.4 Medium tagDiv Composer Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via button Shortcode ≤ 4.8 CVE-2024-3888 Wordfence
4.3 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.4.10 Fixed in 1.4.11 CVE-2023-28492 Patchstack
4.3 Medium CP Contact Form with Paypal Plugin cp-contact-form-with-paypal Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.34 Fixed in 1.3.35 CVE-2023-27460 Patchstack
4.3 Medium Calculated Fields Form Plugin calculated-fields-form Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.1.120 Fixed in 1.1.121 CVE-2023-26523 Patchstack
4.3 Medium Search in Place Plugin search-in-place Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.104 Fixed in 1.0.105 CVE-2023-26521 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email Spoofing No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23738 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23735 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Authentication Bypass WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23730 Patchstack
4.3 Medium Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-35632 Patchstack
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.5 Medium ChaosTheory Theme chaostheory Cross-Site Scripting ≤ 1.3 Fixed in 1.3.2 CVE-2024-34766 Patchstack
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-34767 Patchstack
6.5 Medium Elegant Blocks Plugin elegant-blocks Cross-Site Scripting Amazing Gutenberg Blocks plugin <= 1.7 - Cross Site Scripting (XSS) ≤ 1.7 CVE-2024-34769 Patchstack
6.5 Medium Popup Maker WP Plugin popup-maker-wp Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-34770 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.16 Fixed in 2.0.17 CVE-2024-34789 Patchstack
5.9 Medium ImageMagick Sharpen Resized Images Theme imagemagick-sharpen-resized-images Cross-Site Scripting ≤ 1.1.7 CVE-2024-34790 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.0.9 Fixed in 1.2 CVE-2024-34791 Patchstack
5.9 Medium WP Next Post Navi Plugin wp-next-post-navi Cross-Site Scripting ≤ 1.8.3 CVE-2024-34793 Patchstack
6.5 Medium Tainacan Plugin tainacan Cross-Site Scripting ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34795 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-34796 Patchstack
5.9 Medium Simple Popup Manager Plugin simple-popup-manager Cross-Site Scripting ≤ 1.3.5 CVE-2024-34797 Patchstack
6.5 Medium Praison SEO Plugin seo-wordpress Cross-Site Scripting ≤ 4.0.15 Fixed in 4.0.16 CVE-2024-34801 Patchstack
5.3 Medium Contact Form Widget Plugin new-contact-form-widget Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34754 Patchstack
5.3 Medium Debug Log – Manger Tool Plugin debug-log-config-tool Information Disclosure Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2024-34798 Patchstack
4.3 Medium Fastly Plugin fastly Broken Access Control ≤ 1.2.25 Fixed in 1.2.26 CVE-2024-34803 Patchstack
4.4 Medium Blocksy Companion Plugin blocksy-companion Server-Side Request Forgery ≤ 2.0.42 Fixed in 2.0.43 CVE-2024-35633 Patchstack
4.4 Medium Ninja Tables Plugin ninja-tables Server-Side Request Forgery ≤ 5.0.9 Fixed in 5.0.10 CVE-2024-35635 Patchstack
4.4 Medium Church Admin Plugin church-admin Server-Side Request Forgery ≤ 4.3.6 Fixed in 4.4.0 CVE-2024-35637 Patchstack
4.3 Medium ActiveDEMAND Plugin activedemand Cross-Site Request Forgery No login needed ≤ 0.2.43 CVE-2024-35638 Patchstack
5.9 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2024-35639 Patchstack
5.9 Medium Safety Exit Plugin safety-exit Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2024-35640 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only