WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,201–15,250 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 305 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.05.0 Fixed in 3.05.1 CVE-2023-51424 Patchstack
6.3 Medium Ultimate Addons for Beaver Builder Plugin ultimate-addons-for-beaver-builder-lite Path Traversal Limited Arbitrary File Download ≤ 1.35.13 Fixed in 1.35.14 CVE-2023-51401 Patchstack
8.8 High Ultimate Addons for Beaver Builder Plugin ultimate-addons-for-beaver-builder-lite Privilege Escalation ≤ 1.35.14 Fixed in 1.35.15 CVE-2023-51398 Patchstack
8.8 High ARMember Plugin armember-membership Privilege Escalation ≤ 4.0.10 Fixed in 4.0.11 CVE-2023-51356 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.20 Fixed in 1.36.21 CVE-2023-50890 Patchstack
7.5 High Adifier System Plugin Local File Inclusion No login needed < 3.1.4 Fixed in 3.1.4 CVE-2023-49753 Patchstack
8.8 High JetEngine Plugin Privilege Escalation ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-48757 Patchstack
6.8 Medium Salon booking system Plugin salon-booking-system Privilege Escalation Editor+ Privilege Escalation ≤ 8.6 Fixed in 8.7 CVE-2023-48319 Patchstack
7.3 High wpForo Forum Plugin wpforo Privilege Escalation No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2023-47868 Patchstack
8.8 High Thrive Theme Builder Theme Privilege Escalation Authenticated Privilege Escalation < 3.24.0 Fixed in 3.24.0 CVE-2023-47782 Patchstack
8.0 High WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Privilege Escalation Authenticated Privilege Escalation ≤ 7.6.6 Fixed in 7.6.7 CVE-2023-47683 Patchstack
7.2 High WP User Frontend Plugin wp-user-frontend Privilege Escalation Authenticated Privilege Escalation ≤ 3.6.5 Fixed in 3.6.6 CVE-2023-47682 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion ≤ 1.6.3 Fixed in 1.6.4 CVE-2023-47679 Patchstack
8.6 High The Plus Addons for Elementor Pro Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.2.8 Fixed in 5.2.9 CVE-2023-47178 Patchstack
8.2 High ICS Calendar Plugin ics-calendar Server-Side Request Forgery SSRF and Arbitrary File Read No login needed ≤ 10.12.0.3 Fixed in 10.12.0.4 CVE-2023-46784 Patchstack
7.1 High Ultimate Addons for WPBakery Page Builder Plugin Local File Inclusion No login needed ≤ 3.19.14 Fixed in 3.19.15 CVE-2023-46205 Patchstack
5.3 Medium Popup by Supsystic Plugin popup-by-supsystic Information Disclosure Unauthenticated Subscriber Email Addresses Disclosure No login needed ≤ 1.10.19 Fixed in 1.10.20 CVE-2023-46197 Patchstack
8.8 High Themify Ultra Theme Privilege Escalation Authenticated Privilege Escalation ≤ 7.3.5 Fixed in 7.3.6 CVE-2023-46145 Patchstack
6.5 Medium Remote Content Shortcode Plugin remote-content-shortcode Local File Inclusion ≤ 1.5 CVE-2023-45652 Patchstack
7.1 High Events Rich Snippets for Google Plugin rich-snippets-vevents Cross-Site Request Forgery CSRF Leading to Privilege Escalation No login needed ≤ 1.8 CVE-2023-44478 Patchstack
5.3 Medium CP Polls Plugin cp-polls Other Polls Limitation Bypass No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24873 Patchstack
5.3 Medium CP Polls Plugin cp-polls Content Injection No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24874 Patchstack
5.3 Medium Defender Security Plugin defender-security Authentication Bypass IP Restriction Bypass No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2024-25595 Patchstack
4.3 Medium Comments Like Dislike Plugin comments-like-dislike Authentication Bypass IP Restriction Bypass Vulnerability ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-25906 Patchstack
5.3 Medium IP Blocker Lite Plugin ip-address-blocker Authentication Bypass No login needed ≤ 11.1.1 CVE-2024-30479 Patchstack
3.7 Low CGC Maintenance Mode Plugin cgc-maintenance-mode Authentication Bypass IP Filtering Bypass No login needed ≤ 1.2 CVE-2024-30480 Patchstack
5.3 Medium Newsletter Plugin newsletter Authentication Bypass IP Blacklist Bypass No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2024-30522 Patchstack
7.5 High WP Express Checkout (Accept PayPal Payments) Plugin wp-express-checkout Price Manipulation No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2024-30527 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.7 Fixed in 14.8 CVE-2024-30540 Patchstack
5.3 Medium Captcha by BestWebSoft Plugin captcha-bws Authentication Bypass Captcha Bypass No login needed ≤ 5.2.0 Fixed in 5.2.1 CVE-2024-31295 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Other Bypass Vulnerability No login needed ≤ 3.11.2 Fixed in 3.11.3 CVE-2024-31341 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure File Password Lock Bypass No login needed ≤ 3.2.82 Fixed in 3.2.83 CVE-2024-32131 Patchstack
4.3 Medium Pricing Table by Supsystic Plugin pricing-table-by-supsystic Content Injection ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-32790 Patchstack
8.8 High WZone Plugin Privilege Escalation ≤ 14.0.10 CVE-2024-33549 Patchstack
8.8 High WP Masquerade Plugin wp-masquerade Privilege Escalation Authenticated Account Takeover ≤ 1.1.0 CVE-2024-33550 Patchstack
9.8 Critical XStore Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33552 Patchstack
9.8 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33567 Patchstack
7.2 High Instant Images Plugin instant-images Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 6.1.0 Fixed in 6.1.1 CVE-2024-33569 Patchstack
9.9 Critical Customify Site Library Plugin customify-sites Remote Code Execution ≤ 0.0.9 CVE-2024-33644 Patchstack
5.3 Medium WTI Like Post Plugin wti-like-post Authentication Bypass IP Restriction Bypass Vulnerability No login needed ≤ 1.4.6 CVE-2024-33917 Patchstack
7.2 High EAN for WooCommerce Plugin ean-for-woocommerce Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 4.8.9 Fixed in 4.9.0 CVE-2024-34370 Patchstack
6.5 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Arbitrary Shortcode Execution Meta Data and Taxonomies Filter plugin <= 1.3.3.2 - Arbitrary Shortcode Execution No login needed ≤ 1.3.3.2 Fixed in 1.3.3.3 CVE-2024-34434 Patchstack
8.6 High Simple Membership Plugin simple-membership Privilege Escalation Unauthenticated Membership Role Privilege Escalation No login needed ≤ 4.3.4 Fixed in 4.3.5 CVE-2023-41957 Patchstack
8.8 High Simple Membership Plugin simple-membership Privilege Escalation Authenticated Account Takeover ≤ 4.3.4 Fixed in 4.3.5 CVE-2023-41956 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Contributor+ Privilege Escalation ≤ 5.8.8 Fixed in 5.8.9 CVE-2023-41955 Patchstack
8.6 High ProfilePress Plugin wp-user-avatar Privilege Escalation Unauthenticated Limited Privilege Escalation No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41954 Patchstack
8.8 High GiveWP Plugin give Privilege Escalation GiveWP Manager+ Privilege Escalation ≤ 2.33.0 Fixed in 2.33.1 CVE-2023-41665 Patchstack
8.8 High WPvivid Backup and Migration Plugin wpvivid-backuprestore Privilege Escalation Privilege Escalation on Staging Environment ≤ 0.9.90 Fixed in 0.9.91 CVE-2023-41243 Patchstack
8.6 High Phlox Shop Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.0.0 CVE-2023-39163 Patchstack
8.6 High Phlox Portfolio Plugin auxin-portfolio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-38399 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only