WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,501–1,550 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 31 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.0 Critical Multi Uploader for Gravity Forms Plugin gf-multi-uploader Arbitrary File Upload No login needed ≤ 1.1.3 Fixed in 1.1.5 CVE-2025-23921 Patchstack
9.9 Critical Smallerik File Browser Plugin smallerik-file-browser Arbitrary File Upload ≤ 1.1 CVE-2025-23918 Patchstack
9.8 Critical AdForest Theme Authentication Bypass No login needed ≤ 5.1.8 CVE-2024-12857 Wordfence
9.8 Critical WPBot Pro Wordpress Chatbot Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 13.5.4 CVE-2024-13091 Wordfence
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Arbitrary File Upload ≤ 1.6.7 Fixed in 1.7.0 CVE-2025-22723 Patchstack
9.8 Critical Easy Real Estate Plugin easy-real-estate Privilege Escalation No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-32555 Patchstack
9.3 Critical Multiple Carousel Plugin multicarousel SQL Injection No login needed ≤ 2.0 CVE-2025-22553 Patchstack
9.0 Critical Fancy Product Designer Plugin fancy-product-designer Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51919 Patchstack
9.8 Critical Homey Login Register Plugin homey-login-register Privilege Escalation No login needed ≤ 2.4.0 CVE-2024-51888 Patchstack
9.3 Critical Fancy Product Designer Plugin fancy-product-designer SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51818 Patchstack
9.8 Critical ARPrice Plugin arprice PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49688 Patchstack
9.3 Critical ARPrice Plugin arprice SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49655 Patchstack
9.8 Critical Adifier System Plugin Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed ≤ 3.1.7 CVE-2024-13375 Wordfence
10.0 Critical iSpring Embedder Plugin embed-ispring Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.0 CVE-2025-23922 Patchstack
9.8 Critical WP Options Editor Plugin wp-options-editor Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.1 CVE-2025-23797 Patchstack
9.9 Critical WR Price List Manager For Woocommerce Plugin wr-price-list-for-woocommerce Remote Code Execution ≤ 1.0.8 CVE-2025-22782 Patchstack
9.3 Critical Course Booking System Plugin course-booking-system SQL Injection No login needed ≤ 6.0.6 Fixed in 6.0.7 CVE-2025-22785 Patchstack
9.8 Critical Post Grid and Gutenberg Blocks Plugin post-grid Privilege Escalation Unauthenticated Privilege Escalation No login needed 2.2.85 – 2.3.3 CVE-2024-9636 Wordfence
9.8 Critical Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Authentication Bypass Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.7 - Authentication Bypass via pms_payment_id No login needed ≤ 2.13.7 CVE-2024-12919 Wordfence
9.8 Critical GiveWP Plugin give PHP Object Injection No login needed ≤ 3.19.3 Fixed in 3.19.4 CVE-2025-22777 Patchstack
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.19.2 - Unauthenticated PHP Object Injection No login needed ≤ 3.19.2 CVE-2024-12877 Wordfence
9.8 Critical WPBookit Plugin wpbookit Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 1.6.4 CVE-2024-10215 Wordfence
10.0 Critical 4ECPS Web Forms Plugin 4ecps-webforms Arbitrary File Upload No login needed ≤ 0.2.18 CVE-2025-22504 Patchstack
9.3 Critical Emailing Subscription Plugin email-suscripcion SQL Injection No login needed ≤ 1.4.1 CVE-2025-22540 Patchstack
9.3 Critical Virtual Bot Plugin virtual-bot SQL Injection No login needed ≤ 1.0.0 CVE-2025-22542 Patchstack
9.8 Critical Post Grid Master Plugin ajax-filter-posts Broken Access Control Missing Authorization to Unauthenticated Local PHP File Inclusion No login needed ≤ 3.4.12 CVE-2024-11642 Wordfence
9.8 Critical AdForest Theme Privilege Escalation Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 5.1.6 CVE-2024-11350 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unuathenticated Remote Code Execution No login needed ≤ 4.24.12 CVE-2024-11635 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion No login needed ≤ 4.24.15 CVE-2024-11613 Wordfence
10.0 Critical JobBoard Job listing Plugin job-board-light Arbitrary File Upload No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-43243 Patchstack
9.8 Critical WPGuppy Plugin wpguppy-lite PHP Object Injection No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-49222 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2024-49649 Patchstack
9.1 Critical WP Ultimate Exporter Plugin wp-ultimate-exporter Remote Code Execution ≤ 2.9.1 Fixed in 2.9.2 CVE-2024-56278 Patchstack
9.3 Critical SSL Wireless SMS Notification Plugin ssl-wireless-sms-notification SQL Injection No login needed ≤ 3.5.0 Fixed in 3.6.0 CVE-2024-56284 Patchstack
9.3 Critical Multiple Shipping And Billing Address For Woocommerce Plugin different-shipping-and-billing-address-for-woocommerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.2 Fixed in 1.3 CVE-2024-56290 Patchstack
9.8 Critical WordPress Auction Plugin SQL Injection Editor+ SQL Injection No login needed ≤ 3.7 CVE-2024-8855 WPScan
9.8 Critical School Management System – SakolaWP Plugin sakolawp-lite Privilege Escalation SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation No login needed ≤ 1.0.8 CVE-2024-12470 Wordfence
9.8 Critical PayU CommercePro Plugin payu-india Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.8.3 CVE-2024-12264 Wordfence
9.8 Critical SEO LAT Auto Post Plugin seo-beginner-auto-post Broken Access Control Missing Authorization to File Overwrite/Upload (Remote Code Execution) No login needed ≤ 2.2.1 CVE-2024-12252 Wordfence
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
9.9 Critical Dynamics 365 Integration Plugin integration-dynamics Remote Code Execution Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection ≤ 1.3.23 CVE-2024-12583 Wordfence
9.1 Critical WPMasterToolKit Plugin wpmastertoolkit Arbitrary File Upload ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56249 Patchstack
9.8 Critical Agency Toolkit Plugin agency-toolkit Privilege Escalation No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-56066 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56045 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Authentication Bypass Unauthenticated Arbitrary User Token Generation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56044 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56043 Patchstack
9.8 Critical VibeBP Plugin vibebp Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9.4.1 Fixed in 1.9.9.5 CVE-2024-56040 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56042 Patchstack
9.3 Critical VibeBP Plugin vibebp SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.7.7 Fixed in 1.9.9.7.7 CVE-2024-56039 Patchstack
10.0 Critical WP SuperBackup Plugin indeed-wp-superbackup Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56064 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only