WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,501–15,550 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 311 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Media Cleaner Plugin media-cleaner Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 6.7.2 Fixed in 6.7.3 CVE-2024-33922 Patchstack
4.7 Medium Share This Image Plugin share-this-image Open Redirect No login needed ≤ 1.97 CVE-2024-33930 Patchstack
9.6 Critical Xserver Migrator Plugin xserver-migrator Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.6.1 CVE-2024-33913 Patchstack
6.5 Medium WordPress Geo Controller Plugin PHP Object Injection No login needed < 8.6.5 Fixed in 8.6.5 CVE-2024-3591 WPScan
4.3 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-33585 Patchstack
5.3 Medium Photo Gallery by 10Web Plugin photo-gallery Broken Access Control No login needed ≤ 1.8.20 Fixed in 1.8.21 CVE-2024-33586 Patchstack
5.3 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Broken Access Control No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2024-33587 Patchstack
5.4 Medium Knowledge Base documentation & wiki plugin – BasePress Plugin basepress Broken Access Control ≤ 2.16.1 Fixed in 2.16.2.1 CVE-2024-33588 Patchstack
6.5 Medium KB Support Plugin kb-support Broken Access Control ≤ 1.6.0 Fixed in 1.6.1 CVE-2024-33589 Patchstack
5.0 Medium Knowledge Base documentation & wiki plugin – BasePress Plugin basepress Server-Side Request Forgery ≤ 2.16.1 Fixed in 2.16.2.1 CVE-2024-33590 Patchstack
7.5 High Easy Accept Payments Plugin wordpress-easy-paypal-payment-or-donation-accept-plugin Broken Access Control No login needed ≤ 4.9.10 Fixed in 5.0 CVE-2024-33591 Patchstack
4.3 Medium Smart Forms Plugin smart-forms Broken Access Control ≤ 2.6.91 Fixed in 2.6.92 CVE-2024-33593 Patchstack
7.5 High Leaky Paywall Plugin leaky-paywall Price Manipulation No login needed ≤ 4.20.8 Fixed in 4.20.9 CVE-2024-33594 Patchstack
4.3 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on Duplicate Post ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-33595 Patchstack
5.3 Medium Five Star Restaurant Reservations Plugin restaurant-reservations Broken Access Control No login needed ≤ 2.6.16 Fixed in 2.6.17 CVE-2024-33596 Patchstack
7.5 High SSU Plugin wp-s3-smart-upload Broken Access Control No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-33597 Patchstack
7.5 High Piotnet Addons For Elementor Pro Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 7.1.17 CVE-2024-33635 Patchstack
5.4 Medium WP Page Post Widget Clone Plugin wp-page-post-widget-clone Broken Access Control ≤ 1.0.1 CVE-2024-33636 Patchstack
6.5 Medium Save as PDF plugin by Pdfcrowd Plugin save-as-pdf-by-pdfcrowd Broken Access Control Broken Access Control to Stored XSS ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-33684 Patchstack
6.5 Medium XStore Core Plugin Path Traversal Limited Arbitrary File Download ≤ 5.3.5 CVE-2024-33558 Patchstack
5.3 Medium Client Dash Plugin client-dash Broken Access Control No login needed ≤ 2.2.1 CVE-2024-33652 Patchstack
10.0 Critical OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Arbitrary File Upload Unauthenticated API Access to Arbitrary File Upload No login needed ≤ 12.4 Fixed in 12.5 CVE-2024-33566 Patchstack
5.3 Medium Assistant – Every Day Productivity Apps Plugin assistant Information Disclosure Every Day Productivity Apps plugin <= 1.4.9.1 - Sensitive Data Exposure No login needed ≤ 1.4.9.1 Fixed in 1.4.9.2 CVE-2024-33538 Patchstack
5.3 Medium User Meta Plugin user-meta Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0 Fixed in 3.1 CVE-2024-33575 Patchstack
7.5 High Solid Affiliate Plugin Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 1.9.1 CVE-2024-33637 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 7.1.17 CVE-2024-33634 Patchstack
4.4 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Server-Side Request Forgery ≤ 4.0.0 CVE-2024-33629 Patchstack
4.4 Medium Absolutely Glamorous Custom Admin Plugin ag-custom-admin Server-Side Request Forgery Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) ≤ 7.2.2 CVE-2024-33627 Patchstack
4.7 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Open Redirect No login needed ≤ 4.4.4 Fixed in 4.4.5 CVE-2024-33584 Patchstack
9.0 Critical XStore Core Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 5.3.5 CVE-2024-33553 Patchstack
5.4 Medium Custom field finder Plugin custom-field-finder PHP Object Injection No login needed ≤ 0.3 Fixed in 0.4 CVE-2024-33641 Patchstack
9.3 Critical WZone Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 14.0.10 CVE-2024-33544 Patchstack
9.6 Critical WZone Plugin SQL Injection Arbitrary SQL Update Execution ≤ 14.0.10 CVE-2024-33546 Patchstack
9.3 Critical XStore Core Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.3.5 CVE-2024-33551 Patchstack
9.3 Critical XStore Theme SQL Injection Unauthenticated SQL Injection No login needed ≤ 9.3.5 CVE-2024-33559 Patchstack
4.3 Medium Crelly Slider Plugin crelly-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-33542 Patchstack
7.1 High Regenerate post permalink Plugin regenerate-post-permalinks Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed ≤ 1.0.3 CVE-2024-33681 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Cross-Site Request Forgery No login needed ≤ 7.1.17 CVE-2024-33632 Patchstack
4.3 Medium Pathway Theme pathway Broken Access Control Broken Access Control vulnerability affecting multiple WordPress themes by Extend Themes ≤ 1.0.15, ≤ 1.0.8, ≤ 1.0.13, … Fixed in 1.0.16 CVE-2024-33686 Patchstack
6.5 Medium WP Portfolio Theme wp-portfolio Cross-Site Scripting ≤ 2.4 Fixed in 2.5 CVE-2024-33537 Patchstack
6.5 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting ≤ 1.1.35 Fixed in 1.1.36 CVE-2024-33539 Patchstack
6.5 Medium ColorNews Theme colornews Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-33540 Patchstack
7.1 High WZone Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 14.0.10 CVE-2024-33548 Patchstack
7.1 High XStore Core Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.5 CVE-2024-33554 Patchstack
7.1 High XStore Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.3.5 CVE-2024-33562 Patchstack
7.1 High VOD Infomaniak Plugin vod-infomaniak Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-33571 Patchstack
6.5 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting ≤ 2.4.26 CVE-2024-33630 Patchstack
6.5 Medium Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 7.1.17 CVE-2024-33631 Patchstack
7.1 High Piotnet Addons For Elementor Pro Plugin piotnet-addons-for-elementor-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.17 CVE-2024-33633 Patchstack
6.5 Medium Pretty Google Calendar Plugin pretty-google-calendar Cross-Site Scripting ≤ 1.7.2 CVE-2024-33640 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only