WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,551–15,600 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 312 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Advanced Most Recent Posts Mod Plugin advanced-most-recent-posts-mod Cross-Site Scripting ≤ 1.6.5.2 CVE-2024-33643 Patchstack
7.1 High Easy Set Favicon Plugin easy-set-favicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-33645 Patchstack
7.1 High Sticky Anything Plugin toast-stick-anything Broken Access Control Broken Access Control to XSS No login needed ≤ 2.1.5 CVE-2024-33646 Patchstack
6.5 Medium Recencio Book Reviews Plugin recencio-book-reviews Cross-Site Scripting ≤ 1.66.0 Fixed in 1.70.0 CVE-2024-33648 Patchstack
6.5 Medium Opal Widgets For Elementor Plugin opal-widgets-for-elementor Cross-Site Scripting ≤ 1.6.9 CVE-2024-33649 Patchstack
2.7 Low BackUpWordPress Plugin backupwordpress Path Traversal Authenticated (Admin+) Directory Traversal ≤ 3.13 CVE-2024-3034 Wordfence
5.4 Medium Post Slider Plugin adl-post-slider Broken Access Control ≤ 1.6.7 CVE-2022-40975 Patchstack
5.9 Medium Filterable Portfolio Plugin filterable-portfolio Cross-Site Scripting ≤ 1.6.4 CVE-2024-4234 Patchstack
4.3 Medium Teluro Theme teluro Cross-Site Request Forgery No login needed ≤ 1.0.31 Fixed in 1.0.36 CVE-2024-33688 Patchstack
4.3 Medium Radio Station Plugin radio-station Cross-Site Request Forgery No login needed ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-33689 Patchstack
4.3 Medium Financio Theme financio Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-33690 Patchstack
4.3 Medium OptinMonster Plugin optinmonster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Notice Dismissal No login needed ≤ 2.15.3 Fixed in 2.16.0 CVE-2024-33691 Patchstack
5.9 Medium Smart Recent Posts Widget Plugin smart-recent-posts-widget Cross-Site Scripting ≤ 1.0.3 CVE-2024-33692 Patchstack
5.9 Medium Meks Smart Social Widget Plugin meks-smart-social-widget Cross-Site Scripting ≤ 1.6.4 CVE-2024-33693 Patchstack
5.9 Medium Meks ThemeForest Smart Widget Plugin meks-themeforest-smart-widget Cross-Site Scripting ≤ 1.5 Fixed in 1.6 CVE-2024-33694 Patchstack
5.9 Medium Fan Page Widget by ThemeNcode Plugin facebook-fan-page-widget Cross-Site Scripting ≤ 2.0 CVE-2024-33695 Patchstack
5.9 Medium WordPress Ad Widget Plugin ad-widget Cross-Site Scripting ≤ 2.20.0 CVE-2024-33696 Patchstack
5.9 Medium CF7 File Download – File Download for CF7 Plugin cf7-file-download Cross-Site Scripting ≤ 2.0 CVE-2024-33697 Patchstack
4.3 Medium Reviews Plus Plugin reviews-plus Broken Access Control ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-32822 Patchstack
5.3 Medium VK Block Patterns Plugin vk-block-patterns Broken Access Control No login needed ≤ 1.31.0 Fixed in 1.31.1.1 CVE-2024-32826 Patchstack
4.3 Medium Flexible Shipping Plugin flexible-shipping Broken Access Control ≤ 4.24.15 Fixed in 4.24.16 CVE-2024-32828 Patchstack
4.3 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.31 Fixed in 1.10.32 CVE-2024-32829 Patchstack
4.7 Medium Page Builder: Live Composer Plugin live-composer-page-builder Broken Access Control ≤ 1.5.38 Fixed in 1.5.39 CVE-2024-32957 Patchstack
4.3 Medium Contact Form 7 Extension For Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Request Forgery No login needed ≤ 0.5.70 CVE-2024-33677 Patchstack
4.3 Medium ClickCease Click Fraud Protection Plugin clickcease-click-fraud-protection Cross-Site Request Forgery No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-33678 Patchstack
4.3 Medium FameTheme Demo Importer Plugin famethemes-demo-importer Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-33679 Patchstack
5.4 Medium MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.2 CVE-2024-33680 Patchstack
5.4 Medium WP GDPR Compliance Plugin wp-gdpr-compliance Cross-Site Request Forgery No login needed ≤ 2.0.23 CVE-2024-33682 Patchstack
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.3 CVE-2024-33683 Patchstack
7.2 High WP SMTP Plugin SQL Injection The WP SMTP plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in versions 1.2 to 1.2.6 due to insufficient escaping on the user supplied parameter and… 1.2 – 1.2.6 CVE-2024-1789 Wordfence
5.9 Medium Advanced Post List Plugin advanced-post-list Cross-Site Scripting ≤ 0.5.6.1 CVE-2024-33642 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 CVE-2024-33639 Patchstack
5.9 Medium Annual Archive Plugin anual-archive Cross-Site Scripting ≤ 1.6.0 CVE-2024-33598 Patchstack
5.4 Medium Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-33638 Patchstack
4.3 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Request Forgery No login needed ≤ 1.2.4 CVE-2024-33650 Patchstack
5.4 Medium MF Gig Calendar Plugin mf-gig-calendar Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2024-33651 Patchstack
5.4 Medium Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-33592 Patchstack
5.3 Medium LoginPress Pro Plugin Authentication Bypass Captcha Bypass No login needed < 3.0.0 Fixed in 3.0.0 CVE-2024-32676 Patchstack
4.3 Medium Google Analytics by Monster Insights Plugin google-analytics-for-wordpress Broken Access Control ≤ 8.21.0 Fixed in 8.22.0 CVE-2023-52220 Patchstack
6.5 Medium Blocksy Plugin blocksy Cross-Site Scripting ≤ 2.0.33 Fixed in 2.0.34 CVE-2024-32961 Patchstack
7.1 High UDesign Theme u-design Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.3 CVE-2024-4077 Patchstack
9.1 Critical Advanced Order Export For WooCommerce Plugin woo-order-export-lite Remote Code Execution ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-31266 Patchstack
9.6 Critical DX-Watermark Plugin dx-watermark Cross-Site Request Forgery CSRF to Arbitrary File Upload and XSS No login needed ≤ 1.0.4 CVE-2024-30560 Patchstack
8.8 High WP Setup Wizard Plugin Information Disclosure Auth. Full Database Download ≤ 1.0.8.1 Fixed in 1.0.8.2 CVE-2024-25917 Patchstack
9.0 Critical Anti-Malware Security and Brute-Force Firewall Plugin gotmls Remote Code Execution Unauthenticated Predictable Nonce Brute-Force Leading to RCE No login needed ≤ 4.21.96 Fixed in 4.23.56 CVE-2024-22144 Patchstack
9.8 Critical Login as User or Customer (User Switching) Plugin login-as-customer-or-user Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.8 CVE-2023-51484 Patchstack
9.9 Critical Eazy Plugin Manager Plugin plugins-on-steroids Remote Code Execution Auth. Arbitrary Options Update lead to RCE ≤ 4.1.2 Fixed in 4.1.3 CVE-2023-51482 Patchstack
9.8 Critical Build App Online Plugin build-app-online Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.19 CVE-2023-51478 Patchstack
9.8 Critical BuddyBoss Theme Authentication Bypass Unauth. Arbitrary WordPress Settings Change No login needed ≤ 2.4.60 Fixed in 2.4.61 CVE-2023-51477 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 7.1.9.7 Fixed in 7.1.9.8 CVE-2023-51472 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only