WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,801–15,850 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 317 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WPC Grouped Product for WooCommerce Plugin wpc-grouped-product Broken Access Control ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-32520 Patchstack
4.3 Medium Open Close WooCommerce Store Plugin woc-open-close Broken Access Control ≤ 4.9.1 Fixed in 4.9.2 CVE-2024-32522 Patchstack
4.3 Medium Custom Order Statuses for WooCommerce Plugin custom-order-statuses-for-woocommerce Broken Access Control ≤ 1.5.2 CVE-2024-32524 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Broken Access Control ≤ 7.1.6 Fixed in 7.1.7 CVE-2024-32525 Patchstack
5.3 Medium Speed Optimizer Plugin sg-cachepress Broken Access Control No login needed ≤ 7.4.6 Fixed in 7.5.0 CVE-2024-32532 Patchstack
5.7 Medium WordPress Plugin Salon Booking System Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting (XSS) < 9.6.3 Fixed in 9.6.3 CVE-2024-2101 WPScan
4.3 Medium Fatal Error Notify Plugin fatal-error-notify Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2024-32455 Patchstack
8.6 High MoveTo Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.2 CVE-2024-25911 Patchstack
8.2 High LiteSpeed Cache Plugin litespeed-cache Broken Access Control Unauthenticated Broken Access Control on API No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-45000 Patchstack
8.3 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Site Wide Stored XSS No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-40000 Patchstack
7.5 High Citadela Listing Plugin citadela-directory Information Disclosure Unauth. Sensitive Data Exposure No login needed ≤ 5.18.1 CVE-2024-32086 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9.2 Fixed in 2.6.9.3 CVE-2024-32557 Patchstack
4.7 Medium Freshdesk (official) Plugin freshdesk-support Open Redirect No login needed ≤ 2.3.6 Fixed in 2.4.0 CVE-2024-32129 Patchstack
4.3 Medium Login With Ajax Plugin login-with-ajax Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-30546 Patchstack
5.4 Medium e2pdf Plugin e2pdf Cross-Site Request Forgery No login needed ≤ 1.20.27 Fixed in 1.23.00 CVE-2024-31373 Patchstack
4.3 Medium AppPresser Plugin apppresser Cross-Site Request Forgery No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2024-31374 Patchstack
4.3 Medium Dashboard To-Do List Plugin dashboard-to-do-list Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-31376 Patchstack
5.4 Medium MailChimp Forms by MailMunch Plugin mailchimp-forms-by-mailmunch Cross-Site Request Forgery No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2024-31378 Patchstack
4.3 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Request Forgery No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-31379 Patchstack
4.3 Medium Spotlight Social Media Feeds Plugin spotlight-social-photo-feeds Cross-Site Request Forgery No login needed ≤ 1.6.10 Fixed in 1.6.11 CVE-2024-31381 Patchstack
4.3 Medium Blocksy Plugin blocksy Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2024-31382 Patchstack
4.3 Medium PopularFX Theme popularfx Cross-Site Request Forgery No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-31383 Patchstack
4.3 Medium Spa and Salon Theme spa-and-salon Cross-Site Request Forgery No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-31384 Patchstack
4.3 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31385 Patchstack
4.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Request Forgery No login needed ≤ 1.0.25 Fixed in 1.0.26 CVE-2024-31388 Patchstack
5.4 Medium MihanPanel Plugin mihanpanel-lite Cross-Site Request Forgery No login needed < 12.7 Fixed in 12.7 CVE-2024-31389 Patchstack
4.3 Medium Popup by Supsystic Plugin popup-by-supsystic Broken Access Control ≤ 1.10.27 Fixed in 1.10.28 CVE-2024-31421 Patchstack
4.3 Medium Favicon Plugin favicon-by-realfavicongenerator Cross-Site Request Forgery No login needed ≤ 1.3.29 Fixed in 1.3.30 CVE-2024-31422 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
5.4 Medium Amelia Plugin ameliabooking Cross-Site Request Forgery No login needed ≤ 1.0.95 Fixed in 1.0.96 CVE-2024-31425 Patchstack
4.3 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Request Forgery No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-31426 Patchstack
4.3 Medium Marker.io Plugin marker-io Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-31427 Patchstack
4.3 Medium The Conference Theme the-conference Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-31428 Patchstack
4.3 Medium Sarada Lite Theme sarada-lite Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-31429 Patchstack
4.3 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-31431 Patchstack
5.3 Medium Restrict Content Plugin restrict-content Broken Access Control No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-31432 Patchstack
4.3 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2024-31433 Patchstack
5.4 Medium Newsletter Plugin newsletter Cross-Site Request Forgery No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2024-31434 Patchstack
4.3 Medium Currency per Product for WooCommerce Plugin currency-per-product-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.7.0 CVE-2024-31920 Patchstack
4.3 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Request Forgery No login needed ≤ 5.2.15 Fixed in 5.2.16 CVE-2024-31921 Patchstack
4.3 Medium WordPress Hosting Benchmark tool Plugin wpbenchmark Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-31922 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-31923 Patchstack
5.4 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Request Forgery No login needed ≤ 1.5.35 Fixed in 1.5.36 CVE-2024-31933 Patchstack
4.3 Medium NewsXpress Theme newsxpress Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-31938 Patchstack
4.3 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.2.104 Fixed in 1.2.105 CVE-2024-31940 Patchstack
5.4 Medium CP Media Player Plugin audio-and-video-player Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.2.0 CVE-2024-31941 Patchstack
4.3 Medium Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-31942 Patchstack
4.3 Medium Before And After Plugin before-and-after Cross-Site Request Forgery No login needed ≤ 3.9 CVE-2024-32084 Patchstack
5.4 Medium Citadela Listing Plugin Cross-Site Request Forgery No login needed < 5.20.0 Fixed in 5.20.0 CVE-2024-32085 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.15.20 Fixed in 6.15.21 CVE-2024-32088 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only