WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,201–16,250 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 325 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Action Network Plugin wp-action-network SQL Injection The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3 due to insufficient escaping on the user supplied parameter… 1.4.3 CVE-2024-2954 Wordfence
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-30194 Patchstack
7.1 High New RoyalSlider Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2024-30195 Patchstack
7.1 High Easy Social Share Buttons Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.4 Fixed in 9.5 CVE-2024-30196 Patchstack
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-27188 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30197 Patchstack
5.8 Medium BuddyForms Plugin buddyforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2024-30198 Patchstack
7.1 High WordPress Importer Plugin wp-smart-import Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-30201 Patchstack
7.1 High WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2024-30199 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.5.41.7212 Fixed in 7.5.44.7212 CVE-2024-22299 Patchstack
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.11 Fixed in 5.7.12 CVE-2024-22300 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.24 Fixed in 2.0.25 CVE-2023-52228 Patchstack
7.1 High CformsII Plugin cforms2 Cross-Site Scripting No login needed ≤ 15.0.5 CVE-2024-22149 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack
7.1 High WP Editor Plugin wp-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-24700 Patchstack
7.1 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.2.5 Fixed in 13.2.6 CVE-2024-24800 Patchstack
6.5 Medium WP SMS Plugin wp-sms Cross-Site Scripting ≤ 6.3.4 Fixed in 6.4 CVE-2024-25920 Patchstack
7.1 High Widgets Controller Plugin widgets-controller Cross-Site Scripting No login needed ≤ 1.1 CVE-2024-25926 Patchstack
7.1 High Fusion Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39306 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6.20 Fixed in 1.6.6.24 CVE-2024-22311 Patchstack
8.7 High Knowledge Base for Documentation, FAQs with AI Assistance Plugin echo-knowledge-base PHP Object Injection No login needed ≤ 11.30.2 Fixed in 11.31.0 CVE-2024-24842 Patchstack
10.0 Critical WappPress Plugin wapppress-builds-android-app-for-website Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.3 Fixed in 6.0.0 CVE-2023-49815 Patchstack
9.9 Critical Elementor Website Builder Plugin elementor Arbitrary File Upload 3.3.0 – 3.18.1 Fixed in 3.18.2 CVE-2023-48777 Patchstack
8.0 High Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Arbitrary File Upload ≤ 11.0.2 Fixed in 11.1 CVE-2023-48275 Patchstack
8.5 High Avada Theme Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39307 Patchstack
9.0 Critical JupiterX Core Plugin Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 3.3.5 Fixed in 3.3.8 CVE-2023-38388 Patchstack
9.1 Critical WP Child Theme Generator Plugin wp-child-theme-generator Arbitrary File Upload ≤ 1.0.9 CVE-2023-47873 Patchstack
9.1 Critical WP Githuber MD Plugin wp-githuber-md Arbitrary File Upload ≤ 1.16.2 Fixed in 1.16.3 CVE-2023-47846 Patchstack
9.1 Critical CataBlog Plugin catablog Arbitrary File Upload ≤ 1.7.0 CVE-2023-47842 Patchstack
9.1 Critical Manager for Icomoon Plugin manager-for-icomoon Arbitrary File Upload ≤ 2.0 Fixed in 2.1 CVE-2023-29386 Patchstack
9.3 Critical Quiz And Survey Master Plugin quiz-master-next SQL Injection Unauthenticated SQL Injection No login needed ≤ 8.1.4 Fixed in 8.1.5 CVE-2023-28787 Patchstack
7.1 High Glaze Blog Lite Theme glaze-blog-lite Cross-Site Scripting Reflected Cross-Site Scripting (XSS) vulnerability in multiple WordPress themes No login needed ≤ <= 1.1.4, ≤ 1.0.8, ≤ 2.1.3, … Fixed in 1.1.5 CVE-2023-28687 Patchstack
5.3 Medium Community by PeepSo Plugin peepso-core Information Disclosure Server Information Disclosure No login needed ≤ 6.0.9.0 Fixed in 6.1.0.0 CVE-2023-27630 Patchstack
7.4 High User Registration Plugin user-registration PHP Object Injection Authenticated PHP Object Injection ≤ 2.3.2.1 Fixed in 2.3.3 CVE-2023-27459 Patchstack
7.2 High Types Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4.17 Fixed in 3.4.18 CVE-2023-27440 Patchstack
5.9 Medium Upload Resume Plugin resume-upload-form Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.0 CVE-2023-25965 Patchstack
10.0 Critical MainWP File Uploader Extension Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.1 Fixed in 4.1.1 CVE-2023-23656 Patchstack
7.2 High Theme Editor Plugin theme-editor Arbitrary File Upload ≤ 2.7.1 Fixed in 2.8 CVE-2023-6091 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
7.5 High CF7 Google Sheets Connector Plugin cf7-google-sheets-connector Information Disclosure Sensitive Data Exposure via Debug Log No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-44989 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck
4.3 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2023-52214 Patchstack
6.5 Medium SalesKing Plugin Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22156 Patchstack
6.5 Medium Radio Player Plugin radio-player Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-2906 Patchstack
4.3 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Broken Access Control MPG plugin <= 3.4.0 - Broken Access Control ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-30235 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30234 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only