WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,251–16,300 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 326 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WholesaleX Plugin wholesalex Information Disclosure Sensitive Data Exposure on User Export ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30233 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9 Fixed in 2.6.9.1 CVE-2024-30232 Patchstack
9.1 Critical Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-30231 Patchstack
4.3 Medium PopupAlly Plugin popupally Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-23520 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-24711 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control Missing Authorization to Non-Arbitrary Plugin Installation ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-24718 Patchstack
4.3 Medium Location Picker at Checkout for WooCommerce Plugin map-location-picker-at-checkout-for-woocommerce Broken Access Control ≤ 1.8.9 Fixed in 1.9.0 CVE-2024-24719 Patchstack
6.5 Medium WooCommerce Box Office Plugin woocommerce-box-office Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-24799 Patchstack
4.3 Medium Calliope Theme calliope Cross-Site Request Forgery No login needed ≤ 1.0.33 Fixed in 1.0.35 CVE-2024-2904 Patchstack
4.3 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-24805 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 9.4.3 Fixed in 9.4.3.1 CVE-2023-23991 Patchstack
7.1 High Front End Users Plugin front-end-only-users Cross-Site Scripting No login needed < 3.2.25 Fixed in 3.2.25 CVE-2023-33322 Patchstack
6.5 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting ≤ 20230901 Fixed in 20230902 CVE-2023-7251 Patchstack
7.1 High Contact Form With Captcha Plugin contact-form-with-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 CVE-2023-45771 Patchstack
7.1 High Cosmetsy theme (core plugin) Plugin Cross-Site Scripting Reflected Cross-Site Scripting vulnerability in multiple WordPress components by KlbTheme No login needed ≤ 1.3.0, ≤ 1.0.9, ≤ 1.3.3, … CVE-2023-49839 Patchstack
6.5 Medium EnvíaloSimple Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2023-51416 Patchstack
5.9 Medium WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting ≤ 2.6.11 Fixed in 2.6.12 CVE-2024-2889 Patchstack
6.5 Medium Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin post-and-page-builder Cross-Site Scripting ≤ 1.26.2 Fixed in 1.26.3 CVE-2024-2888 Patchstack
5.3 Medium Backup and Restore Plugin Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 1.45 CVE-2023-7232 WPScan
4.3 Medium Google Maps CP Plugin codepeople-post-map Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.43 Fixed in 1.0.44 CVE-2023-25039 Patchstack
6.5 Medium Advance WordPress Search Plugin th-advance-product-search Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 1.2.1 CVE-2022-38057 Patchstack
5.4 Medium MainWP Wordfence Extension Plugin Broken Access Control Subscriber+ Arbitrary Plugin Activation ≤ 4.0.7 Fixed in 4.0.8 CVE-2023-22699 Patchstack
5.4 Medium ShareThis Dashboard for Google Analytics Plugin googleanalytics Broken Access Control ≤ 3.1.4 Fixed in 3.1.5 CVE-2022-45851 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45356 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45352 Patchstack
5.4 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45351 Patchstack
4.3 Medium Betheme Theme Broken Access Control ≤ 26.6.1 Fixed in 26.6.3 CVE-2022-45349 Patchstack
6.3 Medium SEO Plugin by Squirrly SEO Plugin squirrly-seo Broken Access Control ≤ 12.1.20 Fixed in 12.1.21 CVE-2022-44626 Patchstack
6.5 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control No login needed ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27608 Patchstack
7.3 High Youzify - Buddypress Moderation Plugin youzify-moderation Cross-Site Scripting Buddypress Moderation plugin <= 1.2.5 - Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2024-2864 Patchstack
4.3 Medium Educenter Theme educenter Broken Access Control ≤ 1.5.5 CVE-2023-30480 Patchstack
4.3 Medium RealHomes Theme Broken Access Control ≤ 4.0.2 CVE-2023-37885 Patchstack
5.4 Medium RealHomes Theme Broken Access Control ≤ 4.0.2 CVE-2023-37886 Patchstack
8.2 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 3.3.9 Fixed in 3.4.0 CVE-2024-24832 Patchstack
4.3 Medium BEAR Plugin woo-bulk-editor Broken Access Control ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24835 Patchstack
4.3 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 5.4.11 Fixed in 5.4.12 CVE-2024-24840 Patchstack
4.3 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control Broken Access Control on Duplicate Post ≤ 3.11.10 Fixed in 3.11.11 CVE-2024-24883 Patchstack
5.4 Medium WP Media folder Plugin Broken Access Control Plugin Settings Change ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25907 Patchstack
5.3 Medium Quicksand Post Filter jQuery Plugin quicksand-jquery-post-filter Broken Access Control No login needed ≤ 3.1.1 CVE-2024-24850 Patchstack
6.5 Medium YITH WooCommerce Gift Cards Premium Plugin yith-woocommerce-gift-cards-premium Cross-Site Scripting Unauth. Gift Card Creation Leading to Stored XSS No login needed ≤ 3.23.1 Fixed in 3.24.0 CVE-2022-44633 Patchstack
4.3 Medium AJAX Thumbnail Rebuild Plugin ajax-thumbnail-rebuild Broken Access Control ≤ 1.13 Fixed in 1.14 CVE-2022-47604 Patchstack
4.3 Medium WP Media folder Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Modification ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25908 Patchstack
9.8 Critical MoveTo Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 6.2 CVE-2024-25912 Patchstack
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-25935 Patchstack
7.5 High FunnelKit Checkout Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 3.10.3 Fixed in 3.11.0 CVE-2023-51672 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Settings Change ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27607 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Authentication Bypass Broken Authentication No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2022-44595 Patchstack
6.5 Medium Code Embed Plugin simple-embed-code Denial of Service Denial of Service Attack ≤ 2.3.6 Fixed in 2.3.7 CVE-2023-49837 Patchstack
4.3 Medium Download Media Plugin download-media Broken Access Control ≤ 1.4.2 CVE-2024-27190 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only