WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,601–1,650 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 33 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.1.1 CVE-2024-10124 Wordfence
9.8 Critical Sign In With Google Plugin sign-in-with-google Authentication Bypass Authentication Bypass in authenticate_user No login needed ≤ 1.8.0 CVE-2024-11015 Wordfence
9.3 Critical Revy Plugin revy SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.18 CVE-2024-54215 Patchstack
10.0 Critical Pie Register Premium Plugin pie-register-premium Arbitrary File Upload No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-53822 Patchstack
9.8 Critical Sweet Date Theme sweetdate Privilege Escalation No login needed ≤ 3.7.3 Fixed in 3.8.0 CVE-2024-43222 Patchstack
9.8 Critical Integrate Google Drive Plugin integrate-google-drive Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.1.99 Fixed in 1.2.0 CVE-2023-32117 Patchstack
9.8 Critical WP Umbrella: Update Backup Restore & Monitoring Plugin wp-health Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.17.0 CVE-2024-12209 Wordfence
9.1 Critical Simple User Registration Plugin wp-registration Broken Access Control Broken Access Control on User Deletion No login needed ≤ 5.5 Fixed in 6.0 CVE-2024-53810 Patchstack
9.3 Critical Auction Plugin wp-auctions SQL Injection No login needed ≤ 3.7 CVE-2024-51615 Patchstack
10.0 Critical Revy Plugin revy Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.18 CVE-2024-54214 Patchstack
9.0 Critical s2Member Plugin s2member Remote Code Execution No login needed ≤ 241114 Fixed in 241216 CVE-2024-51815 Patchstack
9.8 Critical SV100 Companion Plugin sv100-companion Broken Access Control Missing Authorization to Unuathenticated Arbitrary Options Update No login needed ≤ 2.0.02 CVE-2024-12155 Wordfence
9.3 Critical FAT Services Booking Plugin fat-services-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.6 CVE-2024-54221 Patchstack
10.0 Critical Fediverse Embeds Plugin fediverse-embeds Arbitrary File Upload No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-52476 Patchstack
9.3 Critical Express Payments Module Plugin express-pay SQL Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-52474 Patchstack
10.0 Critical Pathomation Plugin pathomation Arbitrary File Upload No login needed ≤ 2.5.1 CVE-2024-52490 Patchstack
9.8 Critical Wawp Plugin automation-web-platform Privilege Escalation Account Takeover No login needed ≤ 3.0.18 Fixed in 3.0.18 CVE-2024-52475 Patchstack
9.9 Critical Tumult Hype Animations Plugin tumult-hype-animations Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function ≤ 1.9.15 CVE-2024-11082 Wordfence
9.9 Critical Widget Options – The #1 WordPress Widget & Block Control Plugin widget-options Remote Code Execution The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution ≤ 4.0.7 CVE-2024-8672 Wordfence
9.8 Critical Contest Gallery Plugin contest-gallery Privilege Escalation Unauthenticated Arbitrary Password Reset to Privilege Escalation/Account Takeover No login needed ≤ 24.0.7 CVE-2024-11103 Wordfence
9.8 Critical WP JobSearch Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 2.6.7 CVE-2024-11925 Wordfence
9.8 Critical AppPresser – Mobile App Framework Plugin apppresser Privilege Escalation Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset No login needed ≤ 4.4.6 CVE-2024-11024 Wordfence
9.8 Critical Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Broken Access Control Authorization Bypass via Reverse DNS Spoofing to Unauthenticated Arbitrary Plugin Installation No login needed ≤ 6.43.2 CVE-2024-10542 Wordfence
9.8 Critical School Management Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 91.5.0 CVE-2024-9659 Wordfence
9.8 Critical WPGYM Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 67.1.0 CVE-2024-9942 Wordfence
9.8 Critical FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider Plugin fluent-smtp PHP Object Injection WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider <= 2.2.82 - Unauthenticated PHP Object Injection No login needed ≤ 2.2.82 CVE-2024-9511 Wordfence
9.8 Critical Social Login Plugin oa-social-login Authentication Bypass Authentication Bypass via Disqus OAuth provider No login needed ≤ 5.9.0 CVE-2024-10961 Wordfence
9.8 Critical UserPlus Plugin userplus Privilege Escalation No login needed ≤ 2.0 CVE-2024-52442 Patchstack
9.8 Critical Team Rosters Plugin team-rosters PHP Object Injection No login needed ≤ 4.8.2 CVE-2024-52439 Patchstack
9.8 Critical Xpresslane Fast Checkout Plugin xpresslane-integration-for-woocommerce PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-52440 Patchstack
9.8 Critical Quick Learn Plugin quick-learn PHP Object Injection No login needed ≤ 1.0.1 CVE-2024-52441 Patchstack
9.8 Critical Geolocator Plugin geolocator PHP Object Injection No login needed ≤ 1.1 CVE-2024-52443 Patchstack
9.6 Critical Exclusive Content Password Protect Plugin exclusive-content-password-protect Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.1.0 CVE-2024-52402 Patchstack
9.6 Critical Hacklog DownloadManager Plugin hacklog-downloadmanager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.1.4 CVE-2024-52401 Patchstack
9.3 Critical WordPress Video Robot - The Ultimate Video Importer Plugin SQL Injection No login needed ≤ 1.20.0 CVE-2024-52431 Patchstack
9.8 Critical Lis Video Gallery Plugin lis-video-gallery PHP Object Injection No login needed ≤ 0.2.1 CVE-2024-52430 Patchstack
9.8 Critical NIX Anti-Spam Light Plugin nix-anti-spam-light PHP Object Injection No login needed ≤ 0.0.4 CVE-2024-52432 Patchstack
9.8 Critical My Geo Posts Free Plugin my-geo-posts-free PHP Object Injection No login needed ≤ 1.2 CVE-2024-52433 Patchstack
9.9 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution ≤ 2.3.11 Fixed in 2.3.12 CVE-2024-52427 Patchstack
9.9 Critical WP Quick Setup Plugin wp-quick-setup Remote Code Execution Arbitrary Plugin and Theme Installation to Remote Code Execution ≤ 2.0 CVE-2024-52429 Patchstack
9.1 Critical Popup by Supsystic Plugin popup-by-supsystic Remote Code Execution ≤ 1.10.29 Fixed in 1.10.30 CVE-2024-52434 Patchstack
9.1 Critical Convert Docx2post Plugin convert-docx2post Arbitrary File Upload ≤ 1.4 CVE-2024-52397 Patchstack
9.1 Critical CDI Plugin collect-and-deliver-interface-for-woocommerce Arbitrary File Upload ≤ 5.5.3 Fixed in 5.5.6 CVE-2024-52398 Patchstack
9.9 Critical Writer Helper Plugin writer-helper Arbitrary File Upload ≤ 3.1.6 CVE-2024-52399 Patchstack
9.9 Critical Gallerio Plugin gallerio Arbitrary File Upload ≤ 1.01 CVE-2024-52400 Patchstack
9.9 Critical User Management Plugin user-management Arbitrary File Upload ≤ 1.1 Fixed in 1.2 CVE-2024-52403 Patchstack
9.9 Critical CF7 Reply Manager Plugin cf7-reply-manager Arbitrary File Upload ≤ 1.2.3 CVE-2024-52404 Patchstack
9.9 Critical B-Banner Slider Plugin b-banner-slider Arbitrary File Upload ≤ 1.1 CVE-2024-52405 Patchstack
9.9 Critical CSV to html Plugin csv-to-html Arbitrary File Upload ≤ 3.26 Fixed in 3.27 CVE-2024-52406 Patchstack
9.9 Critical BasePress Migration Tools Plugin basepress-migration-tools Arbitrary File Upload ≤ 1.0.0 CVE-2024-52407 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only