WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,701–16,750 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 335 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Traffic Manager Plugin traffic-manager Broken Access Control WordPress Traffic Manager Plugin <= 1.4.5 is vulnerable to Broken Access Control ≤ 1.4.5 CVE-2022-41695 Patchstack
5.4 Medium Image Zoom Plugin image-zoom Broken Access Control WordPress Image Zoom Plugin <= 1.8.8 is vulnerable to Broken Access Control ≤ 1.8.8 CVE-2022-41619 Patchstack
5.4 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2022-40702 Patchstack
4.3 Medium Ultimate Addons for Beaver Builder – Lite Plugin ultimate-addons-for-beaver-builder-lite Broken Access Control Lite Plugin <= 1.5.5 is vulnerable to Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2023-23882 Patchstack
5.4 Medium URL Shortener by MyThemeShop Plugin mts-url-shortener Broken Access Control WordPress URL Shortener by MyThemeShop Plugin <= 1.0.17 is vulnerable to Broken Access Control ≤ 1.0.17 CVE-2023-23896 Patchstack
7.1 High 3D Tag Cloud Plugin cardoza-3d-tag-cloud Cross-Site Request Forgery WordPress 3D Tag Cloud Plugin <= 3.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.8 CVE-2022-41990 Patchstack
5.4 Medium Cart2Cart: Magento to WooCommerce Migration Plugin cart2cart-magento-to-woocommerce-migration Broken Access Control WordPress Cart2Cart: Magento to WooCommerce Migration Plugin <= 2.0.0 is vulnerable to Broken Access Control ≤ 2.0.0 CVE-2023-34379 Patchstack
6.3 Medium Advanced Dynamic Pricing for WooCommerce Plugin advanced-dynamic-pricing-for-woocommerce Broken Access Control WordPress Advanced Dynamic Pricing for WooCommerce Plugin <= 4.1.5 is vulnerable to Broken Access Control ≤ 4.1.5 Fixed in 4.1.6 CVE-2022-40203 Patchstack
4.3 Medium Sales Report Email for WooCommerce Plugin woo-advanced-sales-report-email Broken Access Control WordPress Sales Report Email for WooCommerce Plugin <= 2.8 is vulnerable to Broken Access Control ≤ 2.8 Fixed in 2.9 CVE-2022-38141 Patchstack
6.5 Medium HREFLANG Tags Lite Plugin hreflang-tags-by-dcgws Authentication Bypass WordPress HREFLANG Tags Lite Plugin <= 2.0.0 is vulnerable to Broken Authentication No login needed ≤ 2.0.0 CVE-2022-36418 Patchstack
5.3 Medium FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Privilege Escalation Fastest WordPress Migration & Duplicator < 2.2 - Directory Listing to Account Takeover and Sensitive Data Exposure No login needed < 2.2 Fixed in 2.2 CVE-2023-6592 WPScan
9.8 Critical WordPress Database Administrator Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.3 CVE-2023-3211 WPScan
8.1 High DeMomentSomTres WordPress Export Posts With Images Plugin Broken Access Control Subscriber+ unauthorized data export ≤ 20220825 CVE-2023-5905 WPScan
6.5 Medium Constant Contact Forms by MailMunch Plugin constant-contact-forms-by-mailmunch Cross-Site Scripting WordPress Constant Contact Forms by MailMunch Plugin <= 2.0.11 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.11 CVE-2024-22137 Patchstack
7.1 High Profile Builder Pro Plugin Cross-Site Scripting WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22142 Patchstack
6.5 Medium Quiz Maker Plugin quiz-maker Denial of Service Improper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a Denial of Service (DoS) attack against… prior to 6.5.0.6 CVE-2024-22027 jpcert
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Cross-Site Request Forgery via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6242 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings No login needed ≤ 2.2.8, ≤ 4.5.4 CVE-2023-6244 Wordfence
9.8 Critical POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp Broken Access Control Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API No login needed ≤ 2.8.7 CVE-2023-6875 Wordfence
4.4 Medium Collect.chat Chatbot ⚡️ Plugin Cross-Site Scripting The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output e… 2.3.9 CVE-2023-5691 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.2 CVE-2023-6684 Wordfence
4.3 Medium WP 2FA – Two-factor authentication Plugin wp-2fa Cross-Site Request Forgery Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2023-6520 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Broken Access Control WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6158 Wordfence
4.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 9.7.4 CVE-2023-6594 Wordfence
3.7 Low Advanced Custom Fields (ACF) Plugin advanced-custom-fields Information Disclosure WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure No login needed 3.1.1 – 6.0.2 Fixed in 6.0.3 CVE-2022-40696 Patchstack
6.3 Medium ProfileGrid – User Profiles, Memberships, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control ≤ 5.0.3 Fixed in 5.0.4 CVE-2022-36352 Patchstack
5.4 Medium Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More Plugin woocommerce-wholesale-prices Broken Access Control WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control ≤ 2.1.5 Fixed in 2.1.5.1 CVE-2022-34344 Patchstack
7.6 High Events Shortcodes For The Events Calendar Plugin template-events-calendar SQL Injection WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-52142 Patchstack
9.1 Critical HTML5 MP3 Player with Folder Feedburner Playlist Free Plugin html5-mp3-player-with-mp3-folder-feedburner-playlist PHP Object Injection WordPress HTML5 MP3 Player with Folder Feedburner Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52202 Patchstack
5.3 Medium Download Monitor Plugin download-monitor Information Disclosure WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.7.60 Fixed in 4.7.70 CVE-2022-45354 Patchstack
5.3 Medium FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Information Disclosure WordPress FastDup Plugin <= 2.1.7 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2023-51406 Patchstack
5.3 Medium WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Plugin wp-optin-wheel Information Disclosure WordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-51408 Patchstack
7.1 High CPT Bootstrap Carousel Plugin cpt-bootstrap-carousel Cross-Site Scripting WordPress CPT Bootstrap Carousel Plugin <= 1.12 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2023-52196 Patchstack
5.9 Medium Ads Invalid Click Protection Plugin ads-invalid-click-protection Cross-Site Scripting WordPress Ads Invalid Click Protection Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 CVE-2023-52197 Patchstack
6.5 Medium Private Google Calendars Plugin private-google-calendars Cross-Site Scripting WordPress Private Google Calendars Plugin <= 20231125 is vulnerable to Cross Site Scripting (XSS) ≤ 20231125 CVE-2023-52198 Patchstack
5.3 Medium Defender Security – Malware Scanner, Login Security & Firewall Plugin defender-security Information Disclosure WordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.1.0 Fixed in 4.2.0 CVE-2023-51490 Patchstack
5.3 Medium Database Cleaner: Clean, Optimize & Repair Plugin database-cleaner Information Disclosure WordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data Exposure No login needed ≤ 0.9.8 Fixed in 0.9.9 CVE-2023-51508 Patchstack
7.6 High pTypeConverter Plugin ptypeconverter SQL Injection WordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL Injection ≤ 0.2.8.1 CVE-2023-52201 Patchstack
5.9 Medium cformsII Plugin cforms2 Cross-Site Scripting WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS) ≤ 15.0.5 CVE-2023-52203 Patchstack
8.5 High Randomize Plugin randomize SQL Injection WordPress Randomize Plugin <= 1.4.3 is vulnerable to SQL Injection ≤ 1.4.3 CVE-2023-52204 Patchstack
7.7 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection WordPress Page Builder: Live Composer Plugin <= 1.5.25 is vulnerable to PHP Object Injection ≤ 1.5.25 CVE-2023-52206 Patchstack
7.1 High Rate Star Review – AJAX Reviews for Content, with Star Ratings Plugin rate-star-review Cross-Site Scripting WordPress Rate Star Review Plugin <= 1.5.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52213 Patchstack
4.3 Medium JS & CSS Script Optimizer Plugin js-css-script-optimizer Cross-Site Request Forgery WordPress JS & CSS Script Optimizer Plugin <= 0.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 0.3.3 CVE-2023-52216 Patchstack
9.6 Critical ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Request Forgery WordPress ARMember Plugin <= 4.0.22 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object Injection No login needed ≤ 4.0.22 Fixed in 4.0.23 CVE-2023-52200 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack
9.1 Critical HTML5 MP3 Player with Playlist Free Plugin html5-mp3-player-with-playlist PHP Object Injection WordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object Injection ≤ 3.0.0 CVE-2023-52207 Patchstack
7.5 High Coupon Referral Program Plugin Information Disclosure WordPress Coupon Referral Program Plugin <= 1.7.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2023-52190 Patchstack
5.3 Medium Constant Contact Forms Plugin constant-contact-forms Information Disclosure WordPress Constant Contact Forms Plugin <= 2.4.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.4.2 CVE-2023-52208 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.2.2 Fixed in 8.3.0 CVE-2023-52222 Patchstack
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only