WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,751–16,800 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 336 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium WP Media folder Plugin Broken Access Control Plugin Settings Change ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25907 Patchstack
5.3 Medium Quicksand Post Filter jQuery Plugin quicksand-jquery-post-filter Broken Access Control No login needed ≤ 3.1.1 CVE-2024-24850 Patchstack
6.5 Medium YITH WooCommerce Gift Cards Premium Plugin yith-woocommerce-gift-cards-premium Cross-Site Scripting Unauth. Gift Card Creation Leading to Stored XSS No login needed ≤ 3.23.1 Fixed in 3.24.0 CVE-2022-44633 Patchstack
4.3 Medium AJAX Thumbnail Rebuild Plugin ajax-thumbnail-rebuild Broken Access Control ≤ 1.13 Fixed in 1.14 CVE-2022-47604 Patchstack
4.3 Medium WP Media folder Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Modification ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25908 Patchstack
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-25935 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Settings Change ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27607 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Authentication Bypass Broken Authentication No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2022-44595 Patchstack
6.5 Medium Code Embed Plugin simple-embed-code Denial of Service Denial of Service Attack ≤ 2.3.6 Fixed in 2.3.7 CVE-2023-49837 Patchstack
4.3 Medium Download Media Plugin download-media Broken Access Control ≤ 1.4.2 CVE-2024-27190 Patchstack
5.9 Medium WP Coder Plugin wp-coder Cross-Site Scripting ≤ 3.5 Fixed in 3.5.1 CVE-2024-2578 Patchstack
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting ≤ 2.0.16 Fixed in 2.1.0 CVE-2024-2579 Patchstack
6.5 Medium Automation By Autonami Plugin wp-marketing-automations Cross-Site Scripting ≤ 2.8.2 Fixed in 2.8.3 CVE-2024-2580 Patchstack
6.5 Medium Crisp Plugin crisp Cross-Site Scripting Live Chat and Chatbot plugin <= 0.44 - Cross Site Scripting (XSS) ≤ 0.44 Fixed in 0.45 CVE-2024-27963 Patchstack
5.9 Medium WPFunnels Plugin wpfunnels Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-27965 Patchstack
5.9 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting ≤ 8.2.2 Fixed in 8.2.3 CVE-2024-27966 Patchstack
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
6.5 Medium Free Downloads WooCommerce Plugin download-now-for-woocommerce Cross-Site Scripting ≤ 3.5.8.2 Fixed in 3.5.8.3 CVE-2024-27969 Patchstack
5.4 Medium WP SendFox Plugin wp-sendfox Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-27970 Patchstack
5.4 Medium PropertyHive Plugin propertyhive PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-27985 Patchstack
6.5 Medium WEN Responsive Columns Plugin wen-responsive-columns Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-27988 Patchstack
6.5 Medium WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs Cross-Site Scripting ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-27989 Patchstack
6.5 Medium The Moneytizer Plugin the-moneytizer Cross-Site Scripting ≤ 9.5.20 Fixed in 9.6.1 CVE-2024-27990 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.2.3 Fixed in 3.2.4 CVE-2024-27991 Patchstack
5.9 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting ≤ 4.0.23 Fixed in 4.0.24 CVE-2024-27995 Patchstack
6.5 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control No login needed ≤ 1.0 CVE-2023-52229 Patchstack
4.3 Medium Live Sales Notification for Woocommerce – Woomotiv Plugin Cross-Site Request Forgery Woomotiv <= 3.4.3 - Cross-Site Request Forgery via ajax_cancel_review No login needed ≤ 3.4.3 CVE-2024-1325 Wordfence
6.1 Medium Website Article Monetization By MageNet Plugin website-article-monetization-by-magenet Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.11 CVE-2024-1379 Wordfence
6.4 Medium Animated Headline Plugin animated-headline Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.0 CVE-2024-2304 Wordfence
5.3 Medium Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 1.3.1 CVE-2024-1119 Wordfence
4.3 Medium RevivePress – Keep your Old Content Evergreen Plugin wp-auto-republish Broken Access Control Keep your Old Content Evergreen <= 1.5.6 - Missing Authorization ≤ 1.5.6 CVE-2024-1844 Wordfence
5.3 Medium Coming Soon, Under Construction & Maintenance Mode By Dazzler Plugin Broken Access Control Maintenance Mode Bypass No login needed ≤ 2.1.2 CVE-2024-1181 Wordfence
5.3 Medium Coming Soon & Maintenance Mode by Colorlib Plugin colorlib-coming-soon-maintenance Information Disclosure Information Exposure No login needed ≤ 1.0.99 CVE-2024-1473 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4 CVE-2024-2129 Wordfence
5.3 Medium Easy Maintenance Mode Plugin easy-maintenance-mode-coming-soon Information Disclosure Information Exposure No login needed ≤ 1.4.2 CVE-2024-1477 Wordfence
5.4 Medium Permalink Manager Plugin permalink-manager-for-woocommerce Broken Access Control Missing Authorization to Authenticated(Author+) Arbitrary Post Slug Modification ≤ 2.4.3.1 CVE-2024-2538 Wordfence
6.1 Medium Travelpayouts Plugin travelpayouts Open Redirect No login needed ≤ 1.1.15 CVE-2024-0337 WPScan
5.4 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting XSS via Header Injection No login needed < 2.8.10 Fixed in 2.8.10 CVE-2023-7246 WPScan
6.4 Medium Standout Color Boxes and Buttons Plugin standout-color-boxes-and-buttons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.7.0 CVE-2024-2474 Wordfence
6.4 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Cross-Site Scripting Weglot <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 4.2.5 CVE-2024-2124 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.3 CVE-2024-2255 Wordfence
6.4 Medium GamiPress – Button Plugin gamipress-button Cross-Site Scripting Button <= 1.0.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.7 CVE-2024-2460 Wordfence
4.3 Medium WooCommerce POS Plugin Information Disclosure Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure ≤ 1.4.11 CVE-2024-2384 Wordfence
4.3 Medium Smart Custom Fields Plugin smart-custom-fields Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure ≤ 4.2.2 CVE-2024-1995 Wordfence
6.4 Medium Contests by Rewards Fuel Plugin contests-from-rewards-fuel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via update_rewards_fuel_api_key ≤ 2.0.64 CVE-2024-1787 Wordfence
5.4 Medium Contests by Rewards Fuel Plugin contests-from-rewards-fuel Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0.62 CVE-2024-1785 Wordfence
6.1 Medium Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms Plugin advanced-form-integration SQL Injection Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id No login needed ≤ 1.82.0 CVE-2024-2387 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-27996 Patchstack
5.9 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.6.0 Fixed in 45.7.0 CVE-2024-27997 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only