WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 16,851–16,900 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 338 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.5.4 (Pro) & <= 2.2.8 (Free) - Cross-Site Request Forgery via save_virtual_event_settings No login needed ≤ 2.2.8, ≤ 4.5.4 CVE-2023-6244 Wordfence
9.8 Critical POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp Broken Access Control Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API No login needed ≤ 2.8.7 CVE-2023-6875 Wordfence
4.4 Medium Collect.chat Chatbot ⚡️ Plugin Cross-Site Scripting The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output e… 2.3.9 CVE-2023-5691 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.2 CVE-2023-6684 Wordfence
4.3 Medium WP 2FA – Two-factor authentication Plugin wp-2fa Cross-Site Request Forgery Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2023-6520 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Broken Access Control WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6158 Wordfence
4.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 9.7.4 CVE-2023-6594 Wordfence
3.7 Low Advanced Custom Fields (ACF) Plugin advanced-custom-fields Information Disclosure WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure No login needed 3.1.1 – 6.0.2 Fixed in 6.0.3 CVE-2022-40696 Patchstack
6.3 Medium ProfileGrid – User Profiles, Memberships, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control ≤ 5.0.3 Fixed in 5.0.4 CVE-2022-36352 Patchstack
5.4 Medium Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More Plugin woocommerce-wholesale-prices Broken Access Control WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control ≤ 2.1.5 Fixed in 2.1.5.1 CVE-2022-34344 Patchstack
7.6 High Events Shortcodes For The Events Calendar Plugin template-events-calendar SQL Injection WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-52142 Patchstack
9.1 Critical HTML5 MP3 Player with Folder Feedburner Playlist Free Plugin html5-mp3-player-with-mp3-folder-feedburner-playlist PHP Object Injection WordPress HTML5 MP3 Player with Folder Feedburner Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52202 Patchstack
5.3 Medium Download Monitor Plugin download-monitor Information Disclosure WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.7.60 Fixed in 4.7.70 CVE-2022-45354 Patchstack
5.3 Medium FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Information Disclosure WordPress FastDup Plugin <= 2.1.7 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2023-51406 Patchstack
5.3 Medium WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Plugin wp-optin-wheel Information Disclosure WordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-51408 Patchstack
7.1 High CPT Bootstrap Carousel Plugin cpt-bootstrap-carousel Cross-Site Scripting WordPress CPT Bootstrap Carousel Plugin <= 1.12 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2023-52196 Patchstack
5.9 Medium Ads Invalid Click Protection Plugin ads-invalid-click-protection Cross-Site Scripting WordPress Ads Invalid Click Protection Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 CVE-2023-52197 Patchstack
6.5 Medium Private Google Calendars Plugin private-google-calendars Cross-Site Scripting WordPress Private Google Calendars Plugin <= 20231125 is vulnerable to Cross Site Scripting (XSS) ≤ 20231125 CVE-2023-52198 Patchstack
5.3 Medium Defender Security – Malware Scanner, Login Security & Firewall Plugin defender-security Information Disclosure WordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.1.0 Fixed in 4.2.0 CVE-2023-51490 Patchstack
5.3 Medium Database Cleaner: Clean, Optimize & Repair Plugin database-cleaner Information Disclosure WordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data Exposure No login needed ≤ 0.9.8 Fixed in 0.9.9 CVE-2023-51508 Patchstack
7.6 High pTypeConverter Plugin ptypeconverter SQL Injection WordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL Injection ≤ 0.2.8.1 CVE-2023-52201 Patchstack
5.9 Medium cformsII Plugin cforms2 Cross-Site Scripting WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS) ≤ 15.0.5 CVE-2023-52203 Patchstack
8.5 High Randomize Plugin randomize SQL Injection WordPress Randomize Plugin <= 1.4.3 is vulnerable to SQL Injection ≤ 1.4.3 CVE-2023-52204 Patchstack
7.7 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection WordPress Page Builder: Live Composer Plugin <= 1.5.25 is vulnerable to PHP Object Injection ≤ 1.5.25 CVE-2023-52206 Patchstack
7.1 High Rate Star Review – AJAX Reviews for Content, with Star Ratings Plugin rate-star-review Cross-Site Scripting WordPress Rate Star Review Plugin <= 1.5.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52213 Patchstack
4.3 Medium JS & CSS Script Optimizer Plugin js-css-script-optimizer Cross-Site Request Forgery WordPress JS & CSS Script Optimizer Plugin <= 0.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 0.3.3 CVE-2023-52216 Patchstack
9.6 Critical ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Request Forgery WordPress ARMember Plugin <= 4.0.22 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object Injection No login needed ≤ 4.0.22 Fixed in 4.0.23 CVE-2023-52200 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack
9.1 Critical HTML5 MP3 Player with Playlist Free Plugin html5-mp3-player-with-playlist PHP Object Injection WordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object Injection ≤ 3.0.0 CVE-2023-52207 Patchstack
7.5 High Coupon Referral Program Plugin Information Disclosure WordPress Coupon Referral Program Plugin <= 1.7.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2023-52190 Patchstack
5.3 Medium Constant Contact Forms Plugin constant-contact-forms Information Disclosure WordPress Constant Contact Forms Plugin <= 2.4.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.4.2 CVE-2023-52208 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.2.2 Fixed in 8.3.0 CVE-2023-52222 Patchstack
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack
9.9 Critical Gecka Terms Thumbnails Plugin gecka-terms-thumbnails PHP Object Injection WordPress Gecka Terms Thumbnails Plugin <= 1.1 is vulnerable to PHP Object Injection ≤ 1.1 CVE-2023-52219 Patchstack
10.0 Critical Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics Plugin taggbox-widget PHP Object Injection WordPress Taggbox Plugin <= 3.1 is vulnerable to PHP Object Injection No login needed ≤ 3.1 CVE-2023-52225 Patchstack
6.5 Medium Mapster WP Maps Plugin mapster-wp-maps Cross-Site Scripting WordPress Mapster WP Maps Plugin <= 1.2.38 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.38 CVE-2024-21744 Patchstack
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack
7.6 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp SQL Injection WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection ≤ 1.12.8 Fixed in 1.12.9 CVE-2024-21747 Patchstack
6.5 Medium WP Tabs – Responsive Tabs Plugin wp-expand-tabs-free Cross-Site Scripting WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-52124 Patchstack
6.5 Medium iframe Plugin iframe Cross-Site Scripting WordPress iFrame Plugin <= 4.8 is vulnerable to Cross Site Scripting (XSS) ≤ 4.8 Fixed in 4.9 CVE-2023-52125 Patchstack
5.3 Medium Send Users Email Plugin send-users-email Information Disclosure WordPress Send Users Email Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-52126 Patchstack
7.5 High WP Stripe Checkout Plugin wp-stripe-checkout Information Disclosure WordPress WP Stripe Checkout Plugin <= 1.2.2.37 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.2.2.37 Fixed in 1.2.2.38 CVE-2023-52143 Patchstack
5.3 Medium 404 Solution Plugin 404-solution Information Disclosure WordPress 404 Solution Plugin <= 2.33.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.33.0 Fixed in 2.33.1 CVE-2023-52146 Patchstack
5.3 Medium Affiliates Manager Plugin affiliates-manager Information Disclosure WordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.9.30 Fixed in 2.9.31 CVE-2023-52148 Patchstack
5.3 Medium Uncanny Automator – Automate everything with the #1 no-code automation and integration Plugin uncanny-automator Information Disclosure WordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 5.1.0.2 Fixed in 5.1.0.3 CVE-2023-52151 Patchstack
10.0 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Arbitrary File Upload Best Help Desk & Support Plugin Plugin <= 2.7.1 is vulnerable to Arbitrary File Upload No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46839 Patchstack
4.3 Medium Doofinder WP & WooCommerce Search Plugin doofinder-for-woocommerce Broken Access Control WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Control ≤ 2.0.33 Fixed in 2.1.1 CVE-2023-51678 Patchstack
4.3 Medium Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.20 Fixed in 6.21 CVE-2023-51535 Patchstack
5.4 Medium Stylish Price List – Price Table Builder & QR Code Restaurant Menu Plugin stylish-price-list Broken Access Control WordPress Stylish Price List Plugin <= 7.0.17 is vulnerable to Broken Access Control ≤ 7.0.17 Fixed in 7.0.18 CVE-2023-51673 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only