WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,651–1,700 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.9 Critical | Push Notifications for WordPress by PushAssist | Arbitrary File Upload |
≤ 3.0.8 |
CVE-2024-52408 |
Patchstack | |
| 9.8 Critical | AJAX Random Posts | PHP Object Injection No login needed |
≤ 0.3.3 |
CVE-2024-52409 |
Patchstack | |
| 9.8 Critical | Referrer Detector | PHP Object Injection No login needed |
≤ 4.2.1.0 |
CVE-2024-52410 |
Patchstack | |
| 9.8 Critical | Advanced Personalization | PHP Object Injection No login needed |
≤ 1.1.2 |
CVE-2024-52411 |
Patchstack | |
| 9.8 Critical | Xin | PHP Object Injection No login needed |
≤ 1.0.8.1 |
CVE-2024-52412 |
Patchstack | |
| 9.8 Critical | Airin Blog | PHP Object Injection No login needed |
≤ 1.6.1 Fixed in 1.6.3 |
CVE-2024-52413 |
Patchstack | |
| 9.8 Critical | WDES Responsive Mobile Menu | PHP Object Injection No login needed |
≤ 5.3.18 |
CVE-2024-52414 |
Patchstack | |
| 10.0 Critical | Debug Tool | Remote Code Execution No login needed |
≤ 2.2 |
CVE-2024-52416 |
Patchstack | |
| 9.8 Critical | Backup and Staging by WP Time Capsule | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.22.21 |
CVE-2024-8856 |
Wordfence | |
| 9.8 Critical | Really Simple Security (Free, Pro, and Pro Multisite) | Authentication Bypass No login needed |
9.0.0 – 9.1.1.1 |
CVE-2024-10924 |
Wordfence | |
| 9.9 Critical | KBucket | Arbitrary File Upload |
≤ 4.2.2 Fixed in 4.2.3 |
CVE-2024-52369 |
Patchstack | |
| 9.9 Critical | Hive Support | Arbitrary File Upload WordPress Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin <= 1.1.1 - Arbitrary File Upload |
≤ 1.1.1 Fixed in 1.1.2 |
CVE-2024-52370 |
Patchstack | |
| 10.0 Critical | Easy CSV Importer BETA | Arbitrary File Upload No login needed |
≤ 7.0.0 |
CVE-2024-52372 |
Patchstack | |
| 10.0 Critical | Devexhub Gallery | Arbitrary File Upload No login needed |
≤ 2.0.1 |
CVE-2024-52373 |
Patchstack | |
| 10.0 Critical | Do That Task | Arbitrary File Upload No login needed |
≤ 1.5.5 |
CVE-2024-52374 |
Patchstack | |
| 10.0 Critical | Datasets Manager by Arttia Creative | Arbitrary File Upload No login needed |
≤ 1.5 |
CVE-2024-52375 |
Patchstack | |
| 10.0 Critical | Boat Rental | Arbitrary File Upload No login needed |
≤ 1.0.1 |
CVE-2024-52376 |
Patchstack | |
| 10.0 Critical | Instant Image Generator | Arbitrary File Upload No login needed |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2024-52377 |
Patchstack | |
| 10.0 Critical | kineticPay for WooCommerce | Arbitrary File Upload No login needed |
≤ 2.0.8 Fixed in 3.0 |
CVE-2024-52379 |
Patchstack | |
| 10.0 Critical | Picsmize | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-52380 |
Patchstack | |
| 9.8 Critical | Matix Popup Builder | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0.0 |
CVE-2024-52382 |
Patchstack | |
| 9.9 Critical | Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation | Arbitrary File Upload |
≤ 2.4.9 |
CVE-2024-52384 |
Patchstack | |
| 9.1 Critical | Podlove Podcast Publisher | Remote Code Execution Admin+ Remote Code Execution (RCE) |
≤ 4.1.15 Fixed in 4.1.17 |
CVE-2024-52393 |
Patchstack | |
| 9.8 Critical | Chartify – WordPress Chart | Local File Inclusion WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source No login needed |
≤ 2.9.5 |
CVE-2024-10571 |
Wordfence | |
| 9.8 Critical | MultiManager WP – Manage All Your WordPress Sites Easily | Authentication Bypass Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User Impersonation No login needed |
≤ 1.0.5 |
CVE-2024-11028 |
Wordfence | |
| 9.8 Critical | WordPress User Extra Fields | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 16.6 |
CVE-2024-11150 |
Wordfence | |
| 9.8 Critical | WooCommerce Upload Files | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 84.3 |
CVE-2024-10820 |
Wordfence | |
| 9.8 Critical | Relais 2FA | Authentication Bypass No login needed |
≤ 1.0 |
CVE-2024-10245 |
Wordfence | |
| 10.0 Critical | The Novel Design Store Directory | Arbitrary File Upload No login needed |
≤ 4.3.0 |
CVE-2024-51788 |
Patchstack | |
| 10.0 Critical | Image Classify | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-51789 |
Patchstack | |
| 10.0 Critical | HB AUDIO GALLERY | Arbitrary File Upload No login needed |
≤ 3.0 |
CVE-2024-51790 |
Patchstack | |
| 10.0 Critical | Forms | Arbitrary File Upload No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2024-51791 |
Patchstack | |
| 10.0 Critical | Audio Record | Arbitrary File Upload No login needed |
≤ 1.0 |
CVE-2024-51792 |
Patchstack | |
| 10.0 Critical | RepairBuddy | Arbitrary File Upload No login needed |
≤ 3.8115 Fixed in 3.8116 |
CVE-2024-51793 |
Patchstack | |
| 9.8 Critical | RegistrationMagic – User Registration Plugin with Custom Registration Forms | Privilege Escalation User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery No login needed |
≤ 6.0.2.6 |
CVE-2024-10508 |
Wordfence | |
| 9.8 Critical | Leopard | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update No login needed |
≤ 3.1.1 |
CVE-2024-10589 |
Wordfence | |
| 9.8 Critical | WordPress User Extra Fields | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 16.5 |
CVE-2024-10801 |
Wordfence | |
| 9.8 Critical | WP Membership | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.6.2 |
CVE-2024-10547 |
Wordfence | |
| 9.8 Critical | Category Ajax Filter | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 2.8.2 |
CVE-2024-10871 |
Wordfence | |
| 9.8 Critical | WPLMS Learning Management System | Path Traversal Unauthenticated Arbitrary File Read and Deletion No login needed |
≤ 4.962 |
CVE-2024-10470 |
Wordfence | |
| 9.8 Critical | WooCommerce Support Ticket System | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 17.7 |
CVE-2024-10627 |
Wordfence | |
| 9.8 Critical | WooCommerce Support Ticket System | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 17.6 |
CVE-2024-10625 |
Wordfence | |
| 9.8 Critical | Debug Tool | Broken Access Control Unauthenticated Arbitrary File Creation No login needed |
≤ 2.2 |
CVE-2024-10586 |
Wordfence | |
| 9.8 Critical | CE21 Suite | Information Disclosure JWT Token Disclosure No login needed |
≤ 2.2.0 |
CVE-2024-10285 |
Wordfence | |
| 9.8 Critical | CE21 Suite | Authentication Bypass No login needed |
≤ 2.2.0 |
CVE-2024-10284 |
Wordfence | |
| 9.6 Critical | Registrations for The Events Calendar | Cross-Site Scripting Unauthenticated Stored XSS No login needed |
< 2.12.4 Fixed in 2.12.4 |
CVE-2024-7982 |
WPScan | |
| 10.0 Critical | WP JobSearch | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.6.7 |
CVE-2024-8615 |
Wordfence | |
| 9.9 Critical | WP JobSearch | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 2.6.7 |
CVE-2024-8614 |
Wordfence | |
| 9.9 Critical | mFolio Lite | Broken Access Control Missing Authorization to Authenticated (Author+) File Upload via EXE and SVG Files |
≤ 1.2.1 |
CVE-2024-9307 |
Wordfence | |
| 9.8 Critical | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | SQL Injection Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection No login needed |
≤ 24.0.3 |
CVE-2024-10687 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.