WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 17,151–17,200 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Admin side data storage for Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated Bookmark Status Alteration No login needed |
≤ 1.1.1 |
CVE-2024-1778 |
Wordfence | |
| 4.3 Medium | Admin side data storage for Contact Form 7 | Cross-Site Request Forgery No login needed |
≤ 1.1.1 |
CVE-2024-1777 |
Wordfence | |
| 5.3 Medium | Admin side data storage for Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated Read Status Update No login needed |
≤ 1.1.1 |
CVE-2024-1779 |
Wordfence | |
| 4.3 Medium | Event Tickets and Registration | Broken Access Control Missing Authorization |
≤ 5.8.1 |
CVE-2024-1053 |
Wordfence | |
| 5.4 Medium | User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | Cross-Site Scripting Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.0.13 |
CVE-2024-0903 |
Wordfence | |
| 4.3 Medium | Debug | Cross-Site Request Forgery WordPress Debug Plugin <= 1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.10 |
CVE-2024-24798 |
Patchstack | |
| 4.3 Medium | JTRT Responsive Tables | Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 4.1.9 |
CVE-2024-24802 |
Patchstack | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 4.3 Medium | Quicksand Post Filter jQuery | Cross-Site Request Forgery WordPress Quicksand Post Filter jQuery Plugin Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.1 |
CVE-2024-24849 |
Patchstack | |
| 4.3 Medium | Themify Builder | Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.0.5 Fixed in 7.0.6 |
CVE-2024-24872 |
Patchstack | |
| 4.3 Medium | Admin Menu Editor | Cross-Site Request Forgery WordPress Admin Menu Editor Plugin <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.12 Fixed in 1.12.1 |
CVE-2024-24876 |
Patchstack | |
| 4.3 Medium | TinyMCE and TinyMCE Advanced Professsional Formats and Styles | Cross-Site Request Forgery WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.1.2 |
CVE-2024-25904 |
Patchstack | |
| 6.4 Medium | 3D FlipBook – PDF Flipbook | Cross-Site Scripting PDF Flipbook WordPress <= 1.15.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks |
≤ 1.15.3 |
CVE-2024-1081 |
Wordfence | |
| 5.3 Medium | Simple Job Board | Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed |
≤ 2.10.8 |
CVE-2024-0593 |
Wordfence | |
| 5.4 Medium | Multi Step Form | Cross-Site Request Forgery WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.18 |
CVE-2024-25905 |
Patchstack | |
| 5.3 Medium | WooCommerce Google Sheet Connector | Broken Access Control Missing Authorization No login needed |
≤ 1.3.11 |
CVE-2024-1562 |
Wordfence | |
| 4.7 Medium | Database Reset | Cross-Site Request Forgery Cross-Site Request Forgery to WP Reset Plugin Installation No login needed |
≤ 3.22 |
CVE-2024-1501 |
Wordfence | |
| 6.5 Medium | Plugin Groups | Broken Access Control Missing Authorization to Unauthenticated Denial of Service No login needed |
≤ 2.0.6 |
CVE-2024-1108 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.58.3 |
CVE-2024-1058 |
Wordfence | |
| 5.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery |
≤ 5.9.8 |
CVE-2024-1171 |
Wordfence | |
| 6.5 Medium | AMP for WP | Broken Access Control Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data |
≤ 1.0.93.1 |
CVE-2024-1043 |
Wordfence | |
| 5.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion |
≤ 5.9.8 |
CVE-2024-1172 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Broken Access Control Missing Authorization to Settings Update in stopOptimizeAll |
≤ 3.1.13 |
CVE-2024-1090 |
Wordfence | |
| 4.3 Medium | Contact Form builder with drag & drop for WordPress – Kali Forms | Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization |
≤ 2.3.41 |
CVE-2024-1218 |
Wordfence | |
| 4.3 Medium | Tutor LMS | Broken Access Control Missing Authorization |
≤ 2.6.0 |
CVE-2024-1133 |
Wordfence | |
| 5.3 Medium | Sunshine Photo Cart: Free Client Galleries for Photographers | Information Disclosure Unauthenticated Sensitive Information Exposure via Invoice No login needed |
≤ 3.0.24 |
CVE-2024-1294 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.10.1 |
CVE-2024-0838 |
Wordfence | |
| 4.4 Medium | Best WordPress Gallery Plugin – FooGallery | Cross-Site Scripting FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings |
≤ 2.4.7 |
CVE-2024-0604 |
Wordfence | |
| 5.3 Medium | Royal Elementor Addons and Templates | Broken Access Control Missing Authorization via wpr_update_form_action_meta No login needed |
≤ 1.3.87 |
CVE-2024-0516 |
Wordfence | |
| 5.3 Medium | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | Broken Access Control Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via pms_stripe_connect_handle_authorization_return No login needed |
≤ 2.11.1 |
CVE-2024-1389 |
Wordfence | |
| 6.1 Medium | Cost of Goods Sold (COGS): Cost & Profit Calculator for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2.8 |
CVE-2024-0821 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in optimizeAllOn No login needed |
≤ 3.1.13 |
CVE-2024-1336 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Broken Access Control Missing Authorization to Settings Update in disableOptimization |
≤ 3.1.13 |
CVE-2024-0984 |
Wordfence | |
| 4.4 Medium | Insert PHP Code Snippet | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.3.4 |
CVE-2024-0658 |
Wordfence | |
| 6.1 Medium | Microsoft Clarity | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.9.3 |
CVE-2024-0590 |
Wordfence | |
| 6.4 Medium | Page scroll to id | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.7.8 |
CVE-2024-1445 |
Wordfence | |
| 6.4 Medium | Booster for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 7.1.6 |
CVE-2024-1054 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in disableOptimization No login needed |
≤ 3.1.13 |
CVE-2024-1335 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via add_to_wishlist No login needed |
≤ 1.3.87 |
CVE-2024-0512 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.9.8 |
CVE-2024-1276 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via add_to_compare No login needed |
≤ 1.3.87 |
CVE-2024-0514 |
Wordfence | |
| 5.3 Medium | Directorist | Broken Access Control Missing Authorization to Unauthenticated Settings Change No login needed |
≤ 7.8.4 |
CVE-2024-1322 |
Wordfence | |
| 4.3 Medium | Schema & Structured Data for WP & AMP | Broken Access Control Missing Authorization to reCaptcha Key Modification |
≤ 1.26 |
CVE-2024-1288 |
Wordfence | |
| 4.4 Medium | Password Protected | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.6.6 |
CVE-2024-0656 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.58.2 |
CVE-2024-1070 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via remove_from_compare No login needed |
≤ 1.3.87 |
CVE-2024-0515 |
Wordfence | |
| 5.3 Medium | My Private Site | Broken Access Control Improper Access Control to Sensitive Information Exposure via REST API No login needed |
≤ 3.0.14 |
CVE-2024-0978 |
Wordfence | |
| 4.4 Medium | Simple Share Buttons Adder | Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via CSS Settings |
≤ 8.4.11 |
CVE-2024-0621 |
Wordfence | |
| 6.4 Medium | Schema & Structured Data for WP & AMP | Cross-Site Scripting Authenticated (Custom) Stored Cross-Site Scripting |
≤ 1.26 |
CVE-2024-1586 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Broken Access Control Missing Authorization to Settings Update in optimizeAllOn |
≤ 3.1.13 |
CVE-2024-1089 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.