WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 1,701–1,750 of 2,548 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Request Forgery Dynamic Text Extension plugin <= 5.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.0.1 Fixed in 5.0.2 CVE-2024-56218 Patchstack
5.4 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56222 Patchstack
4.3 Medium SearchIQ Plugin searchiq Cross-Site Request Forgery No login needed ≤ 4.6 Fixed in 4.7 CVE-2024-56229 Patchstack
7.1 High WP Nice Loader Plugin wp-nice-loader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0.4 CVE-2024-56232 Patchstack
4.3 Medium DN Shipping by Weight for WooCommerce Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.2 Fixed in 1.2 CVE-2024-11842 WPScan
4.7 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery Admin+ SSRF < 2.4.2 Fixed in 2.4.2 CVE-2024-10903 WPScan
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
6.1 Medium GTPayment Donations Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-11607 WPScan
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack
5.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Request Forgery Settings update via CSRF No login needed < 3.2.43 Fixed in 3.2.43 CVE-2024-10892 WPScan
5.3 Medium Memberful Plugin memberful-wp Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.73.9 CVE-2024-11294 Wordfence
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.23 Fixed in 1.24 CVE-2024-56017 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed ≤ 7.11.10 Fixed in 7.11.11 CVE-2024-54357 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Cross-Site Request Forgery No login needed < 6.3.2 Fixed in 6.3.2 CVE-2024-37251 Patchstack
7.1 High Tidy Up Plugin tidy-up Cross-Site Request Forgery CSRF to Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2024-56015 Patchstack
9.6 Critical GitSync Plugin git-sync Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 1.1.0 CVE-2024-54368 Patchstack
7.2 High Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.83 Fixed in 2.0.85 CVE-2024-54385 Patchstack
7.1 High Increase Sociability Plugin increase-sociability Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.0 CVE-2024-54395 Patchstack
7.1 High Visual Recent Posts Plugin visual-recent-posts Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.3 CVE-2024-54403 Patchstack
7.1 High I Plant A Tree Plugin i-plant-a-tree Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-54331 Patchstack
4.3 Medium WP Mailster Plugin wp-mailster Cross-Site Request Forgery No login needed ≤ 1.8.17.0 Fixed in 1.8.18.0 CVE-2024-54355 Patchstack
8.8 High Sogrid Plugin sogrid Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5.2 Fixed in 1.5.5 CVE-2024-54352 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5 Fixed in 4.5.2 CVE-2024-54356 Patchstack
4.3 Medium Bet sport Free Plugin bet-sport-free Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2024-54396 Patchstack
9.6 Critical Insertify Plugin insertify Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 1.1.4 CVE-2024-54372 Patchstack
5.4 Medium Ui Slider Filter By Price Plugin ui-slider-filter-by-price Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-54419 Patchstack
5.4 Medium DTC Documents Plugin dtc-documents Cross-Site Request Forgery No login needed ≤ 1.1.05 CVE-2024-54418 Patchstack
6.5 Medium Posti Shipping Plugin posti-shipping Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 3.10.3 Fixed in 3.10.4 CVE-2024-56005 Patchstack
7.1 High Hack-Info Plugin hack-info Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.17 Fixed in 3.18 CVE-2024-54353 Patchstack
7.1 High WP Currency Exchange Rates Plugin wp-currency-exchange-rates Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-54332 Patchstack
7.1 High Multiple Admin Emails Plugin multiple-admin-emails Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54388 Patchstack
7.1 High Push Monkey Pro – Web Push Notifications and WooCommerce Abandoned Cart Plugin push-monkey-desktop-push-notifications Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.9 CVE-2024-54386 Patchstack
7.1 High addWeather Plugin myweather Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2024-54389 Patchstack
7.1 High WP微信机器人 Plugin wp-weixin-robot Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.3.5 CVE-2024-54392 Patchstack
7.1 High WordPress Filter Plugin wordpress-filter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2024-54391 Patchstack
7.1 High Mandrill WP Plugin email-form-under-post Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2024-54394 Patchstack
7.1 High WP Fiddle Plugin wp-fiddle Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54393 Patchstack
7.1 High Go Animate Plugin goanimate Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54397 Patchstack
7.1 High CRUDLab Google Plus Button Plugin crudlab-google-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2024-54399 Patchstack
7.1 High Flaming Forms Plugin flaming-forms Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2024-54398 Patchstack
7.1 High AppMaps Plugin appmaps Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54400 Patchstack
7.1 High Advanced Fancybox Plugin advanced-fancybox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2024-54401 Patchstack
7.1 High MDC Comment Toolbar Plugin mdc-comment-toolbar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54404 Patchstack
7.1 High CK and SyntaxHighlighter Plugin ck-and-syntaxhighlighter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.4.2 CVE-2024-54407 Patchstack
7.1 High ECT Social Share Plugin ect-social-share Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2024-54405 Patchstack
6.5 Medium Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.9 CVE-2024-54408 Patchstack
7.1 High SOPA Blackout Plugin sopa-blackout Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2024-54410 Patchstack
7.1 High XPD Reduce Image Filesize Plugin xpd-reduce-image-filesize Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54409 Patchstack
7.1 High WP Controller Plugin wp-management-controller Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 3.2.0 CVE-2024-54411 Patchstack
7.1 High Display Future Posts Plugin display-future-posts Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.2.3 CVE-2024-54413 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only