WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,701–1,750 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 35 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical All Post Contact Form Plugin allpost-contactform Arbitrary File Upload No login needed ≤ 1.8.2 CVE-2024-50523 Patchstack
10.0 Critical Helloprint Plugin helloprint Arbitrary File Upload No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-50525 Patchstack
10.0 Critical Multi Purpose Mail Form Plugin multi-purpose-mail-form Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-50526 Patchstack
10.0 Critical Stacks Mobile App Builder Plugin stacks-mobile-app-builder Arbitrary File Upload No login needed ≤ 5.2.3 CVE-2024-50527 Patchstack
9.9 Critical Training – Courses Plugin training Arbitrary File Upload Courses plugin <= 2.0.1 - Arbitrary File Upload ≤ 2.0.1 CVE-2024-50529 Patchstack
9.9 Critical Stars SMTP Mailer Plugin stars-smtp-mailer Arbitrary File Upload ≤ 2.2.1 CVE-2024-50530 Patchstack
10.0 Critical RSVPMaker for Toastmasters Plugin rsvpmaker-for-toastmasters Arbitrary File Upload No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2024-50531 Patchstack
9.1 Critical Media LIbrary Assistant Plugin media-library-assistant Remote Code Execution ≤ 3.19 Fixed in 3.20 CVE-2024-51661 Patchstack
9.6 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43984 Patchstack
9.6 Critical EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-49674 Patchstack
9.8 Critical AI Power: Complete AI Pack Plugin gpt3-ai-content-generator Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.8.89 CVE-2024-10392 Wordfence
9.1 Critical W3SPEEDSTER Plugin w3speedster-wp Remote Code Execution Authenticated (Administrator+) Remote Code Execution ≤ 7.26 CVE-2024-8512 Wordfence
10.0 Critical AR For Woocommerce Plugin ar-for-woocommerce Arbitrary File Upload No login needed ≤ 6.3 Fixed in 7.0 CVE-2024-50510 Patchstack
9.9 Critical WP donimedia carousel Plugin wp-donimedia-carousel Arbitrary File Upload ≤ 1.0.1 CVE-2024-50511 Patchstack
9.8 Critical DS.DownloadList Plugin dsdownloadlist PHP Object Injection No login needed ≤ 1.3 CVE-2024-50507 Patchstack
9.8 Critical User Toolkit Plugin user-toolkit Privilege Escalation Account Takeover No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-50503 Patchstack
9.8 Critical Crypto Plugin crypto Authentication Bypass Authentication Bypass via log_in No login needed ≤ 2.18 CVE-2024-9989 Wordfence
9.8 Critical Crypto Plugin crypto Authentication Bypass Authentication Bypass via register No login needed ≤ 2.19 CVE-2024-9988 Wordfence
9.8 Critical Signup Page Plugin signup-page Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0 CVE-2024-50475 Patchstack
9.8 Critical GRÜN spendino Spendenformular Plugin spendino Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0.1 CVE-2024-50476 Patchstack
9.8 Critical Exam Matrix Plugin exam-matrix Privilege Escalation No login needed ≤ 1.5 CVE-2024-50485 Patchstack
9.8 Critical PegaPoll Plugin pegapoll Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0.2 CVE-2024-50490 Patchstack
10.0 Critical aDirectory Plugin adirectory Arbitrary File Upload No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2024-50420 Patchstack
9.9 Critical SurveyJS Plugin surveyjs Arbitrary File Upload ≤ 1.9.136 Fixed in 1.12.4 CVE-2024-50427 Patchstack
10.0 Critical Ajar in5 Embed Plugin ajar-productions-in5-embed Arbitrary File Upload No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-50473 Patchstack
9.9 Critical Marketing Automation by AZEXO Plugin marketing-automation-by-azexo Arbitrary File Upload ≤ 1.27.80 CVE-2024-50480 Patchstack
10.0 Critical Woocommerce Product Design Plugin woo-product-design Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-50482 Patchstack
10.0 Critical Multi Purpose Mail Form Plugin multi-purpose-mail-form Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-50484 Patchstack
10.0 Critical Automatic Translation Plugin automatic-translation Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2024-50493 Patchstack
10.0 Critical Sudan Payment Gateway for WooCommerce Plugin wc-sudan-payment-gateway Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-50494 Patchstack
10.0 Critical Plugin Propagator Plugin wp-propagator Arbitrary File Upload No login needed ≤ 0.1 CVE-2024-50495 Patchstack
10.0 Critical AR Plugin ar-for-wordpress Arbitrary File Upload No login needed ≤ 6.6 Fixed in 7.0 CVE-2024-50496 Patchstack
9.3 Critical Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection No login needed ≤ 1.1 CVE-2024-50479 Patchstack
9.3 Critical RSVP ME Plugin rsvp-me SQL Injection No login needed ≤ 1.9.9 CVE-2024-50491 Patchstack
9.8 Critical 1-Click Login: Passwordless Authentication Plugin swoop-password-free-authentication Authentication Bypass Broken Authentication No login needed 1.4.5 CVE-2024-50478 Patchstack
9.8 Critical Meetup Plugin meetup Authentication Bypass Broken Authentication No login needed ≤ 0.1 CVE-2024-50483 Patchstack
10.0 Critical WP Query Console Plugin wp-query-console Remote Code Execution No login needed ≤ 1.0 CVE-2024-50498 Patchstack
9.8 Critical Stacks Mobile App Builder Plugin stacks-mobile-app-builder Privilege Escalation Account Takeover No login needed ≤ 5.2.3 CVE-2024-50477 Patchstack
9.8 Critical Acnoo Flutter API Plugin acnoo-flutter-api Privilege Escalation Account Takeover No login needed ≤ 1.0.5 CVE-2024-50486 Patchstack
9.8 Critical MaanStore API Plugin maanstore-api Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2024-50487 Patchstack
9.8 Critical Realty Workstation Plugin realty-workstation Privilege Escalation Account Takeover No login needed ≤ 1.0.45 CVE-2024-50489 Patchstack
9.8 Critical Wp Social Login and Register Social Counter Plugin wp-social Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 3.0.7 CVE-2024-9501 Wordfence
9.8 Critical Extensions by HocWP Team Plugin sb-core Authentication Bypass No login needed ≤ 0.2.3.2 CVE-2024-9930 Wordfence
9.8 Critical Wux Blog Editor Plugin wux-blog-editor Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.0.0 CVE-2024-9932 Wordfence
9.8 Critical WatchTowerHQ Plugin watchtowerhq Authentication Bypass Authentication Bypass to Administrator due to Missing Empty Value Check No login needed ≤ 3.10.1 CVE-2024-9933 Wordfence
9.8 Critical Wux Blog Editor Plugin wux-blog-editor Authentication Bypass Authentication Bypass to Administrator No login needed ≤ 3.0.0 CVE-2024-9931 Wordfence
9.8 Critical Comments – wpDiscuz Plugin wpdiscuz Authentication Bypass wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 7.6.24 CVE-2024-9488 Wordfence
9.3 Critical WP Sessions Time Monitoring Full Automatic Plugin activitytime SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-49681 Patchstack
9.9 Critical 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Upload ≤ 1.0.3 CVE-2024-49652 Patchstack
9.9 Critical Portfolleo Plugin portfolleo Arbitrary File Upload ≤ 1.2 CVE-2024-49653 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only