WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 17,551–17,600 of 17,624 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 352 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin Broken Access Control Dynamic Text Extension <= 4.1.0 - Insecure Direct Object Reference ≤ 4.1.0 CVE-2023-6630 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Broken Access Control WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6158 Wordfence
4.4 Medium Formidable Forms Plugin formidable Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 6.7 CVE-2023-6842 Wordfence
6.5 Medium Formidable Forms Plugin formidable Content Injection HTML Injection No login needed ≤ 6.7 CVE-2023-6830 Wordfence
5.4 Medium Metform Elementor Contact Form Builder Plugin metform Cross-Site Request Forgery No login needed ≤ 3.8.1 CVE-2023-6788 Wordfence
4.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 9.7.4 CVE-2023-6594 Wordfence
6.3 Medium ProfileGrid – User Profiles, Memberships, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control ≤ 5.0.3 Fixed in 5.0.4 CVE-2022-36352 Patchstack
5.4 Medium Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More Plugin woocommerce-wholesale-prices Broken Access Control WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control ≤ 2.1.5 Fixed in 2.1.5.1 CVE-2022-34344 Patchstack
5.3 Medium Download Monitor Plugin download-monitor Information Disclosure WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.7.60 Fixed in 4.7.70 CVE-2022-45354 Patchstack
5.3 Medium FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Information Disclosure WordPress FastDup Plugin <= 2.1.7 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2023-51406 Patchstack
5.3 Medium WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Plugin wp-optin-wheel Information Disclosure WordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-51408 Patchstack
5.9 Medium Ads Invalid Click Protection Plugin ads-invalid-click-protection Cross-Site Scripting WordPress Ads Invalid Click Protection Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 CVE-2023-52197 Patchstack
6.5 Medium Private Google Calendars Plugin private-google-calendars Cross-Site Scripting WordPress Private Google Calendars Plugin <= 20231125 is vulnerable to Cross Site Scripting (XSS) ≤ 20231125 CVE-2023-52198 Patchstack
5.3 Medium Defender Security – Malware Scanner, Login Security & Firewall Plugin defender-security Information Disclosure WordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.1.0 Fixed in 4.2.0 CVE-2023-51490 Patchstack
5.3 Medium Database Cleaner: Clean, Optimize & Repair Plugin database-cleaner Information Disclosure WordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data Exposure No login needed ≤ 0.9.8 Fixed in 0.9.9 CVE-2023-51508 Patchstack
5.9 Medium cformsII Plugin cforms2 Cross-Site Scripting WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS) ≤ 15.0.5 CVE-2023-52203 Patchstack
4.3 Medium JS & CSS Script Optimizer Plugin js-css-script-optimizer Cross-Site Request Forgery WordPress JS & CSS Script Optimizer Plugin <= 0.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 0.3.3 CVE-2023-52216 Patchstack
4.8 Medium WP Custom Cursors Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 3.2 CVE-2023-5911 WPScan
5.4 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Scripting Subscriber+ Stored XSS < 4.4.0 Fixed in 4.4.0 CVE-2023-6141 WPScan
6.5 Medium Essential Real Estate Plugin essential-real-estate Denial of Service Subscriber+ Denial of Service via Arbitrary Option Update < 4.4.0 Fixed in 4.4.0 CVE-2023-6139 WPScan
6.1 Medium WP Go Maps Plugin wp-google-maps Cross-Site Scripting Unauthenticated Stored XSS No login needed < 9.0.28 Fixed in 9.0.28 CVE-2023-6627 WPScan
6.1 Medium Email Subscription Popup Plugin Cross-Site Scripting Reflected XSS No login needed < 1.2.20 Fixed in 1.2.20 CVE-2023-6555 WPScan
6.1 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Reflected XSS No login needed < 2.1.9 Fixed in 2.1.9 CVE-2023-6161 WPScan
6.1 Medium WP VR Plugin Cross-Site Scripting Unauthenticated Plugin Downgrade leading to XSS No login needed < 8.3.15 Fixed in 8.3.15 CVE-2023-6529 WPScan
5.3 Medium Constant Contact Forms Plugin constant-contact-forms Information Disclosure WordPress Constant Contact Forms Plugin <= 2.4.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.4.2 CVE-2023-52208 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.2.2 Fixed in 8.3.0 CVE-2023-52222 Patchstack
6.5 Medium Mapster WP Maps Plugin mapster-wp-maps Cross-Site Scripting WordPress Mapster WP Maps Plugin <= 1.2.38 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.38 CVE-2024-21744 Patchstack
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack
5.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization ≤ 4.3.2 CVE-2023-6798 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 4.3.2 CVE-2023-6801 Wordfence
6.5 Medium WP Tabs – Responsive Tabs Plugin wp-expand-tabs-free Cross-Site Scripting WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-52124 Patchstack
6.5 Medium iframe Plugin iframe Cross-Site Scripting WordPress iFrame Plugin <= 4.8 is vulnerable to Cross Site Scripting (XSS) ≤ 4.8 Fixed in 4.9 CVE-2023-52125 Patchstack
5.3 Medium Send Users Email Plugin send-users-email Information Disclosure WordPress Send Users Email Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-52126 Patchstack
5.3 Medium 404 Solution Plugin 404-solution Information Disclosure WordPress 404 Solution Plugin <= 2.33.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.33.0 Fixed in 2.33.1 CVE-2023-52146 Patchstack
5.3 Medium Affiliates Manager Plugin affiliates-manager Information Disclosure WordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.9.30 Fixed in 2.9.31 CVE-2023-52148 Patchstack
5.3 Medium Uncanny Automator – Automate everything with the #1 no-code automation and integration Plugin uncanny-automator Information Disclosure WordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 5.1.0.2 Fixed in 5.1.0.3 CVE-2023-52151 Patchstack
4.3 Medium Doofinder WP & WooCommerce Search Plugin doofinder-for-woocommerce Broken Access Control WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Control ≤ 2.0.33 Fixed in 2.1.1 CVE-2023-51678 Patchstack
4.3 Medium Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.20 Fixed in 6.21 CVE-2023-51535 Patchstack
5.4 Medium Stylish Price List – Price Table Builder & QR Code Restaurant Menu Plugin stylish-price-list Broken Access Control WordPress Stylish Price List Plugin <= 7.0.17 is vulnerable to Broken Access Control ≤ 7.0.17 Fixed in 7.0.18 CVE-2023-51673 Patchstack
4.3 Medium Inline Image Upload for BBPress Plugin image-upload-for-bbpress Cross-Site Request Forgery WordPress Inline Image Upload for BBPress Plugin <= 1.1.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.18 Fixed in 1.1.19 CVE-2023-51668 Patchstack
4.3 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Cross-Site Request Forgery WordPress Awesome Support Plugin <= 6.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.1.5 Fixed in 6.1.6 CVE-2023-51538 Patchstack
5.4 Medium Apollo13 Framework Extensions Plugin apollo13-framework-extensions Cross-Site Request Forgery WordPress Apollo13 Framework Extensions Plugin <= 1.9.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2023-51539 Patchstack
4.3 Medium Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building Plugin icegram Cross-Site Request Forgery WordPress Icegram Plugin <= 3.1.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.18 Fixed in 3.1.19 CVE-2023-52119 Patchstack
5.4 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Cross-Site Request Forgery Ultimate Form Builder Plugin <= 8.5.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.5.2 Fixed in 8.5.5 CVE-2023-52120 Patchstack
5.4 Medium NitroPack – Cache & Speed Optimization for Core Web Vitals, Defer CSS & JavaScript, Lazy load Images Plugin nitropack Cross-Site Request Forgery WordPress NitroPack Plugin <= 1.10.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.10.2 Fixed in 1.10.3 CVE-2023-52121 Patchstack
4.3 Medium Simple Job Board Plugin simple-job-board Cross-Site Request Forgery WordPress Simple Job Board Plugin <= 2.10.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.10.6 Fixed in 2.10.7 CVE-2023-52122 Patchstack
4.3 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Request Forgery WordPress Strong Testimonials Plugin <= 3.1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.10 Fixed in 3.1.11 CVE-2023-52123 Patchstack
4.3 Medium WPC Product Bundles for WooCommerce Plugin woo-product-bundle Cross-Site Request Forgery WordPress WPC Product Bundles for WooCommerce Plugin <= 7.3.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 7.3.1 Fixed in 7.3.2 CVE-2023-52127 Patchstack
4.3 Medium White Label – WordPress Custom Admin, Custom Login Page, and Custom Dashboard Plugin white-label Cross-Site Request Forgery WordPress White Label Plugin <= 2.9.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-52128 Patchstack
6.3 Medium teachPress Plugin teachpress Cross-Site Request Forgery WordPress teachPress Plugin <= 9.0.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 9.0.4 Fixed in 9.0.5 CVE-2023-52129 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only