WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,751–1,800 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 36 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Woocommerce Custom Profile Picture Plugin woo-custom-profile-picture Arbitrary File Upload ≤ 1.0 CVE-2024-49658 Patchstack
10.0 Critical Verbalize WP Plugin verbalize-wp Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49668 Patchstack
9.9 Critical INK Official Plugin ink-official Arbitrary File Upload ≤ 4.1.2 CVE-2024-49669 Patchstack
9.9 Critical AI Image Generator for Your Content & Featured Images – AI Postpix Plugin ai-postpix Arbitrary File Upload ≤ 1.1.8 Fixed in 1.1.8.1 CVE-2024-49671 Patchstack
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Account Takeover via Cookie Leak No login needed ≤ 6.5.0.1 Fixed in 6.5.0.1 CVE-2024-44000 Patchstack
10.0 Critical Sovratec Case Management Plugin sovratec-case-management Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49324 Patchstack
10.0 Critical Affiliator Plugin affiliator-lite Arbitrary File Upload No login needed ≤ 2.1.3 CVE-2024-49326 Patchstack
10.0 Critical Woostagram Connect Plugin woostagram-connect Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-49327 Patchstack
10.0 Critical WP REST API FNS Plugin rest-api-fns Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49329 Patchstack
10.0 Critical Nice Backgrounds Plugin nicebackgrounds Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49330 Patchstack
9.9 Critical Property Lot Management System Plugin plms Arbitrary File Upload ≤ 4.2.38 CVE-2024-49331 Patchstack
10.0 Critical WP Dropbox Dropins Plugin wp-dropbox-dropins Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49607 Patchstack
10.0 Critical photokit Plugin photokit Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49610 Patchstack
9.8 Critical Giveaway Boost Plugin giveaway-boost PHP Object Injection No login needed ≤ 2.1.4 CVE-2024-49332 Patchstack
9.8 Critical Advanced Advertising System Plugin advanced-advertising-system PHP Object Injection No login needed ≤ 1.3.1 CVE-2024-49624 Patchstack
9.8 Critical SiteBuilder Dynamic Components Plugin sitebuilder-dynamic-components PHP Object Injection No login needed ≤ 1.0 CVE-2024-49625 Patchstack
9.8 Critical Shipyaari Shipping Management Plugin shipyaari-shipping-managment PHP Object Injection No login needed ≤ 1.2 CVE-2024-49626 Patchstack
9.6 Critical SSV Events Plugin ssv-events Local File Inclusion Local File Inclusion to RCE No login needed ≤ 3.2.7 CVE-2024-49286 Patchstack
10.0 Critical Product Website Showcase Plugin product-websites-showcase Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49611 Patchstack
9.8 Critical WP REST API FNS Plugin rest-api-fns Privilege Escalation Account Takeover No login needed ≤ 1.0.0 CVE-2024-49328 Patchstack
9.8 Critical Simple User Registration Plugin wp-registration Authentication Bypass Broken Authentication No login needed ≤ 6.7 Fixed in 6.8 CVE-2024-49604 Patchstack
9.8 Critical Adding drop down roles in registration Plugin user-drop-down-roles-in-registration Privilege Escalation No login needed ≤ 1.1 CVE-2024-49217 Patchstack
9.8 Critical Job Board Manager Plugin jemployee Privilege Escalation No login needed ≤ 1.0 CVE-2024-49322 Patchstack
9.3 Critical Ajax Rating with Custom Login Plugin ajax-rating-with-custom-login SQL Injection No login needed ≤ 1.1 CVE-2024-49246 Patchstack
9.3 Critical Email Verification for WooCommerce Plugin emails-verification-for-woocommerce SQL Injection No login needed ≤ 2.8.10 Fixed in 2.9.0 CVE-2024-49305 Patchstack
10.0 Critical Cooked Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49291 Patchstack
10.0 Critical JiangQie Free Mini Program Plugin jiangqie-free-mini-program Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2024-49314 Patchstack
9.8 Critical My Reading Library Plugin my-reading-library PHP Object Injection No login needed ≤ 1.0 CVE-2024-49318 Patchstack
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
9.8 Critical Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Privilege Escalation Privilege Escalation via Registration due to Administrator Default User Role Value No login needed ≤ 3.6.0 CVE-2024-9863 Wordfence
9.8 Critical Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 3.6.0 CVE-2024-9862 Wordfence
9.8 Critical Nextend Social Login Pro Plugin nextend-facebook-connect Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 3.1.14 CVE-2024-9893 Wordfence
9.9 Critical Creates 3D Flipbook, PDF Flipbook Plugin create-flipbook-from-pdf Arbitrary File Upload ≤ 1.2 CVE-2024-48034 Patchstack
10.0 Critical Feed Comments Number Plugin feed-comments-number Arbitrary File Upload No login needed ≤ 0.2.1 CVE-2024-49216 Patchstack
10.0 Critical Digital Lottery Plugin digital-lottery Arbitrary File Upload No login needed ≤ 3.0.5 CVE-2024-49242 Patchstack
9.9 Critical WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Arbitrary File Upload ≤ 1.5.7 CVE-2024-49260 Patchstack
9.8 Critical Disc Golf Manager Plugin disc-golf-manager PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-48026 Patchstack
9.8 Critical IP Loc8 Plugin ip-loc8 PHP Object Injection No login needed ≤ 1.1 CVE-2024-48028 Patchstack
9.8 Critical Telecash Ricaricaweb Plugin telecash-ricaricaweb PHP Object Injection No login needed ≤ 2.2 CVE-2024-48030 Patchstack
9.8 Critical Recently Plugin recently-viewed-most-viewed-and-sold-products-for-woocommerce PHP Object Injection No login needed ≤ 1.1 CVE-2024-49218 Patchstack
10.0 Critical ajax-extend Plugin ajax-extend Remote Code Execution No login needed ≤ 1.0 CVE-2024-49254 Patchstack
9.1 Critical Iconize Plugin iconize Remote Code Execution ≤ 1.2.4 CVE-2024-47649 Patchstack
9.9 Critical External featured image from bing Plugin external-featured-image-from-bing Remote Code Execution ≤ 1.0.2 CVE-2024-48027 Patchstack
9.9 Critical ACF Images Search And Insert Plugin acf-images-search-and-insert Arbitrary File Upload ≤ 1.1.4 CVE-2024-48035 Patchstack
9.1 Critical Contact Form by Supsystic Plugin contact-form-by-supsystic Remote Code Execution ≤ 1.7.28 Fixed in 1.7.29 CVE-2024-48042 Patchstack
10.0 Critical Azz Anonim Posting Plugin azz-anonim-posting Arbitrary File Upload No login needed ≤ 0.9 CVE-2024-49257 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-49271 Patchstack
9.8 Critical BuddyPress Better Registration Plugin better-bp-registration Authentication Bypass Broken Authentication No login needed ≤ 1.6 CVE-2024-49247 Patchstack
9.8 Critical Frontend File Manager Plugin nmedia-user-file-uploader Arbitrary File Upload No login needed ≤ 1.0, < 4.0 Fixed in 4.0 CVE-2016-15042 Wordfence
9.8 Critical Indeed Membership Pro Plugin Authentication Bypass No login needed 7.3 – < 8.6.1 Fixed in 8.6.1 CVE-2020-36832 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only