WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 18,151–18,200 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | VK Blocks | Broken Access Control Missing Authorization to Sensitive Information Exposure |
≤ 1.94.2.2 |
CVE-2024-13635 |
Wordfence | |
| 4.3 Medium | SupportCandy – Helpdesk & Customer Support Ticket System | Broken Access Control Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference |
≤ 3.3.0 |
CVE-2024-13552 |
Wordfence | |
| 6.4 Medium | Advanced File Manager | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload |
≤ 5.2.14 |
CVE-2024-13805 |
Wordfence | |
| 6.1 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.8.3 |
CVE-2024-13431 |
Wordfence | |
| 9.8 Critical | Golo - Directory & Listing, Travel | Broken Access Control Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change No login needed |
≤ 1.6.10 |
CVE-2024-12876 |
Wordfence | |
| 9.8 Critical | InWave Jobs | Privilege Escalation Unauthenticated Privilege Escalation via Password Reset No login needed |
≤ 3.5.1 |
CVE-2025-1315 |
Wordfence | |
| 8.8 High | Eventer - WordPress Event & Booking Manager | SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id |
≤ 3.9.9.2 |
CVE-2025-0959 |
Wordfence | |
| 8.8 High | School Management System | Privilege Escalation Authenticated (Student+) Account Takeover and Privilege Escalation |
≤ 93.0.0 |
CVE-2024-9658 |
Wordfence | |
| 5.3 Medium | School Management System | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 93.0.0 |
CVE-2024-12610 |
Wordfence | |
| 6.5 Medium | School Management System | SQL Injection Authenticated (Student+) SQL Injection via 'view-attendance' |
≤ 92.0.0 |
CVE-2024-12609 |
Wordfence | |
| 5.3 Medium | Platform.ly for WooCommerce | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 1.1.6 |
CVE-2024-13904 |
Wordfence | |
| 6.5 Medium | Hero Maps Premium - Customizable Google Maps | SQL Injection Customizable Google Maps Plugin <= 2.3.9 - Authenticated (Subscriber+) SQL Injection |
≤ 2.3.9 |
CVE-2024-13781 |
Wordfence | |
| 7.5 High | CS Framework | Path Traversal Authenticated (Subscriber+) Arbitrary File Read No login needed |
≤ 7.1 |
CVE-2024-12036 |
Wordfence | |
| 5.3 Medium | School Management System | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 93.0.0 |
CVE-2024-12611 |
Wordfence | |
| 7.5 High | Ultimate Video Player | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 10.0 |
CVE-2024-10804 |
Wordfence | |
| 8.8 High | CS Framework | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 7.0 |
CVE-2024-12035 |
Wordfence | |
| 6.5 Medium | School Management System | SQL Injection Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' |
≤ 92.0.0 |
CVE-2024-12607 |
Wordfence | |
| 7.2 High | Gallery by BestWebSoft – Customizable Image and Photo Galleries | PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection |
≤ 4.7.3 |
CVE-2024-13906 |
Wordfence | |
| 8.8 High | UiPress lite | Effortless custom dashboards, admin themes and pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update |
≤ 3.5.04 |
CVE-2025-1309 |
Wordfence | |
| 6.4 Medium | Flexmls® IDX | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.14.28 |
CVE-2025-0863 |
Wordfence | |
| 7.5 High | CURCY - WooCommerce Multi Currency - Currency Switcher | SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed |
≤ 2.3.6 |
CVE-2024-13320 |
Wordfence | |
| 8.1 High | Flex Mag - Responsive WordPress News | Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion |
≤ 3.5.2 |
CVE-2024-13655 |
Wordfence | |
| 6.4 Medium | Wishlist | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.43 |
CVE-2024-12809 |
Wordfence | |
| 9.8 Critical | WPCOM Member | Authentication Bypass Authentication Bypass via 'user_phone' No login needed |
≤ 1.7.5 |
CVE-2025-1475 |
Wordfence | |
| 4.3 Medium | Homey | Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed |
≤ 2.4.3 |
CVE-2025-0748 |
Wordfence | |
| 4.3 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export |
≤ 4.0.7.3 |
CVE-2024-13526 |
Wordfence | |
| 8.1 High | Homey | Authentication Bypass Limited Authentication Bypass due to Missing Empty Value Check No login needed |
≤ 2.4.3 |
CVE-2025-0749 |
Wordfence | |
| 4.3 Medium | Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics | Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission |
≤ 4.4.1 |
CVE-2025-1666 |
Wordfence | |
| 4.3 Medium | Podlove Podcast Publisher | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed |
≤ 4.2.2 |
CVE-2025-1383 |
Wordfence | |
| 5.5 Medium | Notibar | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 2.1.5 |
CVE-2025-1672 |
Wordfence | |
| 6.5 Medium | Moving Media Library | Path Traversal Authenticated (Administrator+) Directory Traversal to Arbitrary File Deletion |
≤ 1.22 |
CVE-2024-13897 |
Wordfence | |
| 6.1 Medium | Easy Broken Link Checker | Cross-Site Scripting Reflected XSS No login needed |
≤ 9.0.2 |
CVE-2024-13868 |
WPScan | |
| 5.1 Medium | Ad Inserter | Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed |
2.8.0 |
CVE-2025-22623 |
Fluid Attacks | |
| 9.8 Critical | Homey Login Register | Privilege Escalation Unauthenticated Privilege Escalation in homey_register No login needed |
≤ 2.4.0 |
CVE-2024-11951 |
Wordfence | |
| 5.3 Medium | Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More | Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.5.0 |
CVE-2024-11153 |
Wordfence | |
| 7.5 High | Ultimate Member | SQL Injection Unauthenticated SQL Injection via search Parameter No login needed |
≤ 2.10.0 |
CVE-2025-1702 |
Wordfence | |
| 5.3 Medium | Sparkling | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation No login needed |
≤ 2.4.9 |
CVE-2024-13423 |
Wordfence | |
| 9.8 Critical | Homey | Privilege Escalation Unauthenticated Privilege Escalation in homey_save_profile No login needed |
≤ 2.4.2 |
CVE-2024-12281 |
Wordfence | |
| 7.5 High | DesignThemes Core Features | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file No login needed |
≤ 4.7 |
CVE-2024-13471 |
Wordfence | |
| 4.3 Medium | Spreadsheet Integration | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed |
≤ 3.8.2 |
CVE-2025-1463 |
Wordfence | |
| 4.3 Medium | WooMail - WooCommerce Email Customizer | Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection |
≤ 3.0.34 |
CVE-2024-13747 |
Wordfence | |
| 8.8 High | WordPress Awesome Import & Export Plugin - Import & Export WordPress Data | Broken Access Control Import & Export WordPress Data <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Execution/Privilege Escalation |
≤ 4.1.1 |
CVE-2024-13232 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode |
≤ 3.10.7 |
CVE-2024-11731 |
Wordfence | |
| 6.5 Medium | Listingo - Business Listing and Directory | Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.2.7 |
CVE-2024-13815 |
Wordfence | |
| 4.3 Medium | Zass - WooCommerce Theme for Handmade Artists and Artisans | Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import |
≤ 3.9.9.10 |
CVE-2024-13810 |
Wordfence | |
| 9.8 Critical | VEDA - MultiPurpose | PHP Object Injection MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection No login needed |
≤ 4.2 |
CVE-2024-13787 |
Wordfence | |
| 6.5 Medium | Hero Slider - WordPress Slider | SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection |
≤ 1.3.5 |
CVE-2024-13809 |
Wordfence | |
| 6.4 Medium | Point Maker | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1.6 |
CVE-2024-12815 |
Wordfence | |
| 9.8 Critical | WP Real Estate Manager | Authentication Bypass Authentication Bypass via Account Takeover No login needed |
≤ 2.8 |
CVE-2025-1515 |
Wordfence | |
| 6.5 Medium | WP Online Contract | Broken Access Control Missing Authorization to Unauthenticated Settings Import No login needed |
≤ 5.1.4 |
CVE-2025-0954 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.