WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,151–18,200 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 364 of 594
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium VK Blocks Plugin vk-blocks Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 1.94.2.2 CVE-2024-13635 Wordfence
4.3 Medium SupportCandy – Helpdesk & Customer Support Ticket System Plugin supportcandy Broken Access Control Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference ≤ 3.3.0 CVE-2024-13552 Wordfence
6.4 Medium Advanced File Manager Plugin file-manager-advanced Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload ≤ 5.2.14 CVE-2024-13805 Wordfence
6.1 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.8.3 CVE-2024-13431 Wordfence
9.8 Critical Golo - Directory & Listing, Travel Theme Broken Access Control Directory & Listing, Travel WordPress Theme <= 1.6.10 - Missing Authorization to Privilege Escalation via Unauthenticated Arbitrary User Password Change No login needed ≤ 1.6.10 CVE-2024-12876 Wordfence
9.8 Critical InWave Jobs Plugin Privilege Escalation Unauthenticated Privilege Escalation via Password Reset No login needed ≤ 3.5.1 CVE-2025-1315 Wordfence
8.8 High Eventer - WordPress Event & Booking Manager Plugin SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id ≤ 3.9.9.2 CVE-2025-0959 Wordfence
8.8 High School Management System Plugin wpschoolpress Privilege Escalation Authenticated (Student+) Account Takeover and Privilege Escalation ≤ 93.0.0 CVE-2024-9658 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 93.0.0 CVE-2024-12610 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Student+) SQL Injection via 'view-attendance' ≤ 92.0.0 CVE-2024-12609 Wordfence
5.3 Medium Platform.ly for WooCommerce Plugin platformly-for-woocommerce Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.6 CVE-2024-13904 Wordfence
6.5 Medium Hero Maps Premium - Customizable Google Maps Plugin SQL Injection Customizable Google Maps Plugin <= 2.3.9 - Authenticated (Subscriber+) SQL Injection ≤ 2.3.9 CVE-2024-13781 Wordfence
7.5 High CS Framework Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read No login needed ≤ 7.1 CVE-2024-12036 Wordfence
5.3 Medium School Management System Plugin wpschoolpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 93.0.0 CVE-2024-12611 Wordfence
7.5 High Ultimate Video Player Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 10.0 CVE-2024-10804 Wordfence
8.8 High CS Framework Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 7.0 CVE-2024-12035 Wordfence
6.5 Medium School Management System Plugin wpschoolpress SQL Injection Authenticated (Subscriber+) SQL Injection via 'mj_smgt_show_event_task' ≤ 92.0.0 CVE-2024-12607 Wordfence
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
8.8 High UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.5.04 CVE-2025-1309 Wordfence
6.4 Medium Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.28 CVE-2025-0863 Wordfence
7.5 High CURCY - WooCommerce Multi Currency - Currency Switcher Plugin SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed ≤ 2.3.6 CVE-2024-13320 Wordfence
8.1 High Flex Mag - Responsive WordPress News Theme Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 3.5.2 CVE-2024-13655 Wordfence
6.4 Medium Wishlist Plugin wishlist Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.43 CVE-2024-12809 Wordfence
9.8 Critical WPCOM Member Plugin wpcom-member Authentication Bypass Authentication Bypass via 'user_phone' No login needed ≤ 1.7.5 CVE-2025-1475 Wordfence
4.3 Medium Homey Theme Cross-Site Request Forgery Cross-Site Request Forgery to User Verification No login needed ≤ 2.4.3 CVE-2025-0748 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Broken Access Control Events Calendar, Bookings and Tickets <= 4.0.7.3 - Missing Authorization to Authenticated (Subscriber+) Event Attendees Export ≤ 4.0.7.3 CVE-2024-13526 Wordfence
8.1 High Homey Theme Authentication Bypass Limited Authentication Bypass due to Missing Empty Value Check No login needed ≤ 2.4.3 CVE-2025-0749 Wordfence
4.3 Medium Cookie banner plugin for WordPress – Cookiebot CMP by Usercentrics Plugin cookiebot Broken Access Control Cookiebot CMP by Usercentrics <= 4.4.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission ≤ 4.4.1 CVE-2025-1666 Wordfence
4.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery Cross-Site Request Forgery via ajax_transcript_delete Function No login needed ≤ 4.2.2 CVE-2025-1383 Wordfence
5.5 Medium Notibar Plugin notibar Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2.1.5 CVE-2025-1672 Wordfence
6.5 Medium Moving Media Library Plugin moving-media-library Path Traversal Authenticated (Administrator+) Directory Traversal to Arbitrary File Deletion ≤ 1.22 CVE-2024-13897 Wordfence
6.1 Medium Easy Broken Link Checker Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 9.0.2 CVE-2024-13868 WPScan
5.1 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed 2.8.0 CVE-2025-22623 Fluid Attacks
9.8 Critical Homey Login Register Plugin Privilege Escalation Unauthenticated Privilege Escalation in homey_register No login needed ≤ 2.4.0 CVE-2024-11951 Wordfence
5.3 Medium Content Control – The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More Plugin content-control Information Disclosure The Ultimate Content Restriction Plugin! Restrict Content, Create Conditional Blocks & More <= 2.5.0 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.5.0 CVE-2024-11153 Wordfence
7.5 High Ultimate Member Plugin ultimate-member SQL Injection Unauthenticated SQL Injection via search Parameter No login needed ≤ 2.10.0 CVE-2025-1702 Wordfence
5.3 Medium Sparkling Theme sparkling Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Activation/Deactivation No login needed ≤ 2.4.9 CVE-2024-13423 Wordfence
9.8 Critical Homey Theme Privilege Escalation Unauthenticated Privilege Escalation in homey_save_profile No login needed ≤ 2.4.2 CVE-2024-12281 Wordfence
7.5 High DesignThemes Core Features Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file No login needed ≤ 4.7 CVE-2024-13471 Wordfence
4.3 Medium Spreadsheet Integration Plugin wpgsi Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Publish No login needed ≤ 3.8.2 CVE-2025-1463 Wordfence
4.3 Medium WooMail - WooCommerce Email Customizer Plugin Broken Access Control WooCommerce Email Customizer <= 3.0.34 - Authenticated (Subscriber+) Missing Authorization to SQL Injection ≤ 3.0.34 CVE-2024-13747 Wordfence
8.8 High WordPress Awesome Import & Export Plugin - Import & Export WordPress Data Plugin Broken Access Control Import & Export WordPress Data <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Execution/Privilege Escalation ≤ 4.1.1 CVE-2024-13232 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode ≤ 3.10.7 CVE-2024-11731 Wordfence
6.5 Medium Listingo - Business Listing and Directory Theme Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.7 CVE-2024-13815 Wordfence
4.3 Medium Zass - WooCommerce Theme for Handmade Artists and Artisans Theme Broken Access Control WooCommerce Theme for Handmade Artists and Artisans <= 3.9.9.10 - Missing Authorization to Authenticated (Subscriber+) Demo Import ≤ 3.9.9.10 CVE-2024-13810 Wordfence
9.8 Critical VEDA - MultiPurpose Theme PHP Object Injection MultiPurpose WordPress Theme <= 4.2 - Authenticated (Subscriber+) PHP Object Injection No login needed ≤ 4.2 CVE-2024-13787 Wordfence
6.5 Medium Hero Slider - WordPress Slider Plugin SQL Injection WordPress Slider Plugin <= 1.3.5 - Authenticated (Subscriber+) SQL Injection ≤ 1.3.5 CVE-2024-13809 Wordfence
6.4 Medium Point Maker Plugin point-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.6 CVE-2024-12815 Wordfence
9.8 Critical WP Real Estate Manager Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 2.8 CVE-2025-1515 Wordfence
6.5 Medium WP Online Contract Plugin Broken Access Control Missing Authorization to Unauthenticated Settings Import No login needed ≤ 5.1.4 CVE-2025-0954 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only