WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,401–18,450 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 369 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium WP Posts Carousel Plugin wp-posts-carousel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_play_timeout Parameter ≤ 1.3.7 CVE-2025-1491 Wordfence
5.3 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Broken Access Control Missing Authorization to Unauthenticated User Email Retrieval via ays_sccp_reports_user_search Function No login needed ≤ 4.4.7 CVE-2025-1404 Wordfence
7.2 High Album Gallery – WordPress Gallery Plugin new-album-gallery PHP Object Injection WordPress Gallery <= 1.6.3 - Authenticated (Editor+) PHP Object Injection via Gallery Meta ≤ 1.6.3 CVE-2024-13833 Wordfence
4.3 Medium GenerateBlocks Plugin generateblocks Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via 'get_image_description' ≤ 1.9.1 CVE-2024-13546 Wordfence
7.2 High Database Backup and check Tables Automated With Scheduler 2024 Plugin database-backup Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion ≤ 2.36 CVE-2024-13910 Wordfence
4.8 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Server-Side Request Forgery Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.7.4 - Unauthenticated Limited Server-Side Request Forgery in nice_links No login needed ≤ 2.7.4 CVE-2024-13697 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' ≤ 3.4.9 CVE-2025-1291 Wordfence
7.5 High Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Information Disclosure Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.6.9 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.6.9 CVE-2024-13611 Wordfence
8.8 High SurveyJS: Drag & Drop WordPress Form Builder to create, style and embed multiple forms of any complexity Plugin surveyjs Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion via SurveyJS_DeleteFile ≤ 1.12.17 CVE-2024-12544 Wordfence
9.8 Critical SetSail Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.0.3 CVE-2025-1564 Wordfence
7.2 High Database Backup and check Tables Automated With Scheduler 2024 Plugin database-backup Information Disclosure Authenticated (Administrator+) Sensitive Information Exposure ≤ 2.35 CVE-2024-13911 Wordfence
6.5 Medium Authors List Plugin authors-list Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.6 CVE-2024-13806 Wordfence
9.8 Critical Academist Membership Plugin Authentication Bypass Authentication Bypass via Account Takeover No login needed ≤ 1.1.6 CVE-2025-1671 Wordfence
9.8 Critical Alloggio Membership Plugin Authentication Bypass Authentication Bypass via Social Login Account Takeover No login needed ≤ 1.1 CVE-2025-1638 Wordfence
6.5 Medium Simple Download Counter Plugin simple-download-counter Path Traversal Authenticated (Author+) Arbitrary File Read ≤ 2.0 CVE-2025-1730 Wordfence
5.3 Medium IP2Location Redirection Plugin ip2location-redirection Broken Access Control Missing Authorization to Unauthenticated Settings Export No login needed ≤ 1.33.3 CVE-2025-1502 Wordfence
6.4 Medium Page Builder by SiteOrigin Plugin siteorigin-panels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.31.4 CVE-2025-1459 Wordfence
8.1 High Exertio Framework Plugin Privilege Escalation Unauthenticated Arbitrary User Password Update No login needed ≤ 1.3.1 CVE-2024-13373 Wordfence
9.8 Critical Nokri – Job Board Theme Privilege Escalation Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change No login needed ≤ 1.6.2 CVE-2024-12824 Wordfence
4.4 Medium Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site Plugin counter-box Cross-Site Scripting Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-13901 Wordfence
6.1 Medium SKU Generator for WooCommerce Plugin sku-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.2 CVE-2024-9212 Wordfence
6.4 Medium TemplatesNext ToolKit Plugin templatesnext-toolkit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.9 CVE-2024-13559 Wordfence
4.3 Medium Simple:Press Plugin simplepress Cross-Site Request Forgery Cross-Site Request Forgery to Unauthorized Post Editing No login needed ≤ 6.10.12 CVE-2024-13518 Wordfence
6.5 Medium Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 2.28 CVE-2024-13750 Wordfence
6.5 Medium Booking Calendar and Notification Plugin booking-calendar-and-notification Broken Access Control Missing Authorization via wpcb_all_bookings, wpcb_update_booking_post, and wpcb_delete_posts Functions No login needed ≤ 4.0.3 CVE-2024-13746 Wordfence
6.1 Medium Currency Switcher for WooCommerce Plugin currency-switcher-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.16.2 CVE-2024-9217 Wordfence
6.4 Medium Clicface Trombi Plugin clicface-trombi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via nom Parameter ≤ 2.08 CVE-2025-0820 Wordfence
7.5 High Fluent Support – Helpdesk & Customer Support Ticket System Plugin fluent-support Information Disclosure Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 1.8.5 CVE-2024-13568 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Limited Settings Update ≤ 3.4.25 CVE-2025-1780 Wordfence
4.3 Medium BuddyPress WooCommerce My Account Integration. Create WooCommerce Member Pages Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 3.4.24 CVE-2024-13358 Wordfence
6.3 Medium PixelYourSite Plugin pixelyoursite PHP Object Injection Insecure deserialization No login needed 10.1.1.1 CVE-2025-0769 Fluid Attacks
7.2 High Site Mailer Plugin site-mailer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.3 CVE-2025-1319 Wordfence
4.3 Medium NextMove Lite – Thank You Page for WooCommerce Plugin woo-thank-you-page-nextmove-lite Broken Access Control Thank You Page for WooCommerce <= 2.19.0 - Missing Authorization to Authenticated (Subscriber+) Deactivation Reason Submission ≤ 2.19.0 CVE-2024-10860 Wordfence
9.8 Critical DHVC Form Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.4.7 CVE-2024-8420 Wordfence
6.4 Medium URL Media Uploader Plugin url-media-uploader Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery via DNS Rebinding ≤ 1.0.0 CVE-2025-1662 Wordfence
5.5 Medium Modal Portfolio Plugin modal-portfolio Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.7.4.2 CVE-2024-13851 Wordfence
8.8 High WHMPress - WHMCS Client Area Plugin Broken Access Control WHMCS Client Area <= 4.3-revision-3- Authenticated (Subscriber+) Arbitrary Options Update ≤ 4.3-revision-3 CVE-2024-9195 Wordfence
8.1 High Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Privilege Escalation Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 8.1 CVE-2025-1570 Wordfence
7.2 High Tabs for WooCommerce Plugin wc-tabs PHP Object Injection Authentiated (Shop Manager+) PHP Object Injection in product_has_custom_tabs ≤ 1.0.0 CVE-2024-13831 Wordfence
5.9 Medium Order Attachments for WooCommerce Plugin order-attachments-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.5.1 CVE-2024-13638 Wordfence
9.8 Critical WHMpress Plugin Local File Inclusion Unauthenticated Local File Inclusion to Arbitrary Options Update No login needed ≤ 6.3-revision-0 CVE-2024-9193 Wordfence
9.8 Critical WooCommerce Ultimate Gift Card Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.9.2 CVE-2024-8425 Wordfence
4.3 Medium Forex Calculators Plugin fx-calculators Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.3.7 CVE-2024-13716 Wordfence
6.4 Medium Pricing Table by PickPlugins Plugin pricingtable Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.12.10 CVE-2024-13469 Wordfence
6.4 Medium SecuPress Free — WordPress Security Plugin secupress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via secupress_check_ban_ips_form Shortcode ≤ 2.2.5.3 CVE-2024-9019 Wordfence
6.4 Medium WOW Entrance Effects (WEE!) Plugin wow-entrance-effects-wee Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-1560 Wordfence
4.3 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Information Disclosure Authenticated (Contributor+) Restricted Post Disclosure ≤ 1.1.8 CVE-2024-13832 Wordfence
6.5 Medium KiviCare – Clinic & Patient Management System (EHR) Plugin kivicare-clinic-management-system SQL Injection Clinic & Patient Management System (EHR) <= 3.6.7 - Authenticated (Doctor+) SQL Injection via 'u_id' Parameter ≤ 3.6.7 CVE-2025-1572 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Image Comparison Widgets ≤ 2.7.6 CVE-2025-1571 Wordfence
6.4 Medium Product Catalog Simple Plugin post-type-x Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via show_products Shortcode ≤ 1.7.11 CVE-2025-1405 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only