WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,801–1,850 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 37 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
6.4 Medium Code Embed Plugin simple-embed-code Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.5 CVE-2024-10814 Wordfence
8.8 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.1 CVE-2024-10711 Wordfence
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
6.1 Medium WPGlobus Translate Options Plugin wpglobus-translate-options Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-9434 Wordfence
4.3 Medium DarkMySite – Advanced Dark Mode Plugin darkmysite Cross-Site Request Forgery Advanced Dark Mode Plugin for WordPress plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.8 CVE-2024-50466 Patchstack
8.8 High Crypto Plugin crypto Cross-Site Request Forgery Cross-Site Request Forgery to Authentication Bypass No login needed ≤ 2.15 CVE-2024-9990 Wordfence
8.8 High AMP for WP – Accelerated Mobile Pages Plugin accelerated-mobile-pages Cross-Site Request Forgery Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 1.0.99.1 CVE-2024-9598 Wordfence
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
4.3 Medium Transients Manager Plugin transients-manager Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2024-10045 Wordfence
5.4 Medium Category and Taxonomy Meta Fields Plugin wp-custom-taxonomy-meta Cross-Site Request Forgery Cross-Site Request Forgery to Taxonomy Meta Add/Delete No login needed ≤ 1.0.0 CVE-2024-9588 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
5.3 Medium Infinite-Scroll Plugin infinite-scroll Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 2.6.2 CVE-2024-10040 Wordfence
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
6.5 Medium Featured Posts with Multiple Custom Groups (FPMCG) Plugin featured-posts-with-multiple-custom-groups-fpmcg Cross-Site Request Forgery No login needed ≤ 4.0 CVE-2024-48031 Patchstack
4.3 Medium wp-Monalisa Plugin wp-monalisa Cross-Site Request Forgery No login needed ≤ 6.4 Fixed in 6.5 CVE-2024-48038 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation No login needed ≤ 1.35.1 CVE-2024-9351 Wordfence
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation No login needed ≤ 1.35.1 CVE-2024-9352 Wordfence
8.3 High WP Lead Plus X Plugin free-sales-funnel-squeeze-pages-landing-page-builder-templates-make Cross-Site Request Forgery No login needed ≤ 0.99 CVE-2020-36839 Wordfence
8.8 High File Manager Pro Plugin filester Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 8.3.9 CVE-2024-8507 Wordfence
8.3 High Mapplic Lite and Mapplic <= (Various Versions) Plugin Server-Side Request Forgery Server Side Request Forgery to Cross-Site Scirpting No login needed < 1.0.1, < 6.2 Fixed in 1.0.1 CVE-2012-10018 Wordfence
4.3 Medium WP ULike Plugin wp-ulike Cross-Site Request Forgery Cross-Site Request Forgery to Statistic Deletion No login needed ≤ 4.7.4 CVE-2024-9649 Wordfence
4.3 Medium ImagePress – Image Gallery Plugin image-gallery Cross-Site Request Forgery Image Gallery <= 1.2.2 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.2.2 CVE-2024-9778 Wordfence
6.1 Medium Easy PayPal Gift Certificate Plugin paypal-gift-certificate Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options No login needed ≤ 1.2.3 CVE-2024-9592 Wordfence
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.87 CVE-2024-8477 Wordfence
5.4 Medium TinyPNG Plugin tiny-compress-images Cross-Site Request Forgery No login needed ≤ 3.4.3 Fixed in 3.4.4 CVE-2024-47635 Patchstack
5.3 Medium Ultimate Member Plugin ultimate-member Cross-Site Request Forgery Cross-Site Request Forgery to Membership Status Change No login needed ≤ 2.8.6 CVE-2024-8520 Wordfence
4.3 Medium Use Any Font Plugin use-any-font Cross-Site Request Forgery No login needed ≤ 6.3.08 Fixed in 6.3.09 CVE-2024-47305 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2024-8476 Wordfence
4.3 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Cross-Site Request Forgery Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery No login needed ≤ 5.9.1 CVE-2024-7386 Wordfence
8.8 High BA Book Everything Plugin ba-book-everything Cross-Site Request Forgery Cross-Site Request Forgery to Email Address Update/Account Takeover No login needed ≤ 1.6.20 CVE-2024-8795 Wordfence
7.5 High Justified Image Grid Plugin justified-image-grid Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 4.6.1 Fixed in 4.7 CVE-2024-43989 Patchstack
8.8 High PropertyHive Plugin propertyhive Cross-Site Request Forgery Cross-Site Request Forgery via save_account_details No login needed ≤ 2.0.19 CVE-2024-8490 Wordfence
8.8 High Stream Plugin stream Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 4.0.1 CVE-2024-7423 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only