WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,801–1,850 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 37 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical File Manager Plugin wp-file-manager Arbitrary File Upload Unauthenticated Arbitrary File Upload/Download No login needed ≤ 3.0 CVE-2018-25105 Wordfence
9.9 Critical ThemeGrill Demo Importer Plugin Broken Access Control Authorization Bypass to Site Reset 1.3.4 – 1.6.1 CVE-2020-36837 Wordfence
9.8 Critical SiteGround Optimizer Plugin Broken Access Control Missing Authorization No login needed < 5.0.13 Fixed in 5.0.13 CVE-2019-25217 Wordfence
9.8 Critical Advanced Access Manager Plugin advanced-access-manager Path Traversal Unauthenticated Arbitrary File Read No login needed < 5.9.9 Fixed in 5.9.9 CVE-2019-25213 Wordfence
9.8 Critical Kento Post View Counter Plugin kento-post-view-counter SQL Injection No login needed ≤ 2.8 CVE-2016-15040 Wordfence
9.8 Critical ZoomSounds Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.96 CVE-2021-4449 Wordfence
9.8 Critical WordPress Mega Menu Plugin Arbitrary File Upload Arbitrary File Creation No login needed ≤ 2.0.6 CVE-2021-4443 Wordfence
9.8 Critical UltimateAI Plugin Authentication Bypass No login needed ≤ 2.8.3 CVE-2024-9105 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.3 - Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 3.16.3 CVE-2024-9634 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php No login needed ≤ 4.24.11 CVE-2024-9047 Wordfence
9.8 Critical Talkback Plugin talkback-secure-linkback-protocol PHP Object Injection No login needed ≤ 1.0 CVE-2024-48033 Patchstack
9.3 Critical Multi Step for Contact Form Plugin cf7-multi-step SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2024-47331 Patchstack
9.8 Critical GutenKit Plugin gutenkit-blocks-addon Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.1.0 CVE-2024-9234 Wordfence
9.8 Critical Hunk Companion Plugin hunk-companion Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.8.4 CVE-2024-9707 Wordfence
9.8 Critical Pedalo Connector Plugin pedalo-connector Authentication Bypass Authentication Bypass to Administrator No login needed ≤ 2.0.5 CVE-2024-9822 Wordfence
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 2.5.9 Fixed in 2.6.1 CVE-2024-47636 Patchstack
9.8 Critical UserPlus Plugin userplus Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0 CVE-2024-9518 Wordfence
9.8 Critical LatePoint Plugin Authentication Bypass No login needed ≤ 5.0.12 CVE-2024-8943 Wordfence
9.8 Critical LatePoint Plugin SQL Injection Unauthenticated Arbitrary User Password Change via SQL Injection No login needed ≤ 5.0.11 CVE-2024-8911 Wordfence
9.3 Critical YITH WooCommerce Ajax Search Plugin yith-woocommerce-ajax-search SQL Injection No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-47350 Patchstack
9.6 Critical Vmax Project Manager Plugin vmax-project-manager Local File Inclusion Local File Inclusion to RCE No login needed ≤ 1.0 CVE-2024-44014 Patchstack
9.8 Critical WordPress & WooCommerce Affiliate Program Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 8.4.1 CVE-2024-9289 Wordfence
9.8 Critical Echo RSS Feed Post Generator Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 5.4.6 CVE-2024-9265 Wordfence
9.8 Critical Wechat Social login Plugin wechat-social-login Authentication Bypass No login needed ≤ 1.3.0 CVE-2024-9106 Wordfence
9.8 Critical Wechat Social login Plugin wechat-social-login Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.0 CVE-2024-9108 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.16.1 CVE-2024-8353 Wordfence
9.8 Critical Jupiter X Core Plugin jupiterx-core Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.6.5 CVE-2024-7772 Wordfence
9.8 Critical The Events Calendar Plugin the-events-calendar SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.6.4 CVE-2024-8275 Wordfence
9.1 Critical WordPress Simple HTML Sitemap Plugin wp-simple-html-sitemap SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.1 CVE-2024-7385 Wordfence
9.1 Critical Prisna GWT - Google Website Translator Plugin google-website-translator PHP Object Injection Google Website Translator <= 1.4.11 - Authenticated (Admin+) PHP Object Injection ≤ 1.4.11 CVE-2024-8514 Wordfence
9.8 Critical REST API TO MiniProgram Plugin rest-api-to-miniprogram Privilege Escalation Unauthenticated Arbitrary User Email Update and Privilege Escalation via Account Takeover No login needed ≤ 4.7.1 CVE-2024-8485 Wordfence
9.9 Critical Daily Prayer Time Plugin daily-prayer-time-for-mosques SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2024.08.26 CVE-2024-8621 Wordfence
9.9 Critical WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection ≤ 4.8.5 CVE-2024-8436 Wordfence
9.1 Critical WooEvents Plugin Remote Code Execution Unauthenticated Arbitrary File Overwrite No login needed ≤ 4.1.2 CVE-2024-8671 Wordfence
9.9 Critical MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter SQL Injection Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL Injection ≤ 1.3.3.3 CVE-2024-8624 Wordfence
9.8 Critical Donation Forms by Charitable – Donations Plugin & Fundraising Platform Plugin charitable Broken Access Control Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation No login needed ≤ 1.8.1.14 CVE-2024-8791 Wordfence
9.8 Critical Webo-facto Plugin webo-facto-connector Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.40 CVE-2024-8853 Wordfence
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 6.9.7 Fixed in 6.9.8 CVE-2024-43976 Patchstack
9.3 Critical Super Store Finder Plugin superstorefinder-wp SQL Injection No login needed ≤ 6.9.8 Fixed in 6.9.8 CVE-2024-43978 Patchstack
9.3 Critical WPCargo Track & Trace Plugin wpcargo SQL Injection No login needed < 8.0.4 Fixed in 8.0.4 CVE-2024-44004 Patchstack
9.1 Critical Backuply – Backup, Restore, Migrate and Clone Plugin backuply SQL Injection Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection ≤ 1.3.4 CVE-2024-8669 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed ≤ 4.2.7 CVE-2024-8529 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed ≤ 4.2.7 CVE-2024-8522 Wordfence
9.8 Critical WooCommerce Photo Reviews Premium Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 1.3.13.2 CVE-2024-8277 Wordfence
9.8 Critical Opti Marketing Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 2.0.9 CVE-2024-6928 WPScan
9.8 Critical TrueBooker Plugin truebooker-appointment-booking SQL Injection Multiple Unauthenticated SQLi No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6924 WPScan
9.8 Critical WPCOM Member Plugin wpcom-member Privilege Escalation Unauthenticated Privilege Escalation via User Meta No login needed ≤ 1.5.2.1 CVE-2024-7493 Wordfence
9.8 Critical WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Broken Access Control Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update No login needed ≤ 16.26.8 CVE-2024-8292 Wordfence
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed ≤ 4.2.0 CVE-2024-8289 Wordfence
9.8 Critical Viral Signup Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 2.1 CVE-2024-6926 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only