WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,851–1,900 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 38 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium amCharts: Charts and Maps Plugin amcharts-charts-and-maps Cross-Site Scripting Reflected Cross-Site Scripting via Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-8622 Wordfence
4.3 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery Cross-Site Request Forgery via 'addon_enable_disable' No login needed ≤ 2.7.4 CVE-2023-2919 Wordfence
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
4.3 Medium Tourfic Plugin tourfic Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 2.11.20 CVE-2024-8319 Wordfence
5.4 Medium WP Armour Extended Plugin Cross-Site Request Forgery No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43947 Patchstack
4.3 Medium Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Plugin reviews-feed Cross-Site Request Forgery Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-8200 Wordfence
5.4 Medium Ninja Forms Plugin ninja-forms Cross-Site Request Forgery No login needed ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-39628 Patchstack
4.3 Medium LearnPress Plugin learnpress Cross-Site Request Forgery No login needed ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39641 Patchstack
5.4 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-39645 Patchstack
4.3 Medium Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Request Forgery No login needed ≤ 2.6.18 Fixed in 2.6.19 CVE-2024-39657 Patchstack
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Cross-Site Request Forgery No login needed ≤ 2.7.10 Fixed in 2.7.11 CVE-2024-43116 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Cross-Site Request Forgery No login needed ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43117 Patchstack
4.3 Medium Backup and Restore Plugin wp-backitup Cross-Site Request Forgery No login needed ≤ 1.50 CVE-2024-43269 Patchstack
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.82 Fixed in 3.1.83 CVE-2024-43287 Patchstack
4.3 Medium WP Data Access Plugin wp-data-access Cross-Site Request Forgery No login needed ≤ 5.5.7 Fixed in 5.5.9 CVE-2024-43295 Patchstack
5.4 Medium SpeedyCache Plugin speedycache Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-43299 Patchstack
7.1 High Fonts Plugin olympus-google-fonts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43301 Patchstack
4.3 Medium Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43316 Patchstack
4.3 Medium Dark Mode for WP Dashboard Plugin dark-mode-for-wp-dashboard Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-43325 Patchstack
4.3 Medium WP User Manager Plugin wp-user-manager Cross-Site Request Forgery User Profile Builder & Membership plugin <= 2.9.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.10 Fixed in 2.9.11 CVE-2024-43336 Patchstack
4.3 Medium Brave Popup Builder Plugin brave-popup-builder Cross-Site Request Forgery No login needed ≤ 0.7.0 Fixed in 0.7.1 CVE-2024-43337 Patchstack
4.3 Medium Advanced Form Integration Plugin advanced-form-integration Cross-Site Request Forgery The Easiest Integration Plugin plugin <= 1.89.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.89.4 Fixed in 1.89.6 CVE-2024-43340 Patchstack
5.4 Medium WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery WebinarPress plugin <= 1.33.20 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.33.20 Fixed in 1.33.21 CVE-2024-43339 Patchstack
9.6 Critical Favicon Generator Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.5 CVE-2024-7568 Wordfence
6.1 Medium OTA Sync Booking Engine Widget Plugin ota-sync-booking-engine-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2024-7647 Wordfence
6.1 Medium BP Profile Search Plugin bp-profile-search Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 5.7.5 CVE-2024-7850 Wordfence
4.3 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed ≤ 1.8.1 CVE-2023-3408 Wordfence
5.4 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed ≤ 1.8.1 CVE-2023-3409 Wordfence
4.7 Medium Short URL Plugin shorten-url Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed ≤ 1.6.8 CVE-2023-1604 Wordfence
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
4.2 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery No login needed ≤ 1.8.7 CVE-2024-7501 Wordfence
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 7.1.7 CVE-2024-7422 Wordfence
5.8 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed ≤ 1.3.6 CVE-2024-7420 Wordfence
7.1 High Contact Form 7 Summary and Print Plugin cf7-summary-and-print Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-38724 Patchstack
6.1 Medium Christmasify! Plugin christmasify Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5.5 CVE-2024-7574 Wordfence
4.3 Medium Brizy – Page Builder Plugin brizy Cross-Site Request Forgery Page Builder <= 2.5.1 - Cross-Site Request Forgery No login needed ≤ 2.5.1 CVE-2024-6254 Wordfence
8.8 High MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 2.2 CVE-2024-7492 Wordfence
8.5 High Modern Events Calendar Plugin modern-events-calendar-lite Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery ≤ 7.12.1 CVE-2024-6522 Wordfence
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
5.4 Medium Edubin Plugin edubin Server-Side Request Forgery No login needed ≤ 9.2.0 CVE-2024-39637 Patchstack
4.9 Medium AI Engine: ChatGPT Chatbot Plugin ai-engine Server-Side Request Forgery ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-38791 Patchstack
6.4 Medium Remote Content Shortcode Plugin remote-content-shortcode Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 1.5 CVE-2024-2090 Wordfence
6.1 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.2.0.1 CVE-2024-3246 Wordfence
6.3 Medium Social Auto Poster Plugin Cross-Site Request Forgery Cross-Site Request Forgery via Multiple Functions No login needed ≤ 5.3.14 CVE-2024-6751 Wordfence
7.2 High BerqWP Plugin searchpro Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-37942 Patchstack
6.4 Medium JSON Content Importer Plugin json-content-importer Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) ≤ 1.5.6 Fixed in 1.6.0 CVE-2024-38723 Patchstack
7.1 High Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Server-Side Request Forgery No login needed ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38728 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38730 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only