WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,851–1,900 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 38 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation No login needed ≤ 2.1.6 CVE-2024-7950 Wordfence
9.1 Critical The Events Calendar Pro Plugin PHP Object Injection Authenticated (Administrator+) PHP Object Injection to Remote Code Execution ≤ 7.0.2 CVE-2024-8016 Wordfence
9.1 Critical Web Directory Free Plugin web-directory-free Local File Inclusion Unauthenticated LFI No login needed < 1.7.3 Fixed in 1.7.3 CVE-2024-3673 WPScan
10.0 Critical Droip Plugin Path Traversal Unauthenticated Arbitrary File Download/Deletion No login needed ≤ 1.1.1 CVE-2024-43955 Patchstack
9.3 Critical Propovoice Pro Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.7.0.3 CVE-2024-43941 Patchstack
9.8 Critical JobSearch Plugin PHP Object Injection No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-43931 Patchstack
10.0 Critical WBW Product Table PRO Plugin SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed ≤ 1.9.4 Fixed in 1.9.5 CVE-2024-43918 Patchstack
9.3 Critical TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection No login needed ≤ 2.8.2 CVE-2024-43917 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.15 Fixed in 3.2.16 CVE-2024-43144 Patchstack
9.3 Critical Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin SQL Injection Unauthenticated SQL Injection No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43132 Patchstack
9.3 Critical VikRentCar Plugin vikrentcar SQL Injection No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-39653 Patchstack
9.3 Critical ListingPro Theme listingpro SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39622 Patchstack
9.3 Critical ListingPro Plugin listingpro-plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-38795 Patchstack
9.3 Critical Easy Digital Downloads Plugin easy-digital-downloads SQL Injection No login needed ≤ 3.2.12 Fixed in 3.3.1 CVE-2024-5057 Patchstack
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence
9.6 Critical Favicon Generator Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.5 CVE-2024-7568 Wordfence
9.9 Critical WPML Multilingual CMS Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection ≤ 4.6.12 CVE-2024-6386 Wordfence
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 6.3.0.1 Fixed in 6.4 CVE-2024-28000 Patchstack
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
10.0 Critical Woo Inquiry Plugin woo-inquiry SQL Injection Unauthenticated SQL Injection No login needed ≤ 0.1 CVE-2024-7854 Wordfence
9.8 Critical SmartSearch WP Plugin SQL Injection Unauthenticated SQLi No login needed < 2.4.5 Fixed in 2.4.5 CVE-2024-6847 WPScan
9.0 Critical Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Path Traversal Authenticated (Administrator+) Arbitrary File Read And Deletion 2.0 – 2.13.9 CVE-2024-7777 Wordfence
10.0 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 3.14.1 CVE-2024-5932 Wordfence
9.8 Critical myCred Plugin mycred PHP Object Injection No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43354 Patchstack
9.8 Critical Login As Users Plugin login-as-users Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-43311 Patchstack
9.6 Critical Compute Links Plugin compute-links Local File Inclusion Remote File Inclusion No login needed ≤ 1.2.1 CVE-2024-43261 Patchstack
9.0 Critical Crew HRM Plugin hr-management PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-43252 Patchstack
9.9 Critical Bit Form Pro Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 2.6.4 CVE-2024-43249 Patchstack
9.8 Critical JobSearch Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 2.3.4 CVE-2024-43245 Patchstack
9.0 Critical Ultimate Membership Pro Plugin indeed-membership-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43242 Patchstack
9.4 Critical Ultimate Membership Pro Plugin indeed-membership-pro Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43240 Patchstack
10.0 Critical GiveWP Plugin give PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.1 Fixed in 3.14.2 CVE-2024-37099 Patchstack
9.8 Critical GEO my Plugin Remote Code Execution Unauthenticated RCE via LFI No login needed < 4.5.0.2 Fixed in 4.5.0.2 CVE-2024-6330 WPScan
9.8 Critical News Element Elementor Blog Magazine Plugin news-element Local File Inclusion Unauthenticated LFI No login needed < 1.0.6 Fixed in 1.0.6 CVE-2024-6459 WPScan
10.0 Critical InPost for WooCommerce Plugin woo-inpost Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Delete No login needed ≤ 1.4.0, ≤ 1.4.4 CVE-2024-6500 Wordfence
9.8 Critical Grow by Tradedoubler Plugin tradedoubler-affiliate-tracker Local File Inclusion Unauthenticated LFI No login needed ≤ 2.0.21 CVE-2024-6460 WPScan
10.0 Critical BerqWP Plugin searchpro Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2024-43160 Patchstack
9.8 Critical Woffice Plugin woffice Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 5.4.10 Fixed in 5.4.12 CVE-2024-43153 Patchstack
9.8 Critical Participants Database Plugin participants-database PHP Object Injection No login needed ≤ 2.5.9.2 Fixed in 2.5.9.3 CVE-2024-43141 Patchstack
9.1 Critical HUSKY Plugin woocommerce-products-filter Privilege Escalation ≤ 1.3.6.1 Fixed in 1.3.6.2 CVE-2024-43121 Patchstack
9.8 Critical JS Help Desk – The Ultimate Help Desk & Support Plugin js-support-ticket Remote Code Execution The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution No login needed ≤ 2.8.6 CVE-2024-7094 Wordfence
9.8 Critical WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.7.5 - Authentication Bypass to Account Takeover No login needed ≤ 2.7.5 CVE-2024-7503 Wordfence
9.8 Critical Appointment Booking Calendar Plugin and Online Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking Authentication Bypass BookingPress 1.1.6 - 1.1.7 - Authentication Bypass to Account Takeover No login needed 1.1.6 – 1.1.7 CVE-2024-7350 Wordfence
9.8 Critical YayExtra – WooCommerce Extra Product Options Plugin yayextra Arbitrary File Upload WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file Function No login needed ≤ 1.3.7 CVE-2024-7257 Wordfence
9.8 Critical Backup and Staging by WP Time Capsule Plugin wp-time-capsule Authentication Bypass Authentication Bypass and Privilege Escalation No login needed ≤ 1.22.20 Fixed in 1.22.21 CVE-2024-38770 Patchstack
9.0 Critical ListingPro Plugin listingpro-plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39619 Patchstack
9.1 Critical CZ Loan Management Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 1.1 CVE-2024-5975 WPScan
9.8 Critical WpStickyBar Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 2.1.0 CVE-2024-5765 WPScan
9.1 Critical User Profile Builder Plugin profile-builder Broken Access Control Unauthenticated Media Upload No login needed < 3.11.8 Fixed in 3.11.8 CVE-2024-6366 WPScan
9.3 Critical FormLift for Infusionsoft Web Forms Plugin formlift SQL Injection Unauthenticated Blind SQL Injection No login needed ≤ 7.5.17 Fixed in 7.5.18 CVE-2024-38773 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only