WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 19,151–19,200 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 384 of 589
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP Smart Tooltip Plugin wp-smart-tool-tip Cross-Site Scripting ≤ 1.0.0 CVE-2025-23669 Patchstack
6.5 Medium Donate visa Plugin donate-visa Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2025-23656 Patchstack
7.1 High CubePM Plugin cubepm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23574 Patchstack
7.1 High RSVPMaker Volunteer Roles Plugin rsvpmaker-volunteer-roles Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23531 Patchstack
6.5 Medium Minterpress Plugin minterpress Broken Access Control Arbitrary Content Deletion ≤ 1.0.5 CVE-2025-23529 Patchstack
7.1 High Simple Locator Plugin simple-locator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-22513 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 3.4.0 Fixed in 3.4.2 CVE-2025-24754 Patchstack
8.1 High Morkva UA Shipping Plugin morkva-ua-shipping Local File Inclusion No login needed ≤ 1.0.18 Fixed in 1.0.20 CVE-2025-24685 Patchstack
9.3 Critical LTL Freight Quotes – Worldwide Express Edition Plugin ltl-freight-quotes-worldwide-express-edition SQL Injection No login needed ≤ 5.0.20 Fixed in 5.0.21 CVE-2025-24664 Patchstack
9.3 Critical Shipping for Nova Poshta Plugin nova-poshta-ttn SQL Injection No login needed ≤ 1.19.6 Fixed in 1.19.7 CVE-2025-24612 Patchstack
9.8 Critical FundPress Plugin fundpress PHP Object Injection No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-24601 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-24584 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
7.1 High Passwordless WP – Login with your glance or fingerprint Plugin passwordless-wp Cross-Site Scripting Login with your glance or fingerprint Plugin <= 1.1.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23792 Patchstack
7.1 High Shipdeo Plugin shipdeo-woo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 CVE-2025-23457 Patchstack
6.5 Medium Social Share Buttons Plugin share-button Path Traversal Unauthenticated Image Upload & Path Traversal No login needed ≤ 2.7 CVE-2024-13117 WPScan
3.8 Low Crelly Slider Plugin crelly-slider Cross-Site Scripting Admin+ Stored XSS < 1.4.7 Fixed in 1.4.7 CVE-2024-13116 WPScan
4.8 Medium WP Triggers Lite Plugin SQL Injection Admin+ SQL Injection ≤ 2.5.3 CVE-2024-13095 WPScan
7.1 High WP Triggers Lite Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.5.3 CVE-2024-13094 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0.0 CVE-2024-13057 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13056 WPScan
7.1 High Dyn Business Panel Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13055 WPScan
7.1 High Dental Optimizer Patient Generator App Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13052 WPScan
6.5 Medium Altra Side Menu Plugin Cross-Site Request Forgery Abitrary Menu Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12774 WPScan
7.2 High Altra Side Menu Plugin SQL Injection Admin+ SQL Injection ≤ 2.0 CVE-2024-12773 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Bulk Delete via CSRF No login needed ≤ 8.2.4 CVE-2024-12436 WPScan
7.1 High WC Affiliate Plugin wc-affiliate Cross-Site Scripting Reflected XSS No login needed ≤ 2.3.9 CVE-2024-12321 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Event Log Deletion via CSRF No login needed ≤ 8.2.4 CVE-2024-12280 WPScan
5.5 Medium Survey Maker Plugin survey-maker Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question ≤ 5.1.3.3 CVE-2024-13505 Wordfence
6.1 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Cross-Site Scripting A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2024-12334 Wordfence
8.8 High Zox News Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.16.0 CVE-2024-11936 Wordfence
8.8 High VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.7.2 CVE-2024-11641 Wordfence
5.4 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Server-Side Request Forgery MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl ≤ 4.0.5 CVE-2024-10705 Wordfence
5.3 Medium Membership Plugin – Restrict Content Plugin restrict-content Information Disclosure Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 3.2.13 CVE-2024-11090 Wordfence
7.3 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10633 Wordfence
7.2 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Broken Access Control Missing Authorization to Google Sheets Integration Credentials Modification and Stored Cross-Site Scripting No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10574 Wordfence
6.1 Medium Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10636 Wordfence
7.5 High Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin SQL Injection Unauthenticated SQL Injection via id No login needed 7.0.0 – 8.8.0, 20.0.0 – 21.8.0, 30.0.0 – 31.8.0 CVE-2024-10628 Wordfence
7.5 High Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 2.14.5 CVE-2024-13562 Wordfence
6.4 Medium Divi Carousel Lite Plugin wow-carousel-for-divi-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Logo Carousel Widgets ≤ 2.0.4 CVE-2025-0350 Wordfence
3.8 Low Contact Form by Bit Form Plugin bit-form Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.17.4 CVE-2024-13450 Wordfence
4.3 Medium Boom Fest Plugin boom-fest Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update ≤ 2.2.1 CVE-2024-13449 Wordfence
4.3 Medium GoHero Store Customizer for WooCommerce Plugin personalize-woocommerce-cart-page Broken Access Control Missing Authorization to Unuthenticated Settings Update ≤ 3.5 CVE-2024-12826 Wordfence
6.4 Medium ABC Notation Plugin abc-notation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.3 CVE-2024-13551 Wordfence
6.5 Medium ABC Notation Plugin abc-notation Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 6.1.3 CVE-2024-13550 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
6.4 Medium Bilingual Linker Plugin bilingual-linker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4 CVE-2024-13441 Wordfence
6.4 Medium Etsy Importer Plugin etsy-importer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.2 CVE-2024-12817 Wordfence
6.4 Medium Masy Gallery Plugin masy-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13586 Wordfence
6.1 Medium WP Contact Form7 Email Spam Blocker Plugin wp-contact-form7-email-spam-blocker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2024-13467 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only