WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 1,901–1,950 of 2,544 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 39 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Appointmind Plugin appointmind Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.0 Fixed in 4.1.0 CVE-2024-51679 Patchstack
7.1 High W3P SEO Plugin wp-perfect-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8.6 Fixed in 1.8.6 CVE-2024-51684 Patchstack
7.1 High Platform.ly Official Plugin platformly Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 Fixed in 1.14 CVE-2024-51687 Patchstack
7.1 High FraudLabs Pro SMS Verification Plugin fraudlabs-pro-sms-verification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.10.1 Fixed in 1.10.2 CVE-2024-51688 Patchstack
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.25 CVE-2024-51647 Patchstack
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
4.1 Medium Post From Frontend Plugin Cross-Site Request Forgery Post Deletion via CSRF ≤ 1.0.0 CVE-2024-9689 WPScan
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Broken Access Control + CSRF ≤ 4.24.7 Fixed in 4.24.8 CVE-2024-39639 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43118 Patchstack
5.4 Medium Clearfy Cache Plugin clearfy Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2024-43260 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 11.48 Fixed in 11.49 CVE-2024-43933 Patchstack
9.6 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43984 Patchstack
9.6 Critical EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-49674 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
4.3 Medium DarkMySite – Advanced Dark Mode Plugin darkmysite Cross-Site Request Forgery Advanced Dark Mode Plugin for WordPress plugin <= 1.2.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.8 CVE-2024-50466 Patchstack
7.1 High Google Docs RSVP Plugin google-docs-rsvp-guestlist Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-49672 Patchstack
6.1 Medium PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip Plugin 3d-flipbook-dflip-lite Cross-Site Scripting DearFlip <= 2.3.32 - Reflected Cross-Site Scripting No login needed ≤ 2.3.32 CVE-2024-8717 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
7.1 High GoogleDrive folder list Plugin googledrive-folder-list Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49335 Patchstack
7.1 High AVChat Video Chat Plugin avchat-3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2 CVE-2024-49605 Patchstack
7.1 High Endless Posts Navigation Plugin endless-posts-navigation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-49629 Patchstack
8.2 High SafetyForms Plugin safetymails-forms Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49615 Patchstack
8.2 High Back Link Tracker Plugin back-link-tracker Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49617 Patchstack
7.1 High EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.12.14 Fixed in 3.0.0 CVE-2024-44061 Patchstack
8.2 High APA Register Newsletter Form Plugin apa-register-newsletter-form Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49621 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
6.4 Medium RSS Feed Widget Plugin rss-feed-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via rfw-youtube-videos Shortcode ≤ 2.9.9 CVE-2024-10057 Wordfence
7.1 High Cookie Scanner Plugin cookie-scanner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-49220 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.1 High CJ Change Howdy Plugin cj-change-howdy Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.1 CVE-2024-49223 Patchstack
7.1 High Better Author Bio Plugin better-author-bio Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.7.10.11 CVE-2024-49229 Patchstack
7.1 High Ahmeti Wp Timeline Plugin ahmeti-wp-timeline Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.1 CVE-2024-49237 Patchstack
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
7.6 High Surfer Plugin surferseo SQL Injection ≤ 1.5.0.502 Fixed in 1.6.0.523 CVE-2024-49299 Patchstack
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
7.1 High Wsify Widget Plugin wsify-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-48048 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only