WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,901–1,950 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.1 Critical | MasterStudy LMS | Privilege Escalation Privilege Escalation to Instructor No login needed |
< 3.3.24 Fixed in 3.3.24 |
CVE-2024-5973 |
WPScan | |
| 9.8 Critical | WooCommerce - Social Login | Broken Access Control Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation No login needed |
≤ 2.7.3 |
CVE-2024-6636 |
Wordfence | |
| 9.8 Critical | Filter & Grids | Local File Inclusion Unauthenticated LFI No login needed |
< 2.8.33 Fixed in 2.8.33 |
CVE-2024-6164 |
WPScan | |
| 9.8 Critical | 简数采集器 (Keydatas) | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.5.2 |
CVE-2024-6220 |
Wordfence | |
| 9.8 Critical | HUSKY - Products Filter Professional for WooCommerce | SQL Injection Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection No login needed |
≤ 1.3.6 |
CVE-2024-6457 |
Wordfence | |
| 9.1 Critical | Bug Library | Remote Code Execution Unauthenticated RCE No login needed |
< 2.1.1 Fixed in 2.1.1 |
CVE-2024-5450 |
WPScan | |
| 9.1 Critical | Realtyna Organic IDX | Arbitrary File Upload |
≤ 4.14.13 |
CVE-2024-38736 |
Patchstack | |
| 9.1 Critical | Import Spreadsheets from Microsoft Excel | Arbitrary File Upload |
≤ 10.1.4 |
CVE-2024-38734 |
Patchstack | |
| 9.8 Critical | Jobmonster | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 4.7.5 Fixed in 4.7.6 |
CVE-2024-37927 |
Patchstack | |
| 9.3 Critical | Woocommerce OpenPos | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.4.4 |
CVE-2024-37933 |
Patchstack | |
| 9.8 Critical | MStore API – Create Native Android & iOS Apps On The Cloud | Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass No login needed |
≤ 4.14.7 |
CVE-2024-6328 |
Wordfence | |
| 9.8 Critical | JSON API User | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 3.9.3 |
CVE-2024-6624 |
Wordfence | |
| 9.8 Critical | InstaWP Connect – 1-click WP Staging & Migration | Authentication Bypass Authentication Bypass to Admin No login needed |
≤ 0.1.0.44 |
CVE-2024-6397 |
Wordfence | |
| 9.8 Critical | WishList Member X | Information Disclosure Unauthenticated Database Backup Download No login needed |
< 3.26.7 Fixed in 3.26.7 |
CVE-2024-37113 |
Patchstack | |
| 9.9 Critical | Newspack Blocks | Arbitrary File Upload |
≤ 3.0.8 Fixed in 3.0.9 |
CVE-2024-37424 |
Patchstack | |
| 9.9 Critical | Zita Elementor Site Library | Remote Code Execution Arbitrary Code Execution |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-37420 |
Patchstack | |
| 9.9 Critical | Church Admin | Arbitrary File Upload |
≤ 4.4.6 Fixed in 4.4.7 |
CVE-2024-37418 |
Patchstack | |
| 10.0 Critical | WishList Member X | SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed |
< 3.26.7 Fixed in 3.26.7 |
CVE-2024-37112 |
Patchstack | |
| 9.9 Critical | OSM – OpenStreetMap | SQL Injection OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection |
≤ 6.0.3 |
CVE-2024-3604 |
Wordfence | |
| 9.8 Critical | IQ Testimonials | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.2.7 |
CVE-2024-6314 |
Wordfence | |
| 9.8 Critical | Gutenberg Forms | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.2.9 |
CVE-2024-6313 |
Wordfence | |
| 9.6 Critical | Generate PDF using Contact Form 7 | Cross-Site Request Forgery CSRF to Arbitrary File Upload |
≤ 4.1.2 Fixed in 4.1.3 |
CVE-2024-37555 |
Patchstack | |
| 9.8 Critical | SEOPress | PHP Object Injection Unauthenticated Object Injection No login needed |
< 7.9 Fixed in 7.9 |
CVE-2024-5488 |
WPScan | |
| 9.8 Critical | Product Table by WBW | Remote Code Execution Unauthenticated Remote Code Execution No login needed |
≤ 2.0.1 |
CVE-2024-6365 |
Wordfence | |
| 9.8 Critical | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed |
≤ 5.7.25 |
CVE-2024-6172 |
Wordfence | |
| 9.8 Critical | UsersWP – Front-end login form, User Registration, User Profile & Members Directory | SQL Injection Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' No login needed |
≤ 1.2.10 |
CVE-2024-6265 |
Wordfence | |
| 9.3 Critical | Email Subscribers & Newsletters | SQL Injection No login needed |
≤ 5.7.25 Fixed in 5.7.26 |
CVE-2024-37252 |
Patchstack | |
| 9.8 Critical | Quiz Maker | SQL Injection Unauthenticated SQL Injection via 'ays_questions' Parameter No login needed |
≤ 6.5.8.3 |
CVE-2024-6028 |
Wordfence | |
| 10.0 Critical | Several WordPress.org Plugins <= Various Versions | Other Injected Backdoor No login needed |
4.4.6.4 – 4.4.7.1, 1.0.4 – 1.0.5, 1.2.1 – 1.2.2, … |
CVE-2024-6297 |
Wordfence | |
| 10.0 Critical | InstaWP Connect | Arbitrary File Upload No login needed |
≤ 0.1.0.38 Fixed in 0.1.0.39 |
CVE-2024-37228 |
Patchstack | |
| 9.9 Critical | WishList Member X | Remote Code Execution Authenticated Arbitrary PHP Code Execution |
< 3.26.7 Fixed in 3.26.7 |
CVE-2024-37109 |
Patchstack | |
| 9.9 Critical | Consulting Elementor Widgets | Remote Code Execution |
≤ 1.3.0, ≤ 1.2.2 Fixed in 1.3.1 |
CVE-2024-37091 |
Patchstack | |
| 9.0 Critical | Consulting Elementor Widgets | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 1.3.0 Fixed in 1.3.1 |
CVE-2024-37089 |
Patchstack | |
| 9.1 Critical | Squeeze | Arbitrary File Upload |
≤ 1.4 Fixed in 1.4.1 |
CVE-2024-35767 |
Patchstack | |
| 9.8 Critical | JupiterX Core | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 3.3.8 Fixed in 3.4.3 |
CVE-2023-38389 |
Patchstack | |
| 9.8 Critical | Themify - WooCommerce Product Filter | SQL Injection WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter No login needed |
≤ 1.4.9 |
CVE-2024-6027 |
Wordfence | |
| 9.8 Critical | Icegram Express - Email Subscribers, Newsletters and Marketing Automation | SQL Injection Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin No login needed |
≤ 5.7.23 |
CVE-2024-5756 |
Wordfence | |
| 9.8 Critical | Shariff Wrapper | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 4.6.13 |
CVE-2024-4098 |
Wordfence | |
| 10.0 Critical | WP Hotel Booking | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.1.0 |
CVE-2024-3605 |
Wordfence | |
| 9.8 Critical | Lifeline Donation | Authentication Bypass No login needed |
≤ 1.2.6 |
CVE-2024-5432 |
Wordfence | |
| 9.1 Critical | Avada | Broken Access Control Auth. Unrestricted Zip Extraction |
≤ 7.11.1 Fixed in 7.11.2 |
CVE-2023-39312 |
Patchstack | |
| 9.9 Critical | Image Optimizer, Resizer and CDN – Sirv | Arbitrary File Upload Sirv <= 7.2.6 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.2.6 |
CVE-2024-5853 |
Wordfence | |
| 9.8 Critical | Salon Booking System | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 10.2 |
CVE-2024-3229 |
Wordfence | |
| 9.3 Critical | WordPress Picture / Portfolio / Media Gallery | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
≤ 3.0.1 |
CVE-2024-5021 |
Wordfence | |
| 9.8 Critical | Video Gallery – YouTube Playlist, Channel Gallery by YotuWP | Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Unauthenticated Local File Inclusion No login needed |
≤ 1.3.13 |
CVE-2024-4258 |
Wordfence | |
| 9.9 Critical | Woody code snippets – Insert Header Footer Code, AdSense Ads | Remote Code Execution Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution |
≤ 2.5.0 |
CVE-2024-3105 |
Wordfence | |
| 9.8 Critical | WooCommerce - Social Login | PHP Object Injection Social Login <= 2.6.2 - Unauthenticated PHP Object Injection No login needed |
≤ 2.6.2 |
CVE-2024-5871 |
Wordfence | |
| 9.1 Critical | LatePoint | Broken Access Control Missing Authorization and Sensitive Information Exposure via IDOR No login needed |
≤ 4.9.9 |
CVE-2024-2472 |
Wordfence | |
| 9.8 Critical | Where I Was, Where I Will Be | Local File Inclusion Unauthenticated Remote File Inclusion No login needed |
≤ 1.1.1 |
CVE-2024-5577 |
Wordfence | |
| 9.8 Critical | Canto | Local File Inclusion Unauthenticated Remote File Inclusion No login needed |
≤ 3.0.8 |
CVE-2024-4936 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.