WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 19,551–19,600 of 29,413 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | String Locator | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 2.6.6 |
CVE-2024-10936 |
Wordfence | |
| 5.3 Medium | 1003 Mortgage Application | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 1.87 |
CVE-2024-13536 |
Wordfence | |
| 5.5 Medium | WP All Import Pro | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.9.7 |
CVE-2024-8722 |
Wordfence | |
| 9.8 Critical | Adifier System | Privilege Escalation Unauthenticated Arbitrary Password Reset No login needed |
≤ 3.1.7 |
CVE-2024-13375 |
Wordfence | |
| 7.5 High | The Ultimate WordPress Toolkit – WP Extended | SQL Injection WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module No login needed |
≤ 3.0.12 |
CVE-2024-13184 |
Wordfence | |
| 6.4 Medium | Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings | Cross-Site Scripting AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.3 |
CVE-2024-13392 |
Wordfence | |
| 6.4 Medium | Utilities for MTG | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-13433 |
Wordfence | |
| 6.4 Medium | Jet Engine | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter |
≤ 3.6.2 |
CVE-2025-0369 |
Wordfence | |
| 6.4 Medium | Video Share VOD – Turnkey Video Site Builder Script | Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.31 |
CVE-2024-13393 |
Wordfence | |
| 6.4 Medium | Picture Gallery – Frontend Image Uploads, AJAX Photo List | Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode |
≤ 1.5.22 |
CVE-2024-12696 |
Wordfence | |
| 4.4 Medium | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) | Cross-Site Scripting Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title |
≤ 3.3.2 |
CVE-2024-13517 |
Wordfence | |
| 6.4 Medium | JSM Screenshot Machine Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.0 |
CVE-2024-13385 |
Wordfence | |
| 4.4 Medium | MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting |
≤ 1.9.80 |
CVE-2024-13519 |
Wordfence | |
| 6.1 Medium | WP Abstracts | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 2.7.2 |
CVE-2024-12385 |
Wordfence | |
| 4.3 Medium | Buzz Club – Night Club, DJ and Music Festival Event | Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update |
≤ 2.0.4 |
CVE-2025-0515 |
Wordfence | |
| 4.3 Medium | ShipWorks Connector for Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Service Password/Username Update No login needed |
≤ 5.2.5 |
CVE-2024-13317 |
Wordfence | |
| 6.1 Medium | Webcamconsult | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.5.0 |
CVE-2024-13432 |
Wordfence | |
| 6.4 Medium | MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet | Cross-Site Scripting Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.9.29 |
CVE-2024-13391 |
Wordfence | |
| 5.4 Medium | List category posts | Cross-Site Scripting Author+ Stored XSS |
< 0.90.3 Fixed in 0.90.3 |
CVE-2024-9020 |
WPScan | |
| 7.5 High | Ultimate Member | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.9.1 |
CVE-2025-0308 |
Wordfence | |
| 6.1 Medium | Kubio AI Page Builder | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3.5 |
CVE-2024-13516 |
Wordfence | |
| 5.3 Medium | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership | Information Disclosure User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.9.1 - Information Exposure No login needed |
≤ 2.9.1 |
CVE-2025-0318 |
Wordfence | |
| 6.1 Medium | Image Source Control Lite – Show Image Credits and Captions | Cross-Site Scripting Show Image Credits and Captions <= 2.28.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.28.0 |
CVE-2024-13515 |
Wordfence | |
| 4.4 Medium | Podlove Podcast Publisher | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Feed Name |
≤ 4.1.25 |
CVE-2025-0554 |
Wordfence | |
| 5.3 Medium | Evergreen Content Poster – Auto Post and Schedule Your Best Content to Social Media | Broken Access Control Auto Post and Schedule Your Best Content to Social Media <= 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 1.4.4 |
CVE-2024-12071 |
Wordfence | |
| 5.4 Medium | GravityForms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'style_settings' parameter No login needed |
2.9.0.1 – 2.9.1.3 |
CVE-2024-13378 |
Wordfence | |
| 7.2 High | GravityForms | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'alt' parameter No login needed |
≤ 2.9.1.3 |
CVE-2024-13377 |
Wordfence | |
| 5.3 Medium | WP Hotel Booking | Broken Access Control Missing Authorization No login needed |
≤ 2.1.5 |
CVE-2024-12370 |
Wordfence | |
| 6.1 Medium | Proofreading | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.1.1 |
CVE-2024-12466 |
Wordfence | |
| 4.4 Medium | RSS Icon Widget | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 5.2 |
CVE-2024-12203 |
Wordfence | |
| 5.3 Medium | Moving Users | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.05 |
CVE-2024-12637 |
Wordfence | |
| 6.4 Medium | MyBookProgress by Stormhill Media | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via book Parameter |
≤ 1.0.8 |
CVE-2024-12598 |
Wordfence | |
| 6.4 Medium | quote-posttype-plugin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.2 |
CVE-2024-13386 |
Wordfence | |
| 6.5 Medium | Sandbox | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sandbox Download |
≤ 0.4 |
CVE-2024-13367 |
Wordfence | |
| 6.1 Medium | Sandbox | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.4 |
CVE-2024-13366 |
Wordfence | |
| 6.4 Medium | Glofox Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6 |
CVE-2024-12508 |
Wordfence | |
| 7.5 High | Advanced File Manager | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
5.2.12 – 5.2.13 |
CVE-2024-13333 |
Wordfence | |
| 6.5 Medium | Eventer | Path Traversal Authenticated (Subscriber+) Arbitrary File Read |
≤ 3.9.7 |
CVE-2024-10799 |
Wordfence | |
| 6.4 Medium | Checkout for PayPal | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.32 |
CVE-2024-13398 |
Wordfence | |
| 6.1 Medium | WP Inventory Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3.2 |
CVE-2024-13434 |
Wordfence | |
| 6.4 Medium | Payment Button for PayPal | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.3.35 |
CVE-2024-13401 |
Wordfence | |
| 6.5 Medium | SOCIAL.NINJA | Cross-Site Scripting |
≤ 0.2 |
CVE-2025-23907 |
Patchstack | |
| 6.5 Medium | Metaphor Widgets | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 2.4 |
CVE-2025-23816 |
Patchstack | |
| 5.3 Medium | Copy Move Posts | Broken Access Control No login needed |
≤ 1.6 |
CVE-2025-23764 |
Patchstack | |
| 7.1 High | root Cookie | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.6 |
CVE-2025-23815 |
Patchstack | |
| 7.1 High | Auto FTP | Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-23793 |
Patchstack | |
| 5.4 Medium | Woo Tuner | Broken Access Control |
≤ 0.1.2 |
CVE-2025-23761 |
Patchstack | |
| 7.1 High | Chatter | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0.1 |
CVE-2025-23760 |
Patchstack | |
| 4.3 Medium | Sur.ly | Broken Access Control |
≤ 3.0.3 |
CVE-2025-23957 |
Patchstack | |
| 6.5 Medium | Kopa Nictitate Toolkit | Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-23965 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.