WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1,951–2,000 of 2,150 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.0 Critical | CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More | PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed |
≤ 4.4.1 |
CVE-2024-4371 |
Wordfence | |
| 9.8 Critical | Web Directory Free | SQL Injection Unauthenticated SQL Injection No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-3552 |
WPScan | |
| 10.0 Critical | Dokan Pro | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 3.10.3 |
CVE-2024-3922 |
Wordfence | |
| 9.8 Critical | InstaWP Connect – 1-click WP Staging & Migration | Broken Access Control Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation No login needed |
≤ 0.1.0.38 |
CVE-2024-4898 |
Wordfence | |
| 9.9 Critical | Blog2Social: Social Media Auto Post & Scheduler | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 7.4.1 |
CVE-2024-3549 |
Wordfence | |
| 10.0 Critical | BuddyPress Cover | Arbitrary File Upload No login needed |
≤ 2.1.4.2 |
CVE-2024-35746 |
Patchstack | |
| 9.0 Critical | MegaMenu | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 2.3.12 Fixed in 2.3.13 |
CVE-2024-35677 |
Patchstack | |
| 9.9 Critical | Advanced Custom Fields PRO | Local File Inclusion Contributor+ Local File Inclusion |
< 6.2.10 Fixed in 6.2.10 |
CVE-2024-34762 |
Patchstack | |
| 9.1 Critical | Barcode Scanner with Inventory & Order Manager | Broken Access Control Unauthenticated Broken Access Control No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-33565 |
Patchstack | |
| 9.8 Critical | Bricksforge | Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed |
≤ 2.0.17 Fixed in 2.1.1 |
CVE-2024-31244 |
Patchstack | |
| 9.8 Critical | ArForms | Remote Code Execution Unauthenticated RCE No login needed |
< 6.6 Fixed in 6.6 |
CVE-2024-4620 |
WPScan | |
| 9.9 Critical | Quiz And Survey Master – Best Quiz, Exam and Survey | SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection |
≤ 9.0.1 |
CVE-2024-3592 |
Wordfence | |
| 9.1 Critical | Startklar Elementor Addons | Path Traversal Unauthenticated Path Traversal to Arbitrary Directory Deletion No login needed |
≤ 1.7.15 |
CVE-2024-5153 |
Wordfence | |
| 9.8 Critical | Email Subscribers by Icegram Express | SQL Injection Unauthenticated SQL Injection via hash No login needed |
≤ 5.7.20 |
CVE-2024-4295 |
Wordfence | |
| 9.8 Critical | Userpro | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 5.1.8 Fixed in 5.1.9 |
CVE-2024-35700 |
Patchstack | |
| 9.6 Critical | Easy Digital Downloads – Recent Purchases | Local File Inclusion Recent Purchases plugin <= 1.0.2 - Remote File Inclusion No login needed |
≤ 1.0.2 |
CVE-2024-35629 |
Patchstack | |
| 9.1 Critical | Dextaz Ping | Remote Code Execution |
≤ 0.65 |
CVE-2024-34792 |
Patchstack | |
| 9.0 Critical | Stockholm | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 9.6 Fixed in 9.7 |
CVE-2024-34551 |
Patchstack | |
| 9.0 Critical | XStore | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 9.3.8 Fixed in 9.3.9 |
CVE-2024-33560 |
Patchstack | |
| 10.0 Critical | Bricks Builder | Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed |
≤ 1.9.6 Fixed in 1.9.6.1 |
CVE-2024-25600 |
Patchstack | |
| 9.1 Critical | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Arbitrary File Upload Unrestricted Zip Extraction |
≤ 1.5.66 Fixed in 1.5.67 |
CVE-2023-33930 |
Patchstack | |
| 9.1 Critical | The Events Calendar | Cross-Site Scripting Reflected XSS No login needed |
< 6.4.0.1 Fixed in 6.4.0.1 |
CVE-2024-4180 |
WPScan | |
| 9.8 Critical | Social Login Lite For WooCommerce | Authentication Bypass No login needed |
≤ 1.6.0 |
CVE-2024-4552 |
Wordfence | |
| 10.0 Critical | wpDataTables - Tables & Table Charts (Premium) | SQL Injection Tables & Table Charts (Premium) <= 6.3.1 - Unauthenticated SQL Injection No login needed |
≤ 6.3.1 |
CVE-2024-3820 |
Wordfence | |
| 9.9 Critical | wpForo Forum | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.3.3 |
CVE-2024-3200 |
Wordfence | |
| 9.1 Critical | WP STAGING WordPress Backup Plugin – Migration Backup Restore | Arbitrary File Upload Migration Backup Restore <= 3.4.3 - Authenticated (Admin+) Arbitrary File Upload |
≤ 3.4.3 |
CVE-2024-3412 |
Wordfence | |
| 9.1 Critical | Site Reviews | Authentication Bypass IP Spoofing No login needed |
< 7.0.0 Fixed in 7.0.0 |
CVE-2024-3050 |
WPScan | |
| 9.8 Critical | Login with phone number | Authentication Bypass Authentication Bypass due to Missing Empty Value Check No login needed |
≤ 1.7.26 |
CVE-2024-5150 |
Wordfence | |
| 9.8 Critical | Pie Register - Social Sites Login (Add on) | Authentication Bypass Social Sites Login (Add on) <= 1.7.7 - Authentication Bypass No login needed |
≤ 1.7.7 |
CVE-2024-4544 |
Wordfence | |
| 9.8 Critical | Hash Form – Drag & Drop Form Builder | Arbitrary File Upload Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution No login needed |
≤ 1.1.0 |
CVE-2024-5084 |
Wordfence | |
| 9.8 Critical | Country State City Dropdown CF7 | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.7.2 |
CVE-2024-3495 |
Wordfence | |
| 9.8 Critical | WPZOOM Addons for Elementor (Templates, Widgets) | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 1.1.37 |
CVE-2024-5147 |
Wordfence | |
| 9.8 Critical | Business Directory Plugin – Easy Listing Directories | SQL Injection Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter No login needed |
≤ 6.4.2 |
CVE-2024-4443 |
Wordfence | |
| 9.1 Critical | Salon booking system | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 9.9 |
CVE-2024-4442 |
Wordfence | |
| 9.8 Critical | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | Broken Access Control Missing Authorization to Settings Update and Limited Privilege Escalation No login needed |
≤ 5.1.16 |
CVE-2024-2771 |
Wordfence | |
| 10.0 Critical | ActiveDEMAND | Arbitrary File Upload No login needed |
≤ 0.2.41 Fixed in 0.2.42 |
CVE-2024-32809 |
Patchstack | |
| 9.8 Critical | Simple Registration for WooCommerce | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.5.6 |
CVE-2024-32511 |
Patchstack | |
| 9.8 Critical | Demo My | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.0.9.1 Fixed in 1.1.0 |
CVE-2024-31290 |
Patchstack | |
| 9.0 Critical | Rehub | Local File Inclusion Unauthenticated Local File Inclusion No login needed |
≤ 19.6.1 Fixed in 19.6.2 |
CVE-2024-31231 |
Patchstack | |
| 9.8 Critical | WholesaleX | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.3.2 Fixed in 1.3.3 |
CVE-2024-30542 |
Patchstack | |
| 9.3 Critical | Automatic | Path Traversal Unauthenticated Arbitrary File Download and SSRF No login needed |
≤ 3.92.0 Fixed in 3.92.1 |
CVE-2024-27954 |
Patchstack | |
| 9.8 Critical | Masteriyo - LMS | Privilege Escalation No login needed |
≤ 1.7.2 Fixed in 1.7.3 |
CVE-2024-24882 |
Patchstack | |
| 9.8 Critical | SalesKing | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.6.15 Fixed in 1.6.30 |
CVE-2024-22157 |
Patchstack | |
| 9.8 Critical | WP Frontend Profile | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2023-51483 |
Patchstack | |
| 9.8 Critical | Local Delivery Drivers for WooCommerce | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 1.9.0 Fixed in 1.9.1 |
CVE-2023-51481 |
Patchstack | |
| 9.8 Critical | WP MLM Unilevel | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 4.0 |
CVE-2023-51476 |
Patchstack | |
| 9.8 Critical | WebinarIgnition | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 3.05.0 Fixed in 3.05.1 |
CVE-2023-51424 |
Patchstack | |
| 9.8 Critical | XStore Core | Privilege Escalation Unauthenticated Account Takeover No login needed |
≤ 5.3.8 Fixed in 5.3.9 |
CVE-2024-33552 |
Patchstack | |
| 9.8 Critical | Barcode Scanner with Inventory & Order Manager | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-33567 |
Patchstack | |
| 9.9 Critical | Customify Site Library | Remote Code Execution |
≤ 0.0.9 |
CVE-2024-33644 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.