WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1,951–2,000 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 40 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.0 Critical CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.1 CVE-2024-4371 Wordfence
9.8 Critical Web Directory Free Plugin web-directory-free SQL Injection Unauthenticated SQL Injection No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-3552 WPScan
10.0 Critical Dokan Pro Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.10.3 CVE-2024-3922 Wordfence
9.8 Critical InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Broken Access Control Missing Authorization to Unauthenticated API setup/Arbitrary Options Update/Administrative User Creation No login needed ≤ 0.1.0.38 CVE-2024-4898 Wordfence
9.9 Critical Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 7.4.1 CVE-2024-3549 Wordfence
10.0 Critical BuddyPress Cover Plugin bp-cover Arbitrary File Upload No login needed ≤ 2.1.4.2 CVE-2024-35746 Patchstack
9.0 Critical MegaMenu Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.3.12 Fixed in 2.3.13 CVE-2024-35677 Patchstack
9.9 Critical Advanced Custom Fields PRO Plugin Local File Inclusion Contributor+ Local File Inclusion < 6.2.10 Fixed in 6.2.10 CVE-2024-34762 Patchstack
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33565 Patchstack
9.8 Critical Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31244 Patchstack
9.8 Critical ArForms Plugin Remote Code Execution Unauthenticated RCE No login needed < 6.6 Fixed in 6.6 CVE-2024-4620 WPScan
9.9 Critical Quiz And Survey Master – Best Quiz, Exam and Survey Plugin quiz-master-next SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection ≤ 9.0.1 CVE-2024-3592 Wordfence
9.1 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Path Traversal Unauthenticated Path Traversal to Arbitrary Directory Deletion No login needed ≤ 1.7.15 CVE-2024-5153 Wordfence
9.8 Critical Email Subscribers by Icegram Express Plugin email-subscribers SQL Injection Unauthenticated SQL Injection via hash No login needed ≤ 5.7.20 CVE-2024-4295 Wordfence
9.8 Critical Userpro Plugin userpro Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.1.8 Fixed in 5.1.9 CVE-2024-35700 Patchstack
9.6 Critical Easy Digital Downloads – Recent Purchases Plugin edd-recent-purchases Local File Inclusion Recent Purchases plugin <= 1.0.2 - Remote File Inclusion No login needed ≤ 1.0.2 CVE-2024-35629 Patchstack
9.1 Critical Dextaz Ping Plugin dextaz-ping Remote Code Execution ≤ 0.65 CVE-2024-34792 Patchstack
9.0 Critical Stockholm Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 9.6 Fixed in 9.7 CVE-2024-34551 Patchstack
9.0 Critical XStore Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33560 Patchstack
10.0 Critical Bricks Builder Theme Remote Code Execution Unauthenticated Remote Code Execution (RCE) No login needed ≤ 1.9.6 Fixed in 1.9.6.1 CVE-2024-25600 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
9.1 Critical The Events Calendar Plugin the-events-calendar Cross-Site Scripting Reflected XSS No login needed < 6.4.0.1 Fixed in 6.4.0.1 CVE-2024-4180 WPScan
9.8 Critical Social Login Lite For WooCommerce Plugin social-login-lite-for-woocommerce Authentication Bypass No login needed ≤ 1.6.0 CVE-2024-4552 Wordfence
10.0 Critical wpDataTables - Tables & Table Charts (Premium) Plugin SQL Injection Tables & Table Charts (Premium) <= 6.3.1 - Unauthenticated SQL Injection No login needed ≤ 6.3.1 CVE-2024-3820 Wordfence
9.9 Critical wpForo Forum Plugin wpforo SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3.3 CVE-2024-3200 Wordfence
9.1 Critical WP STAGING WordPress Backup Plugin – Migration Backup Restore Plugin wp-staging Arbitrary File Upload Migration Backup Restore <= 3.4.3 - Authenticated (Admin+) Arbitrary File Upload ≤ 3.4.3 CVE-2024-3412 Wordfence
9.1 Critical Site Reviews Plugin site-reviews Authentication Bypass IP Spoofing No login needed < 7.0.0 Fixed in 7.0.0 CVE-2024-3050 WPScan
9.8 Critical Login with phone number Plugin login-with-phone-number Authentication Bypass Authentication Bypass due to Missing Empty Value Check No login needed ≤ 1.7.26 CVE-2024-5150 Wordfence
9.8 Critical Pie Register - Social Sites Login (Add on) Plugin pie-register Authentication Bypass Social Sites Login (Add on) <= 1.7.7 - Authentication Bypass No login needed ≤ 1.7.7 CVE-2024-4544 Wordfence
9.8 Critical Hash Form – Drag & Drop Form Builder Plugin hash-form Arbitrary File Upload Drag & Drop Form Builder <= 1.1.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution No login needed ≤ 1.1.0 CVE-2024-5084 Wordfence
9.8 Critical Country State City Dropdown CF7 Plugin country-state-city-auto-dropdown SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.7.2 CVE-2024-3495 Wordfence
9.8 Critical WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.1.37 CVE-2024-5147 Wordfence
9.8 Critical Business Directory Plugin – Easy Listing Directories Plugin business-directory-plugin SQL Injection Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter No login needed ≤ 6.4.2 CVE-2024-4443 Wordfence
9.1 Critical Salon booking system Plugin salon-booking-system Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 9.9 CVE-2024-4442 Wordfence
9.8 Critical Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Settings Update and Limited Privilege Escalation No login needed ≤ 5.1.16 CVE-2024-2771 Wordfence
10.0 Critical ActiveDEMAND Plugin activedemand Arbitrary File Upload No login needed ≤ 0.2.41 Fixed in 0.2.42 CVE-2024-32809 Patchstack
9.8 Critical Simple Registration for WooCommerce Plugin woocommerce-simple-registration Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.6 CVE-2024-32511 Patchstack
9.8 Critical Demo My Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.0.9.1 Fixed in 1.1.0 CVE-2024-31290 Patchstack
9.0 Critical Rehub Theme Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31231 Patchstack
9.8 Critical WholesaleX Plugin wholesalex Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-30542 Patchstack
9.3 Critical Automatic Plugin Path Traversal Unauthenticated Arbitrary File Download and SSRF No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27954 Patchstack
9.8 Critical Masteriyo - LMS Plugin learning-management-system Privilege Escalation No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-24882 Patchstack
9.8 Critical SalesKing Plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22157 Patchstack
9.8 Critical WP Frontend Profile Plugin wp-front-end-profile Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2023-51483 Patchstack
9.8 Critical Local Delivery Drivers for WooCommerce Plugin local-delivery-drivers-for-woocommerce Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2023-51481 Patchstack
9.8 Critical WP MLM Unilevel Plugin wp-mlm Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 4.0 CVE-2023-51476 Patchstack
9.8 Critical WebinarIgnition Plugin webinar-ignition Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.05.0 Fixed in 3.05.1 CVE-2023-51424 Patchstack
9.8 Critical XStore Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33552 Patchstack
9.8 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33567 Patchstack
9.9 Critical Customify Site Library Plugin customify-sites Remote Code Execution ≤ 0.0.9 CVE-2024-33644 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only