WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,201–20,250 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 405 of 589
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes Plugin elex-bulk-edit-products-prices-attributes-for-woocommerce-basic SQL Injection ≤ 1.4.9 Fixed in 1.5.0 CVE-2025-22352 Patchstack
7.6 High Contact Form 7 Database – CFDB7 Plugin advanced-cf7-database SQL Injection CFDB7 plugin <= 1.0.0 - SQL Injection ≤ 1.0.0 CVE-2025-22351 Patchstack
7.1 High BVD Easy Gallery Manager Plugin bvd-easy-gallery-manager Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-22353 Patchstack
7.1 High Kikx Simple Post Author Filter Plugin sa-post-author-filter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-22355 Patchstack
7.1 High Target Notifications Plugin target-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-22357 Patchstack
7.1 High SyncFields Plugin syncfields Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-22359 Patchstack
7.1 High Wp advertising management Plugin advertising-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-22358 Patchstack
6.5 Medium WPAchievements Free Plugin wpachievements-free Cross-Site Scripting ≤ 1.2.0 CVE-2025-22362 Patchstack
7.5 High Ach Invoice App Plugin ach-invoice-app Local File Inclusion No login needed ≤ 1.0.1 CVE-2025-22364 Patchstack
6.4 Medium Service Box Plugin service-boxs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2024-12699 Wordfence
7.5 High MIPL WC Multisite Sync Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.1.5 CVE-2024-12152 Wordfence
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Missing Authorization to Authenticated (Subscriber+) Limited Path Traversal ≤ 4.24.15 CVE-2024-12719 Wordfence
6.4 Medium Coupon Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-12516 Wordfence
8.8 High Croma Music Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update in ironMusic_ajax ≤ 3.6 CVE-2024-12202 Wordfence
6.1 Medium Booking Calendar and Booking Calendar Pro <= Multiple Versions Plugin booking-calendar Cross-Site Scripting Reflected Cross-Site Scripting via 'calendar_id' No login needed ≤ 3.2.19, ≤ 11.2.19 CVE-2024-12077 Wordfence
5.3 Medium Export Import Menus Plugin Broken Access Control Missing Authorization to Unauthenticated Menu Export No login needed ≤ 1.9.1 CVE-2024-10866 Wordfence
4.3 Medium Aurum - WordPress & WooCommerce Shopping Theme Broken Access Control WordPress & WooCommerce Shopping Theme <= 4.0.2 - Missing Authorization to Authenticated (Subscriber+) Demo Content Import ≤ 4.0.2 CVE-2024-12781 Wordfence
6.4 Medium Marketplace Items Plugin marketplace-items Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.5 CVE-2024-12437 Wordfence
6.4 Medium WP jQuery DataTable Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.0.1 CVE-2024-12499 Wordfence
6.4 Medium Bootstrap Blocks for WP Editor v2 Plugin wp-editor-bootstrap-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5.0 CVE-2024-12495 Wordfence
6.4 Medium Solar Wizard Lite Plugin solar-wizard-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.4 CVE-2024-11764 Wordfence
6.4 Medium Master Addons -- Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip Module ≤ 2.0.6.7 CVE-2024-9502 Wordfence
6.1 Medium Estatik Mortgage Calculator Plugin estatik-mortgage-calculator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.11 CVE-2024-9354 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Sina Image Differ ≤ 3.5.91 CVE-2024-12624 Wordfence
8.8 High SMS Alert Order Notifications – WooCommerce Plugin sms-alert Broken Access Control WooCommerce <= 3.7.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.7.6 CVE-2024-11725 Wordfence
5.3 Medium Passster – Password Protect Pages and Content Plugin content-protector Information Disclosure Password Protect Pages and Content <= 4.2.10 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 4.2.10 CVE-2024-11282 Wordfence
4.8 Medium Category Posts Widget Plugin Cross-Site Scripting Admin+ Stored XSS < 4.9.18 Fixed in 4.9.18 CVE-2024-9638 WPScan
4.8 Medium WordPress Auction Plugin Cross-Site Scripting Editor+ Stored XSS ≤ 3.7 CVE-2024-8857 WPScan
9.8 Critical WordPress Auction Plugin SQL Injection Editor+ SQL Injection No login needed ≤ 3.7 CVE-2024-8855 WPScan
5.3 Medium Tabs Shortcode Plugin Cross-Site Scripting Contributor+ XSS via Shortcode No login needed ≤ 2.0.2 CVE-2024-11606 WPScan
2.7 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.31 Fixed in 1.15.31 CVE-2024-10562 WPScan
2.7 Low Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10102 WPScan
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed ≤ 2.0 CVE-2024-12384 Wordfence
6.4 Medium SweepWidget Contests, Giveaways, Photo Contests, Competitions Plugin sweepwidget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-11756 Wordfence
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
6.4 Medium Candifly Plugin candifly Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.6 CVE-2024-12440 Wordfence
6.4 Medium Geo Content Plugin geo-targetly-geo-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0 CVE-2024-11887 Wordfence
7.1 High JoomSport Plugin joomsport-sports-league-results-management Cross-Site Scripting Reflected Cross-Site Scripting via page No login needed ≤ 5.6.17 CVE-2024-12633 Wordfence
8.8 High Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator Plugin post-saint Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.3.1 CVE-2024-12471 Wordfence
6.4 Medium Meteor Slides Plugin meteor-slides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.7 CVE-2024-12073 Wordfence
6.1 Medium WooCommerce Digital Content Delivery (incl. DRM) – FlickRocket Plugin woocommerce-digital-content-delivery-with-drm-flickrocket Cross-Site Scripting FlickRocket <= 4.75 - Reflected Cross-Site Scripting No login needed ≤ 4.75 CVE-2024-12438 Wordfence
6.1 Medium Binary MLM Woocommerce Plugin woo-binary-mlm Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-12383 Wordfence
6.4 Medium Social Rocket Plugin social-rocket Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.4 CVE-2024-9702 Wordfence
8.6 High Host PHP Info Plugin host-php-info Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.0.4 CVE-2024-12535 Wordfence
6.4 Medium Chatroll Live Chat Plugin chatroll-live-chat Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5.0 CVE-2024-12464 Wordfence
6.4 Medium Marketplace Items Plugin marketplace-items Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'marketplace' Shortcode ≤ 1.5.5 CVE-2024-12439 Wordfence
6.1 Medium SmartEmailing.cz Plugin smartemailing Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-12261 Wordfence
7.5 High Error Log Viewer By WP Guru Plugin error-log-viewer-wp Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed ≤ 1.0.1.3 CVE-2024-12849 Wordfence
6.1 Medium Store credit / Gift cards for woocommerce Plugin store-credit-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.49.46 CVE-2024-11369 Wordfence
6.4 Medium App Embed Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.2 CVE-2024-11749 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only