WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,301–20,350 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 407 of 589
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium ARS Affiliate Page Plugin ars-affiliate-page Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.2 CVE-2024-12098 Wordfence
6.4 Medium Sell Media Plugin sell-media Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5.8.5 CVE-2024-11777 Wordfence
5.4 Medium Chative Live chat and Chatbot Plugin chative-live-chat-and-chatbot Cross-Site Request Forgery Cross-Site Request Forgery via add_chative_widget_action Function No login needed ≤ 1.1 CVE-2024-12541 Wordfence
7.5 High Woomotiv Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.6.1 CVE-2024-12416 Wordfence
6.4 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll Cross-Site Scripting Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.5 CVE-2024-12528 Wordfence
6.5 Medium Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler Plugin cf7-styler Arbitrary Shortcode Execution CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-12419 Wordfence
6.1 Medium Transporters.io Plugin transportersio Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.1.1 CVE-2024-12557 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
4.9 Medium Timeline Designer Plugin timeline-designer SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.4 CVE-2024-11437 Wordfence
6.4 Medium WP Youtube Gallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9 CVE-2024-12590 Wordfence
6.5 Medium Email Subscribers Plugin SQL Injection Admin+ SQL Injection < 5.7.44 Fixed in 5.7.44 CVE-2024-12311 WPScan
6.1 Medium Icegram Engage Plugin icegram Cross-Site Scripting Author+ Stored XSS No login needed < 3.1.32 Fixed in 3.1.32 CVE-2024-12302 WPScan
6.1 Medium Pods – Custom Content Types and Fields Plugin pods Cross-Site Scripting Custom Content Types and Fields < 3.2.8.1 - Admin+ Stored XSS No login needed < 3.2.8.1 Fixed in 3.2.8.1 CVE-2024-11849 WPScan
6.1 Medium Tourmaster Plugin Cross-Site Scripting Unauthenticated Stored XSS via Room Booking No login needed < 5.3.4 Fixed in 5.3.4 CVE-2024-11356 WPScan
8.8 High UpdraftPlus: WP Backup & Migration Plugin updraftplus PHP Object Injection Unauthenticated PHP Object Injection No login needed 1.23.8 – 1.24.11 CVE-2024-10957 Wordfence
6.5 Medium WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts Plugin wedevs-project-manager SQL Injection Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection ≤ 2.6.16 CVE-2024-12195 Wordfence
6.4 Medium WP Multi Store Locator Plugin wp-multi-store-locator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2024-12475 Wordfence
6.1 Medium WP Social AutoConnect Plugin wp-fb-autoconnect Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 4.6.2 CVE-2024-12279 Wordfence
6.1 Medium Turnkey bbPress by WeaverTheme Plugin weaver-for-bbpress Cross-Site Scripting Reflected Cross-Site Scripting via _wpnonce Parameter No login needed ≤ 1.6.3 CVE-2024-12221 Wordfence
6.4 Medium Taskbuilder – WordPress Project & Task Management Plugin taskbuilder Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode ≤ 3.0.6 CVE-2024-11930 Wordfence
9.9 Critical Dynamics 365 Integration Plugin integration-dynamics Remote Code Execution Authenticated (Contributor+) Remote Code Execution and Arbitrary File Read via Twig Server-Side Template Injection ≤ 1.3.23 CVE-2024-12583 Wordfence
8.8 High Backup Migration Plugin backup-backup PHP Object Injection Unauthenticated PHP Object Injection via 'recursive_unserialize_replace' No login needed ≤ 1.4.6 CVE-2024-10932 Wordfence
6.1 Medium WP Smart Import : Import any XML File to Plugin wp-smart-import Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-12701 Wordfence
5.4 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Cross-Site Request Forgery Giveaways and Contests <= 2.7.1 - Cross-Site Request Forgery via reset_installation Function No login needed ≤ 2.7.1 CVE-2024-12545 Wordfence
6.1 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Reflected Cross-Site Scripting via smc_settings_tab, unattachfixit-action, and woofixit-action Parameters No login needed ≤ 3.23 CVE-2024-11974 Wordfence
6.1 Medium WP Compress – Instant Performance & Speed Optimization Plugin wp-compress-image-optimizer Cross-Site Scripting Instant Performance & Speed Optimization <= 6.30.03 - Reflected Cross-Site Scripting via custom_server Parameter No login needed ≤ 6.30.03 CVE-2024-12047 Wordfence
7.3 High WordPress Popular Posts Plugin wordpress-popular-posts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.0 CVE-2024-11733 Wordfence
4.3 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery Server-Side Request Forgery Authenticated (Subscriber+) Limited Server-Side Request Forgery ≤ 1.0.15 CVE-2024-12237 Wordfence
4.3 Medium WP Job Portal – A Complete Recruitment System for Company or Job Board website Plugin Broken Access Control A Complete Recruitment System for Company or Job Board website <= 2.2.4 - Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 2.2.4 CVE-2024-12132 Wordfence
5.4 Medium Post Teaser Plugin post-teaser Broken Access Control Auth. Broken Access Control ≤ 4.1.5 CVE-2022-45811 Patchstack
5.3 Medium WP Table Manager Plugin wp-table-manager Broken Access Control No login needed ≤ 3.5.2 Fixed in 3.5.3 CVE-2022-47601 Patchstack
5.4 Medium GiveWP Plugin give Broken Access Control Arbitrary Content Deletion ≤ 2.25.1 Fixed in 2.25.2 CVE-2023-23672 Patchstack
5.4 Medium WoodMart Theme woodmart Broken Access Control ≤ 7.2.1 Fixed in 7.2.2 CVE-2023-32240 Patchstack
4.3 Medium ARMember Premium Plugin armember Broken Access Control ≤ 5.9.2 Fixed in 5.9.3 CVE-2023-39994 Patchstack
6.5 Medium Analytify Plugin wp-analytify Privilege Escalation Google Analytics Dashboard plugin <= 4.2.3 - Privilege Escalation No login needed ≤ 4.2.3 Fixed in 4.3.0 CVE-2022-45830 Patchstack
6.5 Medium Putler Connector for WooCommerce Plugin woocommerce-putler-connector Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.12.0 Fixed in 2.13.0 CVE-2023-40327 Patchstack
5.4 Medium 10Web Map Builder for Google Maps Plugin wd-google-maps Broken Access Control Notice Dismissal ≤ 1.0.73 Fixed in 1.0.74 CVE-2023-45272 Patchstack
6.5 Medium IMPress Listings Plugin wp-listings Broken Access Control No login needed ≤ 2.6.2 CVE-2023-45633 Patchstack
4.3 Medium Gallery Images Ape Plugin gallery-images-ape Broken Access Control Image Gallery by Ape Plugin <= 2.2.8 is vulnerable to Broken Access Control ≤ 2.2.8 CVE-2022-41995 Patchstack
4.3 Medium Subscribe to Category Plugin subscribe-to-category Broken Access Control WordPress Subscribe to Category Plugin <= 2.7.4 is vulnerable to Broken Access Control ≤ 2.7.4 CVE-2022-43476 Patchstack
4.3 Medium LuckyWP Scripts Control Plugin luckywp-scripts-control Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2023-47778 Patchstack
4.3 Medium 10WebAnalytics Plugin wd-google-analytics Broken Access Control ≤ 1.2.12 CVE-2023-47807 Patchstack
5.3 Medium Porto Theme - Functionality Plugin porto-functionality Broken Access Control No login needed ≤ 2.12.1 Fixed in 2.12.1 CVE-2023-48739 Patchstack
7.1 High JetEngine Plugin jet-engine Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-48758 Patchstack
4.3 Medium FS Poster Plugin fs-poster Cross-Site Request Forgery No login needed ≤ 6.5.8 Fixed in 6.5.9 CVE-2024-37237 Patchstack
4.3 Medium WP Job Manager - Resume Manager Plugin wp-job-manager-resumes Cross-Site Request Forgery No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-37241 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Request Forgery No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37438 Patchstack
4.3 Medium Schema Lite Theme schema-lite Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2024-37452 Patchstack
5.4 Medium BuddyBoss Theme buddyboss-theme Cross-Site Request Forgery No login needed ≤ 2.4.61 Fixed in 2.5.01 CVE-2024-37925 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only