WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,001–2,050 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 41 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Restaurant and Cafe Theme restaurant-and-cafe Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-34379 Patchstack
5.4 Medium Stop Spammers Security | Block Spam Users, Comments, Forms Plugin Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via sfs_process No login needed ≤ 2024.4 CVE-2023-7065 Wordfence
4.3 Medium CM Tooltip Glossary – Powerful Glossary Plugin enhanced-tooltipglossary Cross-Site Request Forgery Powerful Glossary Plugin <= 4.2.11 - Cross-Site Request Forgery No login needed ≤ 4.2.11 CVE-2024-4086 Wordfence
4.3 Medium SVS Pricing Tables Plugin svs-pricing-tables Cross-Site Request Forgery Cross-Site Request Forgery to Pricing Table Deletion No login needed ≤ 1.0.4 CVE-2024-2960 Wordfence
4.3 Medium Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Request Forgery No login needed ≤ 1.8.9 CVE-2024-1415 Wordfence
6.1 Medium Delete Custom Fields Plugin delete-custom-fields Cross-Site Request Forgery Cross-Site Request Forgery to Post Meta Deletion No login needed ≤ 0.3.1 CVE-2024-0613 Wordfence
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 3.0.1 CVE-2024-3215 Wordfence
4.3 Medium SVS Pricing Tables Plugin svs-pricing-tables Cross-Site Request Forgery Cross-Site Request Forgery to Pricing Table Edit/Creation No login needed ≤ 1.0.4 CVE-2024-2959 Wordfence
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.8.0 CVE-2024-3047 Wordfence
4.3 Medium 5280 Bootstrap Modal Contact Form Plugin 5280-bootstrap-modal-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Delete Messages No login needed ≤ 1.0 CVE-2024-0847 Wordfence
4.3 Medium Easy Restaurant Table Booking Plugin fd-elementor-imagebox Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2024-4083 Wordfence
8.3 High ZD YouTube FLV Player Plugin zd-youtube-flv-player Server-Side Request Forgery No login needed ≤ 1.2.6 CVE-2024-2663 Wordfence
6.4 Medium Google Doc Embedder Plugin google-document-embedder Server-Side Request Forgery Authenticated (Contributor+) Blind Server Side Request Forgery ≤ 2.6.4 CVE-2024-0216 Wordfence
5.0 Medium Knowledge Base documentation & wiki plugin – BasePress Plugin basepress Server-Side Request Forgery ≤ 2.16.1 Fixed in 2.16.2.1 CVE-2024-33590 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 7.1.17 CVE-2024-33634 Patchstack
4.4 Medium Auto Featured Image (Auto Post Thumbnail) Plugin auto-post-thumbnail Server-Side Request Forgery ≤ 4.0.0 CVE-2024-33629 Patchstack
4.4 Medium Absolutely Glamorous Custom Admin Plugin ag-custom-admin Server-Side Request Forgery Custom Dashboard & Login Page plugin <= 7.2.2 - Server Side Request Forgery (SSRF) ≤ 7.2.2 CVE-2024-33627 Patchstack
7.1 High Regenerate post permalink Plugin regenerate-post-permalinks Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed ≤ 1.0.3 CVE-2024-33681 Patchstack
5.4 Medium Piotnet Addons For Elementor Pro Plugin Cross-Site Request Forgery No login needed ≤ 7.1.17 CVE-2024-33632 Patchstack
4.3 Medium Teluro Theme teluro Cross-Site Request Forgery No login needed ≤ 1.0.31 Fixed in 1.0.36 CVE-2024-33688 Patchstack
4.3 Medium Radio Station Plugin radio-station Cross-Site Request Forgery No login needed ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-33689 Patchstack
4.3 Medium Financio Theme financio Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-33690 Patchstack
4.3 Medium OptinMonster Plugin optinmonster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Notice Dismissal No login needed ≤ 2.15.3 Fixed in 2.16.0 CVE-2024-33691 Patchstack
4.3 Medium Contact Form 7 Extension For Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Request Forgery No login needed ≤ 0.5.70 CVE-2024-33677 Patchstack
4.3 Medium ClickCease Click Fraud Protection Plugin clickcease-click-fraud-protection Cross-Site Request Forgery No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-33678 Patchstack
4.3 Medium FameTheme Demo Importer Plugin famethemes-demo-importer Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-33679 Patchstack
5.4 Medium MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.2 CVE-2024-33680 Patchstack
5.4 Medium WP GDPR Compliance Plugin wp-gdpr-compliance Cross-Site Request Forgery No login needed ≤ 2.0.23 CVE-2024-33682 Patchstack
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.3 CVE-2024-33683 Patchstack
5.4 Medium Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-33638 Patchstack
4.3 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Request Forgery No login needed ≤ 1.2.4 CVE-2024-33650 Patchstack
5.4 Medium MF Gig Calendar Plugin mf-gig-calendar Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2024-33651 Patchstack
5.4 Medium Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-33592 Patchstack
4.3 Medium YITH WooCommerce Compare Plugin yith-woocommerce-compare Cross-Site Request Forgery No login needed ≤ 2.37.0 Fixed in 2.38.0 CVE-2024-32699 Patchstack
4.3 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Cross-Site Request Forgery No login needed ≤ 2.11.0 Fixed in 2.11.1 CVE-2024-32728 Patchstack
4.3 Medium Royal Elementor Kit Theme royal-elementor-kit Cross-Site Request Forgery No login needed ≤ 1.0.116 Fixed in 1.0.117 CVE-2024-32773 Patchstack
5.4 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 Fixed in 3.0 CVE-2024-32793 Patchstack
4.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 Fixed in 3.0 CVE-2024-32794 Patchstack
4.3 Medium WPCal.io – Easy Meeting Scheduler Plugin wpcal Cross-Site Request Forgery No login needed ≤ 0.9.5.8 Fixed in 0.9.5.9 CVE-2024-32795 Patchstack
4.3 Medium Headline Analyzer Plugin headline-analyzer Cross-Site Request Forgery No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2024-32806 Patchstack
4.3 Medium WP ADA Compliance Check Basic Plugin wp-ada-compliance-check-basic Cross-Site Request Forgery No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-32947 Patchstack
7.1 High The Pack Elementor addons Plugin the-pack-addon Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 2.0.8.3 Fixed in 2.0.8.4 CVE-2024-32785 Patchstack
7.1 High Seers Plugin seers-cookie-consent-banner-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 8.1.0 Fixed in 8.1.1 CVE-2024-32789 Patchstack
4.9 Medium The Pack Elementor addons Plugin the-pack-addon Server-Side Request Forgery ≤ 2.0.8.2 Fixed in 2.0.8.3 CVE-2024-32718 Patchstack
4.9 Medium Embed Google Photos album Plugin embed-google-photos-album-easily Server-Side Request Forgery ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-32775 Patchstack
6.4 Medium SuperFaktura WooCommerce Plugin woocommerce-superfaktura Server-Side Request Forgery ≤ 1.40.3 Fixed in 1.40.4 CVE-2024-32803 Patchstack
5.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Server-Side Request Forgery ≤ 4.0.11 Fixed in 4.0.12 CVE-2024-32812 Patchstack
4.9 Medium Culqi Plugin culqi-checkout Server-Side Request Forgery ≤ 3.0.14 Fixed in 3.0.15 CVE-2024-32819 Patchstack
4.9 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Server-Side Request Forgery ≤ 7.5.43.7212 Fixed in 7.5.45.7212 CVE-2024-32955 Patchstack
6.1 Medium Import WP Plugin Server-Side Request Forgery Admin+ Server-side Request Forgery < 2.13.1 Fixed in 2.13.1 CVE-2023-7253 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only