WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,001–2,050 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 41 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical HT Mega Plugin ht-mega-for-elementor Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-37999 Patchstack
9.0 Critical LWS Affiliation Plugin lws-affiliation Local File Inclusion No login needed ≤ 2.2.6 Fixed in 2.3 CVE-2023-32297 Patchstack
9.8 Critical Woodmart Core Plugin Privilege Escalation No login needed ≤ 1.0.36 Fixed in 1.0.37 CVE-2023-32244 Patchstack
9.8 Critical Houzez Theme Privilege Escalation No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2023-26540 Patchstack
9.8 Critical Houzez Login Register Plugin Privilege Escalation No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2023-26009 Patchstack
9.8 Critical WatchTowerHQ Plugin watchtowerhq Privilege Escalation No login needed ≤ 3.6.16 Fixed in 3.6.17 CVE-2023-25701 Patchstack
9.1 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Arbitrary File Upload Best Help Desk & Support Plugin plugin <= 2.7.7 - Arbitrary File Upload ≤ 2.7.7 Fixed in 2.7.8 CVE-2023-25444 Patchstack
9.9 Critical MainWP Code Snippets Extension Plugin Remote Code Execution Subscriber+ Arbitrary PHP Code Injection/Execution ≤ 4.0.2 Fixed in 4.0.3 CVE-2023-23645 Patchstack
10.0 Critical Copymatic – AI Content Writer & Generator Plugin copymatic Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.6 Fixed in 1.7 CVE-2024-31351 Patchstack
9.8 Critical Penci Soledad Data Migrator Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.3.0 CVE-2024-3551 Wordfence
9.8 Critical Tutor LMS Plugin tutor Broken Access Control Missing Authorization No login needed ≤ 2.7.0 CVE-2024-4223 Wordfence
10.0 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 8.7.01.001 Fixed in 8.7.01.002 CVE-2024-31377 Patchstack
9.9 Critical canvasio3D Light Plugin canvasio3d-light Arbitrary File Upload ≤ 2.5.0 CVE-2024-34411 Patchstack
9.1 Critical Pk Favicon Manager Plugin phpsword-favicon-manager Arbitrary File Upload ≤ 2.1 CVE-2024-34416 Patchstack
9.1 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload Auth. Arbitrary File Upload ≤ 2.2.63 Fixed in 2.2.70 CVE-2024-34440 Patchstack
9.1 Critical Z-Downloads Plugin z-downloads Arbitrary File Upload Auth. Arbitrary File Upload No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2024-34555 Patchstack
10.0 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-32700 Patchstack
9.8 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function No login needed ≤ 1.9.9 CVE-2024-4560 Wordfence
9.8 Critical Hotel Booking Lite Plugin motopress-hotel-booking-lite PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.11.1 CVE-2024-4413 Wordfence
9.8 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Time-Based SQL Injection No login needed ≤ 4.2.6.5 CVE-2024-4434 Wordfence
9.8 Critical Last Viewed Posts by WPBeginner Plugin last-viewed-posts PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-3070 Wordfence
9.8 Critical Porto Theme Local File Inclusion Unauthenticated Local File Inclusion via porto_ajax_posts No login needed ≤ 7.1.0 CVE-2024-3806 Wordfence
9.8 Critical Social Connect Plugin social-connect Authentication Bypass No login needed ≤ 1.2 CVE-2024-4393 Wordfence
9.1 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.7.13 CVE-2024-4346 Wordfence
9.8 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.13 CVE-2024-4345 Wordfence
9.8 Critical Edwiser Bridge Plugin edwiser-bridge Authentication Bypass Authentication Bypass due to Missing Empty Value Check No login needed ≤ 3.0.5 CVE-2024-4186 Wordfence
9.8 Critical InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 0.1.0.22 CVE-2024-2667 Wordfence
9.8 Critical Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin email-subscribers SQL Injection Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection No login needed ≤ 5.7.14 CVE-2024-2876 Wordfence
9.8 Critical Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Improper Missing Encryption Exception Handling to Form Manipulation No login needed ≤ 3.19.4 CVE-2024-3729 Wordfence
9.6 Critical Xserver Migrator Plugin xserver-migrator Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 1.6.1 CVE-2024-33913 Patchstack
10.0 Critical OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Arbitrary File Upload Unauthenticated API Access to Arbitrary File Upload No login needed ≤ 12.4 Fixed in 12.5 CVE-2024-33566 Patchstack
9.0 Critical XStore Core Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 5.3.5 CVE-2024-33553 Patchstack
9.3 Critical WZone Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 14.0.10 CVE-2024-33544 Patchstack
9.6 Critical WZone Plugin SQL Injection Arbitrary SQL Update Execution ≤ 14.0.10 CVE-2024-33546 Patchstack
9.3 Critical XStore Core Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.3.5 CVE-2024-33551 Patchstack
9.3 Critical XStore Theme SQL Injection Unauthenticated SQL Injection No login needed ≤ 9.3.5 CVE-2024-33559 Patchstack
9.9 Critical Timetable and Event Schedule by MotoPress Plugin mp-timetable SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.4.11 CVE-2024-3342 Wordfence
9.8 Critical Product Addons & Fields for WooCommerce Plugin woocommerce-product-addon Arbitrary File Upload Unauthenticated Arbitrary File Upload via ppom_upload_file No login needed ≤ 32.0.18 CVE-2024-3962 Wordfence
9.1 Critical Advanced Order Export For WooCommerce Plugin woo-order-export-lite Remote Code Execution ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-31266 Patchstack
9.6 Critical DX-Watermark Plugin dx-watermark Cross-Site Request Forgery CSRF to Arbitrary File Upload and XSS No login needed ≤ 1.0.4 CVE-2024-30560 Patchstack
9.0 Critical Anti-Malware Security and Brute-Force Firewall Plugin gotmls Remote Code Execution Unauthenticated Predictable Nonce Brute-Force Leading to RCE No login needed ≤ 4.21.96 Fixed in 4.23.56 CVE-2024-22144 Patchstack
9.8 Critical Login as User or Customer (User Switching) Plugin login-as-customer-or-user Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.8 CVE-2023-51484 Patchstack
9.9 Critical Eazy Plugin Manager Plugin plugins-on-steroids Remote Code Execution Auth. Arbitrary Options Update lead to RCE ≤ 4.1.2 Fixed in 4.1.3 CVE-2023-51482 Patchstack
9.8 Critical Build App Online Plugin build-app-online Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.19 CVE-2023-51478 Patchstack
9.8 Critical BuddyBoss Theme Authentication Bypass Unauth. Arbitrary WordPress Settings Change No login needed ≤ 2.4.60 Fixed in 2.4.61 CVE-2023-51477 Patchstack
9.8 Critical Checkout Mestres WP Plugin checkout-mestres-wp Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 7.1.9.7 Fixed in 7.1.9.8 CVE-2023-51472 Patchstack
9.8 Critical Rencontre – Dating Site Plugin rencontre Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.10.1 Fixed in 3.11 CVE-2023-51425 Patchstack
9.9 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.60 Fixed in 1.5.61 CVE-2023-31090 Patchstack
9.1 Critical Newsletters Plugin newsletters-lite Arbitrary File Upload ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-32954 Patchstack
9.3 Critical WP-Recall Plugin wp-recall SQL Injection No login needed ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32709 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only