WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,501–20,550 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 411 of 589
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High BetterLinks Plugin betterlinks Broken Access Control No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2023-45104 Patchstack
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control ≤ 5.36.0 Fixed in 5.36.1 CVE-2023-45101 Patchstack
5.3 Medium WP Job Openings Plugin wp-job-openings Broken Access Control No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2023-45061 Patchstack
5.4 Medium WP Custom Widget area Plugin wp-custom-widget-area Broken Access Control ≤ 1.2.5 CVE-2023-45045 Patchstack
4.3 Medium WP User Frontend Plugin wp-user-frontend Broken Access Control ≤ 3.6.8 Fixed in 3.6.9 CVE-2023-45002 Patchstack
4.3 Medium WP Custom Admin Interface Plugin wp-custom-admin-interface Broken Access Control ≤ 7.32 Fixed in 7.33 CVE-2023-44988 Patchstack
5.3 Medium Schema App Structured Data Plugin schema-app-structured-data-for-schemaorg Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.23.1 Fixed in 1.23.2 CVE-2023-44258 Patchstack
7.1 High Leads CRM Plugin leads-crm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-56027 Patchstack
7.1 High Lemonade Social Networks Autoposter Pinterest Plugin lemonade-sna-pinterest-edition Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-56028 Patchstack
7.1 High Easy Language Switcher Plugin easy-language-switcher Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-56029 Patchstack
7.1 High 10CentMail Plugin 10centmail-subscription-management-and-analytics Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.50 CVE-2024-56030 Patchstack
7.1 High FV Descriptions Plugin fv-descriptions Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2024-56032 Patchstack
7.1 High FAQs Plugin faqs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-56033 Patchstack
6.5 Medium Inline Footnotes Plugin inline-footnotes Cross-Site Scripting ≤ 2.3.0 CVE-2024-56019 Patchstack
7.1 High Services updates for customers Plugin service-updates-for-customers Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-56034 Patchstack
7.1 High Upload Scanner Plugin upload-scanner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-56035 Patchstack
7.1 High odPhotogallery Plugin od-photogallery-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.3 CVE-2024-56036 Patchstack
7.1 High User Referral Plugin user-referral-free Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.0 CVE-2024-56037 Patchstack
7.1 High SendSMS Plugin sendsms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 CVE-2024-56038 Patchstack
7.1 High HTML Forms Plugin html-forms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-56060 Patchstack
7.1 High WP SuperBackup Plugin indeed-wp-superbackup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56069 Patchstack
4.7 Medium AHAthat Plugin Cross-Site Scripting Reflected XSS via REQUEST_URI No login needed ≤ 1.6 CVE-2024-12595 WPScan
5.9 Medium Goodlayers Core Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.0.10 Fixed in 2.0.10 CVE-2024-11357 WPScan
4.8 Medium WP Enabled SVG Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 0.7 CVE-2024-11184 WPScan
6.5 Medium SvegliaT Buttons Plugin svegliat-buttons Cross-Site Scripting ≤ 1.3.0 CVE-2024-56020 Patchstack
6.5 Medium Category Post Shortcode Plugin category-post-shortcode Cross-Site Scripting ≤ 2.4 CVE-2024-56021 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.987 Fixed in 1.7.1 CVE-2024-56062 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 6.0.7 Fixed in 6.0.8 CVE-2024-56063 Patchstack
5.4 Medium Landing Page Cat Plugin landing-page-cat Broken Access Control ≤ 1.7.4 Fixed in 1.7.5 CVE-2024-49686 Patchstack
4.3 Medium Smart Manager Plugin smart-manager-for-wp-e-commerce Broken Access Control ≤ 8.45.0 Fixed in 8.46.0 CVE-2024-49687 Patchstack
5.3 Medium My Wp Brand Plugin my-wp-brand Broken Access Control Hide menu & Hide Plugin plugin <= 1.1.2 - Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-49694 Patchstack
4.3 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-49698 Patchstack
4.3 Medium Paytium Plugin paytium Broken Access Control ≤ 4.4.10 Fixed in 4.4.11 CVE-2024-51667 Patchstack
6.5 Medium Torod Plugin torod Broken Access Control Settings Change No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-55995 Patchstack
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Broken Access Control MightyForms plugin <= 1.3.9 - Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2024-56002 Patchstack
7.4 High WP SuperBackup Plugin indeed-wp-superbackup Broken Access Control Multiple Subscriber+ Broken Access Control vulnerabilities ≤ 2.3.3 Fixed in 2.4 CVE-2024-56070 Patchstack
8.8 High EditionGuard for WooCommerce – eBook Sales with DRM Plugin editionguard-for-woocommerce-ebook-sales-with-drm Cross-Site Request Forgery eBook Sales with DRM plugin <= 3.4.2 - CSRF to Privilege Escalation No login needed ≤ 3.4.2 CVE-2024-56207 Patchstack
8.8 High gap-hub-user-role Plugin gap-hub-user-role Cross-Site Request Forgery CSRF to Broken Authentication No login needed ≤ 3.4.1 CVE-2024-56206 Patchstack
8.8 High Sinking Dropdowns Plugin sinking-dropdowns Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.25 CVE-2024-56204 Patchstack
8.8 High Wayne Audio Player Plugin wayne-audio-player Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.0 CVE-2024-56203 Patchstack
9.8 Critical Agency Toolkit Plugin agency-toolkit Privilege Escalation No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-56066 Patchstack
8.8 High RepairBuddy Plugin computer-repair-shop Privilege Escalation Account Takeover ≤ 3.8119 Fixed in 3.8120 CVE-2024-56061 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin Arbitrary File Deletion Unauthenticated Arbitrary Directory Deletion No login needed ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56045 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Authentication Bypass Unauthenticated Arbitrary User Token Generation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56044 Patchstack
9.8 Critical WPLMS Plugin wplms_plugin Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56043 Patchstack
9.8 Critical VibeBP Plugin vibebp Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 1.9.9.4.1 Fixed in 1.9.9.5 CVE-2024-56040 Patchstack
9.3 Critical WPLMS Plugin wplms_plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.5.3 Fixed in 1.9.9.5.3 CVE-2024-56042 Patchstack
8.5 High VibeBP Plugin vibebp SQL Injection ≤ 1.9.9.5.1 Fixed in 1.9.9.5.1 CVE-2024-56041 Patchstack
9.3 Critical VibeBP Plugin vibebp SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.9.9.7.7 Fixed in 1.9.9.7.7 CVE-2024-56039 Patchstack
10.0 Critical WP SuperBackup Plugin indeed-wp-superbackup Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56064 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only