WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,551–20,600 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 412 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical WPLMS Plugin wplms_plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.9 Fixed in 1.9.9.1 CVE-2024-56046 Patchstack
7.5 High WP SuperBackup Plugin indeed-wp-superbackup PHP Object Injection Subscriber+ PHP Object Injection ≤ 2.3.3 Fixed in 2.4 CVE-2024-56068 Patchstack
6.5 Medium WP-CRM System Plugin wp-crm-system Broken Access Control WP-CRM System plugin <= 3.2.9.1 - Broken Access Control No login needed ≤ 3.2.9.1 Fixed in 3.4.0 CVE-2024-55991 Patchstack
6.5 Medium Smart Shopify Product Plugin smart-shopify-product Broken Access Control Arbitrary Content Deletion ≤ 1.0.2 CVE-2024-56031 Patchstack
7.5 High WP SuperBackup Plugin indeed-wp-superbackup Broken Access Control Unauthenticated Backup File Download No login needed ≤ 2.3.3 Fixed in 2.4 CVE-2024-56067 Patchstack
5.3 Medium WP Cleanfix Plugin wp-cleanfix Broken Access Control No login needed ≤ 5.6.2 Fixed in 5.7.0 CVE-2023-48775 Patchstack
4.3 Medium WooCommerce Subscriptions Plugin woocommerce-subscriptions Broken Access Control < 5.8.0 Fixed in 5.8.0 CVE-2023-50850 Patchstack
9.8 Critical Simple Dashboard Plugin simple-dashboard Privilege Escalation No login needed ≤ 2.0 CVE-2024-56071 Patchstack
9.8 Critical AI Magic Plugin newsletter-page-redirects Privilege Escalation SEO Content Generator & Article Writer plugin <= 1.0.4 - Privilege Escalation No login needed ≤ 1.0.4 Fixed in 1.0.6 CVE-2024-56205 Patchstack
7.1 High Kleo Plugin kleo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.4 Fixed in 5.4.4 CVE-2024-56209 Patchstack
7.1 High Userpro Plugin userpro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.9 CVE-2024-56210 Patchstack
6.5 Medium WPMozo Addons Lite for Elementor Plugin wpmozo-addons-lite-for-elementor Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-56221 Patchstack
7.1 High Gulri Slider Plugin gulri-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.8 Fixed in 3.5.9 CVE-2024-56223 Patchstack
6.5 Medium Ledenbeheer Plugin ledenbeheer-external-connection Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-56224 Patchstack
7.1 High Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56226 Patchstack
7.1 High Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-56228 Patchstack
6.5 Medium SaasPricing Plugin saaspricing Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-56231 Patchstack
7.1 High KinTPV WooConnect Plugin kintpv-connect Cross-Site Scripting No login needed ≤ 8.129 Fixed in 8.141 CVE-2024-56233 Patchstack
5.4 Medium VW Automobile Lite Plugin vw-automobile-lite Broken Access Control ≤ 2.1 CVE-2024-56234 Patchstack
4.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Broken Access Control ≤ 1.7.1001 Fixed in 1.7.1002 CVE-2024-56227 Patchstack
5.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control ≤ 4.10.56 Fixed in 4.10.57 CVE-2024-56225 Patchstack
4.3 Medium Widget Options Plugin widget-options Broken Access Control ≤ 4.0.6.1 Fixed in 4.0.8 CVE-2024-56219 Patchstack
4.3 Medium Download Manager Plugin download-manager Broken Access Control ≤ 3.3.03 Fixed in 3.3.04 CVE-2024-56217 Patchstack
4.3 Medium Member Directory and Contact Form Plugin pta-member-directory Broken Access Control ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-56215 Patchstack
6.5 Medium Coupon Plugin coupon-lite Cross-Site Scripting ≤ 1.2.2 CVE-2024-56235 Patchstack
5.9 Medium Embed PDF Viewer Plugin embed-pdf-viewer Cross-Site Scripting ≤ 2.3.1 Fixed in 2.4.0 CVE-2024-56256 Patchstack
7.1 High WooCommerce PDF Vouchers Plugin woocommerce-pdf-vouchers Cross-Site Scripting PDF Vouchers plugin < 4.9.9 - Cross Site Scripting (XSS) No login needed ≤ 4.9.9 Fixed in 4.9.9 CVE-2024-56265 Patchstack
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Cross-Site Request Forgery Dynamic Text Extension plugin <= 5.0.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 5.0.1 Fixed in 5.0.2 CVE-2024-56218 Patchstack
5.4 Medium CodeBard Help Desk Plugin codebard-help-desk Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56222 Patchstack
4.3 Medium SearchIQ Plugin searchiq Cross-Site Request Forgery No login needed ≤ 4.6 Fixed in 4.7 CVE-2024-56229 Patchstack
7.1 High WP Nice Loader Plugin wp-nice-loader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0.4 CVE-2024-56232 Patchstack
9.8 Critical SSL Wireless SMS Notification Plugin ssl-wireless-sms-notification Privilege Escalation No login needed ≤ 3.6.0 Fixed in 3.7.0 CVE-2024-56220 Patchstack
8.5 High Userpro Plugin userpro SQL Injection ≤ 5.1.9 CVE-2024-56212 Patchstack
8.8 High Userpro Plugin userpro Broken Access Control Authenticated Arbitrary User Meta Update ≤ 5.1.9 CVE-2024-56211 Patchstack
6.5 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 4.0.7 Fixed in 4.0.9 CVE-2024-56213 Patchstack
8.3 High Userpro Plugin userpro Local File Inclusion No login needed ≤ 5.1.9 CVE-2024-56214 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Local File Inclusion ≤ 7.6.3 Fixed in 7.6.5 CVE-2024-56216 Patchstack
7.5 High Dynamic Product Category Grid, Slider for WooCommerce Plugin dynamic-product-categories-design Local File Inclusion ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-56230 Patchstack
9.8 Critical Hunk Companion Plugin hunk-companion Broken Access Control Unauthenticated Plugin Installation No login needed < 1.9.0 Fixed in 1.9.0 CVE-2024-11972 WPScan
6.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Arbitrary Shortcode Execution The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.8.22 CVE-2024-12238 Wordfence
4.8 Medium Give Plugin paystack-for-give Cross-Site Scripting Reflected XSS < 3.19.0 Fixed in 3.19.0 CVE-2024-11921 WPScan
4.3 Medium DN Shipping by Weight for WooCommerce Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.2 Fixed in 1.2 CVE-2024-11842 WPScan
4.8 Medium Float Block Plugin Cross-Site Scripting Admin+ Stored XSS via Widget ≤ 1.7 CVE-2024-11645 WPScan
5.9 Medium WP-SVG Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 0.9 CVE-2024-11644 WPScan
4.8 Medium WP Publications Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.2 CVE-2024-11605 WPScan
4.7 Medium WPForms Plugin wpforms-lite Cross-Site Scripting Admin+ Stored XSS < 1.9.2.3 Fixed in 1.9.2.3 CVE-2024-11223 WPScan
4.7 Medium Broken Link Checker Plugin broken-link-checker Server-Side Request Forgery Admin+ SSRF < 2.4.2 Fixed in 2.4.2 CVE-2024-10903 WPScan
4.9 Medium NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection Authenticated (Admin+) SQL Injection ≤ 8.7.15 CVE-2024-10862 Wordfence
4.3 Medium Avada Builder Plugin Information Disclosure Authenticated (Contributor+) Protected Post Disclosure ≤ 3.11.12 CVE-2024-12335 Wordfence
9.8 Critical WooCommerce Point of Sale Plugin Broken Access Control Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change No login needed ≤ 6.1.0 CVE-2024-11281 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only