WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,701–20,750 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 415 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High WPLMS Plugin wplms_plugin Remote Code Execution Student+ Remote Code Execution (RCE) ≤ 1.9.9.5 Fixed in 1.9.9.5 CVE-2024-56051 Patchstack
6.5 Medium WP Menu Image Plugin wp-menu-image Broken Access Control No login needed ≤ 2.2 Fixed in 2.3 CVE-2024-52485 Patchstack
6.5 Medium Order Delivery & Pickup Location Date Time Plugin order-delivery-pickup-location-date-time-free-version Broken Access Control Settings Change No login needed ≤ 1.1.0 CVE-2024-55997 Patchstack
7.1 High Saoshyant Element Plugin saoshyant-element Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-51646 Patchstack
7.1 High Bootstrap Buttons Plugin bootstrap-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49677 Patchstack
7.1 High Device Detector Plugin device-detector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2024-56010 Patchstack
7.1 High hmd Plugin hmd Cross-Site Scripting No login needed ≤ 2.0 Fixed in 2.2 CVE-2024-54350 Patchstack
7.1 High Image Mapper Plugin image-mapper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.5.3 CVE-2024-56016 Patchstack
8.5 High Dr Affiliate Plugin dr-affiliate SQL Injection ≤ 1.2.3 CVE-2024-55975 Patchstack
8.5 High Saksh Escrow System Plugin saksh-escrow-system SQL Injection ≤ 2.4 CVE-2024-55984 Patchstack
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack
8.5 High YDS Support Ticket System Plugin yds-support-ticket-system SQL Injection ≤ 1.0 CVE-2024-55985 Patchstack
9.8 Critical VRPConnector Plugin vrpconnector PHP Object Injection No login needed ≤ 2.0.1 CVE-2024-56058 Patchstack
8.1 High Axeptio Plugin axeptio-sdk-integration Local File Inclusion No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-54270 Patchstack
9.8 Critical Partners Plugin partners PHP Object Injection No login needed ≤ 0.2.0 CVE-2024-56059 Patchstack
7.5 High Spreadr Woocommerce Plugin spreadr-for-woocomerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-56008 Patchstack
7.5 High Traveler Theme SQL Injection Unauthenticated SQL Injection via order_id No login needed ≤ 3.1.6 CVE-2024-11912 Wordfence
6.5 Medium Traveler Theme Broken Access Control Missing Authorization in Several AJAX Actions ≤ 3.1.6 CVE-2024-11926 Wordfence
5.3 Medium Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Information Disclosure Effortless Memberships, Recurring Payments & Content Restriction <= 2.13.4 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.13.4 CVE-2024-11291 Wordfence
5.4 Medium Peter’s Custom Anti-Spam Plugin peters-custom-anti-spam-image Cross-Site Request Forgery Cross-Site Request Forgery via cas_register_post Function No login needed ≤ 3.2.3 CVE-2024-12554 Wordfence
6.1 Medium Affiliate Program Suite — SliceWP Affiliates Plugin slicewp Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.1.23 CVE-2024-12454 Wordfence
4.3 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Slider and Tabs Widget Elementor Template ≤ 1.1.6 CVE-2024-12340 Wordfence
5.3 Medium Simple Page Access Restriction Plugin simple-page-access-restriction Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.0.29 CVE-2024-11295 Wordfence
9.8 Critical Biagiotti Membership Plugin Authentication Bypass Authentication Bypass via biagiotti_membership_check_facebook_user No login needed ≤ 1.0.2 CVE-2024-12287 Wordfence
5.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Request Forgery Settings update via CSRF No login needed < 3.2.43 Fixed in 3.2.43 CVE-2024-10892 WPScan
4.3 Medium Events Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.2.3 CVE-2024-12061 Wordfence
4.3 Medium LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes Plugin lifterlms Broken Access Control WP LMS for eLearning, Online Courses, & Quizzes <= 7.8.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 7.8.5 CVE-2024-12596 Wordfence
6.4 Medium Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.30 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.30 CVE-2024-12449 Wordfence
5.3 Medium Accept Authorize.NET Payments Using Contact Form 7 Plugin accept-authorize-net-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.2 CVE-2024-12250 Wordfence
8.8 High CRM WordPress Plugin – RepairBuddy Plugin Broken Access Control RepairBuddy <= 3.8120 - Missing Authorization to Account Takeover/Privilege Escalation ≤ 3.8120 CVE-2024-12259 Wordfence
7.5 High Collapsing Categories Plugin collapsing-categories SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.0.8 CVE-2024-12025 Wordfence
6.1 Medium AMP for WP – Accelerated Mobile Pages Plugin accelerated-mobile-pages Cross-Site Scripting Accelerated Mobile Pages <= 1.1.1 - Reflected Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2024-11254 Wordfence
8.1 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer Authentication Bypass Authentication Bypass Due to Insufficiently Unique Key No login needed ≤ 1.2.8 CVE-2024-12432 Wordfence
6.4 Medium Contests by Rewards Fuel Plugin contests-from-rewards-fuel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.65 CVE-2024-12513 Wordfence
6.4 Medium Philantro – Donations and Donor Management Plugin philantro Cross-Site Scripting Donations and Donor Management <= 5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2 CVE-2024-12500 Wordfence
6.4 Medium Easy Waveform Player Plugin easy-waveform-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.0 CVE-2024-11881 Wordfence
6.4 Medium Taeggie Feed Plugin taeggie-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.9 CVE-2024-11748 Wordfence
6.4 Medium ScanCircle Plugin scancircle Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.2 CVE-2024-11439 Wordfence
4.3 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 6.4.8 CVE-2024-10356 Wordfence
5.3 Medium PPWP – Password Protect Pages Plugin password-protect-page Information Disclosure Password Protect Pages <= 1.9.5 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.9.5 CVE-2024-11280 Wordfence
6.1 Medium WooCommerce Additional Fees On Checkout (Free) Plugin woo-additional-fees-on-checkout-wordpress Cross-Site Scripting Reflected Cross-Site Scripting via 'number' No login needed ≤ 1.4.7 CVE-2024-12395 Wordfence
3.7 Low Easy Digital Downloads Plugin easy-digital-downloads Broken Access Control Improper Authorization to Paywall Bypass No login needed 3.1 – 3.3.4 CVE-2024-9654 Wordfence
5.3 Medium Calculated Fields Form Plugin calculated-fields-form Denial of Service No login needed ≤ 5.2.63 CVE-2024-12601 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
6.1 Medium Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS Plugin sikshya Cross-Site Scripting Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter No login needed ≤ 0.0.21 CVE-2024-12127 Wordfence
7.2 High EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Cross-Site Scripting Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name No login needed ≤ 4.0.7.3 CVE-2024-12024 Wordfence
8.8 High s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions Plugin s2member Information Disclosure Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 241114 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 241114 CVE-2024-8326 Wordfence
8.8 High User Role Editor Plugin user-role-editor Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.64.3 CVE-2024-12293 Wordfence
5.3 Medium Memberful Plugin memberful-wp Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.73.9 CVE-2024-11294 Wordfence
6.1 Medium SMS for WooCommerce Plugin wc-sms Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.8.1 CVE-2024-12220 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only