WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 2,051–2,100 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Automatic Plugin Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed < 3.93.0 Fixed in 3.93.0 CVE-2024-32693 Patchstack
5.5 Medium Really Simple SSL Plugin really-simple-ssl Server-Side Request Forgery ≤ 7.2.3 Fixed in 8.0.0 CVE-2024-31229 Patchstack
4.3 Medium PeproDev CF7 Database Plugin pepro-cf7-database Cross-Site Request Forgery No login needed ≤ 1.8.0 Fixed in 1.9.0 CVE-2023-41864 Patchstack
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) ≤ 4.4.7 CVE-2023-6805 Wordfence
4.3 Medium Login With Ajax Plugin login-with-ajax Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-30546 Patchstack
5.4 Medium e2pdf Plugin e2pdf Cross-Site Request Forgery No login needed ≤ 1.20.27 Fixed in 1.23.00 CVE-2024-31373 Patchstack
4.3 Medium AppPresser Plugin apppresser Cross-Site Request Forgery No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2024-31374 Patchstack
4.3 Medium Dashboard To-Do List Plugin dashboard-to-do-list Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-31376 Patchstack
5.4 Medium MailChimp Forms by MailMunch Plugin mailchimp-forms-by-mailmunch Cross-Site Request Forgery No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2024-31378 Patchstack
4.3 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Request Forgery No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-31379 Patchstack
4.3 Medium Spotlight Social Media Feeds Plugin spotlight-social-photo-feeds Cross-Site Request Forgery No login needed ≤ 1.6.10 Fixed in 1.6.11 CVE-2024-31381 Patchstack
4.3 Medium Blocksy Plugin blocksy Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2024-31382 Patchstack
4.3 Medium PopularFX Theme popularfx Cross-Site Request Forgery No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-31383 Patchstack
4.3 Medium Spa and Salon Theme spa-and-salon Cross-Site Request Forgery No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-31384 Patchstack
4.3 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31385 Patchstack
4.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Request Forgery No login needed ≤ 1.0.25 Fixed in 1.0.26 CVE-2024-31388 Patchstack
5.4 Medium MihanPanel Plugin mihanpanel-lite Cross-Site Request Forgery No login needed < 12.7 Fixed in 12.7 CVE-2024-31389 Patchstack
4.3 Medium Favicon Plugin favicon-by-realfavicongenerator Cross-Site Request Forgery No login needed ≤ 1.3.29 Fixed in 1.3.30 CVE-2024-31422 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
5.4 Medium Amelia Plugin ameliabooking Cross-Site Request Forgery No login needed ≤ 1.0.95 Fixed in 1.0.96 CVE-2024-31425 Patchstack
4.3 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Request Forgery No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-31426 Patchstack
4.3 Medium Marker.io Plugin marker-io Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-31427 Patchstack
4.3 Medium The Conference Theme the-conference Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-31428 Patchstack
4.3 Medium Sarada Lite Theme sarada-lite Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-31429 Patchstack
4.3 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-31431 Patchstack
4.3 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2024-31433 Patchstack
5.4 Medium Newsletter Plugin newsletter Cross-Site Request Forgery No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2024-31434 Patchstack
4.3 Medium Currency per Product for WooCommerce Plugin currency-per-product-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.7.0 CVE-2024-31920 Patchstack
4.3 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Request Forgery No login needed ≤ 5.2.15 Fixed in 5.2.16 CVE-2024-31921 Patchstack
4.3 Medium WordPress Hosting Benchmark tool Plugin wpbenchmark Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-31922 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-31923 Patchstack
5.4 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Request Forgery No login needed ≤ 1.5.35 Fixed in 1.5.36 CVE-2024-31933 Patchstack
4.3 Medium NewsXpress Theme newsxpress Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-31938 Patchstack
4.3 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.2.104 Fixed in 1.2.105 CVE-2024-31940 Patchstack
5.4 Medium CP Media Player Plugin audio-and-video-player Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.2.0 CVE-2024-31941 Patchstack
4.3 Medium Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-31942 Patchstack
4.3 Medium Before And After Plugin before-and-after Cross-Site Request Forgery No login needed ≤ 3.9 CVE-2024-32084 Patchstack
5.4 Medium Citadela Listing Plugin Cross-Site Request Forgery No login needed < 5.20.0 Fixed in 5.20.0 CVE-2024-32085 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.15.20 Fixed in 6.15.21 CVE-2024-32088 Patchstack
4.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-32089 Patchstack
4.3 Medium Church Admin Plugin church-admin Cross-Site Request Forgery No login needed ≤ 4.0.27 Fixed in 4.0.28 CVE-2024-32090 Patchstack
6.5 Medium Sangar Slider Plugin sangar-slider-lite Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2024-32091 Patchstack
5.4 Medium Kimili Flash Embed Plugin kimili-flash-embed Cross-Site Request Forgery No login needed ≤ 2.5.3 CVE-2024-32092 Patchstack
5.4 Medium Novelist Plugin novelist Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-32093 Patchstack
4.3 Medium Church Content – Sermons, Events and More Plugin church-theme-content Cross-Site Request Forgery No login needed ≤ 2.6 Fixed in 2.6.1 CVE-2024-32094 Patchstack
4.3 Medium MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Request Forgery No login needed < 1.16.9 Fixed in 1.16.9 CVE-2024-32095 Patchstack
5.4 Medium WP Migration Plugin DB & Files – WP Synchro Plugin wpsynchro Cross-Site Request Forgery No login needed ≤ 1.11.2 Fixed in 1.11.3 CVE-2024-32096 Patchstack
5.4 Medium GEO my Plugin geo-my-wp Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-32097 Patchstack
4.3 Medium WP Mail Catcher Plugin wp-mail-catcher Cross-Site Request Forgery No login needed ≤ 2.1.6 Fixed in 2.1.7 CVE-2024-32099 Patchstack
4.3 Medium Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Cross-Site Request Forgery No login needed ≤ 1.14.3 Fixed in 1.14.4 CVE-2024-32101 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only