WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,051–2,100 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 42 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical WP-Lister Lite for eBay Plugin wp-lister-for-ebay Arbitrary File Upload ≤ 3.5.11 Fixed in 3.6.0 CVE-2024-32836 Patchstack
9.1 Critical ARMember Plugin armember-membership Broken Access Control Membership Plugin plugin <= 4.0.28 - Broken Access Control No login needed ≤ 4.0.28 Fixed in 4.0.29 CVE-2024-32948 Patchstack
10.0 Critical WP Dummy Content Generator Plugin wp-dummy-content-generator Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.2.1 Fixed in 3.3.0 CVE-2024-32599 Patchstack
9.9 Critical Support Genix Plugin support-genix-lite Broken Access Control Broken Access Control lead to Arbitrary File Upload ≤ 1.2.3 Fixed in 1.2.4 CVE-2023-49742 Patchstack
9.9 Critical WP Poll Maker Plugin epoll-wp-voting Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4 CVE-2024-32514 Patchstack
9.3 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.14.4 CVE-2024-32128 Patchstack
10.0 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.9.98 Fixed in 1.9.99 CVE-2023-51409 Patchstack
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion Unauthenticated Local File Inclusion via template No login needed ≤ 3.3.3 CVE-2024-3136 Wordfence
9.8 Critical Simple Job Board Plugin simple-job-board PHP Object Injection Unauthenticated PHP Object Injection via Job Application Fields No login needed ≤ 2.11.0 CVE-2024-1813 Wordfence
9.8 Critical Network Summary Plugin network-summary SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.11 CVE-2024-2804 Wordfence
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.1.5 Fixed in 4.1.6 CVE-2024-31280 Patchstack
9.9 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload < 8.6.03.005 Fixed in 8.6.03.005 CVE-2024-31286 Patchstack
9.1 Critical Auto Poster Plugin auto-poster Arbitrary File Upload ≤ 1.2 CVE-2024-31345 Patchstack
9.0 Critical VideoWhisper Live Streaming Integration Plugin videowhisper-live-streaming-integration Remote Code Execution No login needed ≤ 5.5.15 Fixed in 5.5.16 CVE-2023-25699 Patchstack
9.9 Critical Cwicly Plugin Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 1.4.0.2 Fixed in 1.4.0.3 CVE-2024-24707 Patchstack
10.0 Critical Canto Plugin canto Remote Code Execution Unauth. Remote Code Execution (RCE) No login needed ≤ 3.0.7 CVE-2024-25096 Patchstack
9.9 Critical InstaWP Connect Plugin instawp-connect Remote Code Execution ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-25918 Patchstack
9.1 Critical Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-27951 Patchstack
9.9 Critical WP Fusion Lite Plugin wp-fusion-lite Remote Code Execution ≤ 3.41.24 Fixed in 3.42.10 CVE-2024-27972 Patchstack
9.9 Critical Oxygen Builder Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 4.9 CVE-2024-31380 Patchstack
9.9 Critical Breakdance Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 1.7.2 CVE-2024-31390 Patchstack
9.8 Critical LayerSlider Plugin SQL Injection The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user suppl… No login needed 7.9.11 – 7.10.0 CVE-2024-2879 Wordfence
9.1 Critical Shortcode Addons Plugin shortcode-addons Arbitrary File Upload ≤ 3.2.5 CVE-2024-31114 Patchstack
10.0 Critical Chauffeur Taxi Booking System Plugin Arbitrary File Upload No login needed ≤ 7.2 Fixed in 7.3 CVE-2024-31115 Patchstack
10.0 Critical Integrate Google Drive Plugin integrate-google-drive Broken Access Control Missing Authorization to Unauthenticated Settings Modification and Export No login needed ≤ 1.3.8 CVE-2024-2086 Wordfence
9.3 Critical WP Travel Engine Plugin wp-travel-engine SQL Injection Unauth. Blind SQL Injection No login needed ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-30502 Patchstack
9.3 Critical CRM Perks Forms Plugin crm-perks-forms SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-30498 Patchstack
9.3 Critical ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection No login needed ≤ 5.7.8 Fixed in 5.7.9 CVE-2024-30490 Patchstack
10.0 Critical Salon booking system Plugin salon-booking-system Arbitrary File Upload No login needed ≤ 9.5 Fixed in 9.5.1 CVE-2024-30510 Patchstack
9.9 Critical CubeWP – All-in-One Dynamic Content Framework Plugin cubewp-framework Arbitrary File Upload ≤ 1.1.12 Fixed in 1.1.13 CVE-2024-30500 Patchstack
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion Unauthenticated Local File Inclusion via modal No login needed ≤ 3.3.0 CVE-2024-2411 Wordfence
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Privilege Escalation Unauthenticated Privilege Escalation via stm_lms_register AJAX Action No login needed ≤ 3.3.1 CVE-2024-2409 Wordfence
9.1 Critical Tumult Hype Animations Plugin tumult-hype-animations Arbitrary File Upload ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-2890 Patchstack
9.1 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload ≤ 2.1.4 Fixed in 2.1.5 CVE-2024-29100 Patchstack
9.0 Critical ARMember Plugin armember-membership PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30223 Patchstack
10.0 Critical WholesaleX Plugin wholesalex PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-30224 Patchstack
10.0 Critical WP Migrate Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.6.10 Fixed in 2.6.11 CVE-2024-30225 Patchstack
9.0 Critical BetterDocs Plugin betterdocs PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.3.3 Fixed in 3.3.4 CVE-2024-30226 Patchstack
9.0 Critical Geo Controller Plugin cf-geoplugin PHP Object Injection No login needed ≤ 8.6.4 Fixed in 8.6.5 CVE-2024-30227 Patchstack
9.9 Critical Hercules Core Plugin PHP Object Injection Auth. PHP Object Injection ≤ 6.4 Fixed in 6.5 CVE-2024-30228 Patchstack
10.0 Critical WappPress Plugin wapppress-builds-android-app-for-website Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.3 Fixed in 6.0.0 CVE-2023-49815 Patchstack
9.9 Critical Elementor Website Builder Plugin elementor Arbitrary File Upload 3.3.0 – 3.18.1 Fixed in 3.18.2 CVE-2023-48777 Patchstack
9.0 Critical JupiterX Core Plugin Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 3.3.5 Fixed in 3.3.8 CVE-2023-38388 Patchstack
9.1 Critical WP Child Theme Generator Plugin wp-child-theme-generator Arbitrary File Upload ≤ 1.0.9 CVE-2023-47873 Patchstack
9.1 Critical WP Githuber MD Plugin wp-githuber-md Arbitrary File Upload ≤ 1.16.2 Fixed in 1.16.3 CVE-2023-47846 Patchstack
9.1 Critical CataBlog Plugin catablog Arbitrary File Upload ≤ 1.7.0 CVE-2023-47842 Patchstack
9.1 Critical Manager for Icomoon Plugin manager-for-icomoon Arbitrary File Upload ≤ 2.0 Fixed in 2.1 CVE-2023-29386 Patchstack
9.3 Critical Quiz And Survey Master Plugin quiz-master-next SQL Injection Unauthenticated SQL Injection No login needed ≤ 8.1.4 Fixed in 8.1.5 CVE-2023-28787 Patchstack
10.0 Critical MainWP File Uploader Extension Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.1 Fixed in 4.1.1 CVE-2023-23656 Patchstack
9.1 Critical Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-30231 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only