WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 21,001–21,050 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 421 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High WP Mega Menu Plugin wp-megamenu PHP Object Injection ≤ 1.4.2 CVE-2024-54282 Patchstack
4.3 Medium News Ticker for Elementor Plugin news-ticker-for-elementor Broken Access Control ≤ 2.1.3 CVE-2024-54278 Patchstack
6.5 Medium Nias course Plugin nias-course Cross-Site Scripting ≤ 1.2.10 CVE-2024-54277 Patchstack
6.5 Medium Poll Builder Plugin poll-builder Cross-Site Scripting ≤ 1.3.5 CVE-2024-54276 Patchstack
7.1 High CSV to html Plugin csv-to-html Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.08 Fixed in 3.15 CVE-2024-54275 Patchstack
7.1 High WordPress HelpDesk & Support Ticket System Plugin – Octrace Support Plugin octrace-support Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.7 CVE-2024-54274 Patchstack
9.8 Critical Mail Picker Plugin mail-picker PHP Object Injection No login needed ≤ 1.0.14 Fixed in 1.0.15 CVE-2024-54273 Patchstack
6.5 Medium Radius Blocks Plugin radius-blocks Cross-Site Scripting ≤ 2.1.2 Fixed in 2.2.0 CVE-2024-54272 Patchstack
5.4 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Settings Change ≤ 8.0.2 CVE-2024-54271 Patchstack
4.3 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Broken Access Control ≤ 1.64.0 Fixed in 1.64.1 CVE-2024-54268 Patchstack
4.3 Medium CM Answers Plugin cm-answers Broken Access Control ≤ 3.2.6 Fixed in 3.2.7 CVE-2024-54267 Patchstack
7.1 High ImageRecycle pdf & image compression Plugin imagerecycle-pdf-image-compression Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-54266 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-54265 Patchstack
7.1 High Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-54264 Patchstack
9.9 Critical Import Export For WooCommerce Plugin import-export-for-woocommerce Arbitrary File Upload ≤ 1.6.2 CVE-2024-54262 Patchstack
10.0 Critical TAX SERVICE Electronic HDM Plugin virtual-hdm-for-taxservice-am SQL Injection No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-54261 Patchstack
6.5 Medium DELUCKS SEO Plugin delucks-seo Path Traversal Arbitrary File Download ≤ 2.7.0 CVE-2024-54259 Patchstack
8.5 High Ni CRM Lead Plugin ni-crm-lead SQL Injection ≤ 1.3.0 CVE-2024-54258 Patchstack
7.1 High Easy Blocks pro Plugin easy-blocks-pro Broken Access Control ≤ 1.0.21 CVE-2024-54256 Patchstack
6.3 Medium Pinpoint Booking System Plugin booking-system Broken Access Control ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-54252 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Cross-Site Scripting ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-54250 Patchstack
8.8 High eewee admin custom Plugin eewee-admincustom Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.8.2.4 CVE-2024-54248 Patchstack
6.5 Medium FAQs Plugin faqs Cross-Site Scripting ≤ 1.0.2 CVE-2024-54246 Patchstack
6.5 Medium Clients Plugin clients Cross-Site Scripting ≤ 1.1.4 CVE-2024-54245 Patchstack
6.5 Medium Easy Replace Plugin easy-replace Cross-Site Scripting ≤ 1.3 CVE-2024-54244 Patchstack
6.5 Medium Echoza Plugin echoza Cross-Site Scripting ≤ 0.1.1 CVE-2024-54243 Patchstack
6.5 Medium Simple Notification Plugin simple-notification Broken Access Control ≤ 1.3 CVE-2024-54242 Patchstack
6.5 Medium Elite Notification – Sales Popup, Social Proof, FOMO & WooCommerce Notification Plugin elite-notification Cross-Site Scripting 1.5 CVE-2024-54241 Patchstack
7.1 High Blaze Online eParcel for WooCommerce Plugin blaze-online-eparcel-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2024-54240 Patchstack
9.8 Critical Eyewear prescription form Plugin eyewear-prescription-form Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 4.0.18 Fixed in 4.0.19 CVE-2024-54239 Patchstack
7.1 High Board Document Manager from CHUHPL Plugin board-document-manager-from-chuhpl Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 CVE-2024-54238 Patchstack
7.1 High Ni CRM Lead Plugin ni-crm-lead Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-54237 Patchstack
7.1 High Ni WooCommerce Bulk Product Editor Plugin ni-woocommerce-product-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-54236 Patchstack
7.1 High Shiptimize for WooCommerce Plugin shiptimize-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.86 CVE-2024-54235 Patchstack
9.3 Critical Limit Login Attempts Plugin wp-limit-failed-login-attempts SQL Injection No login needed ≤ 5.5 Fixed in 5.6 CVE-2024-54234 Patchstack
7.1 High Advanced Control Manager for WordPress by ItalyStrap Plugin advanced-control-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16.0 CVE-2024-54233 Patchstack
7.1 High Ni WooCommerce Order Export Plugin ni-woocommerce-order-export Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.6 CVE-2024-54231 Patchstack
5.3 Medium Brands for WooCommerce Plugin brands-for-woocommerce Broken Access Control No login needed ≤ 3.8.2.2 Fixed in 3.8.2.3 CVE-2023-44149 Patchstack
5.3 Medium Comment Blacklist Updater Plugin comment-blacklist-updater Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.2.0 CVE-2023-44147 Patchstack
5.4 Medium Inactive Logout Plugin inactive-logout Broken Access Control ≤ 3.2.2 Fixed in 3.2.3 CVE-2023-44142 Patchstack
5.3 Medium FluentForm Plugin fluentform Broken Access Control No login needed ≤ 5.0.8 Fixed in 5.0.9 CVE-2023-41952 Patchstack
4.3 Medium rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media Broken Access Control ≤ 4.6.14 Fixed in 4.6.15 CVE-2023-41951 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-41875 Patchstack
4.3 Medium SAML SP Single Sign On Plugin miniorange-saml-20-single-sign-on Broken Access Control SSO Login plugin <= 5.0.4 - Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2023-41873 Patchstack
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2023-41870 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.4 Fixed in 0.6.2.5 CVE-2023-41869 Patchstack
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
4.3 Medium Slider Pro Plugin sliderpro Broken Access Control ≤ 4.8.6 Fixed in 4.8.7 CVE-2023-41865 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.0 Fixed in 14.1 CVE-2023-41862 Patchstack
5.4 Medium Click To Tweet Plugin click-to-tweet Broken Access Control No login needed ≤ 2.0.14 CVE-2023-41857 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only