WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 21,151–21,200 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 424 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46840 Patchstack
9.1 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control Unauthenticated Settings Change No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46838 Patchstack
4.3 Medium ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce Plugin woo-alidropship Broken Access Control Broken Access Control + CSRF ≤ 1.0.21 Fixed in 1.0.22 CVE-2022-46811 Patchstack
4.3 Medium Stock Sync for WooCommerce Plugin stock-sync-for-woocommerce Broken Access Control ≤ 2.3.2 Fixed in 2.4.0 CVE-2022-46807 Patchstack
6.5 Medium CURCY Plugin woo-multi-currency Broken Access Control Unauthenticated plugin settings change No login needed ≤ 2.1.25 Fixed in 2.1.26 CVE-2022-46796 Patchstack
6.5 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery CSRF Plugin Settings Reset No login needed ≤ 4.7.2 Fixed in 4.7.3 CVE-2022-46795 Patchstack
5.4 Medium Robo Gallery Plugin robo-gallery Broken Access Control Auth. Broken Access Control ≤ 3.2.9 Fixed in 3.2.11 CVE-2022-45841 Patchstack
6.5 Medium Auto Affiliate Links Plugin wp-auto-affiliate-links Broken Access Control Unauth. Broken Access Control No login needed ≤ 6.2.1.5 Fixed in 6.2.1.6 CVE-2022-45840 Patchstack
5.4 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control Auth. Broken Access Control No login needed ≤ 2.9.13 Fixed in 2.9.14 CVE-2022-45826 Patchstack
3.5 Low Popup Maker Plugin popup-maker Broken Access Control ≤ 1.17.1 Fixed in 1.18.0 CVE-2022-45819 Patchstack
4.3 Medium Formidable Forms Plugin formidable Broken Access Control No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2022-45806 Patchstack
4.3 Medium eRoom – Zoom Meetings & Webinar Plugin eroom-zoom-meetings-webinar Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2022-43472 Patchstack
6.1 Medium MyParcel Plugin woocommerce-myparcel Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.24.1 CVE-2024-9608 Wordfence
6.4 Medium Out of the Block: OpenStreetMap Plugin ootb-openstreetmap Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ootb_query Shortcode ≤ 2.8.3 CVE-2024-11827 Wordfence
8.1 High MainWP Child Plugin mainwp-child Broken Access Control Missing Authorization to Unauthenticated Privilege Escalation No login needed ≤ 5.3.3 CVE-2024-10783 Wordfence
6.3 Medium Notibar – Notification Bar Plugin notibar Arbitrary Shortcode Execution Notification Bar for WordPress <= 2.1.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via njt_nofi_text ≤ 2.1.4 CVE-2024-11012 Wordfence
9.8 Critical Super Backup & Clone - Migrate Plugin Arbitrary File Upload Migrate for WordPress <= 2.3.3 - Unauthenticated Arbitrary File Upload No login needed ≤ 2.3.3 CVE-2024-9290 Wordfence
6.4 Medium Property Hive Stamp Duty Calculator Plugin property-hive-stamp-duty-calculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.22 CVE-2024-12465 Wordfence
4.3 Medium WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion ≤ 1.0.27 CVE-2024-11275 Wordfence
6.5 Medium Simple Link Directory Plugin simple-link-directory Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.4.5 CVE-2024-12417 Wordfence
5.3 Medium Rate My Post – Star Rating Plugin by FeedbackWP Plugin rate-my-post Broken Access Control Star Rating Plugin by FeedbackWP <= 4.2.4 - Unauthenticated Voting On Scheduled Posts No login needed ≤ 4.2.4 CVE-2024-12309 Wordfence
5.4 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) ≤ 4.16.4 CVE-2024-12042 Wordfence
4.3 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Missing Authorization to Authenticated (Subscriber+) WooCommerce Installation ≤ 2.1.12 CVE-2024-11911 Wordfence
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.15 CVE-2024-11910 Wordfence
6.5 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Arbitrary Shortcode Execution Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 5.16.7.1 CVE-2024-12421 Wordfence
6.5 Medium WPMobile.App — Android and iOS Mobile Application Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 11.52 CVE-2024-12420 Wordfence
6.4 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.6 CVE-2024-11754 Wordfence
4.3 Medium Themify Store Locator Plugin themify-store-locator Cross-Site Request Forgery No login needed ≤ 1.1.9 CVE-2024-12414 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin Cross-Site Scripting WordPress Page Builder <= 2.8.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.4.4 CVE-2024-11832 Wordfence
4.8 Medium Image Widget Plugin image-widget Cross-Site Scripting Admin+ Stored XSS < 4.4.11 Fixed in 4.4.11 CVE-2024-10939 WPScan
5.4 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Contributor+ Stored XSS < 3.2.4 Fixed in 3.2.4 CVE-2024-10678 WPScan
4.4 Medium Kadence Blocks Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.2.53 CVE-2024-12581 Wordfence
5.3 Medium Minify HTML Plugin minify-html-markup Denial of Service - Regular Expressions Denial of Service No login needed ≤ 2.1.10 CVE-2024-12579 Wordfence
5.4 Medium SVG Shortcode Plugin svg-shortcode Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.0.1 CVE-2024-12574 Wordfence
6.1 Medium Primer MyData for Woocommerce Plugin primer-mydata Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.1 CVE-2024-11809 Wordfence
6.4 Medium NewsmanApp Plugin newsmanapp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.6 CVE-2024-11767 Wordfence
3.7 Low AR Plugin ar-for-wordpress Broken Access Control Missing Authorization to Unauthenticated Limited File Upload No login needed ≤ 7.3 CVE-2024-12300 Wordfence
6.5 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.8 CVE-2019-25221 Wordfence
6.1 Medium Hello in All Languages Plugin hello-in-all-languages Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2024-12572 Wordfence
4.4 Medium 360 Javascript Viewer Plugin 360deg-javascript-viewer Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.7.29 CVE-2024-12271 Wordfence
6.1 Medium Seraphinite Bulk Discounts for WooCommerce Plugin seraphinite-discount-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-12160 Wordfence
6.5 Medium WoodMart Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.0.3 CVE-2024-12333 Wordfence
6.4 Medium Currency Converter Widget ⚡ PRO Plugin currency-converter-widget-pro Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.6 CVE-2024-11760 Wordfence
4.3 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control Missing Authorization to Authenticated (Contributor+) Information Exposure ≤ 5.1.6 CVE-2024-12329 Wordfence
8.1 High Print Science Designer Plugin print-science-designer PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.3.152 CVE-2024-12312 Wordfence
4.3 Medium Hash Form Plugin hash-form Broken Access Control Missing Authorization to Authenticated (Contributor+) Form Style Creation ≤ 1.2.1 CVE-2024-12201 Wordfence
4.3 Medium Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) Plugin gdpr-cookie-consent Broken Access Control Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) <= 3.6.5 - Missing Authorization to Authenticated (Subscriber+) Whitelist Script ≤ 3.6.5 CVE-2024-11724 Wordfence
5.4 Medium Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder Plugin Cross-Site Scripting Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.20.2 CVE-2024-10583 Wordfence
4.4 Medium NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar Plugin notificationx Cross-Site Scripting Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.9.3 CVE-2024-11727 Wordfence
4.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Disclosure ≤ 9.9.9.3 CVE-2024-11181 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only