WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 21,251–21,300 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 426 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.1 High OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Authentication Bypass SSO (OAuth Client) <= 6.26.3 - Authentication Bypass No login needed ≤ 6.26.3 CVE-2024-10111 Wordfence
6.4 Medium PowerBI Embed Reports Plugin embed-power-bi-reports Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.7 CVE-2024-11901 Wordfence
6.1 Medium dejure.org Vernetzungsfunktion Plugin dejureorg-vernetzungsfunktion Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.97.5 CVE-2024-11417 Wordfence
8.8 High de:branding Plugin debranding Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update ≤ 1.0.2 CVE-2024-11443 Wordfence
6.1 Medium Password for WP Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5 CVE-2024-11419 Wordfence
9.8 Critical Sign In With Google Plugin sign-in-with-google Authentication Bypass Authentication Bypass in authenticate_user No login needed ≤ 1.8.0 CVE-2024-11015 Wordfence
6.4 Medium WP-Revive Adserver Plugin wp-revive-adserver Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-12461 Wordfence
6.4 Medium Surbma | SalesAutopilot Shortcode Plugin surbma-salesautopilot-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5 CVE-2024-11433 Wordfence
6.4 Medium Gutenberg Blocks and Page Layouts – Attire Blocks Plugin attire-blocks Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.5 CVE-2024-11914 Wordfence
6.4 Medium Catch Popup Plugin catch-popup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.4 CVE-2024-11427 Wordfence
6.1 Medium Schema App Structured Data Plugin schema-app-structured-data-for-schemaorg Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.4 CVE-2024-11279 Wordfence
8.8 High HQ Rental Software Plugin hq-rental-software Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.29 CVE-2024-11689 Wordfence
6.4 Medium HostFact bestelformulier integratie Plugin hostfact-bestelformulier-integratie Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2024-11413 Wordfence
4.3 Medium Custom Skins Contact Form 7 Plugin custom-skins-contact-form-7 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update and Skin Creation ≤ 1.0 CVE-2024-12341 Wordfence
6.5 Medium SQL Chart Builder Plugin sql-chart-builder SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3.6 CVE-2024-11430 Wordfence
6.4 Medium Horizontal scroll image slideshow Plugin horizontal-scroll-image-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.1 CVE-2024-11442 Wordfence
5.3 Medium Restrict – membership, site, content and user access restrictions Plugin restricted-content Information Disclosure membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 2.2.8 CVE-2024-11351 Wordfence
6.1 Medium Waymark Plugin waymark Cross-Site Scripting Reflected Cross-Site Scripting via 'content' No login needed ≤ 1.4.1 CVE-2024-12325 Wordfence
5.3 Medium Last Viewed Posts by WPBeginner Plugin last-viewed-posts Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.1 CVE-2024-12294 Wordfence
7.1 High RapidLoad – Optimize Web Vitals Automatically Plugin unusedcss Broken Access Control Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection ≤ 2.4.2 CVE-2024-11840 Wordfence
5.3 Medium Members Plugin members Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 3.2.10 CVE-2024-11008 Wordfence
4.3 Medium Notibar Plugin notibar Broken Access Control ≤ 2.1.4 Fixed in 2.1.5 CVE-2024-54269 Patchstack
6.1 Medium WP Pipes Plugin wp-pipes Cross-Site Scripting Reflected Cross-Site Scripting via x1 Parameter No login needed ≤ 1.4.1 CVE-2024-12283 Wordfence
6.1 Medium WPC Order Notes for WooCommerce Plugin woo-order-notes Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.5.2 CVE-2024-12004 Wordfence
6.1 Medium turboSMTP Plugin turbosmtp Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed ≤ 4.6 CVE-2024-12323 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Information Disclosure WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API No login needed ≤ 4.2.7.3 CVE-2024-11868 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
6.4 Medium iChart – Easy Charts and Graphs Plugin ichart Cross-Site Scripting Easy Charts and Graphs <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter ≤ 2.1.0 CVE-2024-11928 Wordfence
5.3 Medium Simple Restrict Plugin simple-restrict Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.2.7 CVE-2024-11106 Wordfence
6.4 Medium Email Reminders Plugin email-reminders Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 2.0.4 CVE-2024-11945 Wordfence
6.1 Medium Quran multilanguage Text & Audio Plugin quran-text-multilanguage Cross-Site Scripting Reflected Cross-Site Scripting via sourate and lang Parameters No login needed ≤ 2.3.21 CVE-2024-11973 Wordfence
6.4 Medium Property Hive Mortgage Calculator Plugin property-hive-mortgage-calculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via price Parameter ≤ 1.0.6 CVE-2024-11940 Wordfence
6.1 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.8.15 Fixed in 2.8.15 CVE-2024-11107 WPScan
4.9 Medium System Dashboard Plugin system-dashboard Path Traversal Admin+ Path Traversal < 2.8.15 Fixed in 2.8.15 CVE-2024-10708 WPScan
7.7 High Best WordPress Gallery Plugin – FooGallery Plugin Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.26 CVE-2023-6947 Wordfence
8.5 High WPForms Plugin wpforms-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation 1.8.4 – 1.9.2.1 CVE-2024-11205 Wordfence
5.3 Medium ProfilePress Plugin wp-user-avatar Broken Access Control No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2023-41953 Patchstack
6.5 Medium Analytify Plugin wp-analytify Broken Access Control ≤ 5.4.3 Fixed in 5.5.0 CVE-2024-53814 Patchstack
6.5 Medium AIO Contact Plugin aio-contact Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 2.8.1 CVE-2024-54218 Patchstack
4.3 Medium Team Member Plugin team-showcase-supreme Local File Inclusion Multi Language Supported Team plugin <= 7.4 - Limited Local File Inclusion ≤ 7.4 Fixed in 7.5 CVE-2024-52385 Patchstack
5.3 Medium Pie Register Premium Plugin pie-register-premium Broken Access Control No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-52391 Patchstack
5.3 Medium Jobify Theme jobify Broken Access Control No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52480 Patchstack
4.3 Medium Chatter Plugin chatter Broken Access Control ≤ 1.0.1 CVE-2024-53785 Patchstack
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-53816 Patchstack
5.4 Medium ARForms Plugin arforms Broken Access Control Subscriber+ Plugin Settings Change ≤ 6.4.1 CVE-2024-54217 Patchstack
6.5 Medium Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Cross-Site Scripting ≤ 1.3.9 CVE-2024-53791 Patchstack
5.4 Medium FloristPress Plugin bakkbone-florist-companion Broken Access Control Nonce Leakage to Broken Access Control ≤ 7.3.0 Fixed in 7.4.0 CVE-2024-53798 Patchstack
6.5 Medium PostX Plugin ultimate-post Cross-Site Scripting ≤ 4.1.15 Fixed in 4.1.16 CVE-2024-53818 Patchstack
7.1 High AIO Contact Plugin aio-contact Cross-Site Scripting Unauthenticated Site-Wide Cross Site Scripting (XSS) No login needed ≤ 2.8.1 CVE-2024-54219 Patchstack
7.1 High FAT Services Booking Plugin fat-services-booking Cross-Site Scripting Subscriber+ Site-Wide Cross Site Scripting (XSS) No login needed ≤ 5.6 CVE-2024-54220 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only