WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 21,251–21,300 of 29,413 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.1 High | OAuth Single Sign On – SSO (OAuth Client) | Authentication Bypass SSO (OAuth Client) <= 6.26.3 - Authentication Bypass No login needed |
≤ 6.26.3 |
CVE-2024-10111 |
Wordfence | |
| 6.4 Medium | PowerBI Embed Reports | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.7 |
CVE-2024-11901 |
Wordfence | |
| 6.1 Medium | dejure.org Vernetzungsfunktion | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.97.5 |
CVE-2024-11417 |
Wordfence | |
| 8.8 High | de:branding | Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update |
≤ 1.0.2 |
CVE-2024-11443 |
Wordfence | |
| 6.1 Medium | Password for WP | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.5 |
CVE-2024-11419 |
Wordfence | |
| 9.8 Critical | Sign In With Google | Authentication Bypass Authentication Bypass in authenticate_user No login needed |
≤ 1.8.0 |
CVE-2024-11015 |
Wordfence | |
| 6.4 Medium | WP-Revive Adserver | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.1 |
CVE-2024-12461 |
Wordfence | |
| 6.4 Medium | Surbma | SalesAutopilot Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.5 |
CVE-2024-11433 |
Wordfence | |
| 6.4 Medium | Gutenberg Blocks and Page Layouts – Attire Blocks | Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.5 |
CVE-2024-11914 |
Wordfence | |
| 6.4 Medium | Catch Popup | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.4 |
CVE-2024-11427 |
Wordfence | |
| 6.1 Medium | Schema App Structured Data | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.4 |
CVE-2024-11279 |
Wordfence | |
| 8.8 High | HQ Rental Software | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed |
≤ 1.5.29 |
CVE-2024-11689 |
Wordfence | |
| 6.4 Medium | HostFact bestelformulier integratie | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2024-11413 |
Wordfence | |
| 4.3 Medium | Custom Skins Contact Form 7 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update and Skin Creation |
≤ 1.0 |
CVE-2024-12341 |
Wordfence | |
| 6.5 Medium | SQL Chart Builder | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.3.6 |
CVE-2024-11430 |
Wordfence | |
| 6.4 Medium | Horizontal scroll image slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.1 |
CVE-2024-11442 |
Wordfence | |
| 5.3 Medium | Restrict – membership, site, content and user access restrictions | Information Disclosure membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.2.8 |
CVE-2024-11351 |
Wordfence | |
| 6.1 Medium | Waymark | Cross-Site Scripting Reflected Cross-Site Scripting via 'content' No login needed |
≤ 1.4.1 |
CVE-2024-12325 |
Wordfence | |
| 5.3 Medium | Last Viewed Posts by WPBeginner | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.0.1 |
CVE-2024-12294 |
Wordfence | |
| 7.1 High | RapidLoad – Optimize Web Vitals Automatically | Broken Access Control Optimize Web Vitals Automatically <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification and SQL Injection |
≤ 2.4.2 |
CVE-2024-11840 |
Wordfence | |
| 5.3 Medium | Members | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 3.2.10 |
CVE-2024-11008 |
Wordfence | |
| 4.3 Medium | Notibar | Broken Access Control |
≤ 2.1.4 Fixed in 2.1.5 |
CVE-2024-54269 |
Patchstack | |
| 6.1 Medium | WP Pipes | Cross-Site Scripting Reflected Cross-Site Scripting via x1 Parameter No login needed |
≤ 1.4.1 |
CVE-2024-12283 |
Wordfence | |
| 6.1 Medium | WPC Order Notes for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.5.2 |
CVE-2024-12004 |
Wordfence | |
| 6.1 Medium | turboSMTP | Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed |
≤ 4.6 |
CVE-2024-12323 |
Wordfence | |
| 5.3 Medium | LearnPress – WordPress LMS | Information Disclosure WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API No login needed |
≤ 4.2.7.3 |
CVE-2024-11868 |
Wordfence | |
| 7.3 High | Active Products Tables for WooCommerce. Use constructor to create tables | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed |
≤ 1.0.6.5 |
CVE-2024-10959 |
Wordfence | |
| 6.4 Medium | iChart – Easy Charts and Graphs | Cross-Site Scripting Easy Charts and Graphs <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 2.1.0 |
CVE-2024-11928 |
Wordfence | |
| 5.3 Medium | Simple Restrict | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 1.2.7 |
CVE-2024-11106 |
Wordfence | |
| 6.4 Medium | Email Reminders | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.4 |
CVE-2024-11945 |
Wordfence | |
| 6.1 Medium | Quran multilanguage Text & Audio | Cross-Site Scripting Reflected Cross-Site Scripting via sourate and lang Parameters No login needed |
≤ 2.3.21 |
CVE-2024-11973 |
Wordfence | |
| 6.4 Medium | Property Hive Mortgage Calculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via price Parameter |
≤ 1.0.6 |
CVE-2024-11940 |
Wordfence | |
| 6.1 Medium | System Dashboard | Cross-Site Scripting Unauthenticated Stored XSS No login needed |
< 2.8.15 Fixed in 2.8.15 |
CVE-2024-11107 |
WPScan | |
| 4.9 Medium | System Dashboard | Path Traversal Admin+ Path Traversal |
< 2.8.15 Fixed in 2.8.15 |
CVE-2024-10708 |
WPScan | |
| 7.7 High | Best WordPress Gallery Plugin – FooGallery | Path Traversal FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal |
≤ 2.4.26 |
CVE-2023-6947 |
Wordfence | |
| 8.5 High | WPForms | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Payment Refund and Subscription Cancellation |
1.8.4 – 1.9.2.1 |
CVE-2024-11205 |
Wordfence | |
| 5.3 Medium | ProfilePress | Broken Access Control No login needed |
≤ 4.13.1 Fixed in 4.13.2 |
CVE-2023-41953 |
Patchstack | |
| 6.5 Medium | Analytify | Broken Access Control |
≤ 5.4.3 Fixed in 5.5.0 |
CVE-2024-53814 |
Patchstack | |
| 6.5 Medium | AIO Contact | Broken Access Control Unauthenticated Plugin Settings Change No login needed |
≤ 2.8.1 |
CVE-2024-54218 |
Patchstack | |
| 4.3 Medium | Team Member | Local File Inclusion Multi Language Supported Team plugin <= 7.4 - Limited Local File Inclusion |
≤ 7.4 Fixed in 7.5 |
CVE-2024-52385 |
Patchstack | |
| 5.3 Medium | Pie Register Premium | Broken Access Control No login needed |
< 3.8.3.3 Fixed in 3.8.3.3 |
CVE-2024-52391 |
Patchstack | |
| 5.3 Medium | Jobify | Broken Access Control No login needed |
≤ 4.3.0 Fixed in 4.3.0 |
CVE-2024-52480 |
Patchstack | |
| 4.3 Medium | Chatter | Broken Access Control |
≤ 1.0.1 |
CVE-2024-53785 |
Patchstack | |
| 4.3 Medium | Tutor LMS Elementor Addons | Broken Access Control |
≤ 2.1.5 Fixed in 2.1.6 |
CVE-2024-53816 |
Patchstack | |
| 5.4 Medium | ARForms | Broken Access Control Subscriber+ Plugin Settings Change |
≤ 6.4.1 |
CVE-2024-54217 |
Patchstack | |
| 6.5 Medium | Lenxel Core for Lenxel(LNX) LMS | Cross-Site Scripting |
≤ 1.3.9 |
CVE-2024-53791 |
Patchstack | |
| 5.4 Medium | FloristPress | Broken Access Control Nonce Leakage to Broken Access Control |
≤ 7.3.0 Fixed in 7.4.0 |
CVE-2024-53798 |
Patchstack | |
| 6.5 Medium | PostX | Cross-Site Scripting |
≤ 4.1.15 Fixed in 4.1.16 |
CVE-2024-53818 |
Patchstack | |
| 7.1 High | AIO Contact | Cross-Site Scripting Unauthenticated Site-Wide Cross Site Scripting (XSS) No login needed |
≤ 2.8.1 |
CVE-2024-54219 |
Patchstack | |
| 7.1 High | FAT Services Booking | Cross-Site Scripting Subscriber+ Site-Wide Cross Site Scripting (XSS) No login needed |
≤ 5.6 |
CVE-2024-54220 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.