WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 21,301–21,350 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 427 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium ABCBiz Addons and Templates for Elementor Plugin abcbiz-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-54247 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.6.5 Fixed in 1.4.6.6 CVE-2024-54253 Patchstack
6.3 Medium Message Filter for Contact Form 7 Plugin cf7-message-filter Broken Access Control ≤ 1.6.3 Fixed in 1.6.3.1 CVE-2024-54254 Patchstack
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 20.8.0 Fixed in 20.8.1 CVE-2024-53819 Patchstack
9.3 Critical Revy Plugin revy SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.18 CVE-2024-54215 Patchstack
10.0 Critical Pie Register Premium Plugin pie-register-premium Arbitrary File Upload No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-53822 Patchstack
7.5 High Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Local File Inclusion ≤ 1.3.9 CVE-2024-53790 Patchstack
9.8 Critical Sweet Date Theme sweetdate Privilege Escalation No login needed ≤ 3.7.3 Fixed in 3.8.0 CVE-2024-43222 Patchstack
4.3 Medium Super Progressive Web Apps Plugin super-progressive-web-apps Broken Access Control No login needed ≤ 2.2.21 Fixed in 2.2.22 CVE-2023-48277 Patchstack
4.3 Medium Minimum and Maximum Quantity for WooCommerce Plugin min-and-max-quantity-for-woocommerce Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54227 Patchstack
6.5 Medium Prodigy Commerce Plugin prodigy-commerce Broken Access Control ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-54251 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.7 Fixed in 6.4.8 CVE-2024-54224 Patchstack
6.5 Medium Wot Elementor Widgets Plugin wot-elementor-widgets Cross-Site Scripting ≤ 1.0.1 CVE-2024-54228 Patchstack
6.5 Medium Unlock Addons for Elementor Plugin unlock-addons-for-elementor Cross-Site Scripting ≤ 2.2.4 CVE-2024-54230 Patchstack
6.5 Medium RRAddons for Elementor Plugin rrdevs-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.0 CVE-2024-54232 Patchstack
6.5 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Cross-Site Scripting ≤ 1.4.2 CVE-2024-54260 Patchstack
7.1 High Country Blocker Plugin country-blocker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.2 CVE-2024-54226 Patchstack
4.7 Medium Login Widget With Shortcode Plugin login-sidebar-widget Open Redirect No login needed ≤ 6.1.2 CVE-2024-54255 Patchstack
7.5 High Designer Plugin designer Local File Inclusion ≤ 1.4.1 Fixed in 1.5.0 CVE-2024-54225 Patchstack
5.3 Medium ARForms Form Builder Plugin arforms-form-builder Content Injection HTML Injection No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-54223 Patchstack
7.5 High Ebook Store Plugin ebook-store Authentication Bypass Broken Authentication No login needed ≤ 5.775 Fixed in 5.78 CVE-2023-22701 Patchstack
4.3 Medium Kraken.io Image Optimizer Plugin kraken-image-optimizer Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2023-22708 Patchstack
5.2 Medium JobBoardWP – Job Board Listings and Submissions Plugin jobboardwp Broken Access Control Job Board Listings and Submissions plugin <= 1.2.2 - IDOR Leading To Job Removal ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-23715 Patchstack
4.3 Medium Zendesk Support Plugin zendesk Broken Access Control ≤ 1.8.4 Fixed in 1.8.5 CVE-2023-23716 Patchstack
4.3 Medium Shortcodes Plugin wc-shortcodes Broken Access Control No login needed ≤ 3.46 CVE-2023-23725 Patchstack
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.13 Fixed in 1.4.15 CVE-2023-23814 Patchstack
5.4 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change No login needed ≤ 3.5.1.0 Fixed in 3.5.1.1 CVE-2023-23726 Patchstack
4.3 Medium Enhanced Text Widget Plugin enhanced-text-widget Broken Access Control ≤ 1.5.8 Fixed in 1.5.9 CVE-2023-23823 Patchstack
3.1 Low Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Import_WPforms ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23825 Patchstack
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Activate_Plugin No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23834 Patchstack
5.4 Medium Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2023-23868 Patchstack
5.4 Medium WP-RecentComments Plugin wp-recentcomments Broken Access Control ≤ 2.2.7 CVE-2023-23886 Patchstack
5.3 Medium Easy Google Analytics Plugin easy-google-analytics-for-wordpress Broken Access Control No login needed ≤ 1.6.0 CVE-2023-23887 Patchstack
5.3 Medium Simple Giveaways Plugin giveasap Broken Access Control No login needed ≤ 2.48.0 Fixed in 2.48.1 CVE-2023-23893 Patchstack
5.3 Medium Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.7.4 Fixed in 9.7.5 CVE-2023-23975 Patchstack
4.7 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.1.82 Fixed in 1.1.83 CVE-2023-23895 Patchstack
5.4 Medium Reviews and Rating – Google My Business Plugin g-business-reviews-rating Broken Access Control Google My Business plugin <= 4.14 - Broken Access Control No login needed ≤ 4.14 Fixed in 4.15 CVE-2023-23986 Patchstack
3.5 Low WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Broken Access Control ≤ 7.5.14 Fixed in 7.6.0 CVE-2023-24375 Patchstack
5.0 Medium Booking calendar, Appointment Booking System Plugin booking-calendar Broken Access Control ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24407 Patchstack
4.3 Medium PayPal Brasil para WooCommerce Plugin paypal-brasil-para-woocommerce Broken Access Control ≤ 1.4.2 Fixed in 1.4.3 CVE-2023-25026 Patchstack
6.5 Medium Quick Contact Form Plugin quick-contact-form Broken Access Control No login needed ≤ 8.0.3.1 Fixed in 8.0.4 CVE-2023-25035 Patchstack
4.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control ≤ 1.2.34 Fixed in 1.2.35 CVE-2023-25037 Patchstack
5.3 Medium Fantastic Content Protector Free Plugin fantastic-content-protector-free Broken Access Control No login needed ≤ 2.6 CVE-2023-25048 Patchstack
4.3 Medium We’re Open! Plugin opening-hours Broken Access Control No login needed ≤ 1.45 Fixed in 1.46 CVE-2023-25067 Patchstack
5.3 Medium Album and Image Gallery plus Lightbox Plugin album-and-image-gallery-plus-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2023-25060 Patchstack
6.5 Medium Protected Posts Logout Button Plugin protected-posts-logout-button Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2023-25454 Patchstack
5.3 Medium WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Broken Access Control Arbitrary Content Deletion No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2023-25455 Patchstack
5.4 Medium Easy Table of Contents Plugin easy-table-of-contents Broken Access Control ≤ 2.0.45.2 Fixed in 2.0.46 CVE-2023-25469 Patchstack
5.3 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.7 CVE-2023-25703 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control No login needed ≤ 2.3.7 Fixed in 2.3.8 CVE-2023-25486 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only