WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 2,101–2,150 of 2,150 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 43 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical MoveTo Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 6.2 CVE-2024-25912 Patchstack
9.9 Critical Automatic Plugin SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27956 Patchstack
9.8 Critical Create by Mediavine Plugin mediavine-create SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 1.9.4 CVE-2024-1711 Wordfence
9.9 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.11.15 Fixed in 2.11.16 CVE-2024-29135 Patchstack
10.0 Critical Pie Register Plugin pie-register Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.8.3.1 CVE-2024-27957 Patchstack
9.9 Critical File Manager And File Manager Pro (Multiple Versions) Plugin Path Traversal Directory Traversal ≤ 7.2.1, ≤ 8.3.4 CVE-2023-6825 Wordfence
9.8 Critical Malware Scanner Plugin miniorange-malware-protection Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.1.1, ≤ 4.7.2 CVE-2024-2172 Wordfence
9.8 Critical Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member SQL Injection User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to SQL Injection via the 'sor… No login needed 2.1.3 – 2.8.2 CVE-2024-1071 Wordfence
9.8 Critical Migration, Backup, Staging – WPvivid Plugin wpvivid-backuprestore SQL Injection WPvivid plugin for WordPress is vulnerable to SQL Injection via the 'table_prefix' parameter in version 0.9.68 due to insufficient escaping on the… No login needed 0.9.68 CVE-2024-1981 Wordfence
9.1 Critical Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Arbitrary File Upload WordPress Mollie Payments for WooCommerce Plugin <= 7.3.11 is vulnerable to Arbitrary File Upload ≤ 7.3.11 Fixed in 7.3.12 CVE-2023-6090 Patchstack
9.8 Critical MoveTo Plugin SQL Injection WordPress MoveTo Plugin <= 6.2 is vulnerable to SQL Injection No login needed ≤ 6.2 CVE-2024-25910 Patchstack
9.3 Critical postMash – custom post order Plugin postmash SQL Injection custom post order Plugin <= 1.2.0 is vulnerable to SQL Injection No login needed ≤ 1.2.0 CVE-2024-25927 Patchstack
9.8 Critical WP eCommerce Plugin wp-e-commerce SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.15.1 CVE-2024-1514 Wordfence
9.8 Critical NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor Plugin notificationx SQL Injection Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 - Unauthenticated SQL Injection No login needed ≤ 2.8.2 CVE-2024-1698 Wordfence
9.9 Critical WP Media folder Plugin Arbitrary File Upload WordPress WP Media folder Plugin <= 5.7.2 is vulnerable to Arbitrary File Upload ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25909 Patchstack
10.0 Critical MoveTo Plugin Arbitrary File Upload WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload No login needed ≤ 6.2 CVE-2024-25913 Patchstack
10.0 Critical WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin Arbitrary File Upload WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload No login needed ≤ 3.5.12 Fixed in 3.5.13 CVE-2024-25925 Patchstack
9.8 Critical Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.6.5.1 CVE-2024-0610 Wordfence
9.8 Critical MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system SQL Injection for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection No login needed ≤ 3.2.5 CVE-2024-1512 Wordfence
9.8 Critical Web3 – Crypto wallet Login & NFT token gating Plugin web3-authentication Authentication Bypass Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass No login needed < 3.0.0 Fixed in 3.0.0 CVE-2023-6036 WPScan
9.8 Critical ERE Recently Viewed – Essential Real Estate Add-On Plugin ere-recently-viewed PHP Object Injection WordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object Injection No login needed ≤ 1.3 CVE-2024-24797 Patchstack
10.0 Critical Coupon Referral Program Plugin coupon-referral-program PHP Object Injection Unauthenticated PHP Object Injection No login needed < 1.8.4 Fixed in 1.8.4 CVE-2024-25100 Patchstack
9.8 Critical Booking Calendar Plugin booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 9.9 CVE-2024-1207 Wordfence
9.8 Critical Cryptocurrency Widgets – Price Ticker & Coins List Plugin cryptocurrency-price-ticker-widget SQL Injection Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficie… No login needed 2.0 – 2.6.5 CVE-2024-0709 Wordfence
9.1 Critical Photo Gallery by 10Web - Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename ≤ 1.8.19 CVE-2024-0221 Wordfence
9.8 Critical Shield Security – Smart Bot Blocking & Intrusion Prevention Security Plugin Local File Inclusion Smart Bot Blocking & Intrusion Prevention Security <= 18.5.9 - Unauthenticated Local File Inclusion No login needed ≤ 18.5.9 CVE-2023-6989 Wordfence
9.8 Critical 3DPrint Lite Plugin 3dprint-lite Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 1.9.1.5 Fixed in 1.9.1.5 CVE-2021-4436 WPScan
10.0 Critical Barcode Scanner and Inventory manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Arbitrary File Upload WordPress Barcode Scanner with Inventory & Order Manager Plugin <= 1.5.1 is vulnerable to Arbitrary File Upload No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52221 Patchstack
9.8 Critical Stripe Payment Plugin for WooCommerce Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.7.9 CVE-2024-0705 Wordfence
10.0 Critical Social Warfare Plugin Remote Code Execution No login needed < 3.5.3 Fixed in 3.5.3 CVE-2021-4434 Wordfence
9.8 Critical GiveWP Plugin give SQL Injection Unauthenticated SQLi No login needed < 2.24.1 Fixed in 2.24.1 CVE-2023-0224 WPScan
9.8 Critical WordPress Database Administrator Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.3 CVE-2023-3211 WPScan
9.8 Critical The School Management Plugin school-management-system Remote Code Execution Unauthenticated RCE via REST api No login needed < 9.9.7 Fixed in 9.9.7 CVE-2022-1609 WPScan
9.8 Critical Essential Blocks Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed < 4.4.3 Fixed in 4.4.3 CVE-2023-6623 WPScan
9.8 Critical Estatik Real Estate Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed < 4.1.1 Fixed in 4.1.1 CVE-2023-6049 WPScan
9.8 Critical POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp Broken Access Control Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API No login needed ≤ 2.8.7 CVE-2023-6875 Wordfence
9.8 Critical MW WP Form Plugin mw-wp-form Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.1 CVE-2023-6316 Wordfence
9.8 Critical LearnPress Plugin learnpress SQL Injection Unauthenticated SQL Injection via order_by No login needed ≤ 4.2.5.7 CVE-2023-6567 Wordfence
9.1 Critical WP Compress – Image Optimizer [All-In-One] Plugin Path Traversal Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css No login needed ≤ 6.10.33 CVE-2023-6699 Wordfence
9.1 Critical HTML5 MP3 Player with Folder Feedburner Playlist Free Plugin html5-mp3-player-with-mp3-folder-feedburner-playlist PHP Object Injection WordPress HTML5 MP3 Player with Folder Feedburner Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52202 Patchstack
9.6 Critical ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Request Forgery WordPress ARMember Plugin <= 4.0.22 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object Injection No login needed ≤ 4.0.22 Fixed in 4.0.23 CVE-2023-52200 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack
9.1 Critical HTML5 MP3 Player with Playlist Free Plugin html5-mp3-player-with-playlist PHP Object Injection WordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object Injection ≤ 3.0.0 CVE-2023-52207 Patchstack
9.8 Critical Duplicator Plugin duplicator Remote Code Execution Unauthenticated RCE No login needed < 1.3.0 Fixed in 1.3.0 CVE-2018-25095 WPScan
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack
9.9 Critical Gecka Terms Thumbnails Plugin gecka-terms-thumbnails PHP Object Injection WordPress Gecka Terms Thumbnails Plugin <= 1.1 is vulnerable to PHP Object Injection ≤ 1.1 CVE-2023-52219 Patchstack
10.0 Critical Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics Plugin taggbox-widget PHP Object Injection WordPress Taggbox Plugin <= 3.1 is vulnerable to PHP Object Injection No login needed ≤ 3.1 CVE-2023-52225 Patchstack
10.0 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Arbitrary File Upload Best Help Desk & Support Plugin Plugin <= 2.7.1 is vulnerable to Arbitrary File Upload No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46839 Patchstack
9.8 Critical affiliate-toolkit Plugin affiliate-toolkit-starter Server-Side Request Forgery Unauthenticated SSRF No login needed < 3.4.3 Fixed in 3.4.3 CVE-2023-5877 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only