WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 22,151–22,200 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 9.8 Critical | Really Simple Security (Free, Pro, and Pro Multisite) | Authentication Bypass No login needed |
9.0.0 – 9.1.1.1 |
CVE-2024-10924 |
Wordfence | |
| 7.1 High | WP Course Manager | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.3 |
CVE-2024-51658 |
Patchstack | |
| 7.1 High | Twitter @Anywhere Plus | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.0 |
CVE-2024-51659 |
Patchstack | |
| 7.1 High | Appointmind | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 4.0.0 Fixed in 4.1.0 |
CVE-2024-51679 |
Patchstack | |
| 7.1 High | W3P SEO | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.8.6 Fixed in 1.8.6 |
CVE-2024-51684 |
Patchstack | |
| 7.1 High | Platform.ly Official | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1.3 Fixed in 1.14 |
CVE-2024-51687 |
Patchstack | |
| 7.1 High | FraudLabs Pro SMS Verification | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.10.1 Fixed in 1.10.2 |
CVE-2024-51688 |
Patchstack | |
| 9.9 Critical | KBucket | Arbitrary File Upload |
≤ 4.2.2 Fixed in 4.2.3 |
CVE-2024-52369 |
Patchstack | |
| 9.9 Critical | Hive Support | Arbitrary File Upload WordPress Help Desk, Live Chat & AI Chat Bot Plugin for WordPress plugin <= 1.1.1 - Arbitrary File Upload |
≤ 1.1.1 Fixed in 1.1.2 |
CVE-2024-52370 |
Patchstack | |
| 10.0 Critical | Easy CSV Importer BETA | Arbitrary File Upload No login needed |
≤ 7.0.0 |
CVE-2024-52372 |
Patchstack | |
| 10.0 Critical | Devexhub Gallery | Arbitrary File Upload No login needed |
≤ 2.0.1 |
CVE-2024-52373 |
Patchstack | |
| 10.0 Critical | Do That Task | Arbitrary File Upload No login needed |
≤ 1.5.5 |
CVE-2024-52374 |
Patchstack | |
| 10.0 Critical | Datasets Manager by Arttia Creative | Arbitrary File Upload No login needed |
≤ 1.5 |
CVE-2024-52375 |
Patchstack | |
| 10.0 Critical | Boat Rental | Arbitrary File Upload No login needed |
≤ 1.0.1 |
CVE-2024-52376 |
Patchstack | |
| 10.0 Critical | Instant Image Generator | Arbitrary File Upload No login needed |
≤ 1.5.2 Fixed in 1.5.3 |
CVE-2024-52377 |
Patchstack | |
| 7.5 High | DigiPass | Path Traversal Arbitrary File Download No login needed |
≤ 0.3.0 |
CVE-2024-52378 |
Patchstack | |
| 10.0 Critical | kineticPay for WooCommerce | Arbitrary File Upload No login needed |
≤ 2.0.8 Fixed in 3.0 |
CVE-2024-52379 |
Patchstack | |
| 10.0 Critical | Picsmize | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-52380 |
Patchstack | |
| 9.8 Critical | Matix Popup Builder | Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed |
≤ 1.0.0 |
CVE-2024-52382 |
Patchstack | |
| 7.5 High | Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One | Broken Access Control No login needed |
≤ 2.1.2 Fixed in 2.1.3 |
CVE-2024-52383 |
Patchstack | |
| 9.9 Critical | Sage AI: Chatbots, OpenAI GPT-4 Bulk Articles, Dalle-3 Image Generation | Arbitrary File Upload |
≤ 2.4.9 |
CVE-2024-52384 |
Patchstack | |
| 8.1 High | ZIJ KART | Local File Inclusion No login needed |
≤ 1.1 |
CVE-2024-52381 |
Patchstack | |
| 4.9 Medium | WOLF | Path Traversal CSV Limited Path Traversal |
≤ 1.0.8.3 Fixed in 1.0.8.4 |
CVE-2024-52396 |
Patchstack | |
| 8.6 High | Global Gateway e4 | Payeezy Gateway | | Arbitrary File Deletion No login needed |
≤ 2.0 |
CVE-2024-52371 |
Patchstack | |
| 9.1 Critical | Podlove Podcast Publisher | Remote Code Execution Admin+ Remote Code Execution (RCE) |
≤ 4.1.15 Fixed in 4.1.17 |
CVE-2024-52393 |
Patchstack | |
| 8.8 High | Migration, Backup, Staging – WPvivid | PHP Object Injection WPvivid <= 0.9.107 - Unauthenticated PHP Object Injection No login needed |
≤ 0.9.107 |
CVE-2024-10962 |
Wordfence | |
| 9.8 Critical | Chartify – WordPress Chart | Local File Inclusion WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source No login needed |
≤ 2.9.5 |
CVE-2024-10571 |
Wordfence | |
| 8.6 High | Automation By Autonami | SQL Injection Unauthenticated SQLi No login needed |
< 3.3.0 Fixed in 3.3.0 |
CVE-2024-9186 |
WPScan | |
| 5.4 Medium | Simple File List | Cross-Site Scripting Reflected Cross-Site Scripting |
< 6.1.13 Fixed in 6.1.13 |
CVE-2024-10146 |
WPScan | |
| 9.8 Critical | MultiManager WP – Manage All Your WordPress Sites Easily | Authentication Bypass Manage All Your WordPress Sites Easily <= 1.0.5 - Authentication Bypass via User Impersonation No login needed |
≤ 1.0.5 |
CVE-2024-11028 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget |
≤ 1.7.1001 |
CVE-2024-9682 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget |
≤ 1.7.1001 |
CVE-2024-9668 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Template | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget |
≤ 1.7.1001 |
CVE-2024-9059 |
Wordfence | |
| 6.1 Medium | AFI – The Easiest Integration | Cross-Site Scripting The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting No login needed |
≤ 1.92.0 |
CVE-2024-10877 |
Wordfence | |
| 9.8 Critical | WordPress User Extra Fields | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
≤ 16.6 |
CVE-2024-11150 |
Wordfence | |
| 8.8 High | WordPress User Extra Fields | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation |
≤ 16.6 |
CVE-2024-10800 |
Wordfence | |
| 7.5 High | LUNA RADIO PLAYER | Path Traversal Unauthenticated Arbitrary File Read No login needed |
≤ 6.24.01.24 |
CVE-2024-10816 |
Wordfence | |
| 7.3 High | WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts | Broken Access Control Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.13 - Insecure Direct Object Reference to Unauthenticated Authorization Bypass No login needed |
≤ 2.6.13 |
CVE-2024-10174 |
Wordfence | |
| 9.8 Critical | WooCommerce Upload Files | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 84.3 |
CVE-2024-10820 |
Wordfence | |
| 8.1 High | Advanced Order Export For WooCommerce | PHP Object Injection Unauthenticated PHP Object Injection via Order Details No login needed |
≤ 3.5.5 |
CVE-2024-10828 |
Wordfence | |
| 4.3 Medium | Boostify Header Footer Builder for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.3.6 |
CVE-2024-10794 |
Wordfence | |
| 5.3 Medium | Hash Elements | Broken Access Control Missing Authorization to Unauthenticated Draft Post Title Exposure No login needed |
≤ 1.4.7 |
CVE-2024-10802 |
Wordfence | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed |
≤ 2.1.7 |
CVE-2024-10529 |
Wordfence | |
| 4.3 Medium | Kognetiks Chatbot | Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed |
≤ 2.1.8 |
CVE-2024-11143 |
Wordfence | |
| 6.1 Medium | Kognetiks Chatbot | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.7 |
CVE-2024-10684 |
Wordfence | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Update No login needed |
≤ 2.1.7 |
CVE-2024-10531 |
Wordfence | |
| 4.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Addition |
≤ 2.1.7 |
CVE-2024-10530 |
Wordfence | |
| 4.3 Medium | WPForms – Easy Form Builder | Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed |
≤ 1.9.1.6 |
CVE-2024-10593 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce - Lite | Cross-Site Scripting Lite <= 2.8.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.8.0 |
CVE-2024-10882 |
Wordfence | |
| 6.4 Medium | Aqua SVG Sprite | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 3.0.14 |
CVE-2024-9426 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.