WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,451–22,500 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 450 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Accordion title for Elementor Plugin accordion-title-for-elementor Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-51685 Patchstack
8.5 High Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection ≤ 1.1 CVE-2024-51626 Patchstack
7.6 High BetterLinks Plugin betterlinks SQL Injection ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-51672 Patchstack
7.5 High Stacks Mobile App Builder Plugin stacks-mobile-app-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.3 CVE-2024-50528 Patchstack
10.0 Critical All Post Contact Form Plugin allpost-contactform Arbitrary File Upload No login needed ≤ 1.8.2 CVE-2024-50523 Patchstack
10.0 Critical Helloprint Plugin helloprint Arbitrary File Upload No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-50525 Patchstack
10.0 Critical Multi Purpose Mail Form Plugin multi-purpose-mail-form Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-50526 Patchstack
10.0 Critical Stacks Mobile App Builder Plugin stacks-mobile-app-builder Arbitrary File Upload No login needed ≤ 5.2.3 CVE-2024-50527 Patchstack
9.9 Critical Training – Courses Plugin training Arbitrary File Upload Courses plugin <= 2.0.1 - Arbitrary File Upload ≤ 2.0.1 CVE-2024-50529 Patchstack
9.9 Critical Stars SMTP Mailer Plugin stars-smtp-mailer Arbitrary File Upload ≤ 2.2.1 CVE-2024-50530 Patchstack
10.0 Critical RSVPMaker for Toastmasters Plugin rsvpmaker-for-toastmasters Arbitrary File Upload No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2024-50531 Patchstack
7.5 High WP Hotel Booking Plugin wp-hotel-booking Local File Inclusion ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-51582 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
9.1 Critical Media LIbrary Assistant Plugin media-library-assistant Remote Code Execution ≤ 3.19 Fixed in 3.20 CVE-2024-51661 Patchstack
6.1 Medium BBP Core – Expand bbPress powered forums with useful features Plugin bbp-core Cross-Site Scripting Expand bbPress powered forums with useful features <= 1.2.5 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 1.2.5 CVE-2024-9896 Wordfence
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.10.1 CVE-2024-9868 Wordfence
6.1 Medium ReCaptcha Integration Plugin wp-recaptcha-integration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-8739 Wordfence
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
6.5 Medium User Rights Access Manager Plugin user-rights-access-manager Broken Access Control ≤ 1.1.2 CVE-2024-37209 Patchstack
6.5 Medium Htaccess File Editor Plugin htaccess-file-editor Broken Access Control ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-49256 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control ≤ 3.12.3 Fixed in 3.12.4 CVE-2024-48045 Patchstack
5.4 Medium ShortPixel Image Optimizer Plugin shortpixel-image-optimiser Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-48044 Patchstack
4.3 Medium CubeWP Plugin cubewp-framework Broken Access Control ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-48039 Patchstack
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-47314 Patchstack
5.3 Medium Wheel of Life Plugin wheel-of-life Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-47311 Patchstack
5.3 Medium Fluent Support Plugin fluent-support Broken Access Control Broken Access Control on Email Verification No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47302 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-44038 Patchstack
5.4 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Broken Access Control Subscriber+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37250 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin Broken Access Control Contributor+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37249 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium Popup box Plugin ays-popup-box Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2024-37096 Patchstack
7.7 High WishList Member X Plugin Arbitrary File Deletion Authenticated Arbitrary File Deletion ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37108 Patchstack
8.2 High WishList Member X Plugin Cross-Site Scripting Unautenticated Plugin Settings Change Leading to Stored XSS No login needed ≤ 3.26.6 Fixed in 3.26.7 CVE-2024-37106 Patchstack
5.3 Medium Ibtana Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder plugin <= 1.2.3.3 - Broken Access Control No login needed ≤ 1.2.3.3 Fixed in 1.2.3.4 CVE-2024-37123 Patchstack
5.3 Medium Uncanny Automator Pro Plugin uncanny-automator-pro Broken Access Control Unauthenticated License Settings Reset No login needed ≤ 5.3.0.0 Fixed in 5.3.0.1 CVE-2024-37119 Patchstack
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-37204 Patchstack
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
5.4 Medium Demo Awesome Plugin demo-awesome Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-37207 Patchstack
6.5 Medium Ali2Woo Lite Plugin ali2woo-lite Broken Access Control Broken Access Control to XSS ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37214 Patchstack
5.3 Medium Optinly Plugin optinly Broken Access Control No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-37220 Patchstack
4.3 Medium Page Builder Sandwich – Front-End Page Builder Plugin page-builder-sandwich Broken Access Control ≤ 5.1.0 CVE-2024-37218 Patchstack
5.3 Medium Kanban Boards Plugin kanban Broken Access Control No login needed ≤ 2.5.21 CVE-2024-37226 Patchstack
4.3 Medium File Manager Plugin wp-file-manager Broken Access Control ≤ 7.2.7 Fixed in 7.2.8 CVE-2024-37254 Patchstack
8.8 High Hercules Core Plugin Broken Access Control Subscriber+ Arbitrary Settings Change/Access ≤ 6.5 Fixed in 6.7 CVE-2024-37232 Patchstack
5.3 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-37269 Patchstack
5.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 3.1.4 Fixed in 3.2.0 CVE-2024-37255 Patchstack
5.3 Medium Featured Image from URL Plugin featured-image-from-url Broken Access Control No login needed ≤ 4.8.1 Fixed in 4.8.2 CVE-2024-37276 Patchstack
5.3 Medium Progress Planner Plugin progress-planner Broken Access Control No login needed ≤ 0.9.1 Fixed in 0.9.2 CVE-2024-37411 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only