WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,551–22,600 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 452 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Youzify Plugin youzify Broken Access Control ≤ 1.2.6 Fixed in 1.2.8 CVE-2024-39635 Patchstack
5.3 Medium Icegram Plugin icegram Broken Access Control Unauthenticated Message Duplication No login needed ≤ 3.1.24 Fixed in 3.1.25 CVE-2024-39625 Patchstack
6.5 Medium WP Social Feed Gallery Plugin insta-gallery Broken Access Control No login needed ≤ 4.3.9 Fixed in 4.4.0 CVE-2024-39640 Patchstack
4.3 Medium WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Broken Access Control + CSRF ≤ 4.24.7 Fixed in 4.24.8 CVE-2024-39639 Patchstack
7.3 High WooCommerce PDF Vouchers Plugin Broken Access Control Unauthenticated Multiple Vulnerabilities No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2024-39650 Patchstack
7.3 High Filter & Grids Plugin ymc-smart-filter Authentication Bypass Broken Authentication No login needed ≤ 2.8.33 Fixed in 2.8.34 CVE-2024-39664 Patchstack
5.3 Medium Sign-up Sheets Plugin sign-up-sheets Broken Access Control No login needed ≤ 2.2.12 Fixed in 2.2.13 CVE-2024-39654 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43118 Patchstack
5.3 Medium TypeSquare Webfonts Plugin xserver-typesquare-webfonts Broken Access Control No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-43120 Patchstack
4.3 Medium Aruba HiSpeed Cache Plugin aruba-hispeed-cache Broken Access Control ≤ 2.0.12 Fixed in 2.0.13 CVE-2024-43119 Patchstack
6.5 Medium Robin image optimizer Plugin robin-image-optimizer Broken Access Control ≤ 1.6.9 Fixed in 1.7.0 CVE-2024-43122 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.1 Fixed in 3.2.2 CVE-2024-43136 Patchstack
4.3 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Broken Access Control ≤ 2.6 Fixed in 2.6.1 CVE-2024-43134 Patchstack
4.3 Medium Tutor LMS Plugin tutor Broken Access Control ≤ 2.7.3 Fixed in 2.7.4 CVE-2024-43142 Patchstack
6.3 Medium AMP for WP Plugin accelerated-mobile-pages Broken Access Control ≤ 1.0.96.1 Fixed in 1.0.97 CVE-2024-43146 Patchstack
6.4 Medium Registrations for the Events Calendar Plugin registrations-for-the-events-calendar Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-43143 Patchstack
4.3 Medium FormCraft Plugin formcraft-form-builder Broken Access Control ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-43157 Patchstack
4.3 Medium Advanced Cron Manager – debug & control Plugin advanced-cron-manager Broken Access Control debug & control plugin <= 2.5.9 - Broken Access Control ≤ 2.5.9 Fixed in 2.5.10 CVE-2024-43154 Patchstack
7.5 High Masteriyo - LMS Plugin learning-management-system Broken Access Control No login needed ≤ 1.11.4 Fixed in 1.11.5 CVE-2024-43158 Patchstack
4.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Broken Access Control ≤ 3.2.12 Fixed in 3.3.1 CVE-2024-43162 Patchstack
5.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control No login needed ≤ 1.11.6 Fixed in 1.12.0 CVE-2024-43159 Patchstack
6.5 Medium Bitly Plugin wp-bitly Broken Access Control No login needed ≤ 2.7.2 CVE-2024-43209 Patchstack
4.3 Medium Send Emails with Mandrill Plugin send-emails-with-mandrill Broken Access Control ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-43208 Patchstack
5.9 Medium MailChimp Subscribe Forms Plugin mailchimp-subscribe-sm Cross-Site Scripting Stored Cross-Site Scripting ≤ 4.0.9.9 CVE-2024-43211 Patchstack
4.3 Medium Social Slider Feed Plugin instagram-slider-widget Broken Access Control ≤ 2.2.2 Fixed in 2.2.5 CVE-2024-43215 Patchstack
7.5 High WpTravelly Plugin tour-booking-manager Broken Access Control No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-43212 Patchstack
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control ≤ 4.0.3.2 Fixed in 4.0.4.0 CVE-2024-43223 Patchstack
5.3 Medium Persian WooCommerce Plugin persian-woocommerce Broken Access Control No login needed ≤ 7.1.6 Fixed in 9.0.0 CVE-2024-43219 Patchstack
4.3 Medium WP Search Analytics Plugin search-analytics Broken Access Control ≤ 1.4.9 Fixed in 1.4.10 CVE-2024-43229 Patchstack
5.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-43253 Patchstack
7.1 High Meta Box – WordPress Custom Fields Framework Plugin meta-box Broken Access Control ≤ 5.9.10 Fixed in 5.9.11 CVE-2024-43235 Patchstack
5.4 Medium Clearfy Cache Plugin clearfy Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2024-43260 Patchstack
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-43254 Patchstack
5.4 Medium Backup and Restore Plugin wp-backitup Broken Access Control ≤ 1.50 CVE-2024-43268 Patchstack
5.4 Medium Icegram Collect Plugin icegram-rainmaker Broken Access Control ≤ 1.3.14 Fixed in 1.3.15 CVE-2024-43273 Patchstack
5.3 Medium Backup and Restore Plugin wp-backitup Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.50 CVE-2024-43270 Patchstack
5.3 Medium UsersWP Plugin userswp Broken Access Control No login needed ≤ 1.2.15 Fixed in 1.2.16 CVE-2024-43277 Patchstack
5.8 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control The Ultimate Help Desk plugin <= 2.8.6 - Broken Access Control No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-43274 Patchstack
6.3 Medium Presto Player Plugin presto-player Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-43285 Patchstack
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2024-43293 Patchstack
5.3 Medium Atarim Plugin atarim-visual-collaboration Broken Access Control No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-43290 Patchstack
4.3 Medium Flash & HTML5 Video Plugin html5-video-player Broken Access Control ≤ 2.5.30 Fixed in 2.5.31 CVE-2024-43296 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2024-43298 Patchstack
4.3 Medium Clone Plugin wp-clone-by-wp-academy Broken Access Control ≤ 2.4.5 Fixed in 2.4.6 CVE-2024-43297 Patchstack
4.3 Medium Fonts Plugin olympus-google-fonts Broken Access Control ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43302 Patchstack
5.4 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.1.9 Fixed in 7.2.0 CVE-2024-43312 Patchstack
6.5 Medium Print Barcode Labels for your WooCommerce products/orders Plugin a4-barcode-generator Broken Access Control ≤ 3.4.9 Fixed in 3.4.10 CVE-2024-43310 Patchstack
4.3 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Broken Access Control ≤ 1.3.9.3 Fixed in 1.3.9.4 CVE-2024-43314 Patchstack
4.3 Medium Photo Engine Plugin wplr-sync Broken Access Control ≤ 6.4.0 Fixed in 6.4.1 CVE-2024-43332 Patchstack
5.3 Medium ReviewX Plugin reviewx Broken Access Control No login needed ≤ 1.6.28 Fixed in 1.6.29 CVE-2024-43323 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only