WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,601–22,650 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 453 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Order Tracking Plugin order-tracking Broken Access Control WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control ≤ 3.3.12 Fixed in 3.3.13 CVE-2024-43343 Patchstack
6.5 Medium Hello Agency Theme hello-agency Broken Access Control No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-43341 Patchstack
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control ≤ 5.3.0 Fixed in 5.5.7 CVE-2024-43355 Patchstack
5.3 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-43923 Patchstack
5.3 Medium YARPP Plugin yet-another-related-posts-plugin Broken Access Control No login needed ≤ 5.30.10 CVE-2024-43919 Patchstack
5.4 Medium JobSearch Plugin wp-jobsearch Broken Access Control ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43928 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control ≤ 1.8.14 Fixed in 1.8.15 CVE-2024-43925 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Broken Access Control ≤ 5.6.2 Fixed in 5.6.3 CVE-2024-43932 Patchstack
6.5 Medium JobSearch Plugin Broken Access Control No login needed ≤ 2.5.4 Fixed in 2.5.6 CVE-2024-43929 Patchstack
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Broken Access Control Settings Change ≤ 2.1.10 Fixed in 2.1.11 CVE-2024-43937 Patchstack
5.4 Medium LWS Affiliation Plugin lws-affiliation Broken Access Control ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43962 Patchstack
6.5 Medium Memberpress Plugin Broken Access Control No login needed ≤ 1.11.34 Fixed in 1.11.35 CVE-2024-43956 Patchstack
4.3 Medium Newspack Plugin newspack-plugin Broken Access Control ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-43968 Patchstack
6.5 Medium ReviveNews Theme revivenews Broken Access Control No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-43974 Patchstack
4.3 Medium GetPaid Plugin invoicing Broken Access Control ≤ 2.8.11 Fixed in 2.8.12 CVE-2024-43973 Patchstack
6.5 Medium Fota WP Theme fotawp Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-43980 Patchstack
6.5 Medium Blockbooster Theme blockbooster Broken Access Control No login needed ≤ 1.0.10 Fixed in 1.0.11 CVE-2024-43979 Patchstack
4.3 Medium GeoDirectory Plugin geodirectory Broken Access Control ≤ 2.3.70 Fixed in 2.3.71 CVE-2024-43981 Patchstack
6.5 Medium Blogpoet Theme blogpoet Broken Access Control No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-43998 Patchstack
8.8 High Login As Users Plugin login-as-users Broken Access Control Broken Access Control to Account Takeover ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-43982 Patchstack
4.3 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.6 Fixed in 5.3.7 CVE-2024-44006 Patchstack
4.3 Medium WP Free SSL – Free SSL Certificate for WordPress and force HTTPS Plugin wp-free-ssl Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-44020 Patchstack
5.3 Medium Contact Form 7 Campaign Monitor Extension Plugin contact-form-7-campaign-monitor-extension Arbitrary File Deletion No login needed ≤ 0.4.67 CVE-2024-44019 Patchstack
4.3 Medium JoomSport Plugin joomsport-sports-league-results-management Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-44031 Patchstack
5.4 Medium Truepush Plugin truepush-free-web-push-notifications Broken Access Control ≤ 1.0.8 CVE-2024-44021 Patchstack
4.3 Medium HelloAsso Plugin helloasso Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2024-44052 Patchstack
4.3 Medium Ads by WPQuads Plugin quick-adsense-reloaded Broken Access Control ≤ 2.0.84 Fixed in 2.0.85 CVE-2024-47317 Patchstack
6.5 Medium Templately Plugin templately Broken Access Control No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-47308 Patchstack
4.3 Medium PWA for WP & AMP Plugin pwa-for-wp Broken Access Control No login needed ≤ 1.7.72 Fixed in 1.7.73 CVE-2024-47318 Patchstack
5.3 Medium Popup Maker Plugin popup-maker Broken Access Control No login needed ≤ 1.19.2 Fixed in 1.20.0 CVE-2024-47358 Patchstack
6.5 Medium WP Datepicker Plugin wp-datepicker Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-47321 Patchstack
5.3 Medium Depicter Slider Plugin depicter Broken Access Control No login needed ≤ 3.2.2 Fixed in 3.5.0 CVE-2024-47359 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Broken Access Control ≤ 1.13.6 Fixed in 1.13.7 CVE-2024-47361 Patchstack
4.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-47362 Patchstack
8.2 High MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control No login needed ≤ 3.2.12 Fixed in 3.2.13 CVE-2024-37094 Patchstack
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.0.4 CVE-2024-10367 Wordfence
6.4 Medium AtomChat Plugin atomchat Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via atomchat Shortcode ≤ 1.1.5 CVE-2024-10232 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget ≤ 3.3.1 CVE-2024-9655 Wordfence
5.4 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Broken Access Control MPG <= 4.0.1 - Missing Authorization ≤ 4.0.1 CVE-2024-7424 Wordfence
6.5 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.3 CVE-2024-6479 Wordfence
6.4 Medium SIP Reviews Shortcode for WooCommerce Plugin sip-reviews-shortcode-woocommerce Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 1.2.3 CVE-2024-6480 Wordfence
4.3 Medium JobSearch Plugin wp-jobsearch Broken Access Control No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-43930 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 11.48 Fixed in 11.49 CVE-2024-43933 Patchstack
9.6 Critical Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Request Forgery CSRF to Remote Code Execution (RCE) No login needed ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43984 Patchstack
9.6 Critical EKC Tournament Manager Plugin ekc-tournament-manager Cross-Site Request Forgery CSRF to Arbitrary File Upload No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-49674 Patchstack
5.4 Medium Custom Twitter Feeds (Tweets Widget) Plugin custom-twitter-feeds Cross-Site Request Forgery No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49685 Patchstack
6.1 Medium WPGlobus Translate Options Plugin wpglobus-translate-options Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-9434 Wordfence
6.4 Medium WP Simple Anchors Links Plugin wp-simple-anchors-links Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpanchor Shortcode ≤ 1.0.0 CVE-2024-9446 Wordfence
5.3 Medium Get Quote For Woocommerce – Request A Quote For Woocommerce Plugin get-a-quote-for-woocommerce Broken Access Control Request A Quote For Woocommerce <= 1.0.0 - Missing Authorization to Unauthenticated Quote PDF and CSV Download No login needed ≤ 1.0.0 CVE-2024-9430 Wordfence
6.4 Medium Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) Plugin gift-voucher Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.4.4 CVE-2024-9165 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only