WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,901–22,950 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 459 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Mags Plugin mags Local File Inclusion No login needed ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-49701 Patchstack
7.2 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule PHP Object Injection ≤ 1.22.21 Fixed in 1.22.22 CVE-2024-49684 Patchstack
7.7 High 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Deletion ≤ 1.0.3 CVE-2024-49657 Patchstack
8.8 High iBryl Switch User Plugin ibryl-switch-user Privilege Escalation Account Takeover ≤ 1.0.1 CVE-2024-49675 Patchstack
6.1 Medium Nioland Theme Cross-Site Scripting Reflected Cross-Site Scripting via s No login needed ≤ 1.2.6 CVE-2024-10250 Wordfence
5.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 7.2.2 CVE-2024-8500 Wordfence
4.3 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Information Disclosure Sensitive Information Exposure ≤ 1.8.0 CVE-2024-9530 Wordfence
4.3 Medium Transients Manager Plugin transients-manager Cross-Site Request Forgery No login needed ≤ 2.0.6 CVE-2024-10045 Wordfence
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
8.1 High ProfilePress - Pro Plugin Authentication Bypass Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 4.11.1 CVE-2024-9947 Wordfence
4.3 Medium RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Broken Access Control RSS Import, News Feeds, Feed to Post, and Autoblogging <= 4.23.12 - Missing Authorization ≤ 4.23.12 CVE-2024-9583 Wordfence
6.5 Medium Download Plugin download-plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Metadata and Comment Download ≤ 2.2.0 CVE-2024-9829 Wordfence
7.2 High WooCommerce Order Proposal Plugin Privilege Escalation Authenticated (Shop Manager+) Privilege Escalation via Order Proposal ≤ 2.0.5 CVE-2024-9927 Wordfence
6.4 Medium Anchor Episodes Index (Spotify for Podcasters) Plugin anchor-episodes-index Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via anchor_episodes Shortcode ≤ 2.1.10 CVE-2024-10189 Wordfence
6.1 Medium WP-Members Membership Plugin wp-members Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.4.9.5 CVE-2024-9231 Wordfence
4.3 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Canvas Menu Elementor Template ≤ 1.2.1 CVE-2024-9541 Wordfence
5.5 Medium Category and Taxonomy Image Plugin wp-custom-taxonomy-image Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2024-9591 Wordfence
5.5 Medium Category and Taxonomy Meta Fields Plugin wp-custom-taxonomy-meta Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2024-9589 Wordfence
5.5 Medium Category and Taxonomy Meta Fields Plugin wp-custom-taxonomy-meta Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2024-9590 Wordfence
5.4 Medium Category and Taxonomy Meta Fields Plugin wp-custom-taxonomy-meta Cross-Site Request Forgery Cross-Site Request Forgery to Taxonomy Meta Add/Delete No login needed ≤ 1.0.0 CVE-2024-9588 Wordfence
8.6 High TeploBot - Telegram Bot for WP Plugin green-wp-telegram-bot-by-teplitsa Information Disclosure Telegram Bot for WP <= 1.3 - Telegram Bot Token Disclosure No login needed ≤ 1.3 CVE-2024-9627 Wordfence
5.3 Medium All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Information Disclosure Unauthenticated Information Disclosure via Error Logs No login needed ≤ 7.86 CVE-2024-8852 Wordfence
6.3 Medium Rover IDX Plugin rover-idx Broken Access Control Authenticated (Subscriber+) Missing Authorization via Multiple Functions ≤ 3.0.0.2903 CVE-2024-10003 Wordfence
8.8 High Rover IDX Plugin rover-idx Authentication Bypass Authenticated (Subscriber+) Authentication Bypass to Administrator ≤ 3.0.0.2905 CVE-2024-10002 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
4.3 Medium WP VR Plugin wpvr Broken Access Control ≤ 8.5.4 Fixed in 8.5.5 CVE-2024-49293 Patchstack
4.3 Medium Simple Custom Post Order Plugin simple-custom-post-order Broken Access Control ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-49321 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
7.6 High FunnelKit Automations Plugin wp-marketing-automations SQL Injection ≤ 3.1.2 Fixed in 3.2.0 CVE-2024-47328 Patchstack
7.2 High TS Poll – Survey, Versus Poll, Image Poll, Video Poll Plugin poll-wp SQL Injection Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection < 2.4.0 Fixed in 2.4.0 CVE-2024-8625 WPScan
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Account Takeover via Cookie Leak No login needed ≤ 6.5.0.1 Fixed in 6.5.0.1 CVE-2024-44000 Patchstack
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
7.1 High GoogleDrive folder list Plugin googledrive-folder-list Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49335 Patchstack
7.1 High AVChat Video Chat Plugin avchat-3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2 CVE-2024-49605 Patchstack
7.1 High Endless Posts Navigation Plugin endless-posts-navigation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-49629 Patchstack
8.5 High MPG Plugin multiple-pages-generator-by-porthas SQL Injection MPG plugin <= 3.4.7 - SQL Injection ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-47325 Patchstack
8.5 High Author Discussion Plugin author-discussion SQL Injection ≤ 0.2.2 CVE-2024-49609 Patchstack
8.5 High SW Contact Form Plugin sw-contact-form SQL Injection ≤ 1.0 CVE-2024-49612 Patchstack
8.5 High Simple Code Insert Shortcode Plugin simple-code-insert-shortcode SQL Injection ≤ 1.0 CVE-2024-49613 Patchstack
8.5 High SermonAudio Widgets Plugin sermonaudio-widgets SQL Injection ≤ 1.9.3 CVE-2024-49614 Patchstack
8.2 High SafetyForms Plugin safetymails-forms Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49615 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only