WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,251–2,300 of 2,392 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Comments Extra Fields For Post,Pages and CPT | Cross-Site Request Forgery No login needed |
≤ 5.0 |
CVE-2024-0830 |
Wordfence | |
| 5.4 Medium | Related Posts | Cross-Site Request Forgery No login needed |
≤ 2.2.1 |
CVE-2024-0592 |
Wordfence | |
| 4.3 Medium | MainWP Dashboard | Cross-Site Request Forgery Cross-Site Request Forgery via posting_bulk No login needed |
≤ 4.6.0.1 |
CVE-2024-1642 |
Wordfence | |
| 5.3 Medium | Team Circle Image Slider With Lightbox | Cross-Site Request Forgery The Team Circle Image Slider With Lightbox plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on… No login needed |
1.0 |
CVE-2015-10130 |
Wordfence | |
| 4.3 Medium | Easy Social Feed | Cross-Site Request Forgery No login needed |
≤ 6.5.4 |
CVE-2024-1214 |
Wordfence | |
| 4.3 Medium | Tutor LMS – eLearning and online course solution | Cross-Site Request Forgery eLearning and online course solution <= 2.6.1 - Cross-Site Request Forgery to Plugin Deactivation and Data Erase No login needed |
≤ 2.6.1 |
CVE-2024-1503 |
Wordfence | |
| 5.4 Medium | Easy Social Feed | Cross-Site Request Forgery No login needed |
≤ 6.5.4 |
CVE-2024-1213 |
Wordfence | |
| 7.3 High | Bulgarisation for WooCommerce | Cross-Site Request Forgery No login needed |
≤ 3.0.14 |
CVE-2024-2395 |
Wordfence | |
| 4.3 Medium | LadiApp | Cross-Site Request Forgery Cross-Site Request Forgery via save_config() No login needed |
≤ 4.3 |
CVE-2023-4629 |
Wordfence | |
| 4.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Cross-Site Request Forgery Cross-Site Request Forgery via publish_lp() No login needed |
≤ 4.4 |
CVE-2023-4729 |
Wordfence | |
| 4.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Cross-Site Request Forgery Cross-Site Request Forgery via init_endpoint No login needed |
≤ 4.4 |
CVE-2023-4731 |
Wordfence | |
| 4.3 Medium | LadiApp | Cross-Site Request Forgery Cross-Site Request Forgery via ladiflow_save_hook() No login needed |
≤ 4.4 |
CVE-2023-4628 |
Wordfence | |
| 8.8 High | Digits: WordPress Mobile Number Signup and Login | Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed |
8.4.1 |
CVE-2024-0203 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Reset No login needed |
≤ 1.6.6.20 |
CVE-2024-1760 |
Wordfence | |
| 5.4 Medium | Master Slider - Responsive Touch Slider | Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed |
≤ 3.9.10 |
CVE-2023-6326 |
Wordfence | |
| 4.3 Medium | Complianz – GDPR/CCPA Cookie Consent | Cross-Site Request Forgery GDPR/CCPA Cookie Consent <= 6.5.6 - Cross-Site Request Forgery to Data Request Deletion No login needed |
≤ 6.5.6 |
CVE-2024-1592 |
Wordfence | |
| 5.4 Medium | Sirv | Server-Side Request Forgery |
≤ 7.2.0 Fixed in 7.2.1 |
CVE-2024-27949 |
Patchstack | |
| 5.5 Medium | Friends | Server-Side Request Forgery Authenticated (Admin+) Blind Server-Side Request Forgery |
≤ 2.8.5 |
CVE-2024-1978 |
Wordfence | |
| 4.3 Medium | Marketing Optimizer | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 20200925 |
CVE-2024-1976 |
Wordfence | |
| 5.4 Medium | Thrive Automator | Cross-Site Request Forgery WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.17 Fixed in 1.17.1 |
CVE-2023-51531 |
Patchstack | |
| 4.3 Medium | Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation | Cross-Site Request Forgery WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.5.1 Fixed in 3.5.2 |
CVE-2023-51530 |
Patchstack | |
| 4.3 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Request Forgery WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.3.3 Fixed in 2.3.4 |
CVE-2023-51529 |
Patchstack | |
| 4.3 Medium | AI Power: Complete AI Pack – Powered by GPT-4 | Cross-Site Request Forgery WordPress GPT3 AI Content Writer Plugin <= 1.8.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.8.12 Fixed in 1.8.13 |
CVE-2023-51528 |
Patchstack | |
| 4.3 Medium | Spam protection, Anti-Spam, FireWall by CleanTalk | Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.20 Fixed in 6.21 |
CVE-2023-51696 |
Patchstack | |
| 5.4 Medium | Ecwid Ecommerce Shopping Cart | Cross-Site Request Forgery WordPress Ecwid Shopping Cart Plugin <= 6.12.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.12.4 Fixed in 6.12.5 |
CVE-2023-51533 |
Patchstack | |
| 5.4 Medium | Atahualpa | Cross-Site Request Forgery WordPress Atahualpa Theme <= 3.7.24 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.7.24 |
CVE-2024-27948 |
Patchstack | |
| 5.4 Medium | Easy PayPal & Stripe Buy Now Button | Cross-Site Request Forgery WordPress Easy PayPal Buy Now Button Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.8.1 Fixed in 1.8.2 |
CVE-2023-51683 |
Patchstack | |
| 6.5 Medium | Duplicator – WordPress Migration & Backup | Cross-Site Request Forgery WordPress Duplicator Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.7 Fixed in 1.5.7.1 |
CVE-2023-51681 |
Patchstack | |
| 5.4 Medium | MailerLite – WooCommerce integration | Cross-Site Request Forgery WooCommerce integration Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2023-52223 |
Patchstack | |
| 4.3 Medium | Advanced Flamingo | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2023-52226 |
Patchstack | |
| 5.4 Medium | 1 click disable all | Cross-Site Request Forgery WordPress 1 click disable all Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.1 |
CVE-2024-21749 |
Patchstack | |
| 4.3 Medium | Email Before Download | Cross-Site Request Forgery WordPress Email Before Download Plugin <= 6.9.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.9.7 Fixed in 6.9.8 |
CVE-2024-23519 |
Patchstack | |
| 4.3 Medium | A no-code page builder for beautiful performance-based content | Cross-Site Request Forgery WordPress Setka Editor Plugin <= 2.1.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.1.20 |
CVE-2024-24701 |
Patchstack | |
| 4.3 Medium | Page Restrict | Cross-Site Request Forgery WordPress Page Restrict Plugin <= 2.5.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.5.5 |
CVE-2024-24702 |
Patchstack | |
| 5.4 Medium | Accessibility | Cross-Site Request Forgery WordPress Accessibility Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.6 |
CVE-2024-24705 |
Patchstack | |
| 4.3 Medium | W3SPEEDSTER | Cross-Site Request Forgery WordPress W3SPEEDSTER Plugin <= 7.19 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.19 |
CVE-2024-24708 |
Patchstack | |
| 4.3 Medium | Custom Order Statuses for WooCommerce | Cross-Site Request Forgery WordPress Custom Order Statuses for WooCommerce Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.2 |
CVE-2024-25930 |
Patchstack | |
| 4.3 Medium | Heureka | Cross-Site Request Forgery WordPress Heureka Plugin <= 1.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.8 |
CVE-2024-25931 |
Patchstack | |
| 4.3 Medium | Change Table Prefix | Cross-Site Request Forgery No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2024-25932 |
Patchstack | |
| 4.3 Medium | Easy PayPal & Stripe Buy Now Button | Cross-Site Request Forgery PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.8.3, ≤ 2.1 |
CVE-2024-1719 |
Wordfence | |
| 4.3 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_plugin_activation No login needed |
≤ 1.4.4 |
CVE-2024-0767 |
Wordfence | |
| 6.3 Medium | Oliver POS – A WooCommerce Point of Sale (POS) | Cross-Site Request Forgery A WooCommerce Point of Sale (POS) <= 2.4.1.8 - Cross-Site Request Forgery No login needed |
≤ 2.4.1.8 |
CVE-2024-1954 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_set_default_card No login needed |
≤ 20221130 |
CVE-2024-0431 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_delete_card No login needed |
≤ 20221130 |
CVE-2024-0432 |
Wordfence | |
| 4.3 Medium | Envo's Elementor Templates & Widgets for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery via ajax_theme_activation No login needed |
≤ 1.4.4 |
CVE-2024-0768 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_unset_default_card No login needed |
≤ 20221130 |
CVE-2024-0433 |
Wordfence | |
| 4.3 Medium | Yuki | Cross-Site Request Forgery Cross-Site Request Forgery to Theme Setting Reset No login needed |
≤ 1.3.14 |
CVE-2024-1943 |
Wordfence | |
| 6.4 Medium | Seraphinite Accelerator | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery in OnAdminApi_HtmlCheck |
≤ 2.20.52 |
CVE-2024-1568 |
Wordfence | |
| 4.3 Medium | Categorify | Cross-Site Request Forgery Cross-Site Request Forgery via categorifyAjaxClearCategory No login needed |
≤ 1.0.7.4 |
CVE-2024-1910 |
Wordfence | |
| 4.3 Medium | Categorify | Cross-Site Request Forgery Cross-Site Request Forgery via categorifyAjaxAddCategory No login needed |
≤ 1.0.7.4 |
CVE-2024-1906 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.