WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,151–23,200 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 464 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical Azz Anonim Posting Plugin azz-anonim-posting Arbitrary File Upload No login needed ≤ 0.9 CVE-2024-49257 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Remote Code Execution ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-49271 Patchstack
5.3 Medium WooCommerce Smart Coupons Plugin Broken Access Control Unauthenticated Coupon Creation No login needed < 4.6.5 Fixed in 4.6.5 CVE-2020-36841 Wordfence
9.8 Critical BuddyPress Better Registration Plugin better-bp-registration Authentication Bypass Broken Authentication No login needed ≤ 1.6 CVE-2024-49247 Patchstack
6.4 Medium Zita Elementor Site Library Plugin zita-site-library Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.6.3 CVE-2024-8921 Wordfence
6.4 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 6.4.3 CVE-2024-9444 Wordfence
6.1 Medium Video Grid Plugin video-grid Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.21 CVE-2023-7295 Wordfence
8.8 High Migration, Backup, Staging – WPvivid Plugin Arbitrary File Upload WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 0.9.35 CVE-2020-36842 Wordfence
4.3 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Sina Modal Box Widget Elementor Template ≤ 3.5.7 CVE-2024-9540 Wordfence
5.3 Medium Formidable Form Builder Plugin Information Disclosure Unauthenticated Information Disclosure No login needed < 2.05.03 Fixed in 2.05.03 CVE-2017-20194 Wordfence
7.1 High Google Language Translator Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 6.0.10 Fixed in 6.0.10 CVE-2021-4452 Wordfence
6.4 Medium BigBlueButton Plugin bigbluebutton Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.0.0-beta.4 CVE-2023-7296 Wordfence
7.3 High Timetable and Event Schedule by MotoPress Plugin mp-timetable Broken Access Control Missing Authorization No login needed ≤ 2.3.8 CVE-2020-36840 Wordfence
7.3 High WP Popup Builder – Popup Forms and Marketing Lead Generation Plugin wp-popup-builder Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed ≤ 1.3.5 CVE-2024-9061 Wordfence
9.8 Critical Frontend File Manager Plugin nmedia-user-file-uploader Arbitrary File Upload No login needed ≤ 1.0, < 4.0 Fixed in 4.0 CVE-2016-15042 Wordfence
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_profile' ≤ 4.3.7 CVE-2023-7294 Wordfence
4.3 Medium Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'check_mollie_account_details' ≤ 4.3.7 CVE-2023-7293 Wordfence
4.3 Medium Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'paytium_notice_dismiss' ≤ 4.3.7 CVE-2023-7292 Wordfence
8.3 High WP Lead Plus X Plugin free-sales-funnel-squeeze-pages-landing-page-builder-templates-make Cross-Site Request Forgery No login needed ≤ 0.99 CVE-2020-36839 Wordfence
8.8 High File Manager Pro Plugin filester Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 8.3.9 CVE-2024-8507 Wordfence
7.2 High Rich Reviews Plugin Cross-Site Scripting Stored Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2019-25216 Wordfence
7.1 High Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'create_mollie_account' ≤ 4.3.7 CVE-2023-7291 Wordfence
7.2 High ShopWP Plugin wpshopify Broken Access Control Missing Authorization to Stored Cross-Site Scripting No login needed ≤ 2.0.4 CVE-2019-25214 Wordfence
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 4.6.4 CVE-2021-4447 Wordfence
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 4.5.1 CVE-2021-4445 Wordfence
4.3 Medium Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'check_for_verified_profiles' ≤ 4.3.7 CVE-2023-7290 Wordfence
4.9 Medium WordPress Core Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function ≤ 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, … CVE-2022-4973 Wordfence
6.3 Medium Indeed Membership Pro Plugin Broken Access Control Missing Authorization Checks 7.3 – 8.6 CVE-2020-36833 Wordfence
7.2 High MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance Plugin Cross-Site Scripting The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting No login needed < 3.1.3 Fixed in 3.1.3 CVE-2016-15041 Wordfence
5.4 Medium Paytium: Mollie payment forms & donations Plugin paytium Broken Access Control Missing Authorization in 'paytium_sw_save_api_keys' ≤ 4.3.7 CVE-2023-7289 Wordfence
7.5 High Download Monitor Plugin download-monitor Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 4.7.51 CVE-2022-4972 Wordfence
9.8 Critical Indeed Membership Pro Plugin Authentication Bypass No login needed 7.3 – < 8.6.1 Fixed in 8.6.1 CVE-2020-36832 Wordfence
9.8 Critical File Manager Plugin wp-file-manager Arbitrary File Upload Unauthenticated Arbitrary File Upload/Download No login needed ≤ 3.0 CVE-2018-25105 Wordfence
6.4 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting Authenticted (Contributor+) Stored Cross-Site Scripting via HTML Attribute ≤ 1.9.11 CVE-2024-9582 Wordfence
8.8 High Post Grid Plugin post-grid SQL Injection Contributor+ SQL Injection < 2.1.13 Fixed in 2.1.13 CVE-2021-4450 Wordfence
4.9 Medium Migration, Backup, Staging – WPvivid Plugin Information Disclosure WPvivid <= 0.9.35 - Sensitive Information Disclosure < 0.9.36 Fixed in 0.9.36 CVE-2020-36835 Wordfence
8.3 High Formidable Form Builder Plugin formidable Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed < 2.05.03 Fixed in 2.05.03 CVE-2017-20192 Wordfence
7.5 High File Manager Pro Plugin filester Remote Code Execution Unauthenticated Backup File Download and Upload No login needed ≤ 8.3.9 CVE-2024-8746 Wordfence
6.1 Medium Sassy Social Share Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.3.3 CVE-2022-4971 Wordfence
9.9 Critical ThemeGrill Demo Importer Plugin Broken Access Control Authorization Bypass to Site Reset 1.3.4 – 1.6.1 CVE-2020-36837 Wordfence
8.0 High WP Fastest Cache Plugin wp-fastest-cache Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion < 0.9.0.3 Fixed in 0.9.0.3 CVE-2020-36836 Wordfence
7.3 High ARI-Adminer Plugin Broken Access Control Missing Authorization and No Direct File Access Restrictions No login needed ≤ 1.1.14 CVE-2019-25215 Wordfence
9.8 Critical SiteGround Optimizer Plugin Broken Access Control Missing Authorization No login needed < 5.0.13 Fixed in 5.0.13 CVE-2019-25217 Wordfence
8.3 High Mapplic Lite and Mapplic <= (Various Versions) Plugin Server-Side Request Forgery Server Side Request Forgery to Cross-Site Scirpting No login needed < 1.0.1, < 6.2 Fixed in 1.0.1 CVE-2012-10018 Wordfence
6.5 Medium ACF Quick Edit Fields Plugin acf-quickedit-fields Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference ≤ 3.2.2 CVE-2023-7286 Wordfence
9.8 Critical Advanced Access Manager Plugin advanced-access-manager Path Traversal Unauthenticated Arbitrary File Read No login needed < 5.9.9 Fixed in 5.9.9 CVE-2019-25213 Wordfence
7.3 High Kaswara Modern VC Addons Plugin Broken Access Control Missing Authorization No login needed ≤ 3.0.1 CVE-2021-4448 Wordfence
9.8 Critical Kento Post View Counter Plugin kento-post-view-counter SQL Injection No login needed ≤ 2.8 CVE-2016-15040 Wordfence
6.3 Medium Freemius SDK Plugin Broken Access Control Missing Authorization Checks < 2.0.2, < 1.9.8, < 2.1.0, … Fixed in 2.0.2 CVE-2022-4974 Wordfence
5.0 Medium NextScripts: Social Networks Auto-Poster Plugin social-networks-auto-poster-facebook-twitter-g Broken Access Control Missing Authorization ≤ 4.3.17 CVE-2020-36831 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only