WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 23,151–23,200 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 10.0 Critical | Azz Anonim Posting | Arbitrary File Upload No login needed |
≤ 0.9 |
CVE-2024-49257 |
Patchstack | |
| 9.1 Critical | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Remote Code Execution |
≤ 1.5.121 Fixed in 1.5.122 |
CVE-2024-49271 |
Patchstack | |
| 5.3 Medium | WooCommerce Smart Coupons | Broken Access Control Unauthenticated Coupon Creation No login needed |
< 4.6.5 Fixed in 4.6.5 |
CVE-2020-36841 |
Wordfence | |
| 9.8 Critical | BuddyPress Better Registration | Authentication Bypass Broken Authentication No login needed |
≤ 1.6 |
CVE-2024-49247 |
Patchstack | |
| 6.4 Medium | Zita Elementor Site Library | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.6.3 |
CVE-2024-8921 |
Wordfence | |
| 6.4 Medium | ElementsReady Addons for Elementor | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 6.4.3 |
CVE-2024-9444 |
Wordfence | |
| 6.1 Medium | Video Grid | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.21 |
CVE-2023-7295 |
Wordfence | |
| 8.8 High | Migration, Backup, Staging – WPvivid | Arbitrary File Upload WPvivid <= 0.9.35 - Authenticated (Subscriber+) Arbitrary File Upload |
≤ 0.9.35 |
CVE-2020-36842 |
Wordfence | |
| 4.3 Medium | Sina Extension for Elementor | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Sina Modal Box Widget Elementor Template |
≤ 3.5.7 |
CVE-2024-9540 |
Wordfence | |
| 5.3 Medium | Formidable Form Builder | Information Disclosure Unauthenticated Information Disclosure No login needed |
< 2.05.03 Fixed in 2.05.03 |
CVE-2017-20194 |
Wordfence | |
| 7.1 High | Google Language Translator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
< 6.0.10 Fixed in 6.0.10 |
CVE-2021-4452 |
Wordfence | |
| 6.4 Medium | BigBlueButton | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 3.0.0-beta.4 |
CVE-2023-7296 |
Wordfence | |
| 7.3 High | Timetable and Event Schedule by MotoPress | Broken Access Control Missing Authorization No login needed |
≤ 2.3.8 |
CVE-2020-36840 |
Wordfence | |
| 7.3 High | WP Popup Builder – Popup Forms and Marketing Lead Generation | Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed |
≤ 1.3.5 |
CVE-2024-9061 |
Wordfence | |
| 9.8 Critical | Frontend File Manager | Arbitrary File Upload No login needed |
≤ 1.0, < 4.0 Fixed in 4.0 |
CVE-2016-15042 |
Wordfence | |
| 7.1 High | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'create_mollie_profile' |
≤ 4.3.7 |
CVE-2023-7294 |
Wordfence | |
| 4.3 Medium | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'check_mollie_account_details' |
≤ 4.3.7 |
CVE-2023-7293 |
Wordfence | |
| 4.3 Medium | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'paytium_notice_dismiss' |
≤ 4.3.7 |
CVE-2023-7292 |
Wordfence | |
| 8.3 High | WP Lead Plus X | Cross-Site Request Forgery No login needed |
≤ 0.99 |
CVE-2020-36839 |
Wordfence | |
| 8.8 High | File Manager Pro | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed |
≤ 8.3.9 |
CVE-2024-8507 |
Wordfence | |
| 7.2 High | Rich Reviews | Cross-Site Scripting Stored Cross-Site Scripting No login needed |
≤ 1.7.4 |
CVE-2019-25216 |
Wordfence | |
| 7.1 High | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'create_mollie_account' |
≤ 4.3.7 |
CVE-2023-7291 |
Wordfence | |
| 7.2 High | ShopWP | Broken Access Control Missing Authorization to Stored Cross-Site Scripting No login needed |
≤ 2.0.4 |
CVE-2019-25214 |
Wordfence | |
| 8.8 High | Essential Addons for Elementor | Privilege Escalation Authenticated (Contributor+) Privilege Escalation |
≤ 4.6.4 |
CVE-2021-4447 |
Wordfence | |
| 6.5 Medium | Premium Addons for Elementor | Broken Access Control Authenticated (Subscriber+) Limited Arbitrary Option Update |
≤ 4.5.1 |
CVE-2021-4445 |
Wordfence | |
| 4.3 Medium | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'check_for_verified_profiles' |
≤ 4.3.7 |
CVE-2023-7290 |
Wordfence | |
| 4.9 Medium | WordPress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function |
≤ 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, … |
CVE-2022-4973 |
Wordfence | |
| 6.3 Medium | Indeed Membership Pro | Broken Access Control Missing Authorization Checks |
7.3 – 8.6 |
CVE-2020-36833 |
Wordfence | |
| 7.2 High | MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance | Cross-Site Scripting The Private WordPress Manager for Multiple Website Maintenance Plugin <= 3.1.2 - Stored Cross-Site Scripting No login needed |
< 3.1.3 Fixed in 3.1.3 |
CVE-2016-15041 |
Wordfence | |
| 5.4 Medium | Paytium: Mollie payment forms & donations | Broken Access Control Missing Authorization in 'paytium_sw_save_api_keys' |
≤ 4.3.7 |
CVE-2023-7289 |
Wordfence | |
| 7.5 High | Download Monitor | Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed |
≤ 4.7.51 |
CVE-2022-4972 |
Wordfence | |
| 9.8 Critical | Indeed Membership Pro | Authentication Bypass No login needed |
7.3 – < 8.6.1 Fixed in 8.6.1 |
CVE-2020-36832 |
Wordfence | |
| 9.8 Critical | File Manager | Arbitrary File Upload Unauthenticated Arbitrary File Upload/Download No login needed |
≤ 3.0 |
CVE-2018-25105 |
Wordfence | |
| 6.4 Medium | Accordion Slider | Cross-Site Scripting Authenticted (Contributor+) Stored Cross-Site Scripting via HTML Attribute |
≤ 1.9.11 |
CVE-2024-9582 |
Wordfence | |
| 8.8 High | Post Grid | SQL Injection Contributor+ SQL Injection |
< 2.1.13 Fixed in 2.1.13 |
CVE-2021-4450 |
Wordfence | |
| 4.9 Medium | Migration, Backup, Staging – WPvivid | Information Disclosure WPvivid <= 0.9.35 - Sensitive Information Disclosure |
< 0.9.36 Fixed in 0.9.36 |
CVE-2020-36835 |
Wordfence | |
| 8.3 High | Formidable Form Builder | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
< 2.05.03 Fixed in 2.05.03 |
CVE-2017-20192 |
Wordfence | |
| 7.5 High | File Manager Pro | Remote Code Execution Unauthenticated Backup File Download and Upload No login needed |
≤ 8.3.9 |
CVE-2024-8746 |
Wordfence | |
| 6.1 Medium | Sassy Social Share | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.3.3 |
CVE-2022-4971 |
Wordfence | |
| 9.9 Critical | ThemeGrill Demo Importer | Broken Access Control Authorization Bypass to Site Reset |
1.3.4 – 1.6.1 |
CVE-2020-36837 |
Wordfence | |
| 8.0 High | WP Fastest Cache | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
< 0.9.0.3 Fixed in 0.9.0.3 |
CVE-2020-36836 |
Wordfence | |
| 7.3 High | ARI-Adminer | Broken Access Control Missing Authorization and No Direct File Access Restrictions No login needed |
≤ 1.1.14 |
CVE-2019-25215 |
Wordfence | |
| 9.8 Critical | SiteGround Optimizer | Broken Access Control Missing Authorization No login needed |
< 5.0.13 Fixed in 5.0.13 |
CVE-2019-25217 |
Wordfence | |
| 8.3 High | Mapplic Lite and Mapplic <= (Various Versions) | Server-Side Request Forgery Server Side Request Forgery to Cross-Site Scirpting No login needed |
< 1.0.1, < 6.2 Fixed in 1.0.1 |
CVE-2012-10018 |
Wordfence | |
| 6.5 Medium | ACF Quick Edit Fields | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference |
≤ 3.2.2 |
CVE-2023-7286 |
Wordfence | |
| 9.8 Critical | Advanced Access Manager | Path Traversal Unauthenticated Arbitrary File Read No login needed |
< 5.9.9 Fixed in 5.9.9 |
CVE-2019-25213 |
Wordfence | |
| 7.3 High | Kaswara Modern VC Addons | Broken Access Control Missing Authorization No login needed |
≤ 3.0.1 |
CVE-2021-4448 |
Wordfence | |
| 9.8 Critical | Kento Post View Counter | SQL Injection No login needed |
≤ 2.8 |
CVE-2016-15040 |
Wordfence | |
| 6.3 Medium | Freemius SDK | Broken Access Control Missing Authorization Checks |
< 2.0.2, < 1.9.8, < 2.1.0, … Fixed in 2.0.2 |
CVE-2022-4974 |
Wordfence | |
| 5.0 Medium | NextScripts: Social Networks Auto-Poster | Broken Access Control Missing Authorization |
≤ 4.3.17 |
CVE-2020-36831 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.