WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 2,301–2,350 of 2,392 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Categorify | Cross-Site Request Forgery Cross-Site Request Forgery via categorifyAjaxUpdateFolderPosition No login needed |
≤ 1.0.7.4 |
CVE-2024-1912 |
Wordfence | |
| 4.3 Medium | Categorify | Cross-Site Request Forgery Cross-Site Request Forgery via categorifyAjaxRenameCategory No login needed |
≤ 1.0.7.4 |
CVE-2024-1909 |
Wordfence | |
| 4.3 Medium | Categorify | Cross-Site Request Forgery Cross-Site Request Forgery via categorifyAjaxDeleteCategory No login needed |
≤ 1.0.7.4 |
CVE-2024-1907 |
Wordfence | |
| 5.4 Medium | SuperFaktura WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.40.3 |
CVE-2024-1758 |
Wordfence | |
| 4.9 Medium | Pexels: Free Stock Photos | Server-Side Request Forgery WordPress Pexels: Free Stock Photos Plugin <= 1.2.2 is vulnerable to Server Side Request Forgery (SSRF) |
≤ 1.2.2 |
CVE-2024-25915 |
Patchstack | |
| 4.3 Medium | Colibri WP | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Plugin Installation No login needed |
≤ 1.0.94 |
CVE-2024-1360 |
Wordfence | |
| 4.3 Medium | Admin side data storage for Contact Form 7 | Cross-Site Request Forgery No login needed |
≤ 1.1.1 |
CVE-2024-1777 |
Wordfence | |
| 4.3 Medium | Debug | Cross-Site Request Forgery WordPress Debug Plugin <= 1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.10 |
CVE-2024-24798 |
Patchstack | |
| 4.3 Medium | JTRT Responsive Tables | Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 4.1.9 |
CVE-2024-24802 |
Patchstack | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 4.3 Medium | Quicksand Post Filter jQuery | Cross-Site Request Forgery WordPress Quicksand Post Filter jQuery Plugin Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.1 |
CVE-2024-24849 |
Patchstack | |
| 4.3 Medium | Themify Builder | Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.0.5 Fixed in 7.0.6 |
CVE-2024-24872 |
Patchstack | |
| 4.3 Medium | Admin Menu Editor | Cross-Site Request Forgery WordPress Admin Menu Editor Plugin <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.12 Fixed in 1.12.1 |
CVE-2024-24876 |
Patchstack | |
| 4.3 Medium | TinyMCE and TinyMCE Advanced Professsional Formats and Styles | Cross-Site Request Forgery WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.1.2 |
CVE-2024-25904 |
Patchstack | |
| 5.4 Medium | Multi Step Form | Cross-Site Request Forgery WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.18 |
CVE-2024-25905 |
Patchstack | |
| 4.7 Medium | Database Reset | Cross-Site Request Forgery Cross-Site Request Forgery to WP Reset Plugin Installation No login needed |
≤ 3.22 |
CVE-2024-1501 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in optimizeAllOn No login needed |
≤ 3.1.13 |
CVE-2024-1336 |
Wordfence | |
| 6.1 Medium | Microsoft Clarity | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.9.3 |
CVE-2024-0590 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in disableOptimization No login needed |
≤ 3.1.13 |
CVE-2024-1335 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via add_to_wishlist No login needed |
≤ 1.3.87 |
CVE-2024-0512 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via add_to_compare No login needed |
≤ 1.3.87 |
CVE-2024-0514 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via remove_from_compare No login needed |
≤ 1.3.87 |
CVE-2024-0515 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in stopOptimizeAll No login needed |
≤ 3.1.13 |
CVE-2024-1338 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via remove_from_wishlist No login needed |
≤ 1.3.87 |
CVE-2024-0513 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Removal in reinitialize No login needed |
≤ 3.1.13 |
CVE-2024-1339 |
Wordfence | |
| 4.3 Medium | Custom Twitter Feeds – A Tweets Widget or X Feed Widget | Cross-Site Request Forgery A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update No login needed |
≤ 2.2.1 |
CVE-2024-0379 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in enableOptimization No login needed |
≤ 3.1.13 |
CVE-2024-1334 |
Wordfence | |
| 4.3 Medium | SMTP Mail | Cross-Site Request Forgery WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3.20 |
CVE-2024-25914 |
Patchstack | |
| 4.3 Medium | Link Library | Cross-Site Request Forgery WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.5.13 Fixed in 7.6 |
CVE-2024-24875 |
Patchstack | |
| 4.3 Medium | Contact Form 7 Connector | Cross-Site Request Forgery WordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2024-24884 |
Patchstack | |
| 5.4 Medium | Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting | Cross-Site Request Forgery WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 21.2.8.4 Fixed in 21.2.9 |
CVE-2024-24887 |
Patchstack | |
| 4.3 Medium | WP Contact Form | Cross-Site Request Forgery WordPress WP Contact Form Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.6 |
CVE-2024-24929 |
Patchstack | |
| 4.3 Medium | Basic Log Viewer | Cross-Site Request Forgery WordPress Basic Log Viewer Plugin <= 1.0.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.4 |
CVE-2024-24935 |
Patchstack | |
| 4.3 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery via wpr_update_form_action_meta No login needed |
≤ 1.3.87 |
CVE-2024-0511 |
Wordfence | |
| 5.4 Medium | WP-CFM | Cross-Site Request Forgery WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2024-24706 |
Patchstack | |
| 3.8 Low | WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging | Server-Side Request Forgery The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. Thi… |
4.23.5 |
CVE-2024-0628 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Cross-Site Request Forgery Cross-Site Request Forgery via save_view No login needed |
≤ 3.2.2 |
CVE-2024-0373 |
Wordfence | |
| 7.1 High | Index Now | Cross-Site Request Forgery Cross-Site Request Forgery via reset_form No login needed |
≤ 2.6.3 |
CVE-2024-0428 |
Wordfence | |
| 6.1 Medium | Formidable Forms | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 6.7.2 |
CVE-2024-0660 |
Wordfence | |
| 5.4 Medium | WOLF – WordPress Posts Bulk Editor and Manager Professional | Cross-Site Request Forgery WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery No login needed |
≤ 1.0.8.1 |
CVE-2024-0790 |
Wordfence | |
| 4.3 Medium | Active Products Tables for WooCommerce. Professional products tables for WooCommerce store | Cross-Site Request Forgery No login needed |
≤ 1.0.6.1 |
CVE-2024-0796 |
Wordfence | |
| 4.3 Medium | Affiliates Manager | Cross-Site Request Forgery No login needed |
≤ 2.9.34 |
CVE-2024-0859 |
Wordfence | |
| 4.3 Medium | Views for WPForms | Cross-Site Request Forgery Cross-Site Request Forgery via create_view No login needed |
≤ 3.2.2 |
CVE-2024-0374 |
Wordfence | |
| 4.3 Medium | Orbit Fox by ThemeIsle | Cross-Site Request Forgery No login needed |
≤ 2.10.29 |
CVE-2024-1162 |
Wordfence | |
| 4.3 Medium | Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder | Cross-Site Request Forgery WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.5 |
CVE-2024-22136 |
Patchstack | |
| 8.8 High | Profile Builder Pro | Cross-Site Request Forgery WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.10.0 Fixed in 3.10.1 |
CVE-2024-22140 |
Patchstack | |
| 5.4 Medium | WP Spell Check | Cross-Site Request Forgery WordPress WP Spell Check Plugin <= 9.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 9.17 Fixed in 9.18 |
CVE-2024-22143 |
Patchstack | |
| 5.4 Medium | Frontpage Manager | Cross-Site Request Forgery WordPress Frontpage Manager Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3 |
CVE-2024-22285 |
Patchstack | |
| 4.3 Medium | Browser Theme Color | Cross-Site Request Forgery WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3 |
CVE-2024-22291 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.