WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 23,901–23,950 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 479 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Premium Portfolio Features for Phlox Plugin auxin-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.4 CVE-2024-1384 Wordfence
5.3 Medium Popup Builder Plugin popup-builder Information Disclosure Sensitive Information Exposure via Imported Subscribers CSV File No login needed ≤ 4.3.6 CVE-2024-2541 Wordfence
6.4 Medium Beaver Builder (Lite Version) Plugin beaver-builder-lite-version Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter ≤ 2.8.3.5 CVE-2024-7895 Wordfence
5.3 Medium GiveWP Plugin give Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.15.1 CVE-2024-6551 Wordfence
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack
4.8 Medium CoBlocks Plugin Cross-Site Scripting Editor+ Stored XSS < 3.1.13 Fixed in 3.1.13 CVE-2024-7132 WPScan
4.8 Medium Viral Signup Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 2.1 CVE-2024-6927 WPScan
5.4 Medium Gutentor Plugin gutentor Cross-Site Scripting Contributor+ Stored XSS < 3.3.6 Fixed in 3.3.6 CVE-2024-5417 WPScan
8.8 High Front End Users Plugin front-end-only-users SQL Injection Authenticated (Contributor+) Time-Based SQL Injection ≤ 3.2.28 CVE-2024-7607 Wordfence
5.4 Medium WP Accessibility Helper Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 0.6.2.8 CVE-2024-5987 Wordfence
4.4 Medium WP To Do Plugin wp-todo Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Task Comments ≤ 1.3.0 CVE-2024-3944 Wordfence
6.4 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.28 CVE-2024-7606 Wordfence
4.3 Medium The Post Grid Plugin the-post-grid Information Disclosure Authenticated (Contributor+) Information Disclosure ≤ 7.7.11 CVE-2024-7418 Wordfence
8.1 High MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Deletion ≤ 5.7.0.1 CVE-2024-7856 Wordfence
7.2 High Theme Editor Plugin theme-editor PHP Object Injection Authenticated (Admin+) PHAR Deserialization ≤ 2.8 CVE-2022-2440 Wordfence
5.3 Medium Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free Plugin funnelforms-free Broken Access Control Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion No login needed ≤ 3.7.3.2 CVE-2024-5857 Wordfence
6.5 Medium Media Library Folders Plugin media-library-plus SQL Injection Authenticated (Subscriber+) Second-Order SQL Injection ≤ 8.2.2 CVE-2024-7857 Wordfence
5.3 Medium Permalink Manager Lite Plugin permalink-manager Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 2.4.4 CVE-2024-8195 Wordfence
5.3 Medium Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free Plugin funnelforms-free Broken Access Control Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload No login needed ≤ 3.7.3.2 CVE-2024-7447 Wordfence
6.5 Medium Funnelforms Free Plugin funnelforms-free Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion ≤ 3.7.3.2 CVE-2024-6312 Wordfence
7.2 High Funnelforms Free Plugin funnelforms-free Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 3.7.3.2 CVE-2024-6311 Wordfence
5.3 Medium Mollie Payments for WooCommerce Plugin mollie-payments-for-woocommerce Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 7.7.0 CVE-2024-6448 Wordfence
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.0.3 CVE-2024-8030 Wordfence
5.3 Medium Relevanssi Live Ajax Search Plugin relevanssi-live-ajax-search Information Disclosure Unauthenticated WP_Query Argument Injection No login needed ≤ 2.4 CVE-2024-7573 Wordfence
4.3 Medium Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Plugin reviews-feed Broken Access Control Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 1.1.2 CVE-2024-8199 Wordfence
4.3 Medium Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More Plugin reviews-feed Cross-Site Request Forgery Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More <= 1.1.2 - Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-8200 Wordfence
6.4 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Cross-Site Scripting FREE <= 1.4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Grid Widget ≤ 1.4.4.3 CVE-2024-7791 Wordfence
6.4 Medium Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid Plugin logo-showcase-ultimate Cross-Site Scripting Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.4.1 CVE-2024-8046 Wordfence
6.4 Medium Ninja Tables – Easiest Data Table Builder Plugin ninja-tables Cross-Site Scripting Easiest Data Table Builder <= 5.0.12 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 5.0.12 CVE-2024-7304 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 2.6.7 CVE-2024-6804 Wordfence
4.3 Medium Oxygen Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stylesheet Update ≤ 4.8.3 CVE-2024-6688 Wordfence
5.4 Medium Ninja Forms Plugin ninja-forms Cross-Site Request Forgery No login needed ≤ 3.8.6 Fixed in 3.8.7 CVE-2024-39628 Patchstack
4.3 Medium LearnPress Plugin learnpress Cross-Site Request Forgery No login needed ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39641 Patchstack
5.4 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-39645 Patchstack
4.3 Medium Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce Plugin sender-net-automated-emails Cross-Site Request Forgery No login needed ≤ 2.6.18 Fixed in 2.6.19 CVE-2024-39657 Patchstack
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Cross-Site Request Forgery No login needed ≤ 2.7.10 Fixed in 2.7.11 CVE-2024-43116 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Cross-Site Request Forgery No login needed ≤ 3.9.1 Fixed in 3.9.2 CVE-2024-43117 Patchstack
4.3 Medium Analytify Plugin wp-analytify Cross-Site Request Forgery CSRF Leading to Optout No login needed ≤ 5.3.1 Fixed in 5.4.0 CVE-2024-43265 Patchstack
4.3 Medium Backup and Restore Plugin wp-backitup Cross-Site Request Forgery No login needed ≤ 1.50 CVE-2024-43269 Patchstack
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.82 Fixed in 3.1.83 CVE-2024-43287 Patchstack
4.3 Medium WP Data Access Plugin wp-data-access Cross-Site Request Forgery No login needed ≤ 5.5.7 Fixed in 5.5.9 CVE-2024-43295 Patchstack
5.4 Medium SpeedyCache Plugin speedycache Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-43299 Patchstack
7.1 High Fonts Plugin olympus-google-fonts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43301 Patchstack
4.3 Medium Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43316 Patchstack
4.3 Medium Dark Mode for WP Dashboard Plugin dark-mode-for-wp-dashboard Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-43325 Patchstack
4.3 Medium WP User Manager Plugin wp-user-manager Cross-Site Request Forgery User Profile Builder & Membership plugin <= 2.9.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.9.10 Fixed in 2.9.11 CVE-2024-43336 Patchstack
4.3 Medium Brave Popup Builder Plugin brave-popup-builder Cross-Site Request Forgery No login needed ≤ 0.7.0 Fixed in 0.7.1 CVE-2024-43337 Patchstack
4.3 Medium Advanced Form Integration Plugin advanced-form-integration Cross-Site Request Forgery The Easiest Integration Plugin plugin <= 1.89.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.89.4 Fixed in 1.89.6 CVE-2024-43340 Patchstack
5.5 Medium Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting ≤ .3.102 Fixed in 3.3.103 CVE-2024-43915 Patchstack
4.3 Medium oik Plugin oik Arbitrary File Deletion No login needed ≤ 4.12.0 Fixed in 4.12.1 CVE-2024-43356 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only