WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 23,951–24,000 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 480 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High MyBookTable Bookstore Plugin mybooktable Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.3.9 Fixed in 3.5.0 CVE-2024-43255 Patchstack
5.4 Medium WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery WebinarPress plugin <= 1.33.20 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.33.20 Fixed in 1.33.21 CVE-2024-43339 Patchstack
4.3 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.102 Fixed in 3.3.103 CVE-2024-43916 Patchstack
5.3 Medium myCred Plugin mycred Information Disclosure Sensitive Data Exposure No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43214 Patchstack
5.3 Medium Shared Files Plugin shared-files Arbitrary File Upload Premium Download Manager & Secure File Sharing with Frontend File Upload plugin <= 1.7.28 - Sensitive Data Exposure No login needed ≤ 1.7.28 Fixed in 1.7.29 CVE-2024-43230 Patchstack
6.5 Medium Bit Form Pro Plugin Information Disclosure Authenticated Sensitive Data Exposure ≤ 2.6.4 CVE-2024-43251 Patchstack
6.5 Medium Leopard - WordPress offload media Plugin Information Disclosure Subscriber+ Sensitive Data Exposure ≤ 2.0.36 CVE-2024-43257 Patchstack
5.3 Medium Store Locator Plus Plugin store-locator-le Information Disclosure Sensitive Data Exposure No login needed ≤ 2311.17.01 CVE-2024-43258 Patchstack
5.3 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 3.23 Fixed in 3.24 CVE-2024-43259 Patchstack
5.3 Medium Create by Mediavine Plugin mediavine-create Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.8 Fixed in 1.9.9 CVE-2024-43264 Patchstack
5.3 Medium Contest Gallery Plugin contest-gallery Information Disclosure Unauthenticated Comment UserID And IP address Disclosure No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-43283 Patchstack
7.5 High wpForo Forum Plugin wpforo Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43289 Patchstack
4.3 Medium Flash & HTML5 Video Plugin html5-video-player Information Disclosure Sensitive Data Exposure ≤ 2.5.31 Fixed in 2.5.32 CVE-2024-43319 Patchstack
5.9 Medium WP Testimonial Widget Plugin wp-testimonial-widget Cross-Site Scripting ≤ 3.1 CVE-2024-43967 Patchstack
7.6 High WP Testimonial Widget Plugin wp-testimonial-widget SQL Injection ≤ 3.1 CVE-2024-43966 Patchstack
6.1 Medium Shield Security Plugin wp-simple-firewall Cross-Site Scripting Reflected XSS No login needed < 20.0.6 Fixed in 20.0.6 CVE-2024-7313 WPScan
4.7 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Contributor+ Stored XSS No login needed < 9.1.1 Fixed in 9.1.1 CVE-2024-6879 WPScan
8.8 High Image Hotspot by DevVN Plugin devvn-image-hotspot PHP Object Injection Authenticated (Author+) PHP Object Injection ≤ 1.2.5 CVE-2024-7656 Wordfence
7.2 High Simple Job Board Plugin simple-job-board PHP Object Injection Authenticated (Editor+) PHP Object Injection ≤ 2.12.3 CVE-2024-7351 Wordfence
5.3 Medium WordPress Button Plugin MaxButtons Plugin maxbuttons Information Disclosure Full Path Disclosure No login needed ≤ 9.7.8 CVE-2024-6499 Wordfence
5.0 Medium ImageRecycle pdf & image compression Plugin imagerecycle-pdf-image-compression Broken Access Control Missing Authorization in Several AJAX Actions ≤ 3.1.14 CVE-2024-6631 Wordfence
4.7 Medium ImageRecycle pdf & image compression Plugin imagerecycle-pdf-image-compression Cross-Site Request Forgery Cross-Site Request in Several AJAX Actions No login needed ≤ 3.1.14 CVE-2024-8120 Wordfence
6.4 Medium RT Easy Builder – Advanced addons for Elementor Plugin rt-easy-builder-advanced-addons-for-elementor Cross-Site Scripting Advanced addons for Elementor <= 2.3 - Authenticated (Contributor+) Stored Cross-site Scripting ≤ 2.3 CVE-2024-2254 Wordfence
4.4 Medium Custom Permalinks Plugin custom-permalinks Cross-Site Scripting Authenticated(Editor+) Stored Cross-Site Scripting ≤ 2.6.0 CVE-2023-0926 Wordfence
9.6 Critical Favicon Generator Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 1.5 CVE-2024-7568 Wordfence
6.1 Medium String Locator Plugin string-locator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.6.5 CVE-2023-6987 Wordfence
6.4 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.4.30 CVE-2024-5502 Wordfence
6.1 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting Author+ Stored XSS No login needed 3.1.39 – < 3.1.46 Fixed in 3.1.46 CVE-2024-6715 WPScan
4.8 Medium WP Table Builder Plugin wp-table-builder Cross-Site Scripting Admin+ Stored XSS ≤ 1.5.0 CVE-2024-3282 WPScan
8.8 High WooCommerce Google Feed Manager Plugin wp-product-feed-manager Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Deletion ≤ 2.8.0 CVE-2024-7258 Wordfence
8.8 High File Manager Pro Plugin filester Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 8.3.7 CVE-2024-7559 Wordfence
5.3 Medium WP SMS Plugin wp-sms Broken Access Control No login needed ≤ 6.9.3 Fixed in 6.9.4 CVE-2024-43331 Patchstack
4.3 Medium User Private Files Plugin user-private-files Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Private File Access ≤ 2.1.0 CVE-2024-7848 Wordfence
6.4 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.10.36 CVE-2024-7778 Wordfence
6.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via File Upload ≤ 2.4.7 CVE-2024-6870 Wordfence
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control Missing Authorization to Authenticated (Contributor+) Post Duplication ≤ 7.6.1 CVE-2024-7836 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget Settings ≤ 5.6.2 CVE-2024-5583 Wordfence
7.5 High AcyMailing Plugin acymailing Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload via acym_extractArchive Function ≤ 9.7.2 CVE-2024-7384 Wordfence
9.9 Critical WPML Multilingual CMS Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution via Twig Server-Side Template Injection ≤ 4.6.12 CVE-2024-6386 Wordfence
9.8 Critical LiteSpeed Cache Plugin litespeed-cache Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 6.3.0.1 Fixed in 6.4 CVE-2024-28000 Patchstack
9.8 Critical Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.6.4 CVE-2024-5335 Wordfence
6.1 Medium Phlox PRO Theme Cross-Site Scripting Reflected Cross-Site Scripting via Search Parameters No login needed ≤ 5.16.4 CVE-2024-6339 Wordfence
6.4 Medium Responsive Video Plugin responsive-video Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-7629 Wordfence
5.3 Medium Flamix: Bitrix24 and Contact Form 7 integrations Plugin flamix-bitrix24-and-contact-forms-7-integrations Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.1.0 CVE-2024-6568 Wordfence
5.6 Medium App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder SQL Injection Create Native Android & iOS Apps On The Flight <= 4.3.3 - Unauthenticated Limited SQL Injection via app-builder-search No login needed ≤ 4.3.3 CVE-2024-7651 Wordfence
6.1 Medium LH Add Media From Url Plugin lh-add-media-from-url Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.23 CVE-2024-7090 Wordfence
6.1 Medium OTA Sync Booking Engine Widget Plugin ota-sync-booking-engine-widget Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2024-7647 Wordfence
6.5 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control Missing Authorization to Plugin Deactivation and Data Deletion No login needed ≤ 1.5.6 CVE-2024-7032 Wordfence
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Data Update ≤ 1.5.6 CVE-2024-7030 Wordfence
4.3 Medium Event Espresso 4 Decaf – Event Registration Event Ticketing Plugin event-espresso-decaf Broken Access Control Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification ≤ 4.10.46.decaf CVE-2024-6883 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only