WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,001–24,050 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 481 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Testimonial Widget Plugin wp-testimonial-widget Broken Access Control Missing Authorization No login needed ≤ 3.1 CVE-2024-7390 Wordfence
5.5 Medium WordSurvey Plugin wordsurvey Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via sounding_title Parameter ≤ 3.2 CVE-2024-6767 Wordfence
7.2 High LiquidPoll Plugin wp-poll Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via form_data Parameter No login needed ≤ 3.3.78 CVE-2024-7134 Wordfence
4.3 Medium Hide My Site Plugin hide-my-site Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.2 CVE-2024-5880 Wordfence
10.0 Critical Woo Inquiry Plugin woo-inquiry SQL Injection Unauthenticated SQL Injection No login needed ≤ 0.1 CVE-2024-7854 Wordfence
6.4 Medium Popup Maker Plugin popup-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.19.0 CVE-2024-7054 Wordfence
9.8 Critical SmartSearch WP Plugin SQL Injection Unauthenticated SQLi No login needed < 2.4.5 Fixed in 2.4.5 CVE-2024-6847 WPScan
6.4 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel Widget ≤ 2.1.4 CVE-2024-5576 Wordfence
6.4 Medium WP Last Modified Info Plugin wp-last-modified-info Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lmt-post-modified-info Shortcode ≤ 1.9.0 CVE-2024-6864 Wordfence
8.7 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Arbitrary File Deletion Authenticater (Administrator+) Arbitrary File Deletion 2.0 – 2.13.4 CVE-2024-7782 Wordfence
7.2 High AdRotate – Ad manager & AdSense Ads Plugin adrotate Arbitrary File Upload Ad manager & AdSense Ads <= 5.13.2 - Authenticated (Admin+) Double Extension Arbitrary File Upload ≤ 5.13.2 CVE-2022-1206 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection 2.0 – 2.13.9 CVE-2024-7780 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll Widget ≤ 5.6.2 CVE-2024-6575 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget ≤ 5.6.2 CVE-2024-5763 Wordfence
9.0 Critical Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Path Traversal Authenticated (Administrator+) Arbitrary File Read And Deletion 2.0 – 2.13.9 CVE-2024-7777 Wordfence
5.5 Medium Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Arbitrary File Upload Authenticated (Administrator+) Arbitrary JavaScript File Uploads 2.0 – 2.13.9 CVE-2024-7775 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection via getLogHistory Function 2.0 – 2.13.9 CVE-2024-7702 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed ≤ 3.13.0 CVE-2024-5940 Wordfence
8.8 High Shopping Cart & eCommerce Store Plugin wp-easycart SQL Injection Authenticated (Contributor+) SQL Injection via model_number Parameter ≤ 5.7.2 CVE-2024-7827 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure No login needed ≤ 3.13.0 CVE-2024-5939 Wordfence
10.0 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.14.1 - Unauthenticated PHP Object Injection to Remote Code Execution No login needed ≤ 3.14.1 CVE-2024-5932 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion ≤ 3.14.1 CVE-2024-5941 Wordfence
6.1 Medium BP Profile Search Plugin bp-profile-search Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 5.7.5 CVE-2024-7850 Wordfence
9.8 Critical myCred Plugin mycred PHP Object Injection No login needed ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43354 Patchstack
7.5 High Landing Page Builder Plugin page-builder-add Local File Inclusion ≤ 1.5.2.0 Fixed in 1.5.2.1 CVE-2024-43345 Patchstack
8.3 High EmbedPress Plugin embedpress Local File Inclusion No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2024-43328 Patchstack
5.4 Medium Plugin Notes Plus Plugin plugin-notes-plus Broken Access Control Arbitrary Content Deletion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-43326 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.1.0 Fixed in 6.0.1.1 CVE-2024-43317 Patchstack
9.8 Critical Login As Users Plugin login-as-users Authentication Bypass Broken Authentication No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-43311 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43281 Patchstack
4.7 Medium Salon booking system Plugin salon-booking-system Open Redirect No login needed ≤ 10.8.1 Fixed in 10.9 CVE-2024-43280 Patchstack
5.3 Medium Icegram Plugin icegram Authentication Bypass Unauthenticated Unpublished Campaign Viewer No login needed ≤ 3.1.24 Fixed in 3.1.25 CVE-2024-43272 Patchstack
8.5 High Woo Products Widgets For Elementor Plugin woo-products-widgets-for-elementor Local File Inclusion ≤ 2.0.0 CVE-2024-43271 Patchstack
9.6 Critical Compute Links Plugin compute-links Local File Inclusion Remote File Inclusion No login needed ≤ 1.2.1 CVE-2024-43261 Patchstack
7.1 High Leopard - WordPress offload media Plugin Broken Access Control Subscriber+ Plugin Settings Change ≤ 2.0.36 CVE-2024-43256 Patchstack
9.0 Critical Crew HRM Plugin hr-management PHP Object Injection No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-43252 Patchstack
7.1 High Bit Form Pro Plugin Broken Access Control Authenticated Plugin Settings Change ≤ 2.6.4 CVE-2024-43250 Patchstack
9.9 Critical Bit Form Pro Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 2.6.4 CVE-2024-43249 Patchstack
8.6 High Bit Form Pro Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 2.6.4 CVE-2024-43248 Patchstack
8.8 High WHMpress Plugin Broken Access Control Subscriber+ Arbitrary Settings Change ≤ 6.2-revision-5 CVE-2024-43247 Patchstack
9.8 Critical JobSearch Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 2.3.4 CVE-2024-43245 Patchstack
9.0 Critical Ultimate Membership Pro Plugin indeed-membership-pro PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43242 Patchstack
9.4 Critical Ultimate Membership Pro Plugin indeed-membership-pro Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 12.7 Fixed in 12.8 CVE-2024-43240 Patchstack
4.7 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Open Redirect No login needed ≤ 1.9 Fixed in 1.9.1 CVE-2024-43236 Patchstack
8.5 High Timeline and History slider Plugin timeline-and-history-slider Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43232 Patchstack
8.5 High JetGridBuilder Plugin jetgridbuilder Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-43221 Patchstack
10.0 Critical GiveWP Plugin give PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 3.14.1 Fixed in 3.14.2 CVE-2024-37099 Patchstack
6.1 Medium SmartSearch WP Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.4.5 Fixed in 2.4.5 CVE-2024-6843 WPScan
7.2 High AI Engine Plugin ai-engine Remote Code Execution Admin+ RCE < 2.5.1 Fixed in 2.5.1 CVE-2024-6451 WPScan
9.8 Critical GEO my Plugin Remote Code Execution Unauthenticated RCE via LFI No login needed < 4.5.0.2 Fixed in 4.5.0.2 CVE-2024-6330 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only