WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 24,101–24,150 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | myCred | Cross-Site Scripting |
≤ 2.7.2 Fixed in 2.7.3 |
CVE-2024-43353 |
Patchstack | |
| 6.4 Medium | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | Cross-Site Scripting Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.0.37 |
CVE-2024-7703 |
Wordfence | |
| 8.1 High | Metform Elementor Contact Form Builder | Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed |
≤ 3.2.4 |
CVE-2023-0714 |
Wordfence | |
| 6.8 Medium | BackWPup | Path Traversal Authenticated (Administrator+) Directory Traversal |
≤ 4.0.1 |
CVE-2023-5505 |
Wordfence | |
| 4.3 Medium | Bricks | Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed |
≤ 1.8.1 |
CVE-2023-3408 |
Wordfence | |
| 5.4 Medium | Bricks | Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed |
≤ 1.8.1 |
CVE-2023-3409 |
Wordfence | |
| 6.1 Medium | Slideshow, Image Slider by 2J | Cross-Site Scripting Reflected Cross-Site Scripting via 'post' No login needed |
≤ 1.3.54 |
CVE-2023-4604 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Player Update No login needed |
≤ 2.0.73 |
CVE-2023-4025 |
Wordfence | |
| 4.7 Medium | Short URL | Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed |
≤ 1.6.8 |
CVE-2023-1604 |
Wordfence | |
| 5.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Broken Access Control Missing Authorization via init_endpoint No login needed |
≤ 4.3 |
CVE-2023-4730 |
Wordfence | |
| 6.1 Medium | Admission AppManager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2023-4507 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Player Deletion No login needed |
≤ 2.0.73 |
CVE-2023-4024 |
Wordfence | |
| 6.5 Medium | LOGIN AND REGISTRATION ATTEMPTS LIMIT<= | Other IP Address Spoofing to Protection Mechanism Bypass No login needed |
≤ 2.1 |
CVE-2022-4532 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Settings Update No login needed |
≤ 2.0.73 |
CVE-2023-4027 |
Wordfence | |
| 7.2 High | Skitter Slideshow | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed |
≤ 2.5.2 |
CVE-2022-1751 |
Wordfence | |
| 9.8 Critical | News Element Elementor Blog Magazine | Local File Inclusion Unauthenticated LFI No login needed |
< 1.0.6 Fixed in 1.0.6 |
CVE-2024-6459 |
WPScan | |
| 10.0 Critical | InPost for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Delete No login needed |
≤ 1.4.0, ≤ 1.4.4 |
CVE-2024-6500 |
Wordfence | |
| 8.8 High | JetElements | Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion |
≤ 2.6.20 |
CVE-2024-7145 |
Wordfence | |
| 6.4 Medium | JetElements | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.20 |
CVE-2024-7144 |
Wordfence | |
| 8.8 High | JetTabs | Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion |
≤ 2.2.3 |
CVE-2024-7146 |
Wordfence | |
| 6.4 Medium | JetSearch | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.5.2 |
CVE-2024-7136 |
Wordfence | |
| 6.4 Medium | JetBlocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.12 |
CVE-2024-7147 |
Wordfence | |
| 4.2 Medium | Download Plugins and Themes from Dashboard | Cross-Site Request Forgery No login needed |
≤ 1.8.7 |
CVE-2024-7501 |
Wordfence | |
| 9.8 Critical | Grow by Tradedoubler | Local File Inclusion Unauthenticated LFI No login needed |
≤ 2.0.21 |
CVE-2024-6460 |
WPScan | |
| 7.2 High | WordPress File Upload | Arbitrary File Upload Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed |
≤ 4.24.8 |
CVE-2024-7301 |
Wordfence | |
| 4.3 Medium | Theme My Login | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 7.1.7 |
CVE-2024-7422 |
Wordfence | |
| 4.4 Medium | Cookie Notice & Compliance for GDPR / CCPA | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.4.17.1 |
CVE-2022-3399 |
Wordfence | |
| 4.3 Medium | Custom Field For WP Job Manager | Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure via Shortcode |
≤ 1.2 |
CVE-2023-7049 |
Wordfence | |
| 5.3 Medium | Relevanssi | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 2.25.1, ≤ 4.22.2 |
CVE-2024-7630 |
Wordfence | |
| 5.3 Medium | Newsletters | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 4.9.9 |
CVE-2024-7411 |
Wordfence | |
| 4.3 Medium | ElementsKit Pro | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure |
≤ 3.6.6 |
CVE-2024-7063 |
Wordfence | |
| 6.4 Medium | ElementsKit Pro | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.6.5 |
CVE-2024-7064 |
Wordfence | |
| 8.1 High | MStore API – Create Native Android & iOS Apps On The Cloud | Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed |
≤ 4.15.2 |
CVE-2024-7628 |
Wordfence | |
| 8.1 High | Zephyr Project Manager | Privilege Escalation Authenticated (Subscriber+) Limited Privilege Escalation |
≤ 3.3.101 |
CVE-2024-7624 |
Wordfence | |
| 5.8 Medium | Insert PHP Code Snippet | Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed |
≤ 1.3.6 |
CVE-2024-7420 |
Wordfence | |
| 6.4 Medium | Sheet to Table Live Sync for Google Sheet | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode |
≤ 1.0.1 |
CVE-2024-6532 |
Wordfence | |
| 8.8 High | Depicter — Popup & Slider Builder | Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 3.1.1 |
CVE-2024-4389 |
Wordfence | |
| 6.4 Medium | Gutenberg Blocks, Page Builder – ComboBlocks | Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block |
≤ 2.2.84 |
CVE-2024-7588 |
Wordfence | |
| 6.5 Medium | WPSection | Local File Inclusion Contributor+ Limited Local File Inclusion |
≤ 1.3.8 Fixed in 1.3.9 |
CVE-2024-43165 |
Patchstack | |
| 10.0 Critical | BerqWP | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.7.6 Fixed in 1.7.7 |
CVE-2024-43160 |
Patchstack | |
| 9.8 Critical | Woffice | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 5.4.10 Fixed in 5.4.12 |
CVE-2024-43153 |
Patchstack | |
| 9.8 Critical | Participants Database | PHP Object Injection No login needed |
≤ 2.5.9.2 Fixed in 2.5.9.3 |
CVE-2024-43141 |
Patchstack | |
| 7.5 High | Ultimate Bootstrap Elements for Elementor | Local File Inclusion |
≤ 1.4.4 Fixed in 1.4.5 |
CVE-2024-43140 |
Patchstack | |
| 6.5 Medium | Event Manager for WooCommerce | Local File Inclusion |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2024-43138 |
Patchstack | |
| 7.5 High | WPCafe | Local File Inclusion |
≤ 2.2.28 Fixed in 2.2.29 |
CVE-2024-43135 |
Patchstack | |
| 7.5 High | Docket (WooCommerce Collections / Wishlist / Watchlist) | Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed |
< 1.7.0 Fixed in 1.7.0 |
CVE-2024-43131 |
Patchstack | |
| 6.5 Medium | BetterDocs | Local File Inclusion |
≤ 3.5.8 Fixed in 3.5.9 |
CVE-2024-43129 |
Patchstack | |
| 6.5 Medium | WooCommerce Product Table Lite | Remote Code Execution Arbitrary Code Execution No login needed |
≤ 3.5.1 Fixed in 3.8.6 |
CVE-2024-43128 |
Patchstack | |
| 9.1 Critical | HUSKY | Privilege Escalation |
≤ 1.3.6.1 Fixed in 1.3.6.2 |
CVE-2024-43121 |
Patchstack | |
| 8.6 High | WooCommerce PDF Vouchers | Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed |
< 4.9.5 Fixed in 4.9.5 |
CVE-2024-39651 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.