WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,101–24,150 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 483 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43353 Patchstack
6.4 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0.37 CVE-2024-7703 Wordfence
8.1 High Metform Elementor Contact Form Builder Plugin metform Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed ≤ 3.2.4 CVE-2023-0714 Wordfence
6.8 Medium BackWPup Plugin backwpup Path Traversal Authenticated (Administrator+) Directory Traversal ≤ 4.0.1 CVE-2023-5505 Wordfence
4.3 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed ≤ 1.8.1 CVE-2023-3408 Wordfence
5.4 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed ≤ 1.8.1 CVE-2023-3409 Wordfence
6.1 Medium Slideshow, Image Slider by 2J Plugin 2j-slideshow Cross-Site Scripting Reflected Cross-Site Scripting via 'post' No login needed ≤ 1.3.54 CVE-2023-4604 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Player Update No login needed ≤ 2.0.73 CVE-2023-4025 Wordfence
4.7 Medium Short URL Plugin shorten-url Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed ≤ 1.6.8 CVE-2023-1604 Wordfence
5.3 Medium LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… Plugin ladipage Broken Access Control Missing Authorization via init_endpoint No login needed ≤ 4.3 CVE-2023-4730 Wordfence
6.1 Medium Admission AppManager Plugin admission-appmanager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2023-4507 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Player Deletion No login needed ≤ 2.0.73 CVE-2023-4024 Wordfence
6.5 Medium LOGIN AND REGISTRATION ATTEMPTS LIMIT<= Plugin login-attempts-limit-wp Other IP Address Spoofing to Protection Mechanism Bypass No login needed ≤ 2.1 CVE-2022-4532 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Settings Update No login needed ≤ 2.0.73 CVE-2023-4027 Wordfence
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
9.8 Critical News Element Elementor Blog Magazine Plugin news-element Local File Inclusion Unauthenticated LFI No login needed < 1.0.6 Fixed in 1.0.6 CVE-2024-6459 WPScan
10.0 Critical InPost for WooCommerce Plugin woo-inpost Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read and Delete No login needed ≤ 1.4.0, ≤ 1.4.4 CVE-2024-6500 Wordfence
8.8 High JetElements Plugin Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion ≤ 2.6.20 CVE-2024-7145 Wordfence
6.4 Medium JetElements Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.20 CVE-2024-7144 Wordfence
8.8 High JetTabs Plugin Local File Inclusion Authenticated (Contributor+) Arbitrary Local File Inclusion ≤ 2.2.3 CVE-2024-7146 Wordfence
6.4 Medium JetSearch Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.5.2 CVE-2024-7136 Wordfence
6.4 Medium JetBlocks Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.12 CVE-2024-7147 Wordfence
4.2 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery No login needed ≤ 1.8.7 CVE-2024-7501 Wordfence
9.8 Critical Grow by Tradedoubler Plugin tradedoubler-affiliate-tracker Local File Inclusion Unauthenticated LFI No login needed ≤ 2.0.21 CVE-2024-6460 WPScan
7.2 High WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 4.24.8 CVE-2024-7301 Wordfence
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 7.1.7 CVE-2024-7422 Wordfence
4.4 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.4.17.1 CVE-2022-3399 Wordfence
4.3 Medium Custom Field For WP Job Manager Plugin custom-field-for-wp-job-manager Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure via Shortcode ≤ 1.2 CVE-2023-7049 Wordfence
5.3 Medium Relevanssi Plugin relevanssi Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.25.1, ≤ 4.22.2 CVE-2024-7630 Wordfence
5.3 Medium Newsletters Plugin newsletters-lite Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 4.9.9 CVE-2024-7411 Wordfence
4.3 Medium ElementsKit Pro Plugin Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 3.6.6 CVE-2024-7063 Wordfence
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.6.5 CVE-2024-7064 Wordfence
8.1 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover No login needed ≤ 4.15.2 CVE-2024-7628 Wordfence
8.1 High Zephyr Project Manager Plugin zephyr-project-manager Privilege Escalation Authenticated (Subscriber+) Limited Privilege Escalation ≤ 3.3.101 CVE-2024-7624 Wordfence
5.8 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed ≤ 1.3.6 CVE-2024-7420 Wordfence
6.4 Medium Sheet to Table Live Sync for Google Sheet Plugin sheet-to-wp-table-for-google-sheet Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode ≤ 1.0.1 CVE-2024-6532 Wordfence
8.8 High Depicter — Popup & Slider Builder Plugin depicter Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload ≤ 3.1.1 CVE-2024-4389 Wordfence
6.4 Medium Gutenberg Blocks, Page Builder – ComboBlocks Plugin post-grid Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block ≤ 2.2.84 CVE-2024-7588 Wordfence
6.5 Medium WPSection Plugin wpsection Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-43165 Patchstack
10.0 Critical BerqWP Plugin searchpro Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2024-43160 Patchstack
9.8 Critical Woffice Plugin woffice Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 5.4.10 Fixed in 5.4.12 CVE-2024-43153 Patchstack
9.8 Critical Participants Database Plugin participants-database PHP Object Injection No login needed ≤ 2.5.9.2 Fixed in 2.5.9.3 CVE-2024-43141 Patchstack
7.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-43140 Patchstack
6.5 Medium Event Manager for WooCommerce Plugin mage-eventpress Local File Inclusion ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-43138 Patchstack
7.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.28 Fixed in 2.2.29 CVE-2024-43135 Patchstack
7.5 High Docket (WooCommerce Collections / Wishlist / Watchlist) Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed < 1.7.0 Fixed in 1.7.0 CVE-2024-43131 Patchstack
6.5 Medium BetterDocs Plugin betterdocs Local File Inclusion ≤ 3.5.8 Fixed in 3.5.9 CVE-2024-43129 Patchstack
6.5 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.5.1 Fixed in 3.8.6 CVE-2024-43128 Patchstack
9.1 Critical HUSKY Plugin woocommerce-products-filter Privilege Escalation ≤ 1.3.6.1 Fixed in 1.3.6.2 CVE-2024-43121 Patchstack
8.6 High WooCommerce PDF Vouchers Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39651 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only