WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 2,401–2,450 of 2,543 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 49 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.5.5 Fixed in 4.5.6 CVE-2024-29773 Patchstack
6.5 Medium DearFlip Plugin 3d-flipbook-dflip-lite Cross-Site Scripting ≤ 2.2.26 Fixed in 2.2.27 CVE-2024-29807 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
4.3 Medium Calliope Theme calliope Cross-Site Request Forgery No login needed ≤ 1.0.33 Fixed in 1.0.35 CVE-2024-2904 Patchstack
4.3 Medium Clotya Theme Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in multiple themes by KlbTheme No login needed ≤ 1.1.6, ≤ 1.7.7, ≤ 1.2.2, … CVE-2023-49838 Patchstack
6.5 Medium EnvíaloSimple Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2023-51416 Patchstack
8.8 High CM Download and File Manager Plugin Cross-Site Request Forgery Download Edit via CSRF No login needed < 2.9.1 Fixed in 2.9.1 CVE-2024-1962 WPScan
4.8 Medium CM Download Manager Plugin cm-download-manager Cross-Site Request Forgery Download Deletion via CSRF < 2.9.0 Fixed in 2.9.0 CVE-2024-1232 WPScan
6.8 Medium CM Download and File Manager Plugin Cross-Site Request Forgery Download Unpublish via CSRF < 2.9.0 Fixed in 2.9.0 CVE-2024-1231 WPScan
6.1 Medium easy-popup-show Plugin easy-popup-show Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability in easy-popup-show all versions allows a remote unauthenticated attacker to hijack the authentication of the administrator and to p… No login needed all versions CVE-2024-29009 jpcert
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
8.8 High Booking Calendar Plugin booking Cross-Site Request Forgery CSRF appointment scheduling No login needed < 1.3.83 Fixed in 1.3.83 CVE-2024-0856 WPScan
4.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.01.3 Fixed in 1.01.4 CVE-2024-29093 Patchstack
6.5 Medium Tourfic Plugin tourfic Cross-Site Scripting ≤ 2.11.8 Fixed in 2.11.9 CVE-2024-29134 Patchstack
9.9 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.11.15 Fixed in 2.11.16 CVE-2024-29135 Patchstack
8.5 High Tourfic Plugin tourfic PHP Object Injection ≤ 2.11.17 Fixed in 2.11.19 CVE-2024-29136 Patchstack
7.1 High Tourfic Plugin tourfic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.11.7 Fixed in 2.11.8 CVE-2024-29137 Patchstack
8.8 High Innovs HR Plugin innovs-hr-manager Cross-Site Request Forgery Employee Creation via CSRF No login needed ≤ 1.0.3.4 CVE-2024-0858 WPScan
7.1 High Fontific | Google Fonts Plugin fontific Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.1.6 CVE-2024-27194 Patchstack
7.1 High Watermark RELOADED Plugin watermark-reloaded Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.5 Fixed in 1.4.0 CVE-2024-27195 Patchstack
7.1 High BeePress Plugin beepress Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 6.9.8 CVE-2024-27197 Patchstack
8.8 High TerraClassifieds Plugin terraclassifieds Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.0.3 CVE-2023-51474 Patchstack
5.4 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.101 Fixed in 1.2.102 CVE-2023-51486 Patchstack
5.4 Medium ARI Stream Quiz Plugin ari-stream-quiz Cross-Site Request Forgery WordPress Quizzes Builder plugin <= 1.2.32 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.32 Fixed in 1.3.0 CVE-2023-51487 Patchstack
5.4 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51489 Patchstack
5.4 Medium Depicter Slider Plugin depicter Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-51491 Patchstack
4.3 Medium Export Media URLs Plugin export-media-urls Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 2.0 CVE-2023-51510 Patchstack
4.3 Medium Product Table by WBW Plugin woo-product-tables Cross-Site Request Forgery No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2023-51512 Patchstack
5.4 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Request Forgery No login needed ≤ 8.1.18 Fixed in 8.1.19 CVE-2023-51521 Patchstack
4.3 Medium Split Test For Elementor Plugin split-test-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.9 Fixed in 1.7.0 CVE-2023-51407 Patchstack
4.3 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Cross-Site Request Forgery No login needed ≤ 2.10.4 Fixed in 2.10.5 CVE-2023-51522 Patchstack
4.3 Medium Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.8.3 Fixed in 1.8.4 CVE-2023-51369 Patchstack
4.3 Medium Legal Pages Plugin legal-pages Cross-Site Request Forgery CSRF + Broken Access Control ≤ 1.3.7 Fixed in 1.3.8 CVE-2023-50886 Patchstack
4.3 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Cross-Site Request Forgery No login needed ≤ 2.0.8.4 Fixed in 2.0.8.5 CVE-2023-51525 Patchstack
4.3 Medium HUSKY – Products Filter for WooCommerce (formerly WOOF) Plugin woocommerce-products-filter Cross-Site Request Forgery No login needed ≤ 1.3.4.3 Fixed in 1.3.4.4 CVE-2023-50861 Patchstack
5.4 Medium Sirv Plugin sirv Server-Side Request Forgery ≤ 7.2.0 Fixed in 7.2.1 CVE-2024-27949 Patchstack
5.4 Medium Perfmatters Plugin Broken Access Control WordPress Perfmatters Plugin <= 2.1.6 is vulnerable to Broken Access Control ≤ 2.1.6 Fixed in 2.1.7 CVE-2023-47874 Patchstack
5.4 Medium Thrive Automator Plugin thrive-automator Cross-Site Request Forgery WordPress Thrive Automator Plugin <= 1.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.17 Fixed in 1.17.1 CVE-2023-51531 Patchstack
4.3 Medium Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation Plugin gs-logo-slider Cross-Site Request Forgery WordPress GS Logo Slider Plugin <= 3.5.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2023-51530 Patchstack
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Request Forgery WordPress HT Mega Plugin <= 2.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2023-51529 Patchstack
4.3 Medium AI Power: Complete AI Pack – Powered by GPT-4 Plugin gpt3-ai-content-generator Cross-Site Request Forgery WordPress GPT3 AI Content Writer Plugin <= 1.8.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.8.12 Fixed in 1.8.13 CVE-2023-51528 Patchstack
4.3 Medium Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.20 Fixed in 6.21 CVE-2023-51696 Patchstack
5.4 Medium Ecwid Ecommerce Shopping Cart Plugin ecwid-shopping-cart Cross-Site Request Forgery WordPress Ecwid Shopping Cart Plugin <= 6.12.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.12.4 Fixed in 6.12.5 CVE-2023-51533 Patchstack
5.4 Medium Atahualpa Theme atahualpa Cross-Site Request Forgery WordPress Atahualpa Theme <= 3.7.24 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.7.24 CVE-2024-27948 Patchstack
5.4 Medium Easy PayPal & Stripe Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Request Forgery WordPress Easy PayPal Buy Now Button Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-51683 Patchstack
6.5 Medium Duplicator – WordPress Migration & Backup Plugin duplicator Cross-Site Request Forgery WordPress Duplicator Plugin <= 1.5.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.5.7 Fixed in 1.5.7.1 CVE-2023-51681 Patchstack
5.4 Medium MailerLite – WooCommerce integration Plugin woo-mailerlite Cross-Site Request Forgery WooCommerce integration Plugin <= 2.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2023-52223 Patchstack
4.3 Medium Advanced Flamingo Plugin advanced-flamingo Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2023-52226 Patchstack
5.4 Medium 1 click disable all Plugin first-graders-toolbox Cross-Site Request Forgery WordPress 1 click disable all Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.0.1 CVE-2024-21749 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only