WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,801–24,850 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 497 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Newspack Blocks Plugin Arbitrary File Upload ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37424 Patchstack
9.9 Critical Zita Elementor Site Library Plugin zita-site-library Remote Code Execution Arbitrary Code Execution ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-37420 Patchstack
7.5 High Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Local File Inclusion Elementor Addons plugin <= 1.1.1 - Local File Inclusion No login needed ≤ 1.1.1 Fixed in 1.2.0 CVE-2024-37419 Patchstack
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.4.6 Fixed in 4.4.7 CVE-2024-37418 Patchstack
4.9 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Local File Inclusion ≤ 1.3.0.3 Fixed in 1.3.0.4 CVE-2024-37410 Patchstack
8.5 High Striking Theme Local File Inclusion ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-37268 Patchstack
4.9 Medium Tutor LMS Plugin tutor Path Traversal ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37266 Patchstack
2.7 Low WP Directory Kit Plugin wpdirectorykit Content Injection HTML Injection ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-37253 Patchstack
7.5 High SP Project & Document Manager Plugin sp-client-document-manager Path Traversal Directory Traversal No login needed ≤ 4.71 CVE-2024-37224 Patchstack
3.5 Low WooCommerce Plugin woocommerce Content Injection ≤ 8.9.2 Fixed in 9.0.0 CVE-2024-35777 Patchstack
8.5 High Masterstudy Elementor Widgets Theme SQL Injection SQL Injection vulnerability in multiple StylemixThemes premium themes ≤ 1.2.2, ≤ 1.3.0 Fixed in 1.2.3 CVE-2024-37090 Patchstack
10.0 Critical WishList Member X Plugin SQL Injection Unauthenticated Arbitrary SQL Query Execution No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37112 Patchstack
8.5 High Zoho Marketing Automation Plugin zoho-marketinghub SQL Injection ≤ 1.2.7 CVE-2024-37225 Patchstack
7.6 High Tutor LMS Plugin tutor SQL Injection ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37256 Patchstack
7.6 High Paid Memberships Pro Plugin paid-memberships-pro SQL Injection Authenticated SQL Injection ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-37486 Patchstack
8.5 High Youzify Plugin youzify SQL Injection ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-37494 Patchstack
5.4 Medium WooCommerce Social Login Plugin woo-social-login PHP Object Injection No login needed ≤ 2.6.3 Fixed in 2.7.0 CVE-2024-37502 Patchstack
6.4 Medium Genesis Blocks Plugin genesis-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Sharing Block Attributes ≤ 3.1.3 CVE-2024-3563 Wordfence
8.8 High Pie Register - Basic Plugin pie-register Broken Access Control Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation ≤ 3.8.3.4 CVE-2024-6069 Wordfence
6.4 Medium XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] Plugin faq-for-woocommerce Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.7.0 CVE-2024-5669 Wordfence
9.9 Critical OSM – OpenStreetMap Plugin osm SQL Injection OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) SQL Injection ≤ 6.0.3 CVE-2024-3604 Wordfence
6.5 Medium Cliengo - Chatbot Plugin Broken Access Control Chatbot <= 3.0.2 - Missing Authorization to Unauthenticated Chatbot Settings Update No login needed ≤ 3.0.2 CVE-2024-5992 Wordfence
5.4 Medium Pricing Table Plugin elfsight-pricing-table Broken Access Control Missing Authorization ≤ 2.0.1 CVE-2024-4102 Wordfence
4.3 Medium Just Custom Fields Plugin just-custom-fields Cross-Site Request Forgery Cross-Site Request Forgery via AJAX actions No login needed ≤ 3.3.2 CVE-2024-6168 Wordfence
6.4 Medium Simple Alert Boxes Plugin simple-alert-boxes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Alert Shortcode ≤ 1.4.0 CVE-2024-5937 Wordfence
6.4 Medium Panda Video Plugin pandavideo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.0 CVE-2024-5457 Wordfence
8.8 High Panda Video Plugin pandavideo Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.4.0 CVE-2024-5456 Wordfence
6.4 Medium OSM – OpenStreetMap Plugin osm Cross-Site Scripting OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.0.3 CVE-2024-3603 Wordfence
5.3 Medium Social Sharing Plugin – Kiwi Plugin kiwi-social-share Information Disclosure Kiwi <= 2.1.7 - Information Disclosure No login needed ≤ 2.1.7 CVE-2024-3228 Wordfence
4.3 Medium Comment Images Reloaded Plugin comment-images-reloaded Broken Access Control Authenticated (Subscriber+) Arbitrary Media Deletion ≤ 2.2.1 CVE-2024-5856 Wordfence
5.4 Medium LearnDash LMS - Reports Free Plugin wisdm-reports-for-learndash Broken Access Control Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update ≤ 1.8.2.1 CVE-2024-5648 Wordfence
6.4 Medium Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via EE Events and EE Flipbox Widget ≤ 2.0.32 CVE-2024-4868 Wordfence
5.3 Medium Pricing Table Plugin elfsight-pricing-table Cross-Site Request Forgery Cross-Site Request Forgery via ajax() No login needed ≤ 2.0.1 CVE-2024-4100 Wordfence
5.4 Medium Happy SCSS Compiler - Compile SCSS to CSS automatically Plugin happy-scss-compiler Broken Access Control Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.3.10 CVE-2024-5600 Wordfence
5.3 Medium Product Designer Plugin product-designer Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 1.0.33 CVE-2024-3608 Wordfence
5.3 Medium WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 Plugin wp2speed Broken Access Control Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to use of Hardcoded Credentials No login needed ≤ 1.0.1 CVE-2024-5810 Wordfence
4.3 Medium XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] Plugin faq-for-woocommerce Broken Access Control WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.7.0 CVE-2024-5704 Wordfence
4.3 Medium Just Custom Fields Plugin just-custom-fields Broken Access Control Missing Authorization via AJAX actions ≤ 3.3.2 CVE-2024-6167 Wordfence
5.4 Medium Cliengo - Chatbot Plugin Broken Access Control Chatbot <= 3.0.2 - Missing Authorization to Authorized (Subscriber+) Chatbot Settings Update ≤ 3.0.2 CVE-2024-5993 Wordfence
7.2 High Easy Pixels by JEVNET Plugin easy-pixels-by-jevnet Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.13 CVE-2024-5479 Wordfence
8.8 High ScrollTo Top Plugin scrollto-top Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-6320 Wordfence
8.8 High ScrollTo Bottom Plugin scrollto-bottom Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.1.1 CVE-2024-6321 Wordfence
9.8 Critical IQ Testimonials Plugin iq-testimonials Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.7 CVE-2024-6314 Wordfence
8.8 High Advanced AJAX Page Loader Plugin advanced-ajax-page-loader Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.7.7 CVE-2024-6310 Wordfence
9.8 Critical Gutenberg Forms Plugin forms-gutenberg Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.2.9 CVE-2024-6313 Wordfence
8.8 High Attachment File Icons (AF Icons) Plugin attachment-file-icons Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.3 CVE-2024-6309 Wordfence
7.2 High Bit Form Plugin bit-form Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 2.13.3 CVE-2024-6123 Wordfence
6.4 Medium Webico Slider Flatsome Addons Plugin webico-slider-flatsome-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wbc_image Shortcode ≤ 2.0.1 CVE-2024-5881 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 4.1.2 CVE-2024-6317 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 4.1.2 CVE-2024-6316 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only