WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 201–245 of 245 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High PayPlus Payment Gateway Plugin payplus-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.8 Fixed in 6.6.9 CVE-2024-37459 Patchstack
5.8 Medium YITH WooCommerce Ajax Product Filter Plugin yith-woocommerce-ajax-navigation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.1.0 Fixed in 5.2.0 CVE-2024-37943 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
7.6 High PayPlus Payment Gateway Plugin payplus-payment-gateway SQL Injection Unauthenticated SQLi < 6.6.9 Fixed in 6.6.9 CVE-2024-6205 WPScan
4.3 Medium WP RSS Aggregator Plugin wp-rss-aggregator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feed State Update ≤ 4.23.11 CVE-2024-6621 Wordfence
8.5 High PayPlus Payment Gateway Plugin payplus-payment-gateway SQL Injection ≤ 7.0.7 Fixed in 7.0.8 CVE-2024-37564 Patchstack
5.3 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Broken Access Control Missing Authorization to Order Status Update No login needed ≤ 2.5.0 CVE-2024-0619 Wordfence
7.5 High WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 7.4.0 Fixed in 7.4.1 CVE-2023-35049 Patchstack
8.2 High Paid Memberships Pro CCBill Gateway Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 0.3 Fixed in 0.4 CVE-2023-40608 Patchstack
4.6 Medium SVGator Plugin svgator Cross-Site Scripting Stored XSS via SVG Upload ≤ 1.2.6 CVE-2024-4271 WPScan
5.4 Medium BulkGate SMS Plugin for WooCommerce Plugin woosms-sms-module-for-woocommerce Broken Access Control ≤ 3.0.2 Fixed in 3.0.3 CVE-2023-51679 Patchstack
4.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control ≤ 4.9.7 Fixed in 4.9.8 CVE-2023-52224 Patchstack
7.4 High SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets ≤ 2.0 CVE-2024-5091 Wordfence
7.2 High Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed ≤ 2.0.6.1 CVE-2024-5542 Wordfence
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget ≤ 3.10.9 CVE-2024-5347 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Progress Bar, Header Meta Content, Scroll Navigation, Pricing Table, & Flip Box ≤ 5.5.4 CVE-2024-3718 Wordfence
5.4 Medium WordPress RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GE… No login needed < 4.23.9 Fixed in 4.23.9 CVE-2024-4860 tenable
4.3 Medium Arigato Autoresponder and Newsletter Plugin bft-autoresponder Cross-Site Request Forgery No login needed ≤ 2.7.2.3 Fixed in 2.7.2.4 CVE-2024-34823 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.4.2 CVE-2024-2785 Wordfence
5.3 Medium 2Checkout Payment Gateway for WooCommerce Plugin woocommerce-2checkout-payment Broken Access Control Missing Authorization via sniff_ins No login needed ≤ 6.2 CVE-2024-0629 Wordfence
4.3 Medium Payment Gateway Based Fees and Discounts for WooCommerce Plugin checkout-fees-for-woocommerce Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-33585 Patchstack
5.9 Medium Navigation menu as Dropdown Widget Plugin navigation-menu-as-dropdown-widget Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-32126 Patchstack
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) ≤ 4.4.7 CVE-2023-6805 Wordfence
4.3 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Request Forgery No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2024-31371 Patchstack
5.3 Medium WooCommerce Clover Payment Gateway Plugin woo-clover-gateway-by-zaytech Broken Access Control Missing Authorization via callback_handler No login needed ≤ 1.3.1 CVE-2024-0626 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message ≤ 4.3.3 CVE-2023-6877 Wordfence
5.3 Medium Paid Memberships Pro – Payfast Gateway Add On Plugin pmpro-payfast Information Disclosure Payfast Gateway Add On plugin <= 1.4.1 - Sensitive Data Exposure via Log File No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-30514 Patchstack
5.4 Medium WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Cross-Site Request Forgery No login needed ≤ 7.6.0 Fixed in 7.6.1 CVE-2023-44999 Patchstack
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation ≤ 3.20.1 CVE-2024-2120 Wordfence
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
5.3 Medium Duitku Payment Gateway Plugin duitku-social-payment-gateway Broken Access Control Missing Authorization via check_duitku_response No login needed ≤ 2.11.6 CVE-2024-0631 Wordfence
8.8 High RSS Aggregator by Feedzy Plugin feedzy-rss-feeds SQL Injection Authenticated(Contributor+) SQL Injection ≤ 4.4.2 CVE-2024-1317 Wordfence
6.5 Medium RSS Aggregator by Feedzy Plugin feedzy-rss-feeds Broken Access Control Missing Authorization to Arbitrary Page Creation and Publication ≤ 4.4.2 CVE-2024-1318 Wordfence
9.8 Critical Piraeus Bank WooCommerce Payment Gateway Plugin woo-payment-gateway-for-piraeus-bank SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.6.5.1 CVE-2024-0610 Wordfence
9.8 Critical Web3 – Crypto wallet Login & NFT token gating Plugin web3-authentication Authentication Bypass Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass No login needed < 3.0.0 Fixed in 3.0.0 CVE-2023-6036 WPScan
3.8 Low WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Server-Side Request Forgery The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. Thi… 4.23.5 CVE-2024-0628 Wordfence
4.3 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization ≤ 4.4.1 CVE-2024-1092 Wordfence
4.4 Medium WP RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source ≤ 4.23.4 CVE-2024-0630 Wordfence
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack
5.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization ≤ 4.3.2 CVE-2023-6798 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 4.3.2 CVE-2023-6801 Wordfence
7.5 High WooCommerce Stripe Payment Gateway Plugin woocommerce-gateway-stripe Broken Access Control WordPress WooCommerce Stripe Payment Gateway Plugin <= 7.6.1 is vulnerable to Insecure Direct Object References (IDOR) No login needed ≤ 7.6.1 Fixed in 7.6.2 CVE-2023-51502 Patchstack
7.5 High PayHere Payment Gateway Plugin payhere-payment-gateway Information Disclosure Unauthenticated Log Data Disclosure No login needed < 2.2.12 Fixed in 2.2.12 CVE-2023-6064 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only