WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 2,451–2,500 of 2,544 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | 1 click disable all | Cross-Site Request Forgery WordPress 1 click disable all Plugin <= 1.0.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.1 |
CVE-2024-21749 |
Patchstack | |
| 4.3 Medium | Email Before Download | Cross-Site Request Forgery WordPress Email Before Download Plugin <= 6.9.7 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 6.9.7 Fixed in 6.9.8 |
CVE-2024-23519 |
Patchstack | |
| 4.3 Medium | A no-code page builder for beautiful performance-based content | Cross-Site Request Forgery WordPress Setka Editor Plugin <= 2.1.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.1.20 |
CVE-2024-24701 |
Patchstack | |
| 4.3 Medium | Page Restrict | Cross-Site Request Forgery WordPress Page Restrict Plugin <= 2.5.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.5.5 |
CVE-2024-24702 |
Patchstack | |
| 5.4 Medium | Accessibility | Cross-Site Request Forgery WordPress Accessibility Plugin <= 1.0.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.6 |
CVE-2024-24705 |
Patchstack | |
| 4.3 Medium | W3SPEEDSTER | Cross-Site Request Forgery WordPress W3SPEEDSTER Plugin <= 7.19 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.19 |
CVE-2024-24708 |
Patchstack | |
| 4.3 Medium | Custom Order Statuses for WooCommerce | Cross-Site Request Forgery WordPress Custom Order Statuses for WooCommerce Plugin <= 1.5.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.5.2 |
CVE-2024-25930 |
Patchstack | |
| 4.3 Medium | Heureka | Cross-Site Request Forgery WordPress Heureka Plugin <= 1.0.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.8 |
CVE-2024-25931 |
Patchstack | |
| 4.3 Medium | Change Table Prefix | Cross-Site Request Forgery No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2024-25932 |
Patchstack | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_set_default_card No login needed |
≤ 20221130 |
CVE-2024-0431 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_delete_card No login needed |
≤ 20221130 |
CVE-2024-0432 |
Wordfence | |
| 4.3 Medium | Gestpay for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) via ajax_unset_default_card No login needed |
≤ 20221130 |
CVE-2024-0433 |
Wordfence | |
| 5.4 Medium | SuperFaktura WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.40.3 |
CVE-2024-1758 |
Wordfence | |
| 4.9 Medium | Pexels: Free Stock Photos | Server-Side Request Forgery WordPress Pexels: Free Stock Photos Plugin <= 1.2.2 is vulnerable to Server Side Request Forgery (SSRF) |
≤ 1.2.2 |
CVE-2024-25915 |
Patchstack | |
| 4.3 Medium | Debug | Cross-Site Request Forgery WordPress Debug Plugin <= 1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.10 |
CVE-2024-24798 |
Patchstack | |
| 4.3 Medium | JTRT Responsive Tables | Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 4.1.9 |
CVE-2024-24802 |
Patchstack | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 4.3 Medium | Quicksand Post Filter jQuery | Cross-Site Request Forgery WordPress Quicksand Post Filter jQuery Plugin Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.1 |
CVE-2024-24849 |
Patchstack | |
| 4.3 Medium | Themify Builder | Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.0.5 Fixed in 7.0.6 |
CVE-2024-24872 |
Patchstack | |
| 4.3 Medium | Admin Menu Editor | Cross-Site Request Forgery WordPress Admin Menu Editor Plugin <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.12 Fixed in 1.12.1 |
CVE-2024-24876 |
Patchstack | |
| 4.3 Medium | TinyMCE and TinyMCE Advanced Professsional Formats and Styles | Cross-Site Request Forgery WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.1.2 |
CVE-2024-25904 |
Patchstack | |
| 5.4 Medium | Multi Step Form | Cross-Site Request Forgery WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.18 |
CVE-2024-25905 |
Patchstack | |
| 4.3 Medium | SMTP Mail | Cross-Site Request Forgery WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3.20 |
CVE-2024-25914 |
Patchstack | |
| 7.5 High | popup-builder | Server-Side Request Forgery Admin+ SSRF & File Read No login needed |
< 4.2.6 Fixed in 4.2.6 |
CVE-2023-6294 |
WPScan | |
| 5.4 Medium | lasTunes | Cross-Site Request Forgery Settings Update via CSRF |
≤ 3.6.1 |
CVE-2023-6499 |
WPScan | |
| 4.3 Medium | Splashscreen | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.20 |
CVE-2023-6501 |
WPScan | |
| 4.3 Medium | Link Library | Cross-Site Request Forgery WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.5.13 Fixed in 7.6 |
CVE-2024-24875 |
Patchstack | |
| 4.3 Medium | Contact Form 7 Connector | Cross-Site Request Forgery WordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2024-24884 |
Patchstack | |
| 5.4 Medium | Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting | Cross-Site Request Forgery WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 21.2.8.4 Fixed in 21.2.9 |
CVE-2024-24887 |
Patchstack | |
| 4.3 Medium | WP Contact Form | Cross-Site Request Forgery WordPress WP Contact Form Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.6 |
CVE-2024-24929 |
Patchstack | |
| 4.3 Medium | Basic Log Viewer | Cross-Site Request Forgery WordPress Basic Log Viewer Plugin <= 1.0.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.4 |
CVE-2024-24935 |
Patchstack | |
| 5.4 Medium | WP-CFM | Cross-Site Request Forgery WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.8 Fixed in 1.7.9 |
CVE-2024-24706 |
Patchstack | |
| 5.4 Medium | PDF Flipbook, 3D Flipbook – DearFlip | Cross-Site Scripting DearFlip <= 2.2.26 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.26 |
CVE-2024-0895 |
Wordfence | |
| 6.5 Medium | Portfolio & Image Gallery for WordPress | PowerFolio | Cross-Site Scripting WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) |
≤ 3.1 Fixed in 3.1.1 |
CVE-2024-22150 |
Patchstack | |
| 4.3 Medium | Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder | Cross-Site Request Forgery WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.5 |
CVE-2024-22136 |
Patchstack | |
| 8.8 High | Profile Builder Pro | Cross-Site Request Forgery WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.10.0 Fixed in 3.10.1 |
CVE-2024-22140 |
Patchstack | |
| 5.4 Medium | WP Spell Check | Cross-Site Request Forgery WordPress WP Spell Check Plugin <= 9.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 9.17 Fixed in 9.18 |
CVE-2024-22143 |
Patchstack | |
| 5.4 Medium | Frontpage Manager | Cross-Site Request Forgery WordPress Frontpage Manager Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3 |
CVE-2024-22285 |
Patchstack | |
| 4.3 Medium | Browser Theme Color | Cross-Site Request Forgery WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3 |
CVE-2024-22291 |
Patchstack | |
| 5.4 Medium | FreshMail | Cross-Site Request Forgery WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 2.3.2 |
CVE-2024-22304 |
Patchstack | |
| 7.1 High | Better Anchor Links | Cross-Site Request Forgery WordPress Better Anchor Links Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.5 |
CVE-2024-22287 |
Patchstack | |
| 7.1 High | Custom Dashboard Widgets | Cross-Site Request Forgery WordPress Custom Dashboard Widgets Plugin <= 1.3.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3.1 |
CVE-2024-22290 |
Patchstack | |
| 3.0 Low | TablePress | Server-Side Request Forgery TablePress SSRF vulnerability due to insufficient filtering of cloud provider hosts |
< 2.2.5 |
CVE-2024-23825 |
GitHub_M | |
| 8.8 High | WordPress Users | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 1.4 |
CVE-2023-6390 |
WPScan | |
| 8.8 High | Custom User CSS | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.2 |
CVE-2023-6391 |
WPScan | |
| 5.4 Medium | WP Plugin Lister | Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed |
≤ 2.1.0 |
CVE-2023-6503 |
WPScan | |
| 8.8 High | Autotitle | Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed |
≤ 1.0.3 |
CVE-2023-6946 |
WPScan | |
| 4.3 Medium | Site Notes | Cross-Site Request Forgery Admin Note Deletion via CSRF No login needed |
≤ 2.0.0 |
CVE-2023-6633 |
WPScan | |
| 8.8 High | WP Social Bookmark Menu | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 1.2 |
CVE-2023-7074 |
WPScan |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.