WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,401–25,450 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 509 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Filter Custom Fields & Taxonomies Light Plugin filter-custom-fields-taxonomies-light Broken Access Control ≤ 1.05 CVE-2024-32081 Patchstack
5.3 Medium AdFoxly – Ad Manager, AdSense Ads & Ads.txt Plugin adfoxly Broken Access Control No login needed ≤ 1.8.5 CVE-2024-34802 Patchstack
5.3 Medium Upload Fields for WPForms Plugin upload-fields-for-wpforms Broken Access Control No login needed ≤ 1.0.2 CVE-2024-35661 Patchstack
5.4 Medium Simple COD Fees for WooCommerce Plugin simple-cod-fee-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-35662 Patchstack
8.2 High EventPrime Plugin eventprime-event-calendar-management Price Manipulation Booking Price Manipulation No login needed ≤ 3.3.4 Fixed in 3.3.5 CVE-2024-31275 Patchstack
5.3 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Broken Access Control No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-31276 Patchstack
7.5 High Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-31283 Patchstack
6.5 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.8 Fixed in 3.9.9 CVE-2024-31284 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-31304 Patchstack
6.3 Medium Easy Social Share Buttons Plugin Broken Access Control Multiple Broken Access Control ≤ 9.4 Fixed in 9.5 CVE-2024-31307 Patchstack
4.3 Medium Tracking Code Manager Plugin tracking-code-manager Broken Access Control ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-31347 Patchstack
4.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Broken Access Control ≤ 4.3.1 Fixed in 4.3.2 CVE-2024-31350 Patchstack
5.3 Medium Email Subscribers & Newsletters Plugin email-subscribers Broken Access Control No login needed ≤ 5.7.13 Fixed in 5.7.14 CVE-2024-31352 Patchstack
4.3 Medium Premmerce Product Filter for WooCommerce Plugin premmerce-woocommerce-product-filter Broken Access Control ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-31359 Patchstack
4.3 Medium InstaWP Connect Plugin instawp-connect Broken Access Control ≤ 0.1.0.24 Fixed in 0.1.0.25 CVE-2024-32701 Patchstack
7.7 High ARForms Plugin arforms Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 6.4 Fixed in 6.4.1 CVE-2024-32703 Patchstack
4.3 Medium WP Accessibility Helper (WAH) Plugin wp-accessibility-helper Broken Access Control ≤ 0.6.2.5 Fixed in 0.6.2.6 CVE-2024-31423 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary WordPress Options Removal ≤ 6.4 Fixed in 6.4.1 CVE-2024-32704 Patchstack
7.1 High ARForms Plugin arforms Broken Access Control Subscriber+ Arbitrary Plugin Activation/Deactivation ≤ 6.4 Fixed in 6.4.1 CVE-2024-32705 Patchstack
5.4 Medium AI Post Generator | AutoWriter Plugin ai-post-generator Broken Access Control ≤ 3.3 Fixed in 3.4 CVE-2024-32713 Patchstack
4.3 Medium Academy LMS Plugin academy Broken Access Control ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-32714 Patchstack
7.5 High Olive One Click Demo Import Plugin olive-one-click-demo-import Path Traversal Arbitrary File Download No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-32715 Patchstack
5.3 Medium 5 Stars Rating Funnel Plugin 5-stars-rating-funnel Broken Access Control No login needed ≤ 1.2.67 Fixed in 1.3.02 CVE-2024-32725 Patchstack
5.3 Medium RomethemeForm For Elementor Plugin romethemeform Broken Access Control No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-32727 Patchstack
7.5 High BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control No login needed ≤ 4.3.39 Fixed in 4.5.4 CVE-2024-32777 Patchstack
8.5 High Contest Gallery Plugin contest-gallery Arbitrary File Deletion ≤ 21.3.4 Fixed in 21.3.5 CVE-2024-32778 Patchstack
5.3 Medium Vision Interactive Plugin vision Broken Access Control Image Map Builder plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-32779 Patchstack
4.3 Medium Advanced Testimonial Carousel for Elementor Plugin advanced-testimonial-carousel-for-elementor Broken Access Control ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-32783 Patchstack
4.3 Medium CookieHub Plugin cookiehub Broken Access Control ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-32784 Patchstack
4.3 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Broken Access Control ≤ 3.7.1 Fixed in 3.7.2 CVE-2024-32787 Patchstack
4.3 Medium Hummingbird Plugin hummingbird-performance Broken Access Control ≤ 3.7.3 Fixed in 3.7.4 CVE-2024-32792 Patchstack
5.4 Medium WP LinkedIn Auto Publish Plugin wp-linkedin-auto-publish Broken Access Control ≤ 8.11 Fixed in 8.12 CVE-2024-32797 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Price Manipulation No login needed ≤ 5.8.0 Fixed in 5.8.1 CVE-2024-32798 Patchstack
5.3 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2024-32799 Patchstack
4.3 Medium WP GoToWebinar Plugin wp-gotowebinar Broken Access Control ≤ 14.46 Fixed in 15.1 CVE-2024-32804 Patchstack
6.5 Medium Social Snap Plugin socialsnap Broken Access Control No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-32805 Patchstack
5.3 Medium USPS Shipping for WooCommerce – Live Rates Plugin flexible-shipping-usps Information Disclosure Live Rates plugin <= 1.9.4 - Sensitive Data Exposure via Log File No login needed ≤ 1.9.4 Fixed in 1.10.0 CVE-2024-32811 Patchstack
5.3 Medium Integrate Google Drive Plugin integrate-google-drive Broken Access Control No login needed ≤ 1.3.9 Fixed in 1.3.91 CVE-2024-32813 Patchstack
5.3 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32814 Patchstack
4.3 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Broken Access Control Meta Data and Taxonomies Filter plugin <= 1.3.3 - Broken Access Control ≤ 1.3.3 Fixed in 1.3.3.1 CVE-2024-32818 Patchstack
5.3 Medium Social Share Icons & Social Share Buttons Plugin ultimate-social-media-plus Broken Access Control Broken Access Control lead to Notice Dismissal No login needed ≤ 3.6.2 Fixed in 3.6.3 CVE-2024-32820 Patchstack
4.3 Medium Total Poll Lite Plugin totalpoll-lite Broken Access Control ≤ 4.9.9 Fixed in 4.10.0 CVE-2024-32821 Patchstack
5.4 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-32824 Patchstack
7.5 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control No login needed ≤ 1.2.06 Fixed in 1.2.07 CVE-2024-33543 Patchstack
5.3 Medium WZone Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 14.0.10 CVE-2024-33545 Patchstack
8.3 High WZone Plugin Broken Access Control Site Wide Broken Access Control ≤ 14.0.10 CVE-2024-33547 Patchstack
8.1 High XStore Core Plugin Broken Access Control Multiple Authenticated Broken Access Control ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33555 Patchstack
7.5 High XStore Theme Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33561 Patchstack
7.6 High XStore Theme Broken Access Control ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33563 Patchstack
8.8 High XStore Theme Broken Access Control Arbitrary Option Update ≤ 9.3.8 Fixed in 9.3.9 CVE-2024-33564 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only