WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,451–25,500 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 510 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-33565 Patchstack
4.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Broken Access Control ≤ 3.2.5 Fixed in 3.2.6 CVE-2024-33572 Patchstack
4.3 Medium Aiomatic Plugin Broken Access Control ≤ 1.9.3 Fixed in 1.9.4 CVE-2024-34435 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control Broken Access Control on API No login needed ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-35660 Patchstack
4.3 Medium Debug Log Manager Plugin debug-log-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-35669 Patchstack
5.3 Medium EmbedPress Plugin embedpress Broken Access Control No login needed ≤ 3.9.11 Fixed in 3.9.12 CVE-2024-31274 Patchstack
5.3 Medium JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Broken Access Control No login needed ≤ 2.8.3 Fixed in 2.8.4 CVE-2024-31273 Patchstack
4.3 Medium Flexible Checkout Fields for WooCommerce Plugin flexible-checkout-fields Broken Access Control ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-31267 Patchstack
4.3 Medium Announcer – Notification & message bars Plugin announcer Broken Access Control Notification & message bars plugin <= 6.0 - Broken Access Control ≤ 6.0 Fixed in 6.0.1 CVE-2024-31261 Patchstack
4.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-31252 Patchstack
4.3 Medium All-in-One Video Gallery Plugin all-in-one-video-gallery Broken Access Control ≤ 3.5.2 Fixed in 3.6.0 CVE-2024-31248 Patchstack
9.8 Critical Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31244 Patchstack
7.5 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Setting Deletion No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31243 Patchstack
5.3 Medium Whizzy Plugin whizzy Broken Access Control No login needed ≤ 1.1.18 CVE-2024-30544 Patchstack
5.3 Medium Tainacan Plugin tainacan Broken Access Control No login needed ≤ 0.20.7 Fixed in 0.20.8 CVE-2024-30529 Patchstack
4.3 Medium Sliced Invoices Plugin sliced-invoices Broken Access Control ≤ 3.9.2 Fixed in 3.9.3 CVE-2024-30517 Patchstack
4.3 Medium Events Manager Plugin events-manager Broken Access Control ≤ 6.4.6.4 Fixed in 6.4.7 CVE-2024-30515 Patchstack
3.7 Low weForms Plugin weforms Broken Access Control No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-30512 Patchstack
8.8 High Finale Lite Plugin finale-woocommerce-sales-countdown-timer-discount Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.18.0 Fixed in 2.18.1 CVE-2024-30485 Patchstack
6.5 Medium JCH Optimize Plugin jch-optimize Broken Access Control ≤ 4.0.0 Fixed in 4.0.1 CVE-2024-30481 Patchstack
6.5 Medium YITH WooCommerce Account Funds Premium Plugin Broken Access Control ≤ 1.33.0 Fixed in 1.34.0 CVE-2024-30470 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.4.9 Fixed in 4.4.10 CVE-2024-30467 Patchstack
5.4 Medium WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual Broken Access Control ≤ 5.3.4 Fixed in 5.3.5 CVE-2024-30466 Patchstack
6.5 Medium PageLayer Plugin pagelayer Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2024-30465 Patchstack
5.4 Medium Social Icons Widget & Block by WPZOOM Plugin social-icons-widget-by-wpzoom Broken Access Control ≤ 4.2.15 Fixed in 4.2.16 CVE-2024-30464 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2024-25929 Patchstack
8.8 High NextMove Lite Plugin woo-thank-you-page-nextmove-lite Broken Access Control Subscriber+ Arbitrary Plugin Installation/Activation ≤ 2.17.0 Fixed in 2.18.0 CVE-2024-25092 Patchstack
5.4 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.1.6 Fixed in 6.1.7 CVE-2024-24716 Patchstack
6.5 Medium WooCommerce Box Office Plugin Broken Access Control Unauthenticated Save Ticket Barcode No login needed ≤ 1.1.51 Fixed in 1.1.52 CVE-2023-34003 Patchstack
8.3 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Broken Access Control Multiple Broken Access Control ≤ 1.5.65 Fixed in 1.5.66 CVE-2023-31080 Patchstack
5.4 Medium MainWP UpdraftPlus Extension Plugin Broken Access Control Subscriber+ Arbitrary Plugin Activation ≤ 4.0.6 Fixed in 4.0.7 CVE-2023-23640 Patchstack
5.4 Medium MainWP Staging Extension Plugin Broken Access Control Subscriber+ Arbitrary Plugin Activation ≤ 4.0.3 Fixed in 4.0.4 CVE-2023-23639 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2023-51494 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Information Disclosure Authenticated Arbitrary WordPress Option Disclosure < 7.1.3 Fixed in 7.1.3 CVE-2023-52230 Patchstack
6.5 Medium Booster Plus for WooCommerce Plugin Broken Access Control Authenticated Arbitrary Post/Page Deletion < 7.1.2 Fixed in 7.1.2 CVE-2023-52232 Patchstack
5.3 Medium Awesome Support Plugin awesome-support Broken Access Control No login needed ≤ 6.1.7 Fixed in 6.1.8 CVE-2024-30539 Patchstack
6.5 Medium Calendarista Basic Edition Plugin calendarista-basic-edition Broken Access Control No login needed ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-30534 Patchstack
4.3 Medium WPC Badge Management for WooCommerce Plugin wpc-badge-management Broken Access Control ≤ 2.4.0 Fixed in 2.4.1 CVE-2024-30537 Patchstack
5.3 Medium DELUCKS SEO Plugin delucks-seo Broken Access Control No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-30538 Patchstack
7.1 High New Order Notification for Woocommerce Plugin new-order-notification-for-woocommerce Broken Access Control ≤ 2.0.2 CVE-2024-31098 Patchstack
5.4 Medium PostX Plugin ultimate-post Broken Access Control Author+ Post/Page Duplication ≤ 3.2.3 Fixed in 3.2.4 CVE-2024-31246 Patchstack
4.3 Medium WP Sort Order Plugin wp-sort-order Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-31294 Patchstack
5.3 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Broken Access Control No login needed ≤ 1.24.6 Fixed in 1.24.7 CVE-2024-22151 Patchstack
4.3 Medium Icegram Plugin icegram Broken Access Control ≤ 3.1.21 Fixed in 3.1.22 CVE-2024-21748 Patchstack
5.4 Medium WP-Recall Plugin wp-recall Cross-Site Request Forgery No login needed ≤ 16.26.6 CVE-2024-35657 Patchstack
5.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.6.6 Fixed in 3.6.7 CVE-2024-35659 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 1.93 Fixed in 1.94 CVE-2024-35675 Patchstack
6.5 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.7 Fixed in 1.8 CVE-2024-35676 Patchstack
8.5 High Contact Form to DB by BestWebSoft Plugin contact-form-to-db SQL Injection ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-35678 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.12.0 Fixed in 3.12.1 CVE-2024-35679 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only