WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,701–25,750 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 515 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Captcha Code Plugin captcha-code-authentication Authentication Bypass Captcha Bypass No login needed ≤ 2.9 Fixed in 3.0 CVE-2023-48745 Patchstack
3.7 Low Hide login page Plugin hide-login-page Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 1.1.9 CVE-2023-48335 Patchstack
5.3 Medium Contact Form Email Plugin contact-form-to-email Authentication Bypass Captcha Bypass No login needed ≤ 1.3.41 Fixed in 1.3.42 CVE-2023-48318 Patchstack
5.3 Medium Form Maker by 10Web Plugin form-maker Authentication Bypass Captcha Bypass Vulnerability No login needed ≤ 1.15.20 Fixed in 1.15.21 CVE-2023-48290 Patchstack
5.3 Medium Stripe Payments Plugin stripe-payments Content Injection No login needed ≤ 2.0.79 Fixed in 2.0.80 CVE-2023-48285 Patchstack
5.3 Medium WP Forms Puzzle Captcha Plugin wp-forms-puzzle-captcha Authentication Bypass Captcha Bypass No login needed ≤ 4.1 CVE-2023-48276 Patchstack
5.3 Medium Maspik – Spam blacklist Plugin contact-forms-anti-spam Authentication Bypass Spam Blacklist plugin <= 0.10.3 - IP Filtering Bypass No login needed ≤ 0.10.3 Fixed in 0.10.4 CVE-2023-48271 Patchstack
8.3 High ARMember Plugin armember-membership Privilege Escalation Membership Plan Bypass ≤ 4.0.10 Fixed in 4.0.11 CVE-2023-47837 Patchstack
3.7 Low LWS Hide Login Plugin lws-hide-login Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2023-47818 Patchstack
3.7 Low WP Maintenance Plugin wp-maintenance Authentication Bypass IP Filtering Bypass No login needed ≤ 6.1.3 Fixed in 6.1.4 CVE-2023-47769 Patchstack
5.4 Medium ARI Stream Quiz Plugin ari-stream-quiz Content Injection WordPress Quizzes Builder plugin <= 1.3.2 - Content Injection ≤ 1.3.2 Fixed in 1.3.3 CVE-2023-47513 Patchstack
6.4 Medium Slider Revolution Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Elementor wrapperid and zindex ≤ 6.7.10 CVE-2024-4637 Wordfence
5.3 Medium Defender Security Plugin defender-security Authentication Bypass Masked Login Area View Bypass No login needed ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-47189 Patchstack
7.5 High Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Password Protected View Bypass Vulnerability No login needed ≤ 5.7.1 Fixed in 5.8.0 CVE-2023-46630 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Content Injection No login needed ≤ 7.6.10 Fixed in 7.6.11 CVE-2023-46310 Patchstack
5.4 Medium Responsive Tabs Plugin responsive-tabs Content Injection HTML Content Injection < 4.0.6 Fixed in 4.0.6 CVE-2023-45635 Patchstack
4.3 Medium WP Content Pilot – Autoblogging & Affiliate Marketing Plugin wp-content-pilot Content Injection HTML Injection ≤ 1.3.3 Fixed in 1.3.4 CVE-2023-45053 Patchstack
5.3 Medium Captcha/Honeypot for Contact Form 7 Plugin captcha-for-contact-form-7 Other Capcha Bypass No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2023-45009 Patchstack
6.4 Medium Slider Revolution Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Add Layer class, id, and title Attributes ≤ 6.7.10 CVE-2024-4581 Wordfence
5.3 Medium WP Captcha Plugin wp-captcha Authentication Bypass Captcha Bypass No login needed ≤ 2.0.0 CVE-2023-44235 Patchstack
5.3 Medium Antispam Bee Plugin antispam-bee Authentication Bypass Country IP Restriction Bypass No login needed ≤ 2.11.3 Fixed in 2.11.4 CVE-2023-41134 Patchstack
6.5 Medium Cartpauj Register Captcha Plugin cartpauj-register-captcha Authentication Bypass Captcha Bypass No login needed ≤ 1.0.02 Fixed in 2.0.0 CVE-2023-40673 Patchstack
5.4 Medium Tabs & Accordion Plugin tabs Content Injection ≤ 1.3.10 CVE-2023-40557 Patchstack
5.3 Medium WP-PostRatings Plugin wp-postratings Other Rating limit Bypass No login needed ≤ 1.91 Fixed in 1.91.1 CVE-2023-40332 Patchstack
5.4 Medium Discussion Board Plugin wp-discussion-board Content Injection ≤ 2.4.8 Fixed in 2.4.9 CVE-2023-39161 Patchstack
6.5 Medium Pinpoint Booking System Plugin booking-system Other Parameter Tampering No login needed ≤ 2.9.9.3.4 Fixed in 2.9.9.3.5 CVE-2023-38520 Patchstack
5.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Authentication Bypass IP Bypass Vulnerability No login needed ≤ 2.29.1 Fixed in 2.29.2 CVE-2023-37865 Patchstack
5.3 Medium Hide My WP Ghost Plugin hide-my-wp Authentication Bypass Security Plugin plugin <= 5.0.25 - Captcha Bypass No login needed ≤ 5.0.25 Fixed in 5.0.26 CVE-2023-34001 Patchstack
9.1 Critical Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Arbitrary File Upload Unrestricted Zip Extraction ≤ 1.5.66 Fixed in 1.5.67 CVE-2023-33930 Patchstack
4.3 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.31 Fixed in 1.3.32 CVE-2023-28494 Patchstack
6.4 Medium SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! Plugin suretriggers Cross-Site Scripting Connect All Your Plugins, Apps, Tools & Automate Everything! <= 1.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trigger Link Shortcode ≤ 1.0.47 CVE-2024-5485 Wordfence
6.1 Medium FS Product Inquiry Plugin fs-product-inquiry Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.1.1 CVE-2024-4857 WPScan
8.2 High FS Product Inquiry Plugin fs-product-inquiry Cross-Site Scripting Reflected XSS No login needed ≤ 1.1.1 CVE-2024-4856 WPScan
5.3 Medium BuddyBoss Platform Plugin Broken Access Control Insecure Direct Object Reference on Like Comment No login needed < 2.6.0 Fixed in 2.6.0 CVE-2024-4750 WPScan
8.3 High WP eMember Plugin Cross-Site Scripting Reflected XSS No login needed < 10.3.9 Fixed in 10.3.9 CVE-2024-4749 WPScan
9.1 Critical The Events Calendar Plugin the-events-calendar Cross-Site Scripting Reflected XSS No login needed < 6.4.0.1 Fixed in 6.4.0.1 CVE-2024-4180 WPScan
6.1 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed < 3.2.37 Fixed in 3.2.37 CVE-2024-4057 WPScan
5.4 Medium Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Admin+ Stored XSS < 20240412 Fixed in 20240412 CVE-2024-2470 WPScan
5.4 Medium Insert or Embed Articulate Content into Plugin Remote Code Execution Author+ Upload to RCE ≤ 4.3000000023 CVE-2024-0757 WPScan
5.3 Medium WPUpper Share Buttons Plugin wpupper-share-buttons Broken Access Control Missing Authorization No login needed ≤ 3.43 CVE-2024-4997 Wordfence
4.4 Medium Nafeza Prayer Time Plugin nafeza-prayer-time Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.2.9 CVE-2024-4462 Wordfence
6.4 Medium Cowidgets – Elementor Addons Plugin Cross-Site Scripting Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via heading_tag Parameter ≤ 1.1.2 CVE-2024-4697 Wordfence
6.4 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.2 CVE-2024-4273 Wordfence
4.3 Medium Essential Real Estate Plugin essential-real-estate Broken Access Control Insecure Direct Object Reference to Arbitrary Attachment Deletion ≤ 4.4.4 CVE-2024-4274 Wordfence
6.4 Medium Download Attachments Plugin download-attachments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 CVE-2024-3230 Wordfence
4.4 Medium Fluid Notification Bar Plugin fluid-notification-bar Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.2.3 CVE-2024-3031 Wordfence
5.3 Medium Authorize.net Payment Gateway For WooCommerce Plugin authorizenet-payment-gateway-for-woocommerce Price Manipulation Insufficient Verification of Data Authenticity to Unauthenticated Payment Bypass No login needed ≤ 8.0 CVE-2024-2382 Wordfence
7.5 High WP-DB-Table-Editor Plugin wp-db-table-editor Broken Access Control Missing Authorization to Authenticated(Contributor+) Database Access ≤ 1.8.4 CVE-2024-2019 Wordfence
5.3 Medium Claudio Sanches – Checkout Cielo for WooCommerce Plugin woocommerce-checkout-cielo Broken Access Control Checkout Cielo for WooCommerce <= 1.1.0 - Insufficient Verification of Data Authenticity to Order Payment Status Update No login needed ≤ 1.1.0 CVE-2024-1718 Wordfence
7.2 High Social Link Pages: link-in-bio landing pages for your social media profiles Plugin social-link-pages Broken Access Control Missing Authorization to Arbitrary Page Creation and Cross-Site Scripting No login needed ≤ 1.6.9 CVE-2024-3555 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only