WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,701–26,750 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 535 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Seers Plugin seers-cookie-consent-banner-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 8.1.0 Fixed in 8.1.1 CVE-2024-32789 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32772 Patchstack
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32808 Patchstack
5.3 Medium Rate my Post – WP Rating System Plugin rate-my-post Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-32823 Patchstack
7.1 High ARForms Plugin arforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.4 Fixed in 6.4.1 CVE-2024-32702 Patchstack
5.9 Medium Image Slider Widget Plugin image-slider-widget Cross-Site Scripting ≤ 1.1.125 Fixed in 1.1.127 CVE-2024-32707 Patchstack
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.6.3 Fixed in 2.6.4 CVE-2024-32711 Patchstack
6.5 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting ≤ 2.6.3 Fixed in 2.6.4 CVE-2024-32721 Patchstack
5.9 Medium Coupon & Discount Code Reveal Button Plugin coupon-reveal-button Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-32722 Patchstack
5.9 Medium Advanced Floating Content Plugin advanced-floating-content-lite Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-32723 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.10.25 Fixed in 4.10.26 CVE-2024-32791 Patchstack
5.9 Medium Widget Post Slider Plugin widget-post-slider Cross-Site Scripting ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-32801 Patchstack
5.9 Medium All-in-one Like Widget Plugin all-in-one-facebook-like-widget Cross-Site Scripting ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-32815 Patchstack
5.9 Medium List Custom Taxonomy Widget Plugin list-custom-taxonomy-widget Cross-Site Scripting ≤ 4.1 Fixed in 4.2 CVE-2024-32833 Patchstack
5.9 Medium WooCommerce Shipping Label Plugin shipping-labels-for-woo Cross-Site Scripting ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-32834 Patchstack
7.1 High WP Media Category Management Plugin wp-media-category-management Cross-Site Scripting No login needed ≤ 2.2 Fixed in 2.3.0 CVE-2024-32950 Patchstack
7.1 High Max Addons Pro for Bricks Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32952 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-32956 Patchstack
8.5 High ARForms Plugin arforms SQL Injection Subscriber+ SQL Injection ≤ 6.4 Fixed in 6.4.1 CVE-2024-32706 Patchstack
9.3 Critical WP-Recall Plugin wp-recall SQL Injection No login needed ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32709 Patchstack
8.5 High WP-Recall Plugin wp-recall SQL Injection ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32710 Patchstack
5.3 Medium StreamWeasels Twitch Integration Plugin streamweasels-twitch-integration Information Disclosure API Sensitive Data Exposure No login needed ≤ 1.7.8 Fixed in 1.8.0 CVE-2024-32716 Patchstack
7.5 High Frontend Dashboard Plugin frontend-dashboard Information Disclosure Sensitive Data Exposure on PII No login needed ≤ 2.2.2 Fixed in 2.2.4 CVE-2024-32726 Patchstack
5.9 Medium VikRentCar Plugin vikrentcar Information Disclosure Sensitive Data Exposure via Invoices No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-32780 Patchstack
7.5 High Email Customizer for WooCommerce Plugin email-customizer-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32781 Patchstack
4.3 Medium HT Mega Plugin ht-mega-for-elementor Information Disclosure Sensitive Data Exposure ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-32782 Patchstack
5.3 Medium FG Joomla to Plugin fg-joomla-to-wordpress Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 4.20.2 Fixed in 4.21.0 CVE-2024-32788 Patchstack
4.3 Medium WP Fusion Lite Plugin wp-fusion-lite Information Disclosure Sensitive Data Exposure ≤ 3.42.10 Fixed in 3.43.0 CVE-2024-32796 Patchstack
7.5 High Post Grid Plugin post-grid Information Disclosure Sensitive Data Exposure via API No login needed ≤ 2.2.78 Fixed in 2.2.79 CVE-2024-32816 Patchstack
7.5 High Simply Static Plugin simply-static Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-32825 Patchstack
7.5 High Newsletters Plugin newsletters-lite Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-32953 Patchstack
4.4 Medium Import and export users and customers Plugin import-users-from-csv-with-meta PHP Object Injection ≤ 1.26.2 Fixed in 1.26.3 CVE-2024-32817 Patchstack
5.4 Medium Import Export WordPress Users Plugin users-customers-import-export-for-wp-woocommerce PHP Object Injection Deserialization of untrusted data No login needed ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-32835 Patchstack
9.1 Critical WP-Lister Lite for eBay Plugin wp-lister-for-ebay Arbitrary File Upload ≤ 3.5.11 Fixed in 3.6.0 CVE-2024-32836 Patchstack
4.9 Medium The Pack Elementor addons Plugin the-pack-addon Server-Side Request Forgery ≤ 2.0.8.2 Fixed in 2.0.8.3 CVE-2024-32718 Patchstack
4.9 Medium Embed Google Photos album Plugin embed-google-photos-album-easily Server-Side Request Forgery ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-32775 Patchstack
6.4 Medium SuperFaktura WooCommerce Plugin woocommerce-superfaktura Server-Side Request Forgery ≤ 1.40.3 Fixed in 1.40.4 CVE-2024-32803 Patchstack
5.4 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Server-Side Request Forgery ≤ 4.0.11 Fixed in 4.0.12 CVE-2024-32812 Patchstack
4.9 Medium Culqi Plugin culqi-checkout Server-Side Request Forgery ≤ 3.0.14 Fixed in 3.0.15 CVE-2024-32819 Patchstack
4.9 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Server-Side Request Forgery ≤ 7.5.43.7212 Fixed in 7.5.45.7212 CVE-2024-32955 Patchstack
9.1 Critical ARMember Plugin armember-membership Broken Access Control Membership Plugin plugin <= 4.0.28 - Broken Access Control No login needed ≤ 4.0.28 Fixed in 4.0.29 CVE-2024-32948 Patchstack
6.5 Medium Max Addons Pro for Bricks Plugin Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-32951 Patchstack
4.8 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Contributor+ Stored XSS < 3.1.12 Fixed in 3.1.12 CVE-2024-3261 WPScan
3.8 Low Floating Chat Widget Plugin Cross-Site Scripting Editor+ Stored XSS < 3.1.9 Fixed in 3.1.9 CVE-2024-2972 WPScan
5.4 Medium Better Comments Plugin Cross-Site Scripting Subscriber+ Stored XSS < 1.5.6 Fixed in 1.5.6 CVE-2024-2404 WPScan
5.4 Medium Better Comments Plugin Cross-Site Scripting Admin+ Stored XSS < 1.5.6 Fixed in 1.5.6 CVE-2024-2402 WPScan
6.5 Medium WooCommerce Customers Manager Plugin Information Disclosure Subscriber+ Email Disclosure < 29.8 Fixed in 29.8 CVE-2024-1756 WPScan
5.9 Medium WooCommerce Customers Manager Plugin Cross-Site Scripting Reflected XSS No login needed < 29.8 Fixed in 29.8 CVE-2024-1743 WPScan
6.1 Medium Import WP Plugin Server-Side Request Forgery Admin+ Server-side Request Forgery < 2.13.1 Fixed in 2.13.1 CVE-2023-7253 WPScan
5.3 Medium Shared Files Plugin shared-files Broken Access Control No login needed ≤ 1.7.16 Fixed in 1.7.17 CVE-2024-32679 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only