WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,901–26,950 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 539 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Multi Currency For WooCommerce Plugin wc-multi-currency Broken Access Control ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-32516 Patchstack
4.3 Medium Custom Thank You Page Customize For WooCommerce by Binary Carpenter Plugin bc-woo-custom-thank-you-pages Broken Access Control ≤ 1.4.12 Fixed in 1.4.14 CVE-2024-32517 Patchstack
5.3 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control No login needed ≤ 2.0.0 CVE-2024-32518 Patchstack
4.3 Medium GG Woo Feed for WooCommerce Plugin gg-woo-feed Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-32519 Patchstack
4.3 Medium WPC Grouped Product for WooCommerce Plugin wpc-grouped-product Broken Access Control ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-32520 Patchstack
4.3 Medium Open Close WooCommerce Store Plugin woc-open-close Broken Access Control ≤ 4.9.1 Fixed in 4.9.2 CVE-2024-32522 Patchstack
4.3 Medium Custom Order Statuses for WooCommerce Plugin custom-order-statuses-for-woocommerce Broken Access Control ≤ 1.5.2 CVE-2024-32524 Patchstack
4.3 Medium Theme My Login Plugin theme-my-login Broken Access Control ≤ 7.1.6 Fixed in 7.1.7 CVE-2024-32525 Patchstack
5.3 Medium Speed Optimizer Plugin sg-cachepress Broken Access Control No login needed ≤ 7.4.6 Fixed in 7.5.0 CVE-2024-32532 Patchstack
4.8 Medium WP Staging Plugin wp-staging Cross-Site Scripting Admin+ Stored XSS < 3.4.0, < 5.4.0 Fixed in 3.4.0 CVE-2024-2309 WPScan
5.9 Medium Social Media Share Buttons Plugin Cross-Site Scripting Admin+ Stored XSS via settings < 2.8.9 Fixed in 2.8.9 CVE-2024-2118 WPScan
4.7 Medium Salon booking system Plugin salon-booking-system Cross-Site Scripting Unauthenticated Stored XSS No login needed < 9.6.3 Fixed in 9.6.3 CVE-2024-2102 WPScan
5.7 Medium WordPress Plugin Salon Booking System Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting (XSS) < 9.6.3 Fixed in 9.6.3 CVE-2024-2101 WPScan
5.3 Medium Easy Social Feed Plugin easy-facebook-likebox Cross-Site Scripting Contributor+ Stored XSS No login needed < 6.5.6 Fixed in 6.5.6 CVE-2024-1219 WPScan
5.3 Medium coreActivity Plugin Authentication Bypass Unauthenticated IP Spoofing No login needed < 2.1 Fixed in 2.1 CVE-2024-0868 WPScan
4.3 Medium Fatal Error Notify Plugin fatal-error-notify Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2024-32455 Patchstack
8.6 High MoveTo Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.2 CVE-2024-25911 Patchstack
8.2 High LiteSpeed Cache Plugin litespeed-cache Broken Access Control Unauthenticated Broken Access Control on API No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-45000 Patchstack
8.3 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Unauthenticated Site Wide Stored XSS No login needed ≤ 5.7 Fixed in 5.7.0.1 CVE-2023-40000 Patchstack
7.5 High Citadela Listing Plugin citadela-directory Information Disclosure Unauth. Sensitive Data Exposure No login needed ≤ 5.18.1 CVE-2024-32086 Patchstack
6.4 Medium BA Book Everything Plugin ba-book-everything Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.6.8 CVE-2024-3672 Wordfence
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Coupon Search ≤ 5.46.0 CVE-2024-3869 Wordfence
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 5.46.0 CVE-2024-3243 Wordfence
7.2 High WooCommerce Google Feed Manager Plugin wp-product-feed-manager SQL Injection Authenticated (Admin+) SQL Injection to Reflected Cross-Site Scripting ≤ 2.4.2 CVE-2024-3067 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_timeline' Shortcode ≤ 2.15.7 CVE-2024-1357 Wordfence
6.1 Medium Tainacan Interface Theme tainacan-interface Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.2 CVE-2024-3867 Wordfence
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9.2 Fixed in 2.6.9.3 CVE-2024-32557 Patchstack
4.7 Medium Freshdesk (official) Plugin freshdesk-support Open Redirect No login needed ≤ 2.3.6 Fixed in 2.4.0 CVE-2024-32129 Patchstack
4.3 Medium Login With Ajax Plugin login-with-ajax Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-30546 Patchstack
5.4 Medium e2pdf Plugin e2pdf Cross-Site Request Forgery No login needed ≤ 1.20.27 Fixed in 1.23.00 CVE-2024-31373 Patchstack
4.3 Medium AppPresser Plugin apppresser Cross-Site Request Forgery No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2024-31374 Patchstack
4.3 Medium Dashboard To-Do List Plugin dashboard-to-do-list Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-31376 Patchstack
5.4 Medium MailChimp Forms by MailMunch Plugin mailchimp-forms-by-mailmunch Cross-Site Request Forgery No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2024-31378 Patchstack
4.3 Medium Smash Balloon Social Post Feed Plugin custom-facebook-feed Cross-Site Request Forgery No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-31379 Patchstack
4.3 Medium Spotlight Social Media Feeds Plugin spotlight-social-photo-feeds Cross-Site Request Forgery No login needed ≤ 1.6.10 Fixed in 1.6.11 CVE-2024-31381 Patchstack
4.3 Medium Blocksy Plugin blocksy Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2024-31382 Patchstack
4.3 Medium PopularFX Theme popularfx Cross-Site Request Forgery No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-31383 Patchstack
4.3 Medium Spa and Salon Theme spa-and-salon Cross-Site Request Forgery No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-31384 Patchstack
4.3 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31385 Patchstack
4.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Request Forgery No login needed ≤ 1.0.25 Fixed in 1.0.26 CVE-2024-31388 Patchstack
5.4 Medium MihanPanel Plugin mihanpanel-lite Cross-Site Request Forgery No login needed < 12.7 Fixed in 12.7 CVE-2024-31389 Patchstack
4.3 Medium Popup by Supsystic Plugin popup-by-supsystic Broken Access Control ≤ 1.10.27 Fixed in 1.10.28 CVE-2024-31421 Patchstack
4.3 Medium Favicon Plugin favicon-by-realfavicongenerator Cross-Site Request Forgery No login needed ≤ 1.3.29 Fixed in 1.3.30 CVE-2024-31422 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
5.4 Medium Amelia Plugin ameliabooking Cross-Site Request Forgery No login needed ≤ 1.0.95 Fixed in 1.0.96 CVE-2024-31425 Patchstack
4.3 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Request Forgery No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-31426 Patchstack
4.3 Medium Marker.io Plugin marker-io Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-31427 Patchstack
4.3 Medium The Conference Theme the-conference Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-31428 Patchstack
4.3 Medium Sarada Lite Theme sarada-lite Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-31429 Patchstack
4.3 Medium Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-31431 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only