WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,951–27,000 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 540 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Restrict Content Plugin restrict-content Broken Access Control No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-31432 Patchstack
4.3 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.3.0 Fixed in 6.3.1 CVE-2024-31433 Patchstack
5.4 Medium Newsletter Plugin newsletter Cross-Site Request Forgery No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2024-31434 Patchstack
4.3 Medium Currency per Product for WooCommerce Plugin currency-per-product-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.7.0 CVE-2024-31920 Patchstack
4.3 Medium Ultimate Product Catalogue Plugin ultimate-product-catalogue Cross-Site Request Forgery No login needed ≤ 5.2.15 Fixed in 5.2.16 CVE-2024-31921 Patchstack
4.3 Medium WordPress Hosting Benchmark tool Plugin wpbenchmark Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-31922 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-31923 Patchstack
5.4 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Request Forgery No login needed ≤ 1.5.35 Fixed in 1.5.36 CVE-2024-31933 Patchstack
4.3 Medium NewsXpress Theme newsxpress Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-31938 Patchstack
4.3 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.2.104 Fixed in 1.2.105 CVE-2024-31940 Patchstack
5.4 Medium CP Media Player Plugin audio-and-video-player Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.2.0 CVE-2024-31941 Patchstack
4.3 Medium Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-31942 Patchstack
4.3 Medium Before And After Plugin before-and-after Cross-Site Request Forgery No login needed ≤ 3.9 CVE-2024-32084 Patchstack
5.4 Medium Citadela Listing Plugin Cross-Site Request Forgery No login needed < 5.20.0 Fixed in 5.20.0 CVE-2024-32085 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.15.20 Fixed in 6.15.21 CVE-2024-32088 Patchstack
4.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-32089 Patchstack
4.3 Medium Church Admin Plugin church-admin Cross-Site Request Forgery No login needed ≤ 4.0.27 Fixed in 4.0.28 CVE-2024-32090 Patchstack
6.5 Medium Sangar Slider Plugin sangar-slider-lite Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2024-32091 Patchstack
5.4 Medium Kimili Flash Embed Plugin kimili-flash-embed Cross-Site Request Forgery No login needed ≤ 2.5.3 CVE-2024-32092 Patchstack
5.4 Medium Novelist Plugin novelist Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-32093 Patchstack
4.3 Medium Church Content – Sermons, Events and More Plugin church-theme-content Cross-Site Request Forgery No login needed ≤ 2.6 Fixed in 2.6.1 CVE-2024-32094 Patchstack
4.3 Medium MultiParcels Shipping For WooCommerce Plugin multiparcels-shipping-for-woocommerce Cross-Site Request Forgery No login needed < 1.16.9 Fixed in 1.16.9 CVE-2024-32095 Patchstack
5.4 Medium WP Migration Plugin DB & Files – WP Synchro Plugin wpsynchro Cross-Site Request Forgery No login needed ≤ 1.11.2 Fixed in 1.11.3 CVE-2024-32096 Patchstack
5.4 Medium GEO my Plugin geo-my-wp Cross-Site Request Forgery No login needed ≤ 4.1 Fixed in 4.2 CVE-2024-32097 Patchstack
4.3 Medium WP Mail Catcher Plugin wp-mail-catcher Cross-Site Request Forgery No login needed ≤ 2.1.6 Fixed in 2.1.7 CVE-2024-32099 Patchstack
4.3 Medium Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Cross-Site Request Forgery No login needed ≤ 1.14.3 Fixed in 1.14.4 CVE-2024-32101 Patchstack
4.3 Medium Crony Cronjob Manager Plugin crony Cross-Site Request Forgery No login needed ≤ 0.5.0 CVE-2024-32102 Patchstack
5.4 Medium Siteimprove Plugin siteimprove Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-32103 Patchstack
4.3 Medium NextMove Lite Plugin woo-thank-you-page-nextmove-lite Cross-Site Request Forgery No login needed ≤ 2.18.1 Fixed in 2.18.2 CVE-2024-32104 Patchstack
4.3 Medium Libsyn Publisher Hub Plugin libsyn-podcasting Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-32141 Patchstack
4.3 Medium BEAF Plugin beaf-before-and-after-gallery Cross-Site Request Forgery No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2024-32433 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Cross-Site Request Forgery No login needed ≤ 3.20.2 Fixed in 3.21.0 CVE-2024-32434 Patchstack
4.3 Medium AffiEasy Plugin affieasy Cross-Site Request Forgery No login needed ≤ 1.1.4 Fixed in 1.1.6 CVE-2024-32435 Patchstack
4.3 Medium Gift Vouchers Plugin gift-voucher Cross-Site Request Forgery No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-32436 Patchstack
4.3 Medium eCommerce Product Catalog Plugin ecommerce-product-catalog Cross-Site Request Forgery No login needed ≤ 3.3.28 Fixed in 3.3.29 CVE-2024-32437 Patchstack
4.3 Medium SEO Booster Plugin seo-booster Cross-Site Request Forgery No login needed ≤ 3.8.9 Fixed in 3.8.10 CVE-2024-32438 Patchstack
4.3 Medium WP Client Reports Plugin wp-client-reports Cross-Site Request Forgery No login needed ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-32439 Patchstack
4.3 Medium Asgaros Forum Plugin asgaros-forum Cross-Site Request Forgery No login needed ≤ 2.8.0 Fixed in 2.9.0 CVE-2024-32440 Patchstack
4.3 Medium Zoho Campaigns Plugin zoho-campaigns Cross-Site Request Forgery No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-32441 Patchstack
4.3 Medium Zoho Campaigns Plugin zoho-campaigns Cross-Site Request Forgery No login needed ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-32442 Patchstack
4.3 Medium Download IP2Location Country Blocker Plugin ip2location-country-blocker Cross-Site Request Forgery No login needed ≤ 2.34.2 Fixed in 2.34.3 CVE-2024-32443 Patchstack
5.4 Medium WebinarIgnition Plugin webinar-ignition Cross-Site Request Forgery No login needed ≤ 3.05.8 Fixed in 3.06.0 CVE-2024-32445 Patchstack
5.4 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.5.9 Fixed in 2.5.10 CVE-2024-32446 Patchstack
4.3 Medium AWP Classifieds Plugin another-wordpress-classifieds-plugin Cross-Site Request Forgery No login needed ≤ 4.3.1 Fixed in 4.3.2 CVE-2024-32447 Patchstack
4.3 Medium Ads.txt Admin Plugin ads-txt-admin Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2024-32448 Patchstack
5.4 Medium RestroPress Plugin restropress Cross-Site Request Forgery No login needed ≤ 3.1.2 Fixed in 3.1.2.1 CVE-2024-32449 Patchstack
4.3 Medium WpTravelly Plugin tour-booking-manager Cross-Site Request Forgery No login needed ≤ 1.6.0 Fixed in 1.6.1 CVE-2024-32450 Patchstack
4.3 Medium Legal Pages Plugin legal-pages Cross-Site Request Forgery No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-32451 Patchstack
5.4 Medium WP EasyCart Plugin wp-easycart Cross-Site Request Forgery No login needed ≤ 5.5.19 Fixed in 5.6.0 CVE-2024-32452 Patchstack
7.1 High Social Author Bio Plugin social-autho-bio Cross-Site Scripting Stored XSS via Cross Site Request Forgery (CSRF) No login needed ≤ 2.4 CVE-2024-30545 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only