WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,001–27,050 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 541 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Change default login logo,url and title Plugin change-default-login-logo-url-and-title Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.0 CVE-2024-31086 Patchstack
7.1 High Broken Images Plugin wp-broken-images Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.2 CVE-2024-31093 Patchstack
7.1 High Sync Post With Other Site Plugin sync-post-with-other-site Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.9.1 CVE-2024-32082 Patchstack
7.6 High Product Feed on WooCommerce for Google Plugin purple-xmls-google-product-feed-for-woocommerce SQL Injection Auth. SQL Injection (SQLi) ≤ 3.5.7 CVE-2024-32087 Patchstack
7.6 High Advanced Page Visit Counter Plugin advanced-page-visit-counter SQL Injection Auth. SQL Injection (SQLi) ≤ 8.0.6 CVE-2024-32098 Patchstack
8.5 High BA Book Everything Plugin ba-book-everything SQL Injection Auth. SQL Injection ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-32125 Patchstack
8.5 High Find Duplicates Plugin find-duplicates SQL Injection Auth. SQL Injection ≤ 1.4.6 CVE-2024-32127 Patchstack
9.3 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.14.4 CVE-2024-32128 Patchstack
7.6 High CBX Bookmark & Favorite Plugin cbxwpbookmark SQL Injection ≤ 1.7.20 CVE-2024-32132 Patchstack
7.6 High Forms to Zapier, Integromat, IFTTT, Workato, Automate.io, elastic.io, Built.io, APIANT, Webhook Plugin forms-to-zapier SQL Injection Auth. SQL Injection ≤ 1.1.12 CVE-2024-32134 Patchstack
7.6 High Disable Comments | WPZest Plugin disable-comments-wpz SQL Injection ≤ 1.51 CVE-2024-32135 Patchstack
7.6 High BWL Advanced FAQ Manager Plugin bwl-advanced-faq-manager SQL Injection Auth. SQL Injection ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-32136 Patchstack
8.5 High User Activity Log Pro Plugin SQL Injection Auth. SQL Injection ≤ 2.3.4 CVE-2024-32137 Patchstack
8.5 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress SQL Injection ≤ 4.0.12 Fixed in 4.0.14 CVE-2024-32139 Patchstack
4.4 Medium Import Users from CSV Plugin import-users-from-csv PHP Object Injection ≤ 1.2 Fixed in 1.3 CVE-2024-32431 Patchstack
4.4 Medium ActiveCampaign Plugin activecampaign-subscription-forms Server-Side Request Forgery ≤ 8.1.14 Fixed in 8.1.15 CVE-2024-32430 Patchstack
4.4 Medium Appointment Bookings for Zoom GoogleMeet and more – Wappointment Plugin wappointment Server-Side Request Forgery ≤ 2.6.0 Fixed in 2.6.1 CVE-2024-32454 Patchstack
5.5 Medium Product Feed Manager Plugin best-woocommerce-feed Path Traversal Directory Traversal ≤ 7.3.15 Fixed in 7.3.16 CVE-2023-52144 Patchstack
6.5 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting ≤ 2024.2 Fixed in 2024.3 CVE-2024-32079 Patchstack
7.1 High EZ Form Calculator Plugin ez-form-calculator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.14.0.3 CVE-2024-32133 Patchstack
7.1 High Short URL Plugin shorten-url Cross-Site Scripting No login needed ≤ 1.6.8 CVE-2024-32138 Patchstack
6.5 Medium Libsyn Publisher Hub Plugin libsyn-podcasting Cross-Site Scripting ≤ 1.4.4 CVE-2024-32140 Patchstack
7.1 High WP Google Analytics Events Plugin wp-google-analytics-events Cross-Site Scripting No-Code Custom Event Tracking for Google Analytics plugin <= 2.8.0 - Reflected Cross-Site Scripting No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-32145 Patchstack
6.5 Medium Easy Contact Form Lite Plugin contact-form-lite Cross-Site Scripting ≤ 1.1.23 Fixed in 1.1.25 CVE-2024-32147 Patchstack
7.1 High Jobs Plugin job-postings Cross-Site Scripting No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2024-32149 Patchstack
5.9 Medium MWW Disclaimer Buttons Plugin mww-disclaimer-buttons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.0.2 Fixed in 3.2 CVE-2024-32428 Patchstack
5.9 Medium Remove Footer Credit Plugin remove-footer-credit Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2024-32429 Patchstack
5.9 Medium POEditor Plugin poeditor Cross-Site Scripting ≤ 0.9.8 Fixed in 0.9.9 CVE-2024-32453 Patchstack
4.8 Medium Simple Buttons Creator Plugin Cross-Site Request Forgery Aribtrary Button Deletion via CSRF ≤ 1.04 CVE-2024-2858 WPScan
6.1 Medium Simple Buttons Creator Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.04 CVE-2024-2857 WPScan
4.8 Medium Super Socializer Plugin Cross-Site Scripting Editor+ Stored XSS < 7.13.64 Fixed in 7.13.64 CVE-2024-2836 WPScan
8.7 High Advance Search Plugin Cross-Site Request Forgery Shortcode Deletion via CSRF ≤ 1.1.6 CVE-2024-2739 WPScan
5.4 Medium WP Customer Reviews Plugin wp-customer-reviews Open Redirect Malicious Redirect via HTTP-EQUIV Injection No login needed < 3.7.1 Fixed in 3.7.1 CVE-2024-1849 WPScan
5.4 Medium Responsive Tabs Plugin responsive-tabs Cross-Site Scripting Contributor+ Stored XSS < 4.0.7 Fixed in 4.0.7 CVE-2024-1846 WPScan
8.8 High NPS computy Plugin nps-computy Cross-Site Request Forgery Results Deletion via CSRF No login needed ≤ 2.7.5 CVE-2024-1755 WPScan
4.7 Medium NPS computy Plugin nps-computy Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 2.7.5 CVE-2024-1754 WPScan
5.4 Medium Testimonial Slider Plugin testimonial-slider Cross-Site Scripting Admin+ Stored XSS < 2.3.8 Fixed in 2.3.8 CVE-2024-1746 WPScan
4.7 Medium Carousel Slider Plugin carousel-slider Cross-Site Scripting Editor+ Stored XSS No login needed < 2.2.7 Fixed in 2.2.7 CVE-2024-1712 WPScan
4.8 Medium Top Bar Plugin top-bar Cross-Site Scripting Admin+ Stored XSS < 3.0.5 Fixed in 3.0.5 CVE-2024-1660 WPScan
4.9 Medium WooCommerce Plugin woocommerce Broken Access Control Contributor+ Private/Draft Products Access < 8.6 Fixed in 8.6 CVE-2024-1310 WPScan
6.5 Medium Smart Forms Plugin smart-forms Broken Access Control Subscriber+ Edit Entries via Broken Access Control < 2.6.94 Fixed in 2.6.94 CVE-2024-1307 WPScan
5.4 Medium Smart Forms Plugin smart-forms Cross-Site Request Forgery Edit Entries via CSRF < 2.6.94 Fixed in 2.6.94 CVE-2024-1306 WPScan
4.3 Medium Meta Box Plugin meta-box Information Disclosure Contributor+ Arbitrary Posts' Custom Field Disclosure < 5.9.4 Fixed in 5.9.4 CVE-2024-1204 WPScan
4.3 Medium Fancy Product Designer Plugin Cross-Site Scripting Admin+ Cross Site Scripting via Product Title < 6.1.81 Fixed in 6.1.81 CVE-2024-0902 WPScan
8.1 High WooCommerce Customers Manager Plugin SQL Injection Subscriber+ SQL Injection < 29.7 Fixed in 29.7 CVE-2024-0399 WPScan
6.5 Medium Everest Backup Plugin everest-backup Arbitrary File Upload Admin+ Arbitrary File Upload < 2.2.5 Fixed in 2.2.5 CVE-2023-7201 WPScan
5.4 Medium WP User Profile Avatar Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.0.1 CVE-2023-6067 WPScan
4.3 Medium WPZOOM Social Feed Widget & Block Plugin instagram-widget-by-wpzoom Broken Access Control Missing Authorization to Authenticated (Subscriber+) Instagram Image Deletion ≤ 2.1.13 CVE-2024-3662 Wordfence
4.4 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 4.0.2 CVE-2023-6494 Wordfence
5.4 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Contributor+ Stored XSS < 7.0.5 Fixed in 7.0.5 CVE-2024-2583 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only