WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,751–27,800 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 556 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6.20 Fixed in 1.6.6.24 CVE-2024-22311 Patchstack
8.7 High Knowledge Base for Documentation, FAQs with AI Assistance Plugin echo-knowledge-base PHP Object Injection No login needed ≤ 11.30.2 Fixed in 11.31.0 CVE-2024-24842 Patchstack
10.0 Critical WappPress Plugin wapppress-builds-android-app-for-website Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.3 Fixed in 6.0.0 CVE-2023-49815 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Clients Widget ≤ 5.4.1 CVE-2024-2203 Wordfence
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 2.0.5.6 CVE-2024-2139 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Team Member Listing ≤ 5.4.1 CVE-2024-2210 Wordfence
9.9 Critical Elementor Website Builder Plugin elementor Arbitrary File Upload 3.3.0 – 3.18.1 Fixed in 3.18.2 CVE-2023-48777 Patchstack
8.0 High Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Arbitrary File Upload ≤ 11.0.2 Fixed in 11.1 CVE-2023-48275 Patchstack
8.5 High Avada Theme Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39307 Patchstack
9.0 Critical JupiterX Core Plugin Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 3.3.5 Fixed in 3.3.8 CVE-2023-38388 Patchstack
9.1 Critical WP Child Theme Generator Plugin wp-child-theme-generator Arbitrary File Upload ≤ 1.0.9 CVE-2023-47873 Patchstack
9.1 Critical WP Githuber MD Plugin wp-githuber-md Arbitrary File Upload ≤ 1.16.2 Fixed in 1.16.3 CVE-2023-47846 Patchstack
9.1 Critical CataBlog Plugin catablog Arbitrary File Upload ≤ 1.7.0 CVE-2023-47842 Patchstack
9.1 Critical Manager for Icomoon Plugin manager-for-icomoon Arbitrary File Upload ≤ 2.0 Fixed in 2.1 CVE-2023-29386 Patchstack
9.3 Critical Quiz And Survey Master Plugin quiz-master-next SQL Injection Unauthenticated SQL Injection No login needed ≤ 8.1.4 Fixed in 8.1.5 CVE-2023-28787 Patchstack
7.1 High Glaze Blog Lite Theme glaze-blog-lite Cross-Site Scripting Reflected Cross-Site Scripting (XSS) vulnerability in multiple WordPress themes No login needed ≤ <= 1.1.4, ≤ 1.0.8, ≤ 2.1.3, … Fixed in 1.1.5 CVE-2023-28687 Patchstack
5.3 Medium Community by PeepSo Plugin peepso-core Information Disclosure Server Information Disclosure No login needed ≤ 6.0.9.0 Fixed in 6.1.0.0 CVE-2023-27630 Patchstack
7.4 High User Registration Plugin user-registration PHP Object Injection Authenticated PHP Object Injection ≤ 2.3.2.1 Fixed in 2.3.3 CVE-2023-27459 Patchstack
7.2 High Types Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4.17 Fixed in 3.4.18 CVE-2023-27440 Patchstack
5.9 Medium Upload Resume Plugin resume-upload-form Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.0 CVE-2023-25965 Patchstack
10.0 Critical MainWP File Uploader Extension Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 4.1 Fixed in 4.1.1 CVE-2023-23656 Patchstack
7.2 High Theme Editor Plugin theme-editor Arbitrary File Upload ≤ 2.7.1 Fixed in 2.8 CVE-2023-6091 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
7.5 High CF7 Google Sheets Connector Plugin cf7-google-sheets-connector Information Disclosure Sensitive Data Exposure via Debug Log No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-44989 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck
4.3 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2023-52214 Patchstack
6.5 Medium SalesKing Plugin Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22156 Patchstack
6.5 Medium Radio Player Plugin radio-player Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-2906 Patchstack
4.3 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Broken Access Control MPG plugin <= 3.4.0 - Broken Access Control ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-30235 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30234 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Information Disclosure Sensitive Data Exposure on User Export ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30233 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9 Fixed in 2.6.9.1 CVE-2024-30232 Patchstack
9.1 Critical Product Import Export for WooCommerce Plugin product-import-export-for-woo Arbitrary File Upload ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-30231 Patchstack
4.3 Medium PopupAlly Plugin popupally Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-23520 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-24711 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control Missing Authorization to Non-Arbitrary Plugin Installation ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-24718 Patchstack
4.3 Medium Location Picker at Checkout for WooCommerce Plugin map-location-picker-at-checkout-for-woocommerce Broken Access Control ≤ 1.8.9 Fixed in 1.9.0 CVE-2024-24719 Patchstack
6.5 Medium WooCommerce Box Office Plugin woocommerce-box-office Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-24799 Patchstack
4.3 Medium Calliope Theme calliope Cross-Site Request Forgery No login needed ≤ 1.0.33 Fixed in 1.0.35 CVE-2024-2904 Patchstack
4.3 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-24805 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 9.4.3 Fixed in 9.4.3.1 CVE-2023-23991 Patchstack
5.4 Medium TheGem (Elementor) Theme Cross-Site Scripting Auth. Stored Cross-Site Scripting (XSS) vulnerability in TheGem theme by CodexThemes < 5.8.1.1 Fixed in 5.8.1.1 CVE-2023-32237 Patchstack
7.1 High Front End Users Plugin front-end-only-users Cross-Site Scripting No login needed < 3.2.25 Fixed in 3.2.25 CVE-2023-33322 Patchstack
6.5 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting ≤ 20230901 Fixed in 20230902 CVE-2023-7251 Patchstack
7.1 High Contact Form With Captcha Plugin contact-form-with-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 CVE-2023-45771 Patchstack
4.3 Medium Clotya Theme Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in multiple themes by KlbTheme No login needed ≤ 1.1.6, ≤ 1.7.7, ≤ 1.2.2, … CVE-2023-49838 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only