WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,851–27,900 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 558 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Media folder Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Modification ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-25908 Patchstack
9.8 Critical MoveTo Plugin Broken Access Control Unauthenticated Arbitrary WordPress Settings Change No login needed ≤ 6.2 CVE-2024-25912 Patchstack
5.4 Medium Peach Payments Gateway Plugin wc-peach-payments-gateway Broken Access Control ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-25922 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-25935 Patchstack
7.5 High FunnelKit Checkout Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 3.10.3 Fixed in 3.11.0 CVE-2023-51672 Patchstack
5.4 Medium Points and Rewards for WooCommerce Plugin points-and-rewards-for-woocommerce Broken Access Control Settings Change ≤ 1.5.0 Fixed in 1.6.0 CVE-2023-27607 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Authentication Bypass Broken Authentication No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2022-44595 Patchstack
6.5 Medium Code Embed Plugin simple-embed-code Denial of Service Denial of Service Attack ≤ 2.3.6 Fixed in 2.3.7 CVE-2023-49837 Patchstack
4.3 Medium Download Media Plugin download-media Broken Access Control ≤ 1.4.2 CVE-2024-27190 Patchstack
9.9 Critical Automatic Plugin SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27956 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
5.9 Medium WP Coder Plugin wp-coder Cross-Site Scripting ≤ 3.5 Fixed in 3.5.1 CVE-2024-2578 Patchstack
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting ≤ 2.0.16 Fixed in 2.1.0 CVE-2024-2579 Patchstack
6.5 Medium Automation By Autonami Plugin wp-marketing-automations Cross-Site Scripting ≤ 2.8.2 Fixed in 2.8.3 CVE-2024-2580 Patchstack
7.1 High wp-mpdf Plugin wp-mpdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.1 Fixed in 3.8 CVE-2024-27962 Patchstack
6.5 Medium Crisp Plugin crisp Cross-Site Scripting Live Chat and Chatbot plugin <= 0.44 - Cross Site Scripting (XSS) ≤ 0.44 Fixed in 0.45 CVE-2024-27963 Patchstack
8.8 High Zippy Plugin zippy Arbitrary File Upload ≤ 1.6.9 Fixed in 1.6.10 CVE-2024-27964 Patchstack
5.9 Medium WPFunnels Plugin wpfunnels Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-27965 Patchstack
5.9 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting ≤ 8.2.2 Fixed in 8.2.3 CVE-2024-27966 Patchstack
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
6.5 Medium Free Downloads WooCommerce Plugin download-now-for-woocommerce Cross-Site Scripting ≤ 3.5.8.2 Fixed in 3.5.8.3 CVE-2024-27969 Patchstack
5.4 Medium WP SendFox Plugin wp-sendfox Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-27970 Patchstack
5.4 Medium PropertyHive Plugin propertyhive PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-27985 Patchstack
6.5 Medium WEN Responsive Columns Plugin wen-responsive-columns Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-27988 Patchstack
6.5 Medium WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs Cross-Site Scripting ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-27989 Patchstack
6.5 Medium The Moneytizer Plugin the-moneytizer Cross-Site Scripting ≤ 9.5.20 Fixed in 9.6.1 CVE-2024-27990 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.2.3 Fixed in 3.2.4 CVE-2024-27991 Patchstack
7.1 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.8 Fixed in 0.6.9 CVE-2024-27992 Patchstack
7.1 High Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-27993 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting No login needed ≤ 4.5.0 Fixed in 4.6.0 CVE-2024-27994 Patchstack
5.9 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting ≤ 4.0.23 Fixed in 4.0.24 CVE-2024-27995 Patchstack
8.8 High File Manager Plugin wp-file-manager Cross-Site Request Forgery Cross-Site Request Forgery to Local JS File Inclusion No login needed ≤ 7.2.4 CVE-2024-1538 Wordfence
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
6.5 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control No login needed ≤ 1.0 CVE-2023-52229 Patchstack
8.2 High Olive One Click Demo Import Plugin olive-one-click-demo-import Broken Access Control No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-2702 Patchstack
9.8 Critical Create by Mediavine Plugin mediavine-create SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 1.9.4 CVE-2024-1711 Wordfence
4.3 Medium Live Sales Notification for Woocommerce – Woomotiv Plugin Cross-Site Request Forgery Woomotiv <= 3.4.3 - Cross-Site Request Forgery via ajax_cancel_review No login needed ≤ 3.4.3 CVE-2024-1325 Wordfence
6.1 Medium Website Article Monetization By MageNet Plugin website-article-monetization-by-magenet Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.11 CVE-2024-1379 Wordfence
8.8 High Management App for WooCommerce – Order notifications, Order management, Lead management, Uptime Monitoring Plugin wemanage-app-worker Arbitrary File Upload Order notifications, Order management, Lead management, Uptime Monitoring <= 1.2.2 - Authenticated (Subscriber+) Arbitrary File Upload ≤ 1.2.2 CVE-2024-1205 Wordfence
6.4 Medium Animated Headline Plugin animated-headline Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.0 CVE-2024-2304 Wordfence
5.3 Medium Order Tip for WooCommerce Plugin order-tip-woo Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 1.3.1 CVE-2024-1119 Wordfence
4.3 Medium RevivePress – Keep your Old Content Evergreen Plugin wp-auto-republish Broken Access Control Keep your Old Content Evergreen <= 1.5.6 - Missing Authorization ≤ 1.5.6 CVE-2024-1844 Wordfence
5.3 Medium Coming Soon, Under Construction & Maintenance Mode By Dazzler Plugin Broken Access Control Maintenance Mode Bypass No login needed ≤ 2.1.2 CVE-2024-1181 Wordfence
7.4 High UX Flat Plugin ux-flat Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4 CVE-2024-2459 Wordfence
5.3 Medium Coming Soon & Maintenance Mode by Colorlib Plugin colorlib-coming-soon-maintenance Information Disclosure Information Exposure No login needed ≤ 1.0.99 CVE-2024-1473 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4 CVE-2024-2129 Wordfence
5.3 Medium Easy Maintenance Mode Plugin easy-maintenance-mode-coming-soon Information Disclosure Information Exposure No login needed ≤ 1.4.2 CVE-2024-1477 Wordfence
5.4 Medium Permalink Manager Plugin permalink-manager-for-woocommerce Broken Access Control Missing Authorization to Authenticated(Author+) Arbitrary Post Slug Modification ≤ 2.4.3.1 CVE-2024-2538 Wordfence
7.1 High Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Unauthenticated Stored XSS No login needed < 20240223 Fixed in 20240223 CVE-2024-1983 WPScan
8.8 High Booking Calendar Plugin booking Cross-Site Request Forgery CSRF appointment scheduling No login needed < 1.3.83 Fixed in 1.3.83 CVE-2024-0856 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only