WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 28,351–28,400 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Orbit Fox by ThemeIsle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.10.31 |
CVE-2024-1323 |
Wordfence | |
| 5.3 Medium | WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit | Information Disclosure WordPress WooCommerce Coupon Popup, SmartBar, Slide In | MyShopKit Plugin <= 1.0.9 is vulnerable to Sensitive Data Exposure No login needed |
≤ 1.0.9 |
CVE-2024-1436 |
Patchstack | |
| 7.2 High | Icons Font Loader | Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2024-24714 |
Patchstack | |
| 9.9 Critical | WP Media folder | Arbitrary File Upload WordPress WP Media folder Plugin <= 5.7.2 is vulnerable to Arbitrary File Upload |
≤ 5.7.2 Fixed in 5.7.3 |
CVE-2024-25909 |
Patchstack | |
| 10.0 Critical | MoveTo | Arbitrary File Upload WordPress MoveTo Plugin <= 6.2 is vulnerable to Arbitrary File Upload No login needed |
≤ 6.2 |
CVE-2024-25913 |
Patchstack | |
| 10.0 Critical | WooCommerce Easy Checkout Field Editor, Fees & Discounts | Arbitrary File Upload WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload No login needed |
≤ 3.5.12 Fixed in 3.5.13 |
CVE-2024-25925 |
Patchstack | |
| 4.3 Medium | Brizy – Page Builder | Path Traversal Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal |
≤ 2.4.40 |
CVE-2024-1165 |
Wordfence | |
| 8.8 High | Addon Library | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload |
≤ 1.3.76 |
CVE-2024-1710 |
Wordfence | |
| 5.4 Medium | SuperFaktura WooCommerce | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.40.3 |
CVE-2024-1758 |
Wordfence | |
| 2.2 Low | BackWPup | Other Plaintext Storage of Backup Destination Password |
≤ 4.0.2 |
CVE-2023-5775 |
Wordfence | |
| 6.1 Medium | Archivist – Custom Archive Templates | Cross-Site Scripting Custom Archive Templates <= 1.7.5 - Reflected Cross-Site Scripting No login needed |
≤ 1.7.5 |
CVE-2024-1810 |
Wordfence | |
| 7.1 High | Sitepact | SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed |
≤ 1.0.5 Fixed in 3.0.0 |
CVE-2024-25928 |
Patchstack | |
| 4.9 Medium | Pexels: Free Stock Photos | Server-Side Request Forgery WordPress Pexels: Free Stock Photos Plugin <= 1.2.2 is vulnerable to Server Side Request Forgery (SSRF) |
≤ 1.2.2 |
CVE-2024-25915 |
Patchstack | |
| 6.8 Medium | All In One Favicon | Arbitrary File Deletion WordPress All In One Favicon Plugin <= 4.7 is vulnerable to Arbitrary File Deletion |
≤ 4.7 Fixed in 4.8 |
CVE-2023-24416 |
Patchstack | |
| 4.3 Medium | Colibri Page Builder | Cross-Site Request Forgery Cross-Site Request Fogery via cp_shortcode_refresh No login needed |
≤ 1.0.253 |
CVE-2024-1362 |
Wordfence | |
| 4.3 Medium | Colibri WP | Cross-Site Request Forgery Cross-Site Request Forgery to Limited Plugin Installation No login needed |
≤ 1.0.94 |
CVE-2024-1360 |
Wordfence | |
| 4.3 Medium | Colibri Page Builder | Cross-Site Request Forgery Cross-Site Request Fogery via extend_builder No login needed |
≤ 1.0.253 |
CVE-2024-1361 |
Wordfence | |
| 4.6 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button |
≤ 1.8.2 |
CVE-2024-1590 |
Wordfence | |
| 6.1 Medium | Socialdriver | Cross-Site Scripting Prototype Pollution to XSS No login needed |
< 2024 Fixed in 2024 |
CVE-2023-4826 |
WPScan | |
| 4.3 Medium | Admin side data storage for Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated Bookmark Status Alteration No login needed |
≤ 1.1.1 |
CVE-2024-1778 |
Wordfence | |
| 4.3 Medium | Admin side data storage for Contact Form 7 | Cross-Site Request Forgery No login needed |
≤ 1.1.1 |
CVE-2024-1777 |
Wordfence | |
| 5.3 Medium | Admin side data storage for Contact Form 7 | Broken Access Control Missing Authorization to Unauthenticated Read Status Update No login needed |
≤ 1.1.1 |
CVE-2024-1779 |
Wordfence | |
| 7.2 High | Admin side data storage for Contact Form 7 | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.1.1 |
CVE-2024-1776 |
Wordfence | |
| 4.3 Medium | Event Tickets and Registration | Broken Access Control Missing Authorization |
≤ 5.8.1 |
CVE-2024-1053 |
Wordfence | |
| 5.4 Medium | User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds | Cross-Site Scripting Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.0.13 |
CVE-2024-0903 |
Wordfence | |
| 4.3 Medium | Debug | Cross-Site Request Forgery WordPress Debug Plugin <= 1.10 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.10 |
CVE-2024-24798 |
Patchstack | |
| 4.3 Medium | JTRT Responsive Tables | Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 4.1.9 |
CVE-2024-24802 |
Patchstack | |
| 4.3 Medium | FG PrestaShop to WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery (CSRF) vulnerability in FG PrestaShop, FG Drupal and FG Joomla WordPress plugins No login needed |
≤ 4.44.3, ≤ 3.67.0, ≤ 4.15.0 Fixed in 4.45.0 |
CVE-2024-24837 |
Patchstack | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 4.3 Medium | Quicksand Post Filter jQuery | Cross-Site Request Forgery WordPress Quicksand Post Filter jQuery Plugin Plugin <= 3.1.1 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 3.1.1 |
CVE-2024-24849 |
Patchstack | |
| 4.3 Medium | Themify Builder | Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.0.5 Fixed in 7.0.6 |
CVE-2024-24872 |
Patchstack | |
| 4.3 Medium | Admin Menu Editor | Cross-Site Request Forgery WordPress Admin Menu Editor Plugin <= 1.12 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.12 Fixed in 1.12.1 |
CVE-2024-24876 |
Patchstack | |
| 4.3 Medium | TinyMCE and TinyMCE Advanced Professsional Formats and Styles | Cross-Site Request Forgery WordPress TinyMCE Professional Formats and Styles Plugin <= 1.1.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.1.2 |
CVE-2024-25904 |
Patchstack | |
| 6.4 Medium | 3D FlipBook – PDF Flipbook | Cross-Site Scripting PDF Flipbook WordPress <= 1.15.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks |
≤ 1.15.3 |
CVE-2024-1081 |
Wordfence | |
| 5.3 Medium | Simple Job Board | Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed |
≤ 2.10.8 |
CVE-2024-0593 |
Wordfence | |
| 5.4 Medium | Multi Step Form | Cross-Site Request Forgery WordPress Multi Step Form Plugin <= 1.7.18 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.7.18 |
CVE-2024-25905 |
Patchstack | |
| 5.3 Medium | WooCommerce Google Sheet Connector | Broken Access Control Missing Authorization No login needed |
≤ 1.3.11 |
CVE-2024-1562 |
Wordfence | |
| 4.7 Medium | Database Reset | Cross-Site Request Forgery Cross-Site Request Forgery to WP Reset Plugin Installation No login needed |
≤ 3.22 |
CVE-2024-1501 |
Wordfence | |
| 6.5 Medium | Plugin Groups | Broken Access Control Missing Authorization to Unauthenticated Denial of Service No login needed |
≤ 2.0.6 |
CVE-2024-1108 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.58.3 |
CVE-2024-1058 |
Wordfence | |
| 5.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery |
≤ 5.9.8 |
CVE-2024-1171 |
Wordfence | |
| 6.5 Medium | AMP for WP | Broken Access Control Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data |
≤ 1.0.93.1 |
CVE-2024-1043 |
Wordfence | |
| 5.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion |
≤ 5.9.8 |
CVE-2024-1172 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Broken Access Control Missing Authorization to Settings Update in stopOptimizeAll |
≤ 3.1.13 |
CVE-2024-1090 |
Wordfence | |
| 4.3 Medium | Contact Form builder with drag & drop for WordPress – Kali Forms | Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization |
≤ 2.3.41 |
CVE-2024-1218 |
Wordfence | |
| 4.3 Medium | Tutor LMS | Broken Access Control Missing Authorization |
≤ 2.6.0 |
CVE-2024-1133 |
Wordfence | |
| 5.3 Medium | Sunshine Photo Cart: Free Client Galleries for Photographers | Information Disclosure Unauthenticated Sensitive Information Exposure via Invoice No login needed |
≤ 3.0.24 |
CVE-2024-1294 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.10.1 |
CVE-2024-0838 |
Wordfence | |
| 4.4 Medium | Best WordPress Gallery Plugin – FooGallery | Cross-Site Scripting FooGallery <= 2.4.7 -Authenticated(Administrator+) Stored Cross-Site Scripting via settings |
≤ 2.4.7 |
CVE-2024-0604 |
Wordfence | |
| 5.3 Medium | Royal Elementor Addons and Templates | Broken Access Control Missing Authorization via wpr_update_form_action_meta No login needed |
≤ 1.3.87 |
CVE-2024-0516 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.