WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 28,451–28,500 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.10.1 |
CVE-2024-0438 |
Wordfence | |
| 4.3 Medium | Custom Twitter Feeds – A Tweets Widget or X Feed Widget | Cross-Site Request Forgery A Tweets Widget or X Feed Widget <= 2.2.1 - Cross-Site Request Forgery to Plugin Options Update No login needed |
≤ 2.2.1 |
CVE-2024-0379 |
Wordfence | |
| 5.4 Medium | Tutor LMS | Content Injection Authenticated(Student+) HTML Injection via Q&A |
≤ 2.6.0 |
CVE-2024-1128 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.87 |
CVE-2024-0442 |
Wordfence | |
| 6.4 Medium | Sassy Social Share | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.3.56 |
CVE-2024-1448 |
Wordfence | |
| 6.5 Medium | RSS Aggregator by Feedzy | Broken Access Control Missing Authorization to Arbitrary Page Creation and Publication |
≤ 4.4.2 |
CVE-2024-1318 |
Wordfence | |
| 6.4 Medium | Starbox | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings |
≤ 3.4.8 |
CVE-2023-6806 |
Wordfence | |
| 6.4 Medium | Sydney Toolbox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.25 |
CVE-2024-1447 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Broken Access Control Missing Authorization to Settings Update in enableOptimization |
≤ 3.1.13 |
CVE-2024-0983 |
Wordfence | |
| 4.3 Medium | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | Broken Access Control Effortless Memberships, Recurring Payments & Content Restriction <= 2.11.1 - Missing Authorization via creating_pricing_table_page |
≤ 2.11.1 |
CVE-2024-1390 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.10.18 |
CVE-2024-1242 |
Wordfence | |
| 4.4 Medium | Yet Another Related Posts Plugin (YARPP) | Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via settings |
≤ 5.30.9 |
CVE-2024-0602 |
Wordfence | |
| 4.3 Medium | ImageRecycle pdf & image compression | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update in enableOptimization No login needed |
≤ 3.1.13 |
CVE-2024-1334 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode |
≤ 7.0.1 |
CVE-2024-0792 |
Wordfence | |
| 5.3 Medium | Passster – Password Protect Pages and Content | Broken Access Control Password Protect Pages and Content <= 4.2.6.2 - Missing Authorization to Sensitive Information Exposure No login needed |
≤ 4.2.6.2 |
CVE-2024-0616 |
Wordfence | |
| 6.5 Medium | Link Library | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 7.6 |
CVE-2024-1559 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode |
≤ 7.0.2 |
CVE-2024-1510 |
Wordfence | |
| 9.8 Critical | Piraeus Bank WooCommerce Payment Gateway | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 1.6.5.1 |
CVE-2024-0610 |
Wordfence | |
| 9.8 Critical | MasterStudy LMS WordPress Plugin – for Online Courses and Education | SQL Injection for Online Courses and Education <= 3.2.5 - Unauthenticated SQL Injection No login needed |
≤ 3.2.5 |
CVE-2024-1512 |
Wordfence | |
| 5.3 Medium | Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages | Information Disclosure Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.2 - Unauthenticated Information Exposure No login needed |
≤ 1.7.2 |
CVE-2024-0708 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Raw Content |
≤ 4.8.0 |
CVE-2024-1159 |
Wordfence | |
| 5.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Link |
≤ 4.8.0 |
CVE-2024-1160 |
Wordfence | |
| 5.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL |
≤ 4.8.0 |
CVE-2024-1157 |
Wordfence | |
| 4.3 Medium | SMTP Mail | Cross-Site Request Forgery WordPress SMTP Mail Plugin <= 1.3.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.3.20 |
CVE-2024-25914 |
Patchstack | |
| 5.4 Medium | Chart.js | Cross-Site Scripting Editor+ Stored Cross-Site Scripting in New Chart |
2023.2 – 2023.2 |
CVE-2023-6081 |
WPScan | |
| 7.5 High | popup-builder | Server-Side Request Forgery Admin+ SSRF & File Read No login needed |
< 4.2.6 Fixed in 4.2.6 |
CVE-2023-6294 |
WPScan | |
| 4.8 Medium | Popup Box Pro | Cross-Site Scripting Admin+ Stored XSS |
20.8.7 – < 20.9.0 Fixed in 20.9.0 |
CVE-2023-6591 |
WPScan | |
| 5.4 Medium | Chart.js | Cross-Site Scripting Editor+ Stored Cross-Site Scripting |
2023.2 – 2023.2 |
CVE-2023-6082 |
WPScan | |
| 9.8 Critical | Web3 – Crypto wallet Login & NFT token gating | Authentication Bypass Crypto wallet Login & NFT token gating < 3.0.0 - Authentication Bypass No login needed |
< 3.0.0 Fixed in 3.0.0 |
CVE-2023-6036 |
WPScan | |
| 7.2 High | Smart Manager | SQL Injection Admin+ SQL Injection |
< 8.28.0 Fixed in 8.28.0 |
CVE-2024-0566 |
WPScan | |
| 4.3 Medium | EazyDocs | Broken Access Control Subscriber+ Arbitrary Posts Deletion and Document Management |
2.3.8 – < 2.4.0 Fixed in 2.4.0 |
CVE-2024-0248 |
WPScan | |
| 5.4 Medium | lasTunes | Cross-Site Request Forgery Settings Update via CSRF |
≤ 3.6.1 |
CVE-2023-6499 |
WPScan | |
| 6.1 Medium | MapPress Maps | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 2.88.15 Fixed in 2.88.15 |
CVE-2024-0420 |
WPScan | |
| 6.1 Medium | Analytics Insights for Google Analytics 4 | Open Redirect No login needed |
< 6.3 Fixed in 6.3 |
CVE-2024-0250 |
WPScan | |
| 4.8 Medium | GigPress | Cross-Site Scripting Admin+ Stored Cross Site Scripting |
≤ 2.3.29 |
CVE-2023-7233 |
WPScan | |
| 5.3 Medium | MapPress Maps | Information Disclosure Unauthenticated Arbitrary Private/Draft Post Disclosure No login needed |
< 2.88.16 Fixed in 2.88.16 |
CVE-2024-0421 |
WPScan | |
| 4.3 Medium | Splashscreen | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.20 |
CVE-2023-6501 |
WPScan | |
| 4.3 Medium | Link Library | Cross-Site Request Forgery WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 7.5.13 Fixed in 7.6 |
CVE-2024-24875 |
Patchstack | |
| 4.3 Medium | Contact Form 7 Connector | Cross-Site Request Forgery WordPress Contact Form 7 Connector Plugin <= 1.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2024-24884 |
Patchstack | |
| 5.4 Medium | Photos and Files Contest Gallery – Contact Form, Upload Form, Social Share and Voting | Cross-Site Request Forgery WordPress Contest Gallery Plugin <= 21.2.8.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 21.2.8.4 Fixed in 21.2.9 |
CVE-2024-24887 |
Patchstack | |
| 4.3 Medium | WP Contact Form | Cross-Site Request Forgery WordPress WP Contact Form Plugin <= 1.6 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.6 |
CVE-2024-24929 |
Patchstack | |
| 4.3 Medium | Basic Log Viewer | Cross-Site Request Forgery WordPress Basic Log Viewer Plugin <= 1.0.4 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
≤ 1.0.4 |
CVE-2024-24935 |
Patchstack | |
| 5.4 Medium | KD Coming Soon | PHP Object Injection WordPress KD Coming Soon Plugin <= 1.7 is vulnerable to PHP Object Injection No login needed |
≤ 1.7 |
CVE-2023-46615 |
Patchstack | |
| 8.7 High | ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2024-23512 |
Patchstack | |
| 8.7 High | PropertyHive | PHP Object Injection WordPress PropertyHive Plugin <= 2.0.5 is vulnerable to PHP Object Injection No login needed |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2024-23513 |
Patchstack | |
| 8.2 High | Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – | PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection |
≤ 4.1.1 Fixed in 4.1.2 |
CVE-2024-24796 |
Patchstack | |
| 9.8 Critical | ERE Recently Viewed – Essential Real Estate Add-On | PHP Object Injection WordPress ERE Recently Viewed Plugin <= 1.3 is vulnerable to PHP Object Injection No login needed |
≤ 1.3 |
CVE-2024-24797 |
Patchstack | |
| 7.5 High | Brooklyn | Creative Multi-Purpose Responsive | PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection |
≤ 4.9.7.6 |
CVE-2024-24926 |
Patchstack | |
| 10.0 Critical | Coupon Referral Program | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
< 1.8.4 Fixed in 1.8.4 |
CVE-2024-25100 |
Patchstack | |
| 5.9 Medium | Chartify – WordPress Chart | Cross-Site Scripting WordPress Chartify Plugin <= 2.0.6 is vulnerable to Cross Site Scripting (XSS) |
≤ 2.0.6 Fixed in 2.0.7 |
CVE-2023-47526 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.