WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 28,851–28,900 of 29,007 vulnerabilities

Known WordPress vulnerabilities, page 578 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via featured image alt text ≤ 4.5.3 CVE-2023-6561 Wordfence
6.5 Medium GTG Product Feed for Shopping Plugin gg-woo-feed Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed ≤ 1.2.4 CVE-2023-6638 Wordfence
4.7 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.1.4 CVE-2023-6737 Wordfence
3.1 Low My Sticky Bar Plugin mystickymenu Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed ≤ 2.6.6 CVE-2023-7048 Wordfence
6.4 Medium AMP for WP – Accelerated Mobile Pages Plugin accelerated-mobile-pages Cross-Site Scripting Accelerated Mobile Pages <= 1.0.92 - Authenticated (Contributor+) Cross-Site Scripting via Shortcode ≤ 1.0.92 CVE-2023-6782 Wordfence
5.4 Medium Weaver Xtreme Theme weaver-xtreme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.0 CVE-2023-6990 Wordfence
4.3 Medium LightStart – Maintenance Mode, Coming Soon and Landing Page Builder Plugin wp-maintenance-mode Broken Access Control Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorization ≤ 2.6.8 CVE-2023-7019 Wordfence
9.8 Critical MW WP Form Plugin mw-wp-form Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 5.0.1 CVE-2023-6316 Wordfence
8.1 High Piotnet Forms Plugin piotnetforms Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.0.28 CVE-2023-6220 Wordfence
6.6 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Path Traversal Authenticated(Administrator+) Directory Traversal via Recurring Import Functionality ≤ 1.24.2 CVE-2023-6583 Wordfence
6.4 Medium Post Grid Combo – 36+ Gutenberg Blocks Plugin Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 2.2.64 CVE-2023-6645 Wordfence
6.4 Medium Limit Login Attempts Reloaded Plugin limit-login-attempts-reloaded Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.25.26 CVE-2023-6934 Wordfence
5.4 Medium FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.1.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.4.1.6 CVE-2023-6556 Wordfence
7.2 High Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload ≤ 7.6.2 CVE-2023-6636 Wordfence
8.8 High Slick Social Share Buttons Plugin slick-social-share-buttons Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 2.4.11 CVE-2023-6878 Wordfence
7.2 High ARForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url No login needed ≤ 1.5.8 CVE-2023-6828 Wordfence
9.8 Critical LearnPress Plugin learnpress SQL Injection Unauthenticated SQL Injection via order_by No login needed ≤ 4.2.5.7 CVE-2023-6567 Wordfence
6.4 Medium List category posts Plugin list-category-posts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.89.3 CVE-2023-6994 Wordfence
6.4 Medium Video PopUp Plugin video-popup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.3 CVE-2023-4962 Wordfence
6.5 Medium CAOS | Host Google Analytics Locally Plugin host-analyticsjs-local Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed ≤ 4.7.14 CVE-2023-6637 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload ≤ 2.4.8 CVE-2023-6558 Wordfence
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 5.38.9 CVE-2023-6979 Wordfence
6.4 Medium 3D Flipbook Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Ready Function ≤ 1.15.2 CVE-2023-6776 Wordfence
4.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode ≤ 1.24.3 CVE-2023-6624 Wordfence
5.4 Medium Export WP Page to Static HTML/CSS Plugin export-wp-page-to-static-html Broken Access Control Missing Authorization via Multiple AJAX Actions ≤ 2.1.9 CVE-2023-6369 Wordfence
4.3 Medium Envira Gallery Lite Plugin envira-gallery-lite Broken Access Control Missing Authorization to Gallery Modification via envira_gallery_insert_images ≤ 1.8.7.2 CVE-2023-6742 Wordfence
6.1 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Reflected Cross-Site Scripting Vulnerability via environment_mode No login needed ≤ 4.3.8 CVE-2023-6882 Wordfence
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Missing Authorization via API No login needed ≤ 2.12.5 CVE-2023-6855 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.239 CVE-2023-6988 Wordfence
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Integration Deletion No login needed ≤ 2.33.3 CVE-2023-4248 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Widget ≤ 1.8.18 CVE-2023-6924 Wordfence
6.4 Medium Orbit Fox Companion Plugin themeisle-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields ≤ 2.10.26 CVE-2023-6781 Wordfence
6.4 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.6 CVE-2023-4372 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.2 CVE-2023-6684 Wordfence
8.1 High LearnPress Plugin learnpress Remote Code Execution Command Injection No login needed ≤ 4.2.5.7 CVE-2023-6634 Wordfence
6.1 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.9.1.1, ≤ 3.9.1.1 CVE-2023-6632 Wordfence
7.5 High Backup Migration Plugin backup-backup Information Disclosure Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure No login needed ≤ 1.3.6 CVE-2023-6266 Wordfence
5.3 Medium Manage Notification E-mails Plugin manage-notification-emails Broken Access Control Missing Authorization No login needed ≤ 1.8.5 CVE-2023-6496 Wordfence
9.1 Critical WP Compress – Image Optimizer [All-In-One] Plugin Path Traversal Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css No login needed ≤ 6.10.33 CVE-2023-6699 Wordfence
4.3 Medium WP 2FA Plugin wp-2fa Broken Access Control Insecure Direct Object Reference to Arbitrary Email Sending ≤ 2.5.0 CVE-2023-6506 Wordfence
4.4 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.2.40 CVE-2023-6446 Wordfence
4.3 Medium Easy Social Feed Plugin easy-facebook-likebox Broken Access Control Missing Authorization to Settings Modification ≤ 6.5.2 CVE-2023-6883 Wordfence
4.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object Reference to Information Disclosure ≤ 4.2.5.7 CVE-2023-6223 Wordfence
4.3 Medium WP 2FA – Two-factor authentication Plugin wp-2fa Cross-Site Request Forgery Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2023-6520 Wordfence
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin Broken Access Control Dynamic Text Extension <= 4.1.0 - Insecure Direct Object Reference ≤ 4.1.0 CVE-2023-6630 Wordfence
8.8 High WP Register Profile With Shortcode Plugin wp-register-profile-with-shortcode Cross-Site Request Forgery Cross-Site Request Forgery to User Password Reset No login needed ≤ 3.5.9 CVE-2023-5448 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Broken Access Control WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6158 Wordfence
4.4 Medium Formidable Forms Plugin formidable Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 6.7 CVE-2023-6842 Wordfence
6.5 Medium Formidable Forms Plugin formidable Content Injection HTML Injection No login needed ≤ 6.7 CVE-2023-6830 Wordfence
5.4 Medium Metform Elementor Contact Form Builder Plugin metform Cross-Site Request Forgery No login needed ≤ 3.8.1 CVE-2023-6788 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only