WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 29,551–29,600 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 592 of 594
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload ≤ 7.6.2 CVE-2023-6636 Wordfence
8.8 High Slick Social Share Buttons Plugin slick-social-share-buttons Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 2.4.11 CVE-2023-6878 Wordfence
7.2 High ARForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via arf_http_referrer_url No login needed ≤ 1.5.8 CVE-2023-6828 Wordfence
9.8 Critical LearnPress Plugin learnpress SQL Injection Unauthenticated SQL Injection via order_by No login needed ≤ 4.2.5.7 CVE-2023-6567 Wordfence
6.4 Medium List category posts Plugin list-category-posts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.89.3 CVE-2023-6994 Wordfence
6.4 Medium Video PopUp Plugin video-popup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.3 CVE-2023-4962 Wordfence
6.5 Medium CAOS | Host Google Analytics Locally Plugin host-analyticsjs-local Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed ≤ 4.7.14 CVE-2023-6637 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Arbitrary File Upload Authenticated (Shop Manager+) Arbitrary File Upload ≤ 2.4.8 CVE-2023-6558 Wordfence
8.8 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 5.38.9 CVE-2023-6979 Wordfence
6.4 Medium 3D Flipbook Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Ready Function ≤ 1.15.2 CVE-2023-6776 Wordfence
4.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode ≤ 1.24.3 CVE-2023-6624 Wordfence
5.4 Medium Export WP Page to Static HTML/CSS Plugin export-wp-page-to-static-html Broken Access Control Missing Authorization via Multiple AJAX Actions ≤ 2.1.9 CVE-2023-6369 Wordfence
4.3 Medium Envira Gallery Lite Plugin envira-gallery-lite Broken Access Control Missing Authorization to Gallery Modification via envira_gallery_insert_images ≤ 1.8.7.2 CVE-2023-6742 Wordfence
6.1 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Reflected Cross-Site Scripting Vulnerability via environment_mode No login needed ≤ 4.3.8 CVE-2023-6882 Wordfence
5.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Missing Authorization via API No login needed ≤ 2.12.5 CVE-2023-6855 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.239 CVE-2023-6988 Wordfence
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Cross-Site Request Forgery to Stripe Integration Deletion No login needed ≤ 2.33.3 CVE-2023-4248 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Widget ≤ 1.8.18 CVE-2023-6924 Wordfence
6.4 Medium Orbit Fox Companion Plugin themeisle-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom fields ≤ 2.10.26 CVE-2023-6781 Wordfence
6.4 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.6 CVE-2023-4372 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.2 CVE-2023-6684 Wordfence
8.1 High LearnPress Plugin learnpress Remote Code Execution Command Injection No login needed ≤ 4.2.5.7 CVE-2023-6634 Wordfence
6.1 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.9.1.1, ≤ 3.9.1.1 CVE-2023-6632 Wordfence
7.5 High Backup Migration Plugin backup-backup Information Disclosure Unauthenticated Arbitrary Backup Download to Sensitive Information Exposure No login needed ≤ 1.3.6 CVE-2023-6266 Wordfence
5.3 Medium Manage Notification E-mails Plugin manage-notification-emails Broken Access Control Missing Authorization No login needed ≤ 1.8.5 CVE-2023-6496 Wordfence
9.1 Critical WP Compress – Image Optimizer [All-In-One] Plugin Path Traversal Image Optimizer [All-In-One] <= 6.10.33 - Unauthenticated Directory Traversal via css No login needed ≤ 6.10.33 CVE-2023-6699 Wordfence
4.3 Medium WP 2FA Plugin wp-2fa Broken Access Control Insecure Direct Object Reference to Arbitrary Email Sending ≤ 2.5.0 CVE-2023-6506 Wordfence
4.4 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.2.40 CVE-2023-6446 Wordfence
4.3 Medium Easy Social Feed Plugin easy-facebook-likebox Broken Access Control Missing Authorization to Settings Modification ≤ 6.5.2 CVE-2023-6883 Wordfence
4.3 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object Reference to Information Disclosure ≤ 4.2.5.7 CVE-2023-6223 Wordfence
4.3 Medium WP 2FA – Two-factor authentication Plugin wp-2fa Cross-Site Request Forgery Two-factor authentication for WordPress <= 2.5.0 - Cross-Site Request Forgery No login needed ≤ 2.5.0 CVE-2023-6520 Wordfence
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin Broken Access Control Dynamic Text Extension <= 4.1.0 - Insecure Direct Object Reference ≤ 4.1.0 CVE-2023-6630 Wordfence
8.8 High WP Register Profile With Shortcode Plugin wp-register-profile-with-shortcode Cross-Site Request Forgery Cross-Site Request Forgery to User Password Reset No login needed ≤ 3.5.9 CVE-2023-5448 Wordfence
6.5 Medium EventON - WordPress Virtual Event Calendar Plugin Pro Plugin eventon-lite Broken Access Control WordPress Virtual Event Calendar Plugin Pro <= 4.5.4 & Free <= 2.2.7 - Missing Authorization to Arbitrary Post Meta Update via evo_eventpost_update_meta No login needed ≤ 2.2.7, ≤ 4.5.4 CVE-2023-6158 Wordfence
4.4 Medium Formidable Forms Plugin formidable Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 6.7 CVE-2023-6842 Wordfence
6.5 Medium Formidable Forms Plugin formidable Content Injection HTML Injection No login needed ≤ 6.7 CVE-2023-6830 Wordfence
5.4 Medium Metform Elementor Contact Form Builder Plugin metform Cross-Site Request Forgery No login needed ≤ 3.8.1 CVE-2023-6788 Wordfence
4.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 9.7.4 CVE-2023-6594 Wordfence
3.7 Low Advanced Custom Fields (ACF) Plugin advanced-custom-fields Information Disclosure WordPress Advanced Custom Fields Plugin 3.1.1-6.0.2 is vulnerable to Sensitive Data Exposure No login needed 3.1.1 – 6.0.2 Fixed in 6.0.3 CVE-2022-40696 Patchstack
6.3 Medium ProfileGrid – User Profiles, Memberships, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control WordPress ProfileGrid Plugin <= 5.0.3 is vulnerable to Broken Access Control ≤ 5.0.3 Fixed in 5.0.4 CVE-2022-36352 Patchstack
5.4 Medium Wholesale Suite – WooCommerce Wholesale Prices, B2B, Catalog Mode, Order Form, Wholesale User Roles, Dynamic Pricing & More Plugin woocommerce-wholesale-prices Broken Access Control WordPress Wholesale Suite Plugin <= 2.1.5 is vulnerable to Broken Access Control ≤ 2.1.5 Fixed in 2.1.5.1 CVE-2022-34344 Patchstack
7.6 High Events Shortcodes For The Events Calendar Plugin template-events-calendar SQL Injection WordPress Events Shortcodes & Templates For The Events Calendar Plugin <= 2.3.1 is vulnerable to SQL Injection ≤ 2.3.1 Fixed in 2.3.2 CVE-2023-52142 Patchstack
9.1 Critical HTML5 MP3 Player with Folder Feedburner Playlist Free Plugin html5-mp3-player-with-mp3-folder-feedburner-playlist PHP Object Injection WordPress HTML5 MP3 Player with Folder Feedburner Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52202 Patchstack
5.3 Medium Download Monitor Plugin download-monitor Information Disclosure WordPress Download Monitor Plugin <= 4.7.60 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.7.60 Fixed in 4.7.70 CVE-2022-45354 Patchstack
5.3 Medium FastDup – Fastest WordPress Migration & Duplicator Plugin fastdup Information Disclosure WordPress FastDup Plugin <= 2.1.7 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.1.7 Fixed in 2.1.8 CVE-2023-51406 Patchstack
5.3 Medium WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce Plugin wp-optin-wheel Information Disclosure WordPress WP Optin Wheel Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-51408 Patchstack
7.1 High CPT Bootstrap Carousel Plugin cpt-bootstrap-carousel Cross-Site Scripting WordPress CPT Bootstrap Carousel Plugin <= 1.12 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2023-52196 Patchstack
5.9 Medium Ads Invalid Click Protection Plugin ads-invalid-click-protection Cross-Site Scripting WordPress Ads Invalid Click Protection Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 CVE-2023-52197 Patchstack
6.5 Medium Private Google Calendars Plugin private-google-calendars Cross-Site Scripting WordPress Private Google Calendars Plugin <= 20231125 is vulnerable to Cross Site Scripting (XSS) ≤ 20231125 CVE-2023-52198 Patchstack
5.3 Medium Defender Security – Malware Scanner, Login Security & Firewall Plugin defender-security Information Disclosure WordPress Defender Security Plugin <= 4.1.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.1.0 Fixed in 4.2.0 CVE-2023-51490 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only