WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 29,601–29,650 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 593 of 594
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Database Cleaner: Clean, Optimize & Repair Plugin database-cleaner Information Disclosure WordPress Database Cleaner Plugin <= 0.9.8 is vulnerable to Sensitive Data Exposure No login needed ≤ 0.9.8 Fixed in 0.9.9 CVE-2023-51508 Patchstack
7.6 High pTypeConverter Plugin ptypeconverter SQL Injection WordPress pTypeConverter Plugin <= 0.2.8.1 is vulnerable to SQL Injection ≤ 0.2.8.1 CVE-2023-52201 Patchstack
5.9 Medium cformsII Plugin cforms2 Cross-Site Scripting WordPress CformsII Plugin <= 15.0.5 is vulnerable to Cross Site Scripting (XSS) ≤ 15.0.5 CVE-2023-52203 Patchstack
8.5 High Randomize Plugin randomize SQL Injection WordPress Randomize Plugin <= 1.4.3 is vulnerable to SQL Injection ≤ 1.4.3 CVE-2023-52204 Patchstack
7.7 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection WordPress Page Builder: Live Composer Plugin <= 1.5.25 is vulnerable to PHP Object Injection ≤ 1.5.25 CVE-2023-52206 Patchstack
7.1 High Rate Star Review – AJAX Reviews for Content, with Star Ratings Plugin rate-star-review Cross-Site Scripting WordPress Rate Star Review Plugin <= 1.5.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52213 Patchstack
4.3 Medium JS & CSS Script Optimizer Plugin js-css-script-optimizer Cross-Site Request Forgery WordPress JS & CSS Script Optimizer Plugin <= 0.3.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 0.3.3 CVE-2023-52216 Patchstack
9.6 Critical ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Request Forgery WordPress ARMember Plugin <= 4.0.22 is vulnerable to Cross Site Request Forgery (CSRF) leading to PHP Object Injection No login needed ≤ 4.0.22 Fixed in 4.0.23 CVE-2023-52200 Patchstack
9.1 Critical HTML5 SoundCloud Player with Playlist Free Plugin html5-soundcloud-player-with-playlist PHP Object Injection WordPress HTML5 SoundCloud Player Plugin <= 2.8.0 is vulnerable to PHP Object Injection ≤ 2.8.0 CVE-2023-52205 Patchstack
9.1 Critical HTML5 MP3 Player with Playlist Free Plugin html5-mp3-player-with-playlist PHP Object Injection WordPress HTML5 MP3 Player with Playlist Free Plugin <= 3.0.0 is vulnerable to PHP Object Injection ≤ 3.0.0 CVE-2023-52207 Patchstack
8.8 High WP Blogs' Planetarium Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0 CVE-2023-6532 WPScan
7.5 High Coupon Referral Program Plugin Information Disclosure WordPress Coupon Referral Program Plugin <= 1.7.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2023-52190 Patchstack
8.8 High CommentTweets Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.6 CVE-2023-6845 WPScan
7.5 High Prime Mover Plugin prime-mover Information Disclosure Directory Listing to Sensitive Data Exposure No login needed < 1.9.3 Fixed in 1.9.3 CVE-2023-6505 WPScan
7.5 High Clone Plugin wp-clone-by-wp-academy Information Disclosure Unauthenticated Backup Download No login needed < 2.4.3 Fixed in 2.4.3 CVE-2023-6750 WPScan
4.8 Medium WP Custom Cursors Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 3.2 CVE-2023-5911 WPScan
8.8 High Essential Real Estate Plugin essential-real-estate Arbitrary File Upload Subscriber+ Arbitrary File Upload < 4.4.0 Fixed in 4.4.0 CVE-2023-6140 WPScan
8.8 High Ovic Responsive WPBakery Plugin PHP Object Injection Subscriber+ Option Update < 1.2.9 Fixed in 1.2.9 CVE-2023-5235 WPScan
5.4 Medium Essential Real Estate Plugin essential-real-estate Cross-Site Scripting Subscriber+ Stored XSS < 4.4.0 Fixed in 4.4.0 CVE-2023-6141 WPScan
8.8 High Slider Revolution Plugin PHP Object Injection Author+ Insecure Deserialization leading to RCE < 6.6.19 Fixed in 6.6.19 CVE-2023-6528 WPScan
7.5 High Debug Log Manager Plugin debug-log-manager Information Disclosure Sensitive Logs Exposure No login needed < 2.3.0 Fixed in 2.3.0 CVE-2023-6383 WPScan
9.8 Critical Duplicator Plugin duplicator Remote Code Execution Unauthenticated RCE No login needed < 1.3.0 Fixed in 1.3.0 CVE-2018-25095 WPScan
7.2 High Ni Purchase Order(PO) For WooCommerce Plugin ni-purchase-orderpo-for-woocommerce Arbitrary File Upload Admin+ File Upload to Remote Code Execution ≤ 1.2.1 CVE-2023-5957 WPScan
6.5 Medium Essential Real Estate Plugin essential-real-estate Denial of Service Subscriber+ Denial of Service via Arbitrary Option Update < 4.4.0 Fixed in 4.4.0 CVE-2023-6139 WPScan
6.1 Medium WP Go Maps Plugin wp-google-maps Cross-Site Scripting Unauthenticated Stored XSS No login needed < 9.0.28 Fixed in 9.0.28 CVE-2023-6627 WPScan
6.1 Medium Email Subscription Popup Plugin Cross-Site Scripting Reflected XSS No login needed < 1.2.20 Fixed in 1.2.20 CVE-2023-6555 WPScan
6.1 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Reflected XSS No login needed < 2.1.9 Fixed in 2.1.9 CVE-2023-6161 WPScan
6.1 Medium WP VR Plugin Cross-Site Scripting Unauthenticated Plugin Downgrade leading to XSS No login needed < 8.3.15 Fixed in 8.3.15 CVE-2023-6529 WPScan
5.3 Medium Constant Contact Forms Plugin constant-contact-forms Information Disclosure WordPress Constant Contact Forms Plugin <= 2.4.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.4.2 CVE-2023-52208 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery WordPress WooCommerce Plugin <= 8.2.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 8.2.2 Fixed in 8.3.0 CVE-2023-52222 Patchstack
9.3 Critical Simple Inventory Management – just scan barcode to manage products and orders. For WooCommerce Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection WordPress Barcode Scanner with Inventory & Order Manager Plugin <=1.5.1 is vulnerable to SQL Injection No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-52215 Patchstack
10.0 Critical Woocommerce Tranzila Payment Gateway Plugin woo-tranzila-gateway PHP Object Injection WordPress WooCommerce Tranzila Gateway Plugin <= 1.0.8 is vulnerable to PHP Object Injection No login needed ≤ 1.0.8 CVE-2023-52218 Patchstack
9.9 Critical Gecka Terms Thumbnails Plugin gecka-terms-thumbnails PHP Object Injection WordPress Gecka Terms Thumbnails Plugin <= 1.1 is vulnerable to PHP Object Injection ≤ 1.1 CVE-2023-52219 Patchstack
10.0 Critical Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics Plugin taggbox-widget PHP Object Injection WordPress Taggbox Plugin <= 3.1 is vulnerable to PHP Object Injection No login needed ≤ 3.1 CVE-2023-52225 Patchstack
6.5 Medium Mapster WP Maps Plugin mapster-wp-maps Cross-Site Scripting WordPress Mapster WP Maps Plugin <= 1.2.38 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.38 CVE-2024-21744 Patchstack
6.5 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Cross-Site Scripting WordPress Laybuy Payment Extension for WooCommerce Plugin <= 5.3.9 is vulnerable to Cross Site Scripting (XSS) ≤ 5.3.9 CVE-2024-21745 Patchstack
7.6 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp SQL Injection WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection ≤ 1.12.8 Fixed in 1.12.9 CVE-2024-21747 Patchstack
5.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Missing Authorization ≤ 4.3.2 CVE-2023-6798 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 4.3.2 CVE-2023-6801 Wordfence
6.5 Medium WP Tabs – Responsive Tabs Plugin wp-expand-tabs-free Cross-Site Scripting WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-52124 Patchstack
6.5 Medium iframe Plugin iframe Cross-Site Scripting WordPress iFrame Plugin <= 4.8 is vulnerable to Cross Site Scripting (XSS) ≤ 4.8 Fixed in 4.9 CVE-2023-52125 Patchstack
5.3 Medium Send Users Email Plugin send-users-email Information Disclosure WordPress Send Users Email Plugin <= 1.4.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2023-52126 Patchstack
7.5 High WP Stripe Checkout Plugin wp-stripe-checkout Information Disclosure WordPress WP Stripe Checkout Plugin <= 1.2.2.37 is vulnerable to Sensitive Data Exposure No login needed ≤ 1.2.2.37 Fixed in 1.2.2.38 CVE-2023-52143 Patchstack
5.3 Medium 404 Solution Plugin 404-solution Information Disclosure WordPress 404 Solution Plugin <= 2.33.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.33.0 Fixed in 2.33.1 CVE-2023-52146 Patchstack
5.3 Medium Affiliates Manager Plugin affiliates-manager Information Disclosure WordPress Affiliates Manager Plugin <= 2.9.30 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.9.30 Fixed in 2.9.31 CVE-2023-52148 Patchstack
5.3 Medium Uncanny Automator – Automate everything with the #1 no-code automation and integration Plugin uncanny-automator Information Disclosure WordPress Uncanny Automator Plugin <= 5.1.0.2 is vulnerable to Sensitive Data Exposure No login needed ≤ 5.1.0.2 Fixed in 5.1.0.3 CVE-2023-52151 Patchstack
10.0 Critical JS Help Desk – Best Help Desk & Support Plugin js-support-ticket Arbitrary File Upload Best Help Desk & Support Plugin Plugin <= 2.7.1 is vulnerable to Arbitrary File Upload No login needed ≤ 2.7.1 Fixed in 2.7.2 CVE-2022-46839 Patchstack
4.3 Medium Doofinder WP & WooCommerce Search Plugin doofinder-for-woocommerce Broken Access Control WordPress Doofinder for WooCommerce Plugin <= 2.0.33 is vulnerable to Broken Access Control ≤ 2.0.33 Fixed in 2.1.1 CVE-2023-51678 Patchstack
4.3 Medium Spam protection, Anti-Spam, FireWall by CleanTalk Plugin cleantalk-spam-protect Cross-Site Request Forgery WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.20 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 6.20 Fixed in 6.21 CVE-2023-51535 Patchstack
5.4 Medium Stylish Price List – Price Table Builder & QR Code Restaurant Menu Plugin stylish-price-list Broken Access Control WordPress Stylish Price List Plugin <= 7.0.17 is vulnerable to Broken Access Control ≤ 7.0.17 Fixed in 7.0.18 CVE-2023-51673 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only