WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 251–292 of 292 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.9.80 CVE-2024-13519 Wordfence
4.3 Medium Salvador – AI Image Generator Plugin salvador-ai-image-generator Broken Access Control AI Image Generator plugin <= 1.0.11 - Broken Access Control ≤ 1.0.11 CVE-2025-23954 Patchstack
5.3 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.0.00 CVE-2024-12413 Wordfence
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 20.8.0 Fixed in 20.8.1 CVE-2024-53819 Patchstack
5.2 Medium JobBoardWP – Job Board Listings and Submissions Plugin jobboardwp Broken Access Control Job Board Listings and Submissions plugin <= 1.2.2 - IDOR Leading To Job Removal ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-23715 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack
5.3 Medium WPCasa Plugin wpcasa Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.13 Fixed in 1.3.0 CVE-2024-53826 Patchstack
4.3 Medium My Contador lesr Plugin my-contador-wp Broken Access Control Missing Authorization to Unauthenticated User Registration CSV Export ≤ 2.0 CVE-2024-11334 Wordfence
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
4.3 Medium Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 10.9 Fixed in 10.9.1 CVE-2024-47316 Patchstack
4.3 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.102 Fixed in 3.3.103 CVE-2024-43916 Patchstack
4.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 1.11.4 Fixed in 1.11.5 CVE-2024-43239 Patchstack
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-43266 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43288 Patchstack
5.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.100 Fixed in 3.3.101 CVE-2024-43322 Patchstack
5.3 Medium Propovoice CRM Plugin propovoice Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.6.4 CVE-2024-43350 Patchstack
6.5 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39642 Patchstack
5.3 Medium TrustedLogin Vendor Plugin Information Disclosure Sensitive Data Exposure No login needed < 1.1.1 Fixed in 1.1.1 CVE-2024-37270 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-52186 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2024-25929 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2023-51494 Patchstack
5.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.6.6 Fixed in 3.6.7 CVE-2024-35659 Patchstack
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
6.5 Medium SP Project & Document Manager Plugin Broken Access Control Subscriber+ File Download via IDOR ≤ 4.71 CVE-2024-3749 WPScan
6.5 Medium SP Project & Document Manager Plugin Broken Access Control Data Update via IDOR No login needed ≤ 4.71 CVE-2024-3748 WPScan
4.3 Medium Crelly Slider Plugin crelly-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-33542 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32772 Patchstack
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32808 Patchstack
5.3 Medium Rate my Post – WP Rating System Plugin rate-my-post Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-32823 Patchstack
5.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Ticket leakage through IDOR No login needed < 3.5.2.5 Fixed in 3.5.2.5 CVE-2023-7252 WPScan
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32683 Patchstack
4.3 Medium WP-Recall Plugin wp-recall Broken Access Control Insecure Direct Object References (IDOR) ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32604 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control IDOR on Friend Request ≤ 5.7.6 Fixed in 5.7.7 CVE-2024-31291 Patchstack
4.3 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0.81 Fixed in 1.0.82 CVE-2024-31296 Patchstack
6.5 Medium Whizzy Plugin whizzy Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.1.18 CVE-2024-30543 Patchstack
5.3 Medium Thumbs Rating Plugin thumbs-rating Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 5.1.0 CVE-2024-31095 Patchstack
6.5 Medium WC Marketplace Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-30433 Patchstack
6.5 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.7.2 Fixed in 5.7.3 CVE-2024-30513 Patchstack
4.3 Medium WP User Profile Avatar Plugin Broken Access Control Author+ Avatar Deletion/Update via IDOR < 1.0.1 Fixed in 1.0.1 CVE-2023-6384 WPScan
5.4 Medium Dokan Plugin Cross-Site Scripting Vendor Stored Cross-Site Scripting < 3.6.4 Fixed in 3.6.4 CVE-2022-3194 WPScan
6.4 Medium WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.6.2 CVE-2023-4960 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only