WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 351–400 of 414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Support Genix Plugin support-genix-lite Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.11 Fixed in 1.4.12 CVE-2025-30777 Patchstack
6.5 Medium WooCommerce Multivendor Marketplace – REST API Plugin wcfm-marketplace-rest-api SQL Injection REST API <= 1.6.2 - Authenticated (Subscriber+) SQL Injection ≤ 1.6.2 CVE-2025-1311 Wordfence
5.3 Medium VidoRev Extensions Plugin Broken Access Control Missing Authorization to Unauthenticated Youtube Video Import No login needed ≤ 2.9.9.9.9.9.5 CVE-2025-0955 Wordfence
9.3 Critical Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway SQL Injection No login needed ≤ 1.7.6 CVE-2025-26535 Patchstack
3.8 Low Filebird Plugin filebird Broken Access Control Insecure Direct Object References (IDOR) ≤ 6.4.2.1 Fixed in 6.4.6 CVE-2025-26977 Patchstack
5.3 Medium Amelia Plugin ameliabooking Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-26965 Patchstack
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Local File Inclusion The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion No login needed ≤ 4.2.14 CVE-2025-0493 Wordfence
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.13 Fixed in 4.2.14 CVE-2025-24706 Patchstack
4.4 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting ≤ 1.9.80 CVE-2024-13519 Wordfence
4.3 Medium Salvador – AI Image Generator Plugin salvador-ai-image-generator Broken Access Control AI Image Generator plugin <= 1.0.11 - Broken Access Control ≤ 1.0.11 CVE-2025-23954 Patchstack
5.3 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.0.00 CVE-2024-12413 Wordfence
5.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 20.8.0 Fixed in 20.8.1 CVE-2024-53819 Patchstack
5.2 Medium JobBoardWP – Job Board Listings and Submissions Plugin jobboardwp Broken Access Control Job Board Listings and Submissions plugin <= 1.2.2 - IDOR Leading To Job Removal ≤ 1.2.2 Fixed in 1.2.3 CVE-2023-23715 Patchstack
5.4 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control ≤ 5.0.2 Fixed in 5.0.3 CVE-2023-50899 Patchstack
8.2 High MultiVendorX Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.23 Fixed in 4.0.24 CVE-2023-51355 Patchstack
5.3 Medium WPCasa Plugin wpcasa Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.2.13 Fixed in 1.3.0 CVE-2024-53826 Patchstack
4.3 Medium My Contador lesr Plugin my-contador-wp Broken Access Control Missing Authorization to Unauthenticated User Registration CSV Export ≤ 2.0 CVE-2024-11334 Wordfence
7.5 High Paid Memberships Pro Plugin paid-memberships-pro Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37277 Patchstack
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
4.3 Medium Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 10.9 Fixed in 10.9.1 CVE-2024-47316 Patchstack
7.1 High WCFM Marketplace Plugin wc-multivendor-marketplace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.11 Fixed in 3.6.12 CVE-2024-44009 Patchstack
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed ≤ 4.2.0 CVE-2024-8289 Wordfence
4.3 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.102 Fixed in 3.3.103 CVE-2024-43916 Patchstack
4.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 1.11.4 Fixed in 1.11.5 CVE-2024-43239 Patchstack
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-43266 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43288 Patchstack
7.5 High Stripe Payments For WooCommerce by Checkout Plugin checkout-plugins-stripe-woo Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2024-43315 Patchstack
5.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.100 Fixed in 3.3.101 CVE-2024-43322 Patchstack
5.3 Medium Propovoice CRM Plugin propovoice Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.6.4 CVE-2024-43350 Patchstack
6.5 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39642 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.17 CVE-2024-43213 Patchstack
7.3 High WooCommerce - PDF Vouchers Plugin Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed ≤ 4.9.3 CVE-2024-7027 Wordfence
8.8 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via vendor_id ≤ 1.13.0 CVE-2024-6666 Wordfence
5.3 Medium TrustedLogin Vendor Plugin Information Disclosure Sensitive Data Exposure No login needed < 1.1.1 Fixed in 1.1.1 CVE-2024-37270 Patchstack
9.1 Critical LatePoint Plugin Broken Access Control Missing Authorization and Sensitive Information Exposure via IDOR No login needed ≤ 4.9.9 CVE-2024-2472 Wordfence
8.6 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control No login needed ≤ 4.0.25 Fixed in 4.0.26 CVE-2024-24703 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.2.2 Fixed in 2.2.3 CVE-2023-52186 Patchstack
7.1 High WC Marketplace Plugin dc-woocommerce-multi-vendor Broken Access Control ≤ 4.1.3 Fixed in 4.1.4 CVE-2024-31304 Patchstack
6.5 Medium Product Catalog Enquiry for WooCommerce by MultiVendorX Plugin woocommerce-catalog-enquiry Broken Access Control No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2024-25929 Patchstack
5.3 Medium WooCommerce Product Vendors Plugin Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2023-51494 Patchstack
5.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.6.6 Fixed in 3.6.7 CVE-2024-35659 Patchstack
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
6.5 Medium SP Project & Document Manager Plugin Broken Access Control Subscriber+ File Download via IDOR ≤ 4.71 CVE-2024-3749 WPScan
6.5 Medium SP Project & Document Manager Plugin Broken Access Control Data Update via IDOR No login needed ≤ 4.71 CVE-2024-3748 WPScan
4.3 Medium Crelly Slider Plugin crelly-slider Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-33542 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object References (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32772 Patchstack
5.4 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-32808 Patchstack
5.3 Medium Rate my Post – WP Rating System Plugin rate-my-post Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-32823 Patchstack
5.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Ticket leakage through IDOR No login needed < 3.5.2.5 Fixed in 3.5.2.5 CVE-2023-7252 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only