WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 351–400 of 425 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 8 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WP-Orphanage Extended Plugin wp-orphanage-extended Cross-Site Request Forgery Cross-Site Request Forgery to Orphan Account Privilege Escalation No login needed ≤ 1.2 CVE-2024-11415 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.8 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 1.5.1 CVE-2024-10711 Wordfence
8.8 High Crypto Plugin crypto Cross-Site Request Forgery Cross-Site Request Forgery to Authentication Bypass No login needed ≤ 2.15 CVE-2024-9990 Wordfence
8.8 High AMP for WP – Accelerated Mobile Pages Plugin accelerated-mobile-pages Cross-Site Request Forgery Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 1.0.99.1 CVE-2024-9598 Wordfence
8.3 High WP Lead Plus X Plugin free-sales-funnel-squeeze-pages-landing-page-builder-templates-make Cross-Site Request Forgery No login needed ≤ 0.99 CVE-2020-36839 Wordfence
8.8 High File Manager Pro Plugin filester Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 8.3.9 CVE-2024-8507 Wordfence
8.3 High Mapplic Lite and Mapplic <= (Various Versions) Plugin Server-Side Request Forgery Server Side Request Forgery to Cross-Site Scirpting No login needed < 1.0.1, < 6.2 Fixed in 1.0.1 CVE-2012-10018 Wordfence
8.8 High BA Book Everything Plugin ba-book-everything Cross-Site Request Forgery Cross-Site Request Forgery to Email Address Update/Account Takeover No login needed ≤ 1.6.20 CVE-2024-8795 Wordfence
7.5 High Justified Image Grid Plugin justified-image-grid Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 4.6.1 Fixed in 4.7 CVE-2024-43989 Patchstack
8.8 High PropertyHive Plugin propertyhive Cross-Site Request Forgery Cross-Site Request Forgery via save_account_details No login needed ≤ 2.0.19 CVE-2024-8490 Wordfence
8.8 High Stream Plugin stream Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 4.0.1 CVE-2024-7423 Wordfence
7.1 High Fonts Plugin olympus-google-fonts Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSSvulnerability No login needed ≤ 3.7.7 Fixed in 3.7.8 CVE-2024-43301 Patchstack
7.2 High Skitter Slideshow Plugin wp-skitter-slideshow Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.5.2 CVE-2022-1751 Wordfence
7.1 High Contact Form 7 Summary and Print Plugin cf7-summary-and-print Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-38724 Patchstack
8.8 High MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 2.2 CVE-2024-7492 Wordfence
8.5 High Modern Events Calendar Plugin modern-events-calendar-lite Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery ≤ 7.12.1 CVE-2024-6522 Wordfence
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
7.2 High BerqWP Plugin searchpro Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-37942 Patchstack
7.1 High Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Server-Side Request Forgery No login needed ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38728 Patchstack
8.0 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery < 1.3.2 Fixed in 1.3.2 CVE-2024-1845 WPScan
8.8 High ScrollTo Top Plugin scrollto-top Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-6320 Wordfence
8.8 High ScrollTo Bottom Plugin scrollto-bottom Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.1.1 CVE-2024-6321 Wordfence
8.8 High Advanced AJAX Page Loader Plugin advanced-ajax-page-loader Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.7.7 CVE-2024-6310 Wordfence
8.8 High Attachment File Icons (AF Icons) Plugin attachment-file-icons Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.3 CVE-2024-6309 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 4.1.2 CVE-2024-6317 Wordfence
8.8 High Generate PDF using Contact Form 7 Plugin generate-pdf-using-contact-form-7 Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 4.1.2 CVE-2024-6316 Wordfence
7.2 High Foxiz Theme Server-Side Request Forgery No login needed ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-37260 Patchstack
8.8 High Nested Pages Plugin wp-nested-pages Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 3.2.7 CVE-2024-5943 Wordfence
8.1 High Sola Testimonials Plugin sola-testimonials Cross-Site Request Forgery A cross-site request forgery vulnerability exists in Sola Testimonials versions prior to 3.0.0. If this vulnerability is exploited, an attacker allows a user who logs in to the Wo… No login needed versions prior to 3.0.0 CVE-2024-38345 jpcert
7.2 High UberMenu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 3.8.3 CVE-2024-3593 Wordfence
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
8.5 High ElementsKit PRO Plugin Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 3.6.2 CVE-2024-4404 Wordfence
7.5 High WP STAGING PRO - Backup Duplicator & Migration Plugin wp-staging Cross-Site Request Forgery Backup Duplicator & Migration <= 5.6.0 - Cross-Site Request Forgery to Limited Local File Inclusion No login needed ≤ 5.6.0 CVE-2024-5551 Wordfence
7.5 High Bricksforge Plugin Broken Access Control Unauthenticated Arbitrary WordPress Setting Deletion No login needed ≤ 2.0.17 Fixed in 2.1.1 CVE-2024-31243 Patchstack
8.1 High The Moneytizer Plugin the-moneytizer Cross-Site Request Forgery Cross-Site Request Forgery via multiple AJAX actions ≤ 9.6.3 CVE-2023-6968 Wordfence
8.5 High MemberPress Plugin Server-Side Request Forgery Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode ≤ 1.11.29 CVE-2024-5031 Wordfence
7.1 High WebinarPress Plugin wp-webinarsystem Cross-Site Request Forgery No login needed ≤ 1.33.17 CVE-2024-34818 Patchstack
7.2 High PDF Invoices & Packing Slips for WooCommerce Plugin woocommerce-pdf-invoices-packing-slips Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.8.0 CVE-2024-3047 Wordfence
8.3 High ZD YouTube FLV Player Plugin zd-youtube-flv-player Server-Side Request Forgery No login needed ≤ 1.2.6 CVE-2024-2663 Wordfence
7.1 High Regenerate post permalink Plugin regenerate-post-permalinks Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to XSS No login needed ≤ 1.0.3 CVE-2024-33681 Patchstack
7.1 High The Pack Elementor addons Plugin the-pack-addon Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 2.0.8.3 Fixed in 2.0.8.4 CVE-2024-32785 Patchstack
7.1 High Seers Plugin seers-cookie-consent-banner-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 8.1.0 Fixed in 8.1.1 CVE-2024-32789 Patchstack
7.6 High Automatic Plugin Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed < 3.93.0 Fixed in 3.93.0 CVE-2024-32693 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Cross-Site Request Forgery No login needed ≤ 1.6.93 Fixed in 1.6.94 CVE-2024-31424 Patchstack
7.1 High Social Author Bio Plugin social-autho-bio Cross-Site Scripting Stored XSS via Cross Site Request Forgery (CSRF) No login needed ≤ 2.4 CVE-2024-30545 Patchstack
7.1 High Sync Post With Other Site Plugin sync-post-with-other-site Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 1.9.1 CVE-2024-32082 Patchstack
7.1 High WordPress Tooltips Plugin wordpress-tooltips Cross-Site Request Forgery No login needed ≤ 9.5.3 Fixed in 9.5.9 CVE-2024-31285 Patchstack
8.8 High Ninja Forms Plugin ninja-forms Cross-Site Request Forgery Cross-site request forgery (CSRF) vulnerability exists in Ninja Forms prior to 3.4.31. If a website administrator views a malicious page while logging in, unintended operations ma… No login needed prior to 3.4.31 CVE-2024-25572 jpcert
7.1 High ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 24.0128 Fixed in 24.0303 CVE-2024-31299 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only