WordPress Vulnerability Database

Search All Vulnerabilities

Tip: You can search by CVE ID, software name or slug, or the researcher name. Expand to read about more advanced search options.

If you want to perform more advanced lookups, you can use keywords to further refine your search.

For example, woocommerce researcher:"chloe chamberland" would search for any vulnerabilities discovered by Chloe Chamberland in software that has WooCommerce in the title.

Keywords are added in keyword:value format. If the value contains spaces, you must enclose it in quotation marks.

You can use the following keywords to add criteria to your search:

title
Searches through the title of each vulnerability for matches.
date
Returns vulnerabilities by publication date. Use YYYY-MM-DD, YYYY-MM or YYYY format.
cvss-rating
Use low, medium, high or critical to limit the search to vulnerabilities with the specified rating.
researcher
Returns vulnerabilities credited to researchers containing the given text.
software
Returns vulnerabilities discovered in software containing the given text.
software-slug
Returns vulnerabilities discovered in software exactly matching the given slug.
software-type
Use plugin, theme or core to limit the search to the specified type of software.
By selecting “Search” you acknowledge that you have read and agree to the Wordfence Intelligence Terms and Conditions.

All Vulnerabilities

Title CVE ID CVSS Researchers Date
Themeflection Numbers <= 1.8.1 - Authenticated(Subscriber+) Privilege Escalation via tf_numb_save_licenses CVE-2023-0889 8.8 dc11 March 27, 2023
Waiting: One-click countdowns <= 0.6.2 - Authenticated (Subscriber+) SQL Injection via 'pbc_down[meta][id]' CVE-2023-28659 8.8 Joshua Martinelle March 22, 2023
Events Made Easy <= 2.3.14 - Authenticated (Subscriber+) SQL Injection via 'search_name' CVE-2023-28660 8.8 Joshua Martinelle March 20, 2023
Crocoblock JetEngine <= 3.1.3 - Authenticated(Author+) Arbitrary File Upload to Remote Code Execution CVE-2023-1406 8.8 R3zk0n March 20, 2023
WP Popup Banners <= 1.2.5 - Authenticated (Subscriber+) SQL Injection via 'value' CVE-2023-28661 8.8 Joshua Martinelle March 20, 2023
WP Popup Banners <= 1.2.5 - Authenticated (Subscriber+) SQL Injection CVE-2023-1471 8.8 Etan Imanol Castro Aldrete March 17, 2023
UpdraftPlus 1.22.14 to 1.23.2 and UpdraftPlus (Premium) 2.22.14 to 2.23.2 - Privilege Escalation via updraft_central_ajax_handler 8.8 March 16, 2023
User Role by BestWebSoft <= 1.6.6 - Cross-Site Request Forgery to Privilege Escalation CVE-2023-0820 8.8 dc11 March 13, 2023
Intrepidity <= 1.5.1 - Cross-Site Request Forgery via mytheme_add_admin CVE-2023-27634 8.8 Dave Jong March 13, 2023
Multiple E-plugins (Various Versions) - Authenticated (Subscriber+) Privilege Escalation CVE-2020-36666 8.8 Omar Badran March 6, 2023
WP Dark Mode <= 4.0.7 - Authenticated (Subscriber+) Local File Inclusion via 'style' CVE-2023-0467 8.8 Alex Sanford March 6, 2023
Debug Assistant <= 1.4 - Cross-Site Request Forgery via imlt_create_admin CVE-2023-26516 8.8 Prasanna V Balaji February 28, 2023
OceanWP <= 3.4.1 - Authenticated (Subscriber+) Local File Inclusion CVE-2023-23700 8.8 Rafie Muhammad February 27, 2023
ProfileGrid <= 5.3.0 - Missing Authorization to Arbitrary Password Reset CVE-2023-0940 8.8 dc11 February 27, 2023
Drag and Drop Multiple File Upload – Contact Form 7 <= 1.3.6.5 - Cross-Site Request Forgery in dnd_upload_cf7_upload and dnd_codedropz_upload_delete CVE-2022-45364 8.8 István Márton February 24, 2023
Drag and Drop Multiple File Upload for WooCommerce <= 1.0.8 - Cross-Site Request Forgery in upload and delete_file CVE-2022-45377 8.8 István Márton February 24, 2023
Slimstat Analytics <= 4.9.3.2 - Authenticated (Subscriber+) SQL Injection via Shortcode CVE-2023-0630 8.8 Marc-Alexandre Montpas February 23, 2023
Paytm Payment Gateway <= 2.7.3 - Authenticated (Editor+) SQL Injection via 'post' CVE-2022-45805 8.8 Aman Rawat February 22, 2023
Custom Content Shortcode <= 4.0.2 - Authenticated (Contributor+) Local File Inclusion via Shortcode CVE-2023-0340 8.8 Erwan LR February 22, 2023
WP Meta SEO <= 4.5.2 - Authenticated (Subscriber+) SQL Injection CVE-2023-0875 8.8 dc11 February 22, 2023

Researcher Hall of Fame (Past 30 days)

Rank Name
Vulnerabilities since Aug 30, 2024
Vulns
1 Francesco Carlucci 30
2 vgo0 27
3 wesley (wcraft) 21
4 Lucio Sá 13
5 stealthcopter 10
6 Krzysztof Zając 10
7 Peter Thaleikis 7
8 Marco Wotschka 7
9 Webbernaut 6
10 TANG Cheuk Hei (siunam) 5
11 Daniel Ruf 5
12 zer0gh0st 4
13 LVT-tholv2k 3
14 Robert DeVore 3
15 Le Ngoc Anh 3
16 rezaduty 3
17 Tonn 2
18 Tieu Pham Trong Nhan 2
19 Michelle Porter 2
20 Connor Billings 2

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation