WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 1–46 of 46 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 3.5 Low | The Post Grid | Content Injection Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-List Widening |
< 7.9.5 Fixed in 7.9.5 |
CVE-2026-84151 |
WPScan | |
| 6.5 Medium | The Post Grid | Cross-Site Scripting |
≤ 7.9.5 Fixed in 7.9.6 |
CVE-2026-94680 |
Patchstack | |
| 6.5 Medium | The Post Grid | Cross-Site Scripting |
≤ 7.9.5 Fixed in 7.9.6 |
CVE-2026-94671 |
Patchstack | |
| 9.8 Critical | Post Grid and Gutenberg Blocks – ComboBlocks | Remote Code Execution ComboBlocks 2.2.85 - 2.3.32 - Unauthenticated Hook Injection No login needed |
2.2.85 – 2.3.32 |
CVE-2024-11080 |
Wordfence | |
| 4.3 Medium | The Post Grid | Broken Access Control |
≤ 7.9.2 |
CVE-2026-49054 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.3.23 |
CVE-2025-68605 |
Patchstack | |
| 5.3 Medium | Post Grid and Gutenberg Blocks | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 2.3.23 |
CVE-2025-63043 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Broken Access Control |
≤ 2.3.17 Fixed in 2.3.18 |
CVE-2025-66058 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Broken Access Control |
≤ 2.3.17 Fixed in 2.3.18 |
CVE-2025-62924 |
Patchstack | |
| 8.8 High | Post Grid and Gutenberg Blocks | PHP Object Injection |
≤ 2.3.11 Fixed in 2.3.12 |
CVE-2025-54007 |
Patchstack | |
| 7.5 High | The Post Grid | Local File Inclusion |
≤ 7.7.17 Fixed in 7.7.18 |
CVE-2025-30814 |
Patchstack | |
| 5.3 Medium | Post Grid and Gutenberg Blocks – ComboBlocks | Information Disclosure ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure No login needed |
≤ 2.3.6 |
CVE-2024-13796 |
Wordfence | |
| 6.5 Medium | Post Grid, Slider & Carousel Ultimate | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion |
≤ 1.6.10 Fixed in 1.7 |
CVE-2025-24782 |
Patchstack | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion |
≤ 1.6.10 |
CVE-2024-13408 |
Wordfence | |
| 7.5 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() |
≤ 1.6.10 |
CVE-2024-13409 |
Wordfence | |
| 9.8 Critical | Post Grid and Gutenberg Blocks | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
2.2.85 – 2.3.3 |
CVE-2024-9636 |
Wordfence | |
| 6.5 Medium | Post Grid Elementor Addon | Cross-Site Scripting |
≤ 2.0.18 Fixed in 2.0.19 |
CVE-2024-56268 |
Patchstack | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Broken Access Control No login needed |
≤ 2.1.10 Fixed in 2.2 |
CVE-2023-48750 |
Patchstack | |
| 6.5 Medium | Dynamic Post Grid Elementor Addon | Cross-Site Scripting |
≤ 1.0.6 Fixed in 1.0.7 |
CVE-2024-51852 |
Patchstack | |
| 6.5 Medium | Blocks Post Grid | Cross-Site Scripting |
≤ 1.0.3 |
CVE-2024-51928 |
Patchstack | |
| 6.5 Medium | The Post Grid | Broken Access Control No login needed |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37481 |
Patchstack | |
| 4.3 Medium | The Post Grid | Broken Access Control |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37482 |
Patchstack | |
| 5.4 Medium | The Post Grid | Broken Access Control |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37483 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.2.93 Fixed in 2.2.94 |
CVE-2024-50432 |
Patchstack | |
| 8.8 High | Post Grid | SQL Injection Contributor+ SQL Injection |
< 2.1.13 Fixed in 2.1.13 |
CVE-2021-4450 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode |
≤ 3.9.3 |
CVE-2024-9051 |
Wordfence | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.2.89 Fixed in 2.2.90 |
CVE-2024-47340 |
Patchstack | |
| 4.8 Medium | The Post Grid | Cross-Site Scripting Editor+ Stored XSS via Grid Creation |
< 7.5.0 Fixed in 7.5.0 |
CVE-2024-3635 |
WPScan | |
| 8.8 High | Post Grid and Gutenberg Blocks | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
2.2.87 – 2.2.90 |
CVE-2024-8253 |
Wordfence | |
| 4.3 Medium | The Post Grid | Information Disclosure Authenticated (Contributor+) Information Disclosure |
≤ 7.7.11 |
CVE-2024-7418 |
Wordfence | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Local File Inclusion |
≤ 2.3 Fixed in 2.4 |
CVE-2024-43281 |
Patchstack | |
| 6.4 Medium | Gutenberg Blocks, Page Builder – ComboBlocks | Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block |
≤ 2.2.84 |
CVE-2024-7588 |
Wordfence | |
| 6.5 Medium | ComboBlocks | Cross-Site Scripting |
≤ 2.2.86 Fixed in 2.2.87 |
CVE-2024-43155 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget |
≤ 2.2.85 |
CVE-2024-6346 |
Wordfence | |
| 6.4 Medium | The Post Grid | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag |
≤ 7.7.1 |
CVE-2024-1427 |
Wordfence | |
| 6.5 Medium | The Post Grid | Cross-Site Scripting |
≤ 7.7.1 Fixed in 7.7.2 |
CVE-2024-35739 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute |
≤ 2.2.80 |
CVE-2024-4042 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-1988 |
Wordfence | |
| 6.5 Medium | Post Grid Elementor Addon | Cross-Site Scripting |
≤ 2.0.16 Fixed in 2.0.17 |
CVE-2024-34789 |
Patchstack | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode |
≤ 3.9.1 |
CVE-2024-4043 |
Wordfence | |
| 4.3 Medium | The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | Broken Access Control Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization |
≤ 7.6.1 |
CVE-2024-3936 |
Wordfence | |
| 7.5 High | Post Grid | Information Disclosure Sensitive Data Exposure via API No login needed |
≤ 2.2.78 Fixed in 2.2.79 |
CVE-2024-32816 |
Patchstack | |
| 7.1 High | Post Grid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.74 Fixed in 2.2.76 |
CVE-2024-30441 |
Patchstack | |
| 6.5 Medium | Post Grid, Slider & Carousel Ultimate | Cross-Site Scripting |
≤ 1.6.6 Fixed in 1.6.7 |
CVE-2024-29925 |
Patchstack | |
| 8.8 High | Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup |
≤ 1.6.7 |
CVE-2024-2006 |
Wordfence | |
| 7.5 High | Post Grid Combo – 36+ Gutenberg Blocks | Information Disclosure Information Exposure via get_posts API Endpoint No login needed |
≤ 2.2.68 |
CVE-2023-7072 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.