WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–33 of 33 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94680 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.9.5 Fixed in 7.9.6 CVE-2026-94671 Patchstack
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.9.2 CVE-2026-49054 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.3.23 CVE-2025-68605 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-62924 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Information Disclosure ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure No login needed ≤ 2.3.6 CVE-2024-13796 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Broken Access Control No login needed ≤ 2.1.10 Fixed in 2.2 CVE-2023-48750 Patchstack
6.5 Medium Dynamic Post Grid Elementor Addon Plugin dynamic-post-grid-elementor-addon Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-51852 Patchstack
6.5 Medium Blocks Post Grid Plugin blocks-post-grid Cross-Site Scripting ≤ 1.0.3 CVE-2024-51928 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Broken Access Control No login needed ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37481 Patchstack
4.3 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37482 Patchstack
5.4 Medium The Post Grid Plugin the-post-grid Broken Access Control ≤ 7.7.4 Fixed in 7.7.5 CVE-2024-37483 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.93 Fixed in 2.2.94 CVE-2024-50432 Patchstack
6.4 Medium WP Ultimate Post Grid Plugin wp-ultimate-post-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode ≤ 3.9.3 CVE-2024-9051 Wordfence
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.89 Fixed in 2.2.90 CVE-2024-47340 Patchstack
4.8 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting Editor+ Stored XSS via Grid Creation < 7.5.0 Fixed in 7.5.0 CVE-2024-3635 WPScan
4.3 Medium The Post Grid Plugin the-post-grid Information Disclosure Authenticated (Contributor+) Information Disclosure ≤ 7.7.11 CVE-2024-7418 Wordfence
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43281 Patchstack
6.4 Medium Gutenberg Blocks, Page Builder – ComboBlocks Plugin post-grid Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block ≤ 2.2.84 CVE-2024-7588 Wordfence
6.5 Medium ComboBlocks Plugin post-grid Cross-Site Scripting ≤ 2.2.86 Fixed in 2.2.87 CVE-2024-43155 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget ≤ 2.2.85 CVE-2024-6346 Wordfence
6.4 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag ≤ 7.7.1 CVE-2024-1427 Wordfence
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-35739 Patchstack
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute ≤ 2.2.80 CVE-2024-4042 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-1988 Wordfence
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.16 Fixed in 2.0.17 CVE-2024-34789 Patchstack
6.4 Medium WP Ultimate Post Grid Plugin wp-ultimate-post-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode ≤ 3.9.1 CVE-2024-4043 Wordfence
4.3 Medium The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid Plugin the-post-grid Broken Access Control Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization ≤ 7.6.1 CVE-2024-3936 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Cross-Site Scripting ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-29925 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only