WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 451–500 of 569 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control ≤ 4.0.3.2 Fixed in 4.0.4.0 CVE-2024-43223 Patchstack
6.5 Medium WpEvently Plugin mage-eventpress Cross-Site Scripting ≤ 4.2.5 Fixed in 4.2.6 CVE-2024-49703 Patchstack
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.4.7 CVE-2024-9864 Wordfence
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed ≤ 4.0.4.7 CVE-2024-9865 Wordfence
9.6 Critical SSV Events Plugin ssv-events Local File Inclusion Local File Inclusion to RCE No login needed ≤ 3.2.7 CVE-2024-49286 Patchstack
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-49264 Patchstack
7.3 High Timetable and Event Schedule by MotoPress Plugin mp-timetable Broken Access Control Missing Authorization No login needed ≤ 2.3.8 CVE-2020-36840 Wordfence
4.7 Medium EventPrime Plugin eventprime-event-calendar-management Open Redirect No login needed ≤ 4.0.4.5 Fixed in 4.0.4.6 CVE-2024-47648 Patchstack
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.8 CVE-2024-7149 Wordfence
7.2 High The Events Calendar Plugin the-events-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 6.6.3 CVE-2024-6931 Wordfence
9.8 Critical The Events Calendar Plugin the-events-calendar SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.6.4 CVE-2024-8275 Wordfence
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2024-8476 Wordfence
6.1 Medium Simple Calendar – Google Calendar Plugin google-calendar-events Cross-Site Scripting Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting No login needed ≤ 3.4.2 CVE-2024-8549 Wordfence
9.1 Critical WooEvents Plugin Remote Code Execution Unauthenticated Arbitrary File Overwrite No login needed ≤ 4.1.2 CVE-2024-8671 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed ≤ 4.0.4.3 CVE-2024-8369 Wordfence
4.8 Medium EventON Plugin eventon-lite Cross-Site Scripting Admin+ Stored XSS < 2.2.17 Fixed in 2.2.17 CVE-2024-6910 WPScan
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget ≤ 2.1.8 CVE-2024-7611 Wordfence
6.5 Medium Booking for Appointments and Events Calendar – Amelia Premium Plugin ameliabooking Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed ≤ 1.2.4, ≤ 7.7 CVE-2024-6332 Wordfence
8.8 High WP Events Manager Plugin wp-events-manager SQL Injection Authenticated (Subscriber+) Time-Based SQL Injection ≤ 2.1.11 CVE-2024-7717 Wordfence
9.1 Critical The Events Calendar Pro Plugin PHP Object Injection Authenticated (Administrator+) PHP Object Injection to Remote Code Execution ≤ 7.0.2 CVE-2024-8016 Wordfence
8.5 High Registrations for the Events Calendar Plugin registrations-for-the-events-calendar SQL Injection ≤ 2.12.2 Fixed in 2.12.3 CVE-2024-39638 Patchstack
4.3 Medium Event Espresso 4 Decaf – Event Registration Event Ticketing Plugin event-espresso-decaf Broken Access Control Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification ≤ 4.10.46.decaf CVE-2024-6883 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed ≤ 3.13.0 CVE-2024-5940 Wordfence
6.5 Medium Event Manager for WooCommerce Plugin mage-eventpress Local File Inclusion ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-43138 Patchstack
5.3 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed ≤ 1.2 CVE-2024-6552 Wordfence
8.5 High Modern Events Calendar Plugin modern-events-calendar-lite Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery ≤ 7.12.1 CVE-2024-6522 Wordfence
4.8 Medium Community Events Plugin Cross-Site Scripting Admin+ Stored XSS < 1.5.1 Fixed in 1.5.1 CVE-2024-6270 WPScan
5.9 Medium Eventin Plugin wp-event-solution Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-39648 Patchstack
5.5 Medium Timetable and Event Schedule Plugin mp-timetable PHP Object Injection ≤ 2.4.13 CVE-2024-39630 Patchstack
5.4 Medium Community Events Plugin Cross-Site Request Forgery Event Deletion via CSRF No login needed < 1.5 Fixed in 1.5 CVE-2024-6271 WPScan
6.5 Medium Eventin Plugin wp-event-solution Cross-Site Scripting ≤ 3.3.57 Fixed in 4.0.0 CVE-2024-37507 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
8.8 High Timeline Event History Plugin timeline-event-history PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 3.1 CVE-2024-5726 Wordfence
4.3 Medium Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import ≤ 4.0.4 CVE-2024-6033 Wordfence
6.4 Medium WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Plugin wp-event-manager Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode ≤ 3.1.43 CVE-2024-2691 Wordfence
5.9 Medium EventON Plugin eventon-lite Cross-Site Scripting Admin+ Stored Cross-Site Scripting via event subtitle < 2.2.15 Fixed in 2.2.15 CVE-2024-4752 WPScan
7.5 High Event post Plugin event-post Local File Inclusion No login needed ≤ 5.9.5 Fixed in 5.9.6 CVE-2024-38735 Patchstack
6.5 Medium Events Calendar for Google Plugin events-calendar-for-google Local File Inclusion ≤ 2.1.0 CVE-2024-38716 Patchstack
4.3 Medium Event post Plugin event-post Cross-Site Request Forgery No login needed ≤ 5.9.10 CVE-2024-1375 Wordfence
6.4 Medium Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via EE Events and EE Flipbox Widget ≤ 2.0.32 CVE-2024-4868 Wordfence
7.2 High EventON Plugin eventon-lite Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates No login needed ≤ 2.2.15 CVE-2024-6180 Wordfence
8.8 High Modern Events Calendar Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.11.0 CVE-2024-5441 Wordfence
6.1 Medium Events Manager Plugin events-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.4.8 CVE-2024-5889 Wordfence
5.3 Medium Event Management Tickets Booking Plugin event-monster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.0 CVE-2024-5059 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion ≤ 3.5.2.8 CVE-2024-5860 Wordfence
7.1 High FooEvents for WooCommerce Plugin Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload ≤ 1.19.20 CVE-2024-6000 Wordfence
6.5 Medium The Events Calendar (Free Plugin Broken Access Control Contributor+ Arbitrary Events Access < 6.4.0.1 Fixed in 6.4.0.1 CVE-2024-1295 WPScan
6.4 Medium Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager Cross-Site Scripting Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes ≤ 6.4.7.3 CVE-2024-3492 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only