WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 451–500 of 569 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | EventPrime | Broken Access Control |
≤ 4.0.3.2 Fixed in 4.0.4.0 |
CVE-2024-43223 |
Patchstack | |
| 6.5 Medium | WpEvently | Cross-Site Scripting |
≤ 4.2.5 Fixed in 4.2.6 |
CVE-2024-49703 |
Patchstack | |
| 6.1 Medium | EventPrime – Modern Events Calendar, Bookings and Tickets | Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 4.0.4.7 |
CVE-2024-9864 |
Wordfence | |
| 6.1 Medium | EventPrime – Modern Events Calendar, Bookings and Tickets | Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed |
≤ 4.0.4.7 |
CVE-2024-9865 |
Wordfence | |
| 9.6 Critical | SSV Events | Local File Inclusion Local File Inclusion to RCE No login needed |
≤ 3.2.7 |
CVE-2024-49286 |
Patchstack | |
| 4.3 Medium | EventON PRO - WordPress Virtual Event Calendar | Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed |
≤ 4.6.8 |
CVE-2023-6243 |
Wordfence | |
| 6.5 Medium | Events Addon for Elementor | Cross-Site Scripting |
≤ 2.2.0 Fixed in 2.2.1 |
CVE-2024-49264 |
Patchstack | |
| 7.3 High | Timetable and Event Schedule by MotoPress | Broken Access Control Missing Authorization No login needed |
≤ 2.3.8 |
CVE-2020-36840 |
Wordfence | |
| 4.7 Medium | EventPrime | Open Redirect No login needed |
≤ 4.0.4.5 Fixed in 4.0.4.6 |
CVE-2024-47648 |
Patchstack | |
| 8.8 High | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion |
≤ 4.0.8 |
CVE-2024-7149 |
Wordfence | |
| 7.2 High | The Events Calendar | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 6.6.3 |
CVE-2024-6931 |
Wordfence | |
| 9.8 Critical | The Events Calendar | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.6.4 |
CVE-2024-8275 |
Wordfence | |
| 4.3 Medium | Easy PayPal Events | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed |
≤ 1.2.1 |
CVE-2024-8476 |
Wordfence | |
| 6.1 Medium | Simple Calendar – Google Calendar | Cross-Site Scripting Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting No login needed |
≤ 3.4.2 |
CVE-2024-8549 |
Wordfence | |
| 9.1 Critical | WooEvents | Remote Code Execution Unauthenticated Arbitrary File Overwrite No login needed |
≤ 4.1.2 |
CVE-2024-8671 |
Wordfence | |
| 4.3 Medium | Appointment & Event Booking Calendar Plugin – Webba Booking | Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update |
≤ 5.0.48 |
CVE-2024-8432 |
Wordfence | |
| 5.3 Medium | EventPrime | Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed |
≤ 4.0.4.3 |
CVE-2024-8369 |
Wordfence | |
| 4.8 Medium | EventON | Cross-Site Scripting Admin+ Stored XSS |
< 2.2.17 Fixed in 2.2.17 |
CVE-2024-6910 |
WPScan | |
| 6.4 Medium | Enter Addons – Ultimate Template Builder for Elementor | Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget |
≤ 2.1.8 |
CVE-2024-7611 |
Wordfence | |
| 6.5 Medium | Booking for Appointments and Events Calendar – Amelia Premium | Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed |
≤ 1.2.4, ≤ 7.7 |
CVE-2024-6332 |
Wordfence | |
| 8.8 High | WP Events Manager | SQL Injection Authenticated (Subscriber+) Time-Based SQL Injection |
≤ 2.1.11 |
CVE-2024-7717 |
Wordfence | |
| 9.1 Critical | The Events Calendar Pro | PHP Object Injection Authenticated (Administrator+) PHP Object Injection to Remote Code Execution |
≤ 7.0.2 |
CVE-2024-8016 |
Wordfence | |
| 8.5 High | Registrations for the Events Calendar | SQL Injection |
≤ 2.12.2 Fixed in 2.12.3 |
CVE-2024-39638 |
Patchstack | |
| 4.3 Medium | Event Espresso 4 Decaf – Event Registration Event Ticketing | Broken Access Control Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification |
≤ 4.10.46.decaf |
CVE-2024-6883 |
Wordfence | |
| 6.5 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed |
≤ 3.13.0 |
CVE-2024-5940 |
Wordfence | |
| 6.5 Medium | Event Manager for WooCommerce | Local File Inclusion |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2024-43138 |
Patchstack | |
| 5.3 Medium | Booking for Appointments and Events Calendar – Amelia | Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed |
≤ 1.2 |
CVE-2024-6552 |
Wordfence | |
| 8.5 High | Modern Events Calendar | Server-Side Request Forgery Authenticated (Subscriber+) Server Side Request Forgery |
≤ 7.12.1 |
CVE-2024-6522 |
Wordfence | |
| 4.8 Medium | Community Events | Cross-Site Scripting Admin+ Stored XSS |
< 1.5.1 Fixed in 1.5.1 |
CVE-2024-6270 |
WPScan | |
| 5.9 Medium | Eventin | Cross-Site Scripting |
≤ 4.0.5 Fixed in 4.0.6 |
CVE-2024-39648 |
Patchstack | |
| 5.5 Medium | Timetable and Event Schedule | PHP Object Injection |
≤ 2.4.13 |
CVE-2024-39630 |
Patchstack | |
| 5.4 Medium | Community Events | Cross-Site Request Forgery Event Deletion via CSRF No login needed |
< 1.5 Fixed in 1.5 |
CVE-2024-6271 |
WPScan | |
| 6.5 Medium | Eventin | Cross-Site Scripting |
≤ 3.3.57 Fixed in 4.0.0 |
CVE-2024-37507 |
Patchstack | |
| 6.5 Medium | WP Event Aggregator | Cross-Site Scripting |
≤ 1.7.9 Fixed in 1.8.0 |
CVE-2024-38703 |
Patchstack | |
| 8.8 High | Timeline Event History | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 3.1 |
CVE-2024-5726 |
Wordfence | |
| 4.3 Medium | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Broken Access Control Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import |
≤ 4.0.4 |
CVE-2024-6033 |
Wordfence | |
| 6.4 Medium | WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce | Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode |
≤ 3.1.43 |
CVE-2024-2691 |
Wordfence | |
| 5.9 Medium | EventON | Cross-Site Scripting Admin+ Stored Cross-Site Scripting via event subtitle |
< 2.2.15 Fixed in 2.2.15 |
CVE-2024-4752 |
WPScan | |
| 7.5 High | Event post | Local File Inclusion No login needed |
≤ 5.9.5 Fixed in 5.9.6 |
CVE-2024-38735 |
Patchstack | |
| 6.5 Medium | Events Calendar for Google | Local File Inclusion |
≤ 2.1.0 |
CVE-2024-38716 |
Patchstack | |
| 4.3 Medium | Event post | Cross-Site Request Forgery No login needed |
≤ 5.9.10 |
CVE-2024-1375 |
Wordfence | |
| 6.4 Medium | Extensions for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via EE Events and EE Flipbox Widget |
≤ 2.0.32 |
CVE-2024-4868 |
Wordfence | |
| 7.2 High | EventON | Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting and Plugin Settings Updates No login needed |
≤ 2.2.15 |
CVE-2024-6180 |
Wordfence | |
| 8.8 High | Modern Events Calendar | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 7.11.0 |
CVE-2024-5441 |
Wordfence | |
| 6.1 Medium | Events Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 6.4.8 |
CVE-2024-5889 |
Wordfence | |
| 5.3 Medium | Event Management Tickets Booking | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.4.0 |
CVE-2024-5059 |
Patchstack | |
| 4.3 Medium | Tickera | Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion |
≤ 3.5.2.8 |
CVE-2024-5860 |
Wordfence | |
| 7.1 High | FooEvents for WooCommerce | Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload |
≤ 1.19.20 |
CVE-2024-6000 |
Wordfence | |
| 6.5 Medium | The Events Calendar (Free | Broken Access Control Contributor+ Arbitrary Events Access |
< 6.4.0.1 Fixed in 6.4.0.1 |
CVE-2024-1295 |
WPScan | |
| 6.4 Medium | Events Manager – Calendar, Bookings, Tickets, and more! | Cross-Site Scripting Calendar, Bookings, Tickets, and more! <= 6.4.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via event, location, and event_category Shortcodes |
≤ 6.4.7.3 |
CVE-2024-3492 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.