WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,401–5,450 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 109 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High PayPal Responder Plugin paypal-responder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53750 Patchstack
7.1 High Essential Breadcrumbs Plugin essential-breadcrumbs Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-53778 Patchstack
7.6 High Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods SQL Injection ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-53783 Patchstack
8.1 High Cryptocurrency Widgets For Elementor Plugin cryptocurrency-widgets-for-elementor Local File Inclusion No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-53739 Patchstack
7.1 High Footer Flyout Widget Plugin footer-flyout-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-53732 Patchstack
7.1 High Fence URL Plugin fence-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 CVE-2024-53733 Patchstack
7.1 High Idealien Category Enhancements Plugin idealien-category-enhancements Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53734 Patchstack
7.1 High Custom Shortcode Sidebars Plugin custom-shortcode-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53736 Patchstack
7.1 High Block Editor Bootstrap Blocks Plugin block-editor-bootstrap-blocks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.1 Fixed in 6.6.2 CVE-2024-11402 Patchstack
8.5 High Distance Based Shipping Calculator Plugin distance-based-shipping-calculator SQL Injection ≤ 2.0.23 Fixed in 2.0.24 CVE-2024-52495 Patchstack
7.5 High Absolute Addons For Elementor Plugin absolute-addons Local File Inclusion ≤ 1.0.14 CVE-2024-52496 Patchstack
7.5 High Shopready Plugin shopready-elementor-addon Local File Inclusion ≤ 3.6 CVE-2024-52497 Patchstack
7.5 High SP Blog Designer Plugin sp-blog-designer Local File Inclusion ≤ 1.0.0 CVE-2024-52498 Patchstack
7.5 High Pricing table addon for elementor Plugin pricing-table-addon-for-elementor Local File Inclusion ≤ 1.0.0 CVE-2024-52499 Patchstack
7.5 High Office Locator Plugin office-locator Local File Inclusion ≤ 1.3.0 CVE-2024-52501 Patchstack
7.5 High Jobify Theme jobify Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52481 Patchstack
7.2 High Rank Math SEO Plugin seo-by-rank-math Remote Code Execution Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) ≤ 1.0.231 Fixed in 1.0.232 CVE-2024-11620 Patchstack
7.1 High Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.2 CVE-2024-52470 Patchstack
7.1 High Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.37 CVE-2024-52471 Patchstack
7.1 High Weather Atlas Widget Plugin weather-atlas Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-52472 Patchstack
7.1 High HTML5 Lyrics Karaoke Player Plugin html5-lyrics-karaoke-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 CVE-2024-52473 Patchstack
8.8 High Banner System Plugin banner-system Privilege Escalation ≤ 1.0.0 CVE-2024-52437 Patchstack
8.8 High de:branding Plugin debranding Privilege Escalation ≤ 1.0.2 CVE-2024-52438 Patchstack
8.2 High Post Ideas Plugin post-ideas Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 2 CVE-2024-52451 Patchstack
7.5 High Ultimate Classified Listings Plugin ultimate-classified-listings Local File Inclusion ≤ 1.7 CVE-2024-52448 Patchstack
7.5 High Bootscraper Plugin wp-bootscraper Local File Inclusion No login needed ≤ 2.1.0 Fixed in 4.0.0 CVE-2024-52449 Patchstack
7.5 High nBlocks Plugin nblocks Local File Inclusion ≤ 1.0.2 CVE-2024-52450 Patchstack
8.8 High QRMenu Restaurant QR Menu Lite Plugin qrmenu-lite PHP Object Injection ≤ 1.0.4 CVE-2024-52445 Patchstack
8.8 High Buying Buddy IDX CRM Plugin buying-buddy-idx-crm Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 1.2.8 Fixed in 2.0.0 CVE-2024-52446 Patchstack
7.5 High Opal Woo Custom Product Variation Plugin opal-woo-custom-product-variation Arbitrary File Deletion No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2024-52444 Patchstack
8.6 High Contact Page With Google Map Plugin contact-page-with-google-map Arbitrary File Deletion No login needed ≤ 1.6.1 CVE-2024-52447 Patchstack
7.1 High Hebrew Date Plugin hebrewdates Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.0 Fixed in 2.3.0 CVE-2024-52388 Patchstack
7.1 High Events Manager Pro – extended Plugin events-manager-pro-extended Cross-Site Request Forgery extended plugin <= 0.1 - CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-50532 Patchstack
7.1 High Domain Sharding Plugin domain-sharding Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-50533 Patchstack
7.1 High Sticky Social Bar Plugin sticky-social-bar Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-51631 Patchstack
7.1 High World Prayer Time Plugin world-prayer-time Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-50534 Patchstack
7.1 High Simple Page Specific Sidebars Plugin page-specific-sidebars Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.14.1 CVE-2024-51633 Patchstack
7.1 High SH Slideshow Plugin sh-slideshow Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 4.3 CVE-2024-51632 Patchstack
7.1 High While Loading Plugin while-it-is-loading Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2024-51635 Patchstack
7.1 High Webriti Custom Login Plugin webriti-custom-login-page Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3 CVE-2024-51634 Patchstack
7.1 High Admin SMS Alert Plugin admin-sms-alert Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2024-51637 Patchstack
7.1 High GMO Social Connection Plugin gmo-social-connection Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-51636 Patchstack
7.1 High Awesome Shortcodes For Genesis Plugin awesome-shortcodes-for-genesis Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2024-51638 Patchstack
7.1 High MDR Webmaster Tools Plugin mdr-webmaster-tools Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-51640 Patchstack
7.1 High Naver Blog Plugin naver-blog-api Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-51639 Patchstack
7.1 High Seo Free Plugin seo-free Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2024-51642 Patchstack
7.1 High Advanced PDF Generator Plugin advanced-pdf-generator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.4.0 CVE-2024-51641 Patchstack
7.1 High Addressbook Plugin addressbook Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 CVE-2024-51644 Patchstack
7.1 High Amazon Associate Filter Plugin amazon-associate-filter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.4 CVE-2024-51643 Patchstack
7.1 High e-shops Plugin e-shops-cart2 Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51648 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only