WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,651–5,700 of 6,499 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 114 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.2 High APA Register Newsletter Form Plugin apa-register-newsletter-form Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49621 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
8.5 High Duplicate Title Validate Plugin duplicate-title-validate SQL Injection ≤ 1.0 Fixed in 1.4 CVE-2024-49623 Patchstack
8.8 High GERRYWORKS Post by Mail Plugin gerryworks-post-by-mail Privilege Escalation ≤ 1.0 CVE-2024-49608 Patchstack
7.1 High All in One Slider Plugin all-in-one-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-49323 Patchstack
7.1 High jLayer Parallax Slider Plugin jlayer-parallax-slider-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49334 Patchstack
7.1 High Google Map Locations Plugin google-map-locations Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49606 Patchstack
7.1 High Mitm Bug Tracker Plugin mitm-bug-tracker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49224 Patchstack
7.1 High ADIF Log Search Widget Plugin adif-log-search-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0f CVE-2024-49238 Patchstack
7.1 High Add Categories Post Footer Plugin add-categories-post-footer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49239 Patchstack
7.1 High AB Categories Search Widget Plugin ab-categories-search-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.5 CVE-2024-49240 Patchstack
7.5 High Dynamic Elementor Addons Plugin dynamic-elementor-addons Local File Inclusion ≤ 1.0.0 CVE-2024-49243 Patchstack
7.1 High Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.37 Fixed in 2.7.38 CVE-2024-49248 Patchstack
7.1 High Clio Grow Plugin clio-grow-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-49276 Patchstack
7.1 High CURCY Plugin woo-multi-currency Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49283 Patchstack
7.1 High Animator Plugin scroll-triggered-animations Cross-Site Scripting Scroll Triggered Animations plugin <= 3.0.15 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2024-49308 Patchstack
7.1 High Digitally Plugin digitally Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 CVE-2024-49309 Patchstack
7.1 High Akismet htaccess writer Plugin akismet-htaccess-writer Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2024-49316 Patchstack
7.1 High EasyJobs Plugin easyjobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-43997 Patchstack
7.1 High Cookie Scanner Plugin cookie-scanner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-49220 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.1 High CJ Change Howdy Plugin cj-change-howdy Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.1 CVE-2024-49223 Patchstack
7.1 High Better Author Bio Plugin better-author-bio Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.7.10.11 CVE-2024-49229 Patchstack
7.1 High Ahmeti Wp Timeline Plugin ahmeti-wp-timeline Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.1 CVE-2024-49237 Patchstack
7.1 High VKontakte Wall Post Plugin vkontakte-wall-post Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-49313 Patchstack
8.8 High RS-Members Plugin rs-members Privilege Escalation ≤ 1.0.3 CVE-2024-49219 Patchstack
8.5 High Fluent Support Plugin fluent-support SQL Injection ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47304 Patchstack
8.5 High Classic Editor and Classic Widgets Plugin classic-editor-and-classic-widgets SQL Injection ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-47312 Patchstack
8.5 High CSV Product Import Export for WooCommerce Plugin csv-wc-product-import-export SQL Injection ≤ 1.0.0 CVE-2024-49244 Patchstack
8.5 High Zoho CRM Lead Magnet Plugin zoho-crm-forms SQL Injection ≤ 1.7.9.7 Fixed in 1.7.9.8 CVE-2024-49297 Patchstack
7.6 High Surfer Plugin surferseo SQL Injection ≤ 1.5.0.502 Fixed in 1.6.0.523 CVE-2024-49299 Patchstack
7.5 High Contact Forms, Live Support, CRM, Video Messages Plugin live-support-tickets Information Disclosure Sensitive Data Exposure No login needed ≤ 1.10.2 Fixed in 1.11.1 CVE-2024-49235 Patchstack
7.5 High SSV MailChimp Plugin ssv-mailchimp Local File Inclusion No login needed ≤ 3.1.5 CVE-2024-49285 Patchstack
7.5 High PDF-Rechnungsverwaltung Plugin pdf-rechnungsverwaltung Local File Inclusion No login needed ≤ 0.0.1 CVE-2024-49287 Patchstack
7.5 High Point Maker Plugin point-maker Local File Inclusion ≤ 0.1.4 Fixed in 0.1.5 CVE-2024-49317 Patchstack
8.6 High FREE DOWNLOAD MANAGER Plugin free-download-manager Arbitrary File Deletion No login needed ≤ 1.0.0 CVE-2024-49315 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.3.1 CVE-2024-48021 Patchstack
7.1 High Restaurant Reservations Widget Plugin restaurantconnect-reswidget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-48023 Patchstack
7.1 High Featured Posts with Multiple Custom Groups (FPMCG) Plugin featured-posts-with-multiple-custom-groups-fpmcg Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0 CVE-2024-48032 Patchstack
7.1 High Wsify Widget Plugin wsify-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-48048 Patchstack
7.6 High ShortPixel Image Optimizer Plugin shortpixel-image-optimiser SQL Injection ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-48043 Patchstack
7.5 High Keep Backup Daily Plugin keep-backup-daily Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.3 CVE-2024-48024 Patchstack
7.1 High Encyclopedia / Glossary / Wiki Plugin encyclopedia-lexicon-glossary-wiki-dictionary Cross-Site Scripting No login needed ≤ 1.7.60 Fixed in 1.7.61 CVE-2024-49320 Patchstack
7.1 High disconnected Theme disconnected Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-49268 Patchstack
7.5 High Ahime Image Printer Plugin ahime-image-printer Path Traversal Arbitrary File Download No login needed ≤ 1.0.0 CVE-2024-49245 Patchstack
7.5 High MaxSlider Plugin maxslider Local File Inclusion ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-47351 Patchstack
7.5 High Top Bar – PopUps – by WPOptin Plugin wpoptin Local File Inclusion No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-47645 Patchstack
7.5 High SB Random Posts Widget Plugin sb-random-posts-widget Local File Inclusion ≤ 1.0 Fixed in 1.1 CVE-2024-48029 Patchstack
7.5 High Maan Addons For Elementor Plugin maan-elementor-addons Local File Inclusion ≤ 1.0.1 CVE-2024-49251 Patchstack
8.8 High TAKETIN To WP Membership Plugin taketin-to-wp-membership PHP Object Injection ≤ 2.8.17 CVE-2024-49226 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only