WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 6,151–6,200 of 6,408 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.7 High | Product Designer | PHP Object Injection No login needed |
≤ 1.0.32 Fixed in 1.0.33 |
CVE-2024-31277 |
Patchstack | |
| 7.2 High | RapidLoad Power-Up for Autoptimize | Server-Side Request Forgery No login needed |
≤ 2.2.11 Fixed in 2.2.12 |
CVE-2024-31288 |
Patchstack | |
| 8.8 High | LearnPress – WordPress LMS | Cross-Site Request Forgery WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation No login needed |
≤ 4.0.0 |
CVE-2024-2115 |
Wordfence | |
| 8.5 High | Slivery Extender | Remote Code Execution |
≤ 1.0.2 Fixed in 1.0.3 |
CVE-2024-27191 |
Patchstack | |
| 7.1 High | Tax Rate Upload | Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed |
≤ 2.4.5 |
CVE-2024-31105 |
Patchstack | |
| 7.1 High | Woocommerce Social Media Share Buttons | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 1.3.0 |
CVE-2024-31109 |
Patchstack | |
| 7.1 High | Responsive Image Gallery, Gallery Album | Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0.3 |
CVE-2024-30550 |
Patchstack | |
| 7.1 High | Sticky Anything | Cross-Site Scripting No login needed |
≤ 2.1.5 |
CVE-2024-30551 |
Patchstack | |
| 7.1 High | Add Shortcodes Actions And Filters | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.10 |
CVE-2024-30558 |
Patchstack | |
| 7.1 High | Appointment Calendar | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.9.6 |
CVE-2024-30561 |
Patchstack | |
| 7.1 High | Weekly Class Schedule | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.19 |
CVE-2024-31084 |
Patchstack | |
| 7.1 High | Post-Plugin Library | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.2.1 |
CVE-2024-31085 |
Patchstack | |
| 7.1 High | pageMash > Page Management | Cross-Site Scripting No login needed |
≤ 1.3.0 |
CVE-2024-31087 |
Patchstack | |
| 7.1 High | Hacklog Down As PDF | Cross-Site Scripting No login needed |
≤ 2.3.6 |
CVE-2024-31090 |
Patchstack | |
| 7.1 High | Custom Field Bulk Editor | Cross-Site Scripting No login needed |
≤ 1.9.1 |
CVE-2024-31091 |
Patchstack | |
| 7.1 High | Comic Easel | Cross-Site Scripting No login needed |
≤ 1.15 |
CVE-2024-31092 |
Patchstack | |
| 7.1 High | SEO Title Tag | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.5.9 |
CVE-2024-31097 |
Patchstack | |
| 7.1 High | Kanban Boards | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.21 |
CVE-2024-31103 |
Patchstack | |
| 7.1 High | Yoo Slider | Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.1 |
CVE-2024-31106 |
Patchstack | |
| 7.1 High | OpenID | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.6.1 |
CVE-2024-31107 |
Patchstack | |
| 7.1 High | Contact Form 7 Newsletter | Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2024-31110 |
Patchstack | |
| 7.1 High | Convert Post Types | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2024-31112 |
Patchstack | |
| 7.1 High | SpiderFAQ | Cross-Site Scripting No login needed |
≤ 1.3.2 |
CVE-2024-31123 |
Patchstack | |
| 8.5 High | WP Cost Estimation & Payment Forms Builder | SQL Injection |
≤ 10.1.75 Fixed in 10.1.76 |
CVE-2024-30489 |
Patchstack | |
| 8.5 High | Easy Form Builder | SQL Injection |
≤ 3.7.4 Fixed in 3.7.5 |
CVE-2024-30535 |
Patchstack | |
| 7.6 High | 10Web Map Builder for Google Maps | SQL Injection |
≤ 1.0.74 |
CVE-2024-31116 |
Patchstack | |
| 7.5 High | Layouts for Elementor | Arbitrary File Upload No login needed |
< 1.8 Fixed in 1.8 |
CVE-2024-30533 |
Patchstack | |
| 8.5 High | Filter Custom Fields & Taxonomies Light | PHP Object Injection |
≤ 1.05 |
CVE-2024-31094 |
Patchstack | |
| 7.1 High | Mang Board WP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.8.0 Fixed in 1.8.1 |
CVE-2024-30431 |
Patchstack | |
| 7.1 High | Nexter Blocks | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.5 Fixed in 3.2.6 |
CVE-2024-30435 |
Patchstack | |
| 7.1 High | Limit Attempts by BestWebSoft | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.9 Fixed in 1.3.0 |
CVE-2024-30439 |
Patchstack | |
| 7.1 High | Post Grid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.74 Fixed in 2.2.76 |
CVE-2024-30441 |
Patchstack | |
| 7.1 High | Creative Image Slider – Responsive Slider | Cross-Site Scripting No login needed |
≤ 2.1.3 Fixed in 2.5.0 |
CVE-2024-30447 |
Patchstack | |
| 7.1 High | Booking Activities | Cross-Site Scripting No login needed |
≤ 1.15.19 Fixed in 1.15.20 |
CVE-2024-30449 |
Patchstack | |
| 7.1 High | All In One Redirection | Cross-Site Scripting No login needed |
≤ 2.2.0 |
CVE-2024-30506 |
Patchstack | |
| 7.6 High | WP Travel Engine | SQL Injection |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-30504 |
Patchstack | |
| 7.6 High | Download Monitor | SQL Injection Auth. SQL Injection |
≤ 4.9.4 Fixed in 4.9.5 |
CVE-2024-30501 |
Patchstack | |
| 8.5 High | CRM Perks Forms | SQL Injection |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2024-30499 |
Patchstack | |
| 8.5 High | WP Responsive Tabs horizontal vertical and accordion Tabs | SQL Injection |
≤ 1.1.17 Fixed in 1.1.18 |
CVE-2024-30497 |
Patchstack | |
| 8.5 High | Element Pack Elementor Addons | SQL Injection |
≤ 5.5.3 Fixed in 5.5.4 |
CVE-2024-30496 |
Patchstack | |
| 7.6 High | Falang multilanguage | SQL Injection |
≤ 1.3.47 Fixed in 1.3.48 |
CVE-2024-30495 |
Patchstack | |
| 7.6 High | OSS Aliyun | SQL Injection |
≤ 1.4.10 Fixed in 1.4.11 |
CVE-2024-30494 |
Patchstack | |
| 8.5 High | ProfileGrid | SQL Injection User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - SQL Injection |
≤ 5.7.8 Fixed in 5.7.9 |
CVE-2024-30491 |
Patchstack | |
| 8.5 High | Zotpress | SQL Injection |
≤ 7.3.7 Fixed in 7.3.8 |
CVE-2024-30488 |
Patchstack | |
| 7.6 High | MP3 Audio Player for Music, Radio & Podcast by Sonaar | Broken Access Control |
≤ 5.1 Fixed in 5.1.1 |
CVE-2024-30487 |
Patchstack | |
| 8.5 High | Media Library Folders | SQL Injection Auth. SQL Injection |
≤ 8.1.7 Fixed in 8.1.8 |
CVE-2024-30486 |
Patchstack | |
| 7.6 High | WordPress Announcement & Notification Banner Plugin – Bulletin | SQL Injection Bulletin plugin <= 3.8.5 - SQL Injection |
≤ 3.8.5 Fixed in 3.9.0 |
CVE-2024-30478 |
Patchstack | |
| 7.1 High | Contest Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 24.0.3 Fixed in 24.0.4 |
CVE-2024-30428 |
Patchstack | |
| 7.1 High | Jobeleon | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2022-47153 |
Patchstack | |
| 7.1 High | Mailster | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2024-30503 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.