WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 6,151–6,200 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 124 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.7 High Product Designer Plugin product-designer PHP Object Injection No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2024-31277 Patchstack
7.2 High RapidLoad Power-Up for Autoptimize Plugin unusedcss Server-Side Request Forgery No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-31288 Patchstack
8.8 High LearnPress – WordPress LMS Plugin learnpress Cross-Site Request Forgery WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.0.0 CVE-2024-2115 Wordfence
8.5 High Slivery Extender Plugin slivery-extender Remote Code Execution ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-27191 Patchstack
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2024-31105 Patchstack
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
7.1 High Sticky Anything Plugin toast-stick-anything Cross-Site Scripting No login needed ≤ 2.1.5 CVE-2024-30551 Patchstack
7.1 High Add Shortcodes Actions And Filters Plugin add-actions-and-filters Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.10 CVE-2024-30558 Patchstack
7.1 High Appointment Calendar Plugin appointment-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.6 CVE-2024-30561 Patchstack
7.1 High Weekly Class Schedule Plugin weekly-class-schedule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.19 CVE-2024-31084 Patchstack
7.1 High Post-Plugin Library Plugin post-plugin-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2.1 CVE-2024-31085 Patchstack
7.1 High pageMash > Page Management Plugin pagemash Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2024-31087 Patchstack
7.1 High Hacklog Down As PDF Plugin down-as-pdf Cross-Site Scripting No login needed ≤ 2.3.6 CVE-2024-31090 Patchstack
7.1 High Custom Field Bulk Editor Plugin custom-field-bulk-editor Cross-Site Scripting No login needed ≤ 1.9.1 CVE-2024-31091 Patchstack
7.1 High Comic Easel Plugin comic-easel Cross-Site Scripting No login needed ≤ 1.15 CVE-2024-31092 Patchstack
7.1 High SEO Title Tag Plugin seo-title-tag Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.9 CVE-2024-31097 Patchstack
7.1 High Kanban Boards Plugin kanban Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.21 CVE-2024-31103 Patchstack
7.1 High Yoo Slider Plugin yoo-slider Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2024-31106 Patchstack
7.1 High OpenID Plugin openid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.1 CVE-2024-31107 Patchstack
7.1 High Contact Form 7 Newsletter Plugin contact-form-7-newsletter Cross-Site Scripting No login needed ≤ 2.2 CVE-2024-31110 Patchstack
7.1 High Convert Post Types Plugin convert-post-types Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-31112 Patchstack
7.1 High SpiderFAQ Plugin spider-faq Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2024-31123 Patchstack
8.5 High WP Cost Estimation & Payment Forms Builder Plugin SQL Injection ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-30489 Patchstack
8.5 High Easy Form Builder Plugin easy-form-builder SQL Injection ≤ 3.7.4 Fixed in 3.7.5 CVE-2024-30535 Patchstack
7.6 High 10Web Map Builder for Google Maps Plugin wd-google-maps SQL Injection ≤ 1.0.74 CVE-2024-31116 Patchstack
7.5 High Layouts for Elementor Plugin layouts-for-elementor Arbitrary File Upload No login needed < 1.8 Fixed in 1.8 CVE-2024-30533 Patchstack
8.5 High Filter Custom Fields & Taxonomies Light Plugin filter-custom-fields-taxonomies-light PHP Object Injection ≤ 1.05 CVE-2024-31094 Patchstack
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-30431 Patchstack
7.1 High Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2024-30435 Patchstack
7.1 High Limit Attempts by BestWebSoft Plugin limit-attempts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-30439 Patchstack
7.1 High Post Grid Plugin post-grid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.74 Fixed in 2.2.76 CVE-2024-30441 Patchstack
7.1 High Creative Image Slider – Responsive Slider Plugin creative-image-slider Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.5.0 CVE-2024-30447 Patchstack
7.1 High Booking Activities Plugin booking-activities Cross-Site Scripting No login needed ≤ 1.15.19 Fixed in 1.15.20 CVE-2024-30449 Patchstack
7.1 High All In One Redirection Plugin all-in-one-redirection-404-pages-list Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-30506 Patchstack
7.6 High WP Travel Engine Plugin wp-travel-engine SQL Injection ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-30504 Patchstack
7.6 High Download Monitor Plugin download-monitor SQL Injection Auth. SQL Injection ≤ 4.9.4 Fixed in 4.9.5 CVE-2024-30501 Patchstack
8.5 High CRM Perks Forms Plugin crm-perks-forms SQL Injection ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-30499 Patchstack
8.5 High WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs SQL Injection ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-30497 Patchstack
8.5 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30496 Patchstack
7.6 High Falang multilanguage Plugin falang SQL Injection ≤ 1.3.47 Fixed in 1.3.48 CVE-2024-30495 Patchstack
7.6 High OSS Aliyun Plugin oss-aliyun SQL Injection ≤ 1.4.10 Fixed in 1.4.11 CVE-2024-30494 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - SQL Injection ≤ 5.7.8 Fixed in 5.7.9 CVE-2024-30491 Patchstack
8.5 High Zotpress Plugin zotpress SQL Injection ≤ 7.3.7 Fixed in 7.3.8 CVE-2024-30488 Patchstack
7.6 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.1 Fixed in 5.1.1 CVE-2024-30487 Patchstack
8.5 High Media Library Folders Plugin media-library-plus SQL Injection Auth. SQL Injection ≤ 8.1.7 Fixed in 8.1.8 CVE-2024-30486 Patchstack
7.6 High WordPress Announcement & Notification Banner Plugin – Bulletin Plugin bulletin-announcements SQL Injection Bulletin plugin <= 3.8.5 - SQL Injection ≤ 3.8.5 Fixed in 3.9.0 CVE-2024-30478 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-30428 Patchstack
7.1 High Jobeleon Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2022-47153 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2024-30503 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only