WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 6,251–6,300 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 126 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-30194 Patchstack
7.1 High New RoyalSlider Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2024-30195 Patchstack
7.1 High Easy Social Share Buttons Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.4 Fixed in 9.5 CVE-2024-30196 Patchstack
7.1 High WordPress Importer Plugin wp-smart-import Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-30201 Patchstack
7.1 High WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2024-30199 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.5.41.7212 Fixed in 7.5.44.7212 CVE-2024-22299 Patchstack
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.11 Fixed in 5.7.12 CVE-2024-22300 Patchstack
7.1 High CformsII Plugin cforms2 Cross-Site Scripting No login needed ≤ 15.0.5 CVE-2024-22149 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack
7.1 High WP Editor Plugin wp-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-24700 Patchstack
7.1 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.2.5 Fixed in 13.2.6 CVE-2024-24800 Patchstack
7.1 High Widgets Controller Plugin widgets-controller Cross-Site Scripting No login needed ≤ 1.1 CVE-2024-25926 Patchstack
7.1 High Fusion Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39306 Patchstack
7.1 High Simply Schedule Appointments Plugin simply-schedule-appointments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6.20 Fixed in 1.6.6.24 CVE-2024-22311 Patchstack
8.7 High Knowledge Base for Documentation, FAQs with AI Assistance Plugin echo-knowledge-base PHP Object Injection No login needed ≤ 11.30.2 Fixed in 11.31.0 CVE-2024-24842 Patchstack
8.0 High Widgets for Google Reviews Plugin wp-reviews-plugin-for-google Arbitrary File Upload ≤ 11.0.2 Fixed in 11.1 CVE-2023-48275 Patchstack
8.5 High Avada Theme Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39307 Patchstack
7.1 High Glaze Blog Lite Theme glaze-blog-lite Cross-Site Scripting Reflected Cross-Site Scripting (XSS) vulnerability in multiple WordPress themes No login needed ≤ <= 1.1.4, ≤ 1.0.8, ≤ 2.1.3, … Fixed in 1.1.5 CVE-2023-28687 Patchstack
7.4 High User Registration Plugin user-registration PHP Object Injection Authenticated PHP Object Injection ≤ 2.3.2.1 Fixed in 2.3.3 CVE-2023-27459 Patchstack
7.2 High Types Plugin Arbitrary File Upload Authenticated Arbitrary File Upload ≤ 3.4.17 Fixed in 3.4.18 CVE-2023-27440 Patchstack
7.2 High Theme Editor Plugin theme-editor Arbitrary File Upload ≤ 2.7.1 Fixed in 2.8 CVE-2023-6091 Patchstack
7.5 High CF7 Google Sheets Connector Plugin cf7-google-sheets-connector Information Disclosure Sensitive Data Exposure via Debug Log No login needed ≤ 5.0.5 Fixed in 5.0.6 CVE-2023-44989 Patchstack
7.6 High Booking Calendar Plugin booking SQL Injection ≤ 9.4.3 Fixed in 9.4.3.1 CVE-2023-23991 Patchstack
7.1 High Front End Users Plugin front-end-only-users Cross-Site Scripting No login needed < 3.2.25 Fixed in 3.2.25 CVE-2023-33322 Patchstack
7.1 High Contact Form With Captcha Plugin contact-form-with-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 CVE-2023-45771 Patchstack
7.1 High Cosmetsy theme (core plugin) Plugin Cross-Site Scripting Reflected Cross-Site Scripting vulnerability in multiple WordPress components by KlbTheme No login needed ≤ 1.3.0, ≤ 1.0.9, ≤ 1.3.3, … CVE-2023-49839 Patchstack
7.3 High Youzify - Buddypress Moderation Plugin youzify-moderation Cross-Site Scripting Buddypress Moderation plugin <= 1.2.5 - Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2024-2864 Patchstack
8.2 High EventPrime Plugin eventprime-event-calendar-management Broken Access Control No login needed ≤ 3.3.9 Fixed in 3.4.0 CVE-2024-24832 Patchstack
7.5 High FunnelKit Checkout Plugin Broken Access Control Unauthenticated Arbitrary Post/Page Deletion No login needed ≤ 3.10.3 Fixed in 3.11.0 CVE-2023-51672 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
7.1 High wp-mpdf Plugin wp-mpdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.1 Fixed in 3.8 CVE-2024-27962 Patchstack
8.8 High Zippy Plugin zippy Arbitrary File Upload ≤ 1.6.9 Fixed in 1.6.10 CVE-2024-27964 Patchstack
7.1 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.8 Fixed in 0.6.9 CVE-2024-27992 Patchstack
7.1 High Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-27993 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting No login needed ≤ 4.5.0 Fixed in 4.6.0 CVE-2024-27994 Patchstack
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
8.2 High Olive One Click Demo Import Plugin olive-one-click-demo-import Broken Access Control No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-2702 Patchstack
8.8 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin SQL Injection The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 6.8.6 CVE-2024-1799 Wordfence
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-27998 Patchstack
7.1 High WP Armour – Honeypot Anti Spam Plugin honeypot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2024-29091 Patchstack
7.1 High Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.3 Fixed in 2.4.3.1 CVE-2024-29092 Patchstack
7.1 High HT Easy GA4 ( Google Analytics 4 ) Plugin ht-easy-google-analytics Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-29094 Patchstack
7.1 High Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-29099 Patchstack
7.1 High Extensions For CF7 Plugin extensions-for-cf7 Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29102 Patchstack
7.1 High Database for Contact Form 7 Plugin cf7-database Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29103 Patchstack
7.1 High Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Scripting No login needed ≤ 1.0.27 Fixed in 1.0.28 CVE-2024-29110 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-29113 Patchstack
7.1 High WooThumbs for WooCommerce by Iconic Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-29116 Patchstack
7.1 High Contact Forms by Cimatti Plugin contact-forms Cross-Site Scripting Unauthenticated Stored Cross Site Scripting (XSS) No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-29117 Patchstack
7.1 High WooCommerce License Manager Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-29121 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only