WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 6,251–6,300 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 126 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Advanced Event Manager Plugin advanced-event-manager Cross-Site Scripting ≤ 1.1.6 CVE-2024-53721 Patchstack
6.5 Medium Simple Popup Plugin simple-popup-plugin Cross-Site Scripting ≤ 4.6 CVE-2024-53741 Patchstack
5.4 Medium Build App Online Plugin build-app-online Cross-Site Request Forgery No login needed ≤ 1.0.23 CVE-2024-53751 Patchstack
5.4 Medium WP Revisions Manager Plugin wp-revisions-manager Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2024-53761 Patchstack
4.3 Medium DancePress (TRWA) Plugin dancepress-trwa Cross-Site Request Forgery No login needed ≤ 3.1.11 CVE-2024-53775 Patchstack
4.3 Medium Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2024-53784 Patchstack
6.5 Medium Countdown Timer for Elementor Plugin countdown-timer-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-53743 Patchstack
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
6.5 Medium 소셜 공유 버튼 By 코스모스팜 Plugin cosmosfarm-share-buttons Cross-Site Scripting ≤ 1.9 CVE-2024-53745 Patchstack
6.5 Medium Elementor Button Plus Plugin fd-elementor-button-plus Cross-Site Scripting ≤ 1.3.9 CVE-2024-53746 Patchstack
6.5 Medium Video Player for WPBakery Plugin video-player-for-wpbakery Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2024-53747 Patchstack
6.5 Medium WP Mermaid Plugin wp-mermaid Cross-Site Scripting ≤ 1.0.2 CVE-2024-53748 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
6.5 Medium Stripe Donation Plugin bin-stripe-donation Cross-Site Scripting ≤ 1.2.5 CVE-2024-53752 Patchstack
6.5 Medium Vertical Carousel Plugin vertical-carousel-slider Cross-Site Scripting ≤ 1.0.2 CVE-2024-53756 Patchstack
6.5 Medium WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Scripting ≤ 0.3.1 CVE-2024-53757 Patchstack
6.5 Medium WP MathJax Plugin wp-mathjax-plus Cross-Site Scripting ≤ 1.0.1 CVE-2024-53758 Patchstack
6.5 Medium Capitalize My Title Plugin capitalize-my-title Cross-Site Scripting ≤ 0.5.3 CVE-2024-53760 Patchstack
6.5 Medium Best Addons for Elementor Plugin best-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2024-53763 Patchstack
6.5 Medium Softtemplates For Elementor Plugin softtemplates-for-elementor Cross-Site Scripting ≤ 1.0.8 CVE-2024-53764 Patchstack
6.5 Medium Devnex Addons For Elementor Plugin devnex-addons-for-elementor Cross-Site Scripting ≤ 1.0.9 CVE-2024-53766 Patchstack
6.5 Medium Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting ≤ 1.0.1 CVE-2024-53767 Patchstack
6.5 Medium SimpleSchema Plugin simpleschema-free Cross-Site Scripting ≤ 1.7.6.9 CVE-2024-53771 Patchstack
6.5 Medium Mail Picker Plugin mail-picker Cross-Site Scripting ≤ 1.0.15 Fixed in 1.0.16 CVE-2024-53772 Patchstack
6.5 Medium Znajdź Pracę z Praca.pl Plugin znajdz-prace-z-pracapl Cross-Site Scripting ≤ 2.2.3 CVE-2024-53773 Patchstack
6.5 Medium Sparkle Elementor Kit Plugin sparkle-elementor-kit Cross-Site Scripting ≤ 2.0.9 CVE-2024-53774 Patchstack
6.5 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2024-53786 Patchstack
6.5 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-53787 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
5.3 Medium Content Audit Exporter Plugin content-audit-exporter Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-53768 Patchstack
4.4 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery ≤ 1.3.9.8 Fixed in 1.3.9.9 CVE-2024-53738 Patchstack
6.5 Medium Fintelligence Calculator Plugin fintelligence-calculator Cross-Site Scripting ≤ 1.0.3 CVE-2024-53731 Patchstack
6.5 Medium WP Mailster Plugin wp-mailster Cross-Site Scripting ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53737 Patchstack
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission No login needed ≤ 7.8.5 CVE-2024-10580 Wordfence
4.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure ≤ 7.8.5 CVE-2024-10579 Wordfence
6.4 Medium Spotify Play Button Plugin spotify-play-button-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode ≤ 2.11 CVE-2024-11192 Wordfence
6.4 Medium Support SVG – Upload svg files in wordpress without hassle Plugin support-svg Cross-Site Scripting Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload ≤ 1.1.0 CVE-2024-11091 Wordfence
6.4 Medium Tribute Testimonials – WordPress Testimonial Grid/Slider Plugin tribute-testimonial-gridslider Cross-Site Scripting WordPress Testimonial Grid/Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-10886 Wordfence
6.6 Medium GEO My Plugin Arbitrary File Upload Admin+ Arbitrary File Upload 4.0 – < 4.5, < 3.1 Fixed in 4.5 CVE-2024-9422 WPScan
6.1 Medium Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels Plugin wpfunnels Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.5 CVE-2024-10792 Wordfence
6.1 Medium Theater Plugin theatre Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.18.6.2 CVE-2024-11371 Wordfence
4.8 Medium CM Table Of Contents – WordPress TOC Plugin Cross-Site Scripting WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF < 1.2.4 Fixed in 1.2.4 CVE-2024-5029 WPScan
6.4 Medium Dino Game – Embed Google Chrome Dinosaur Game in Plugin dino-game Cross-Site Scripting Embed Google Chrome Dinosaur Game in WordPress <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11388 Wordfence
4.3 Medium Dynamic Widgets Plugin dynamic-widgets Cross-Site Request Forgery No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-51669 Patchstack
6.3 Medium W3SPEEDSTER Plugin w3speedster-wp Cross-Site Request Forgery No login needed ≤ 7.25 Fixed in 7.27 CVE-2024-52392 Patchstack
6.5 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-30424 Patchstack
5.9 Medium WP Roles at Registration Plugin wp-roles-at-registration Cross-Site Scripting ≤ 0.23 CVE-2023-27609 Patchstack
6.5 Medium Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting ≤ 2.8.3.7 Fixed in 2.8.3.9 CVE-2024-50430 Patchstack
5.4 Medium ARMember Plugin armember-membership Cross-Site Request Forgery No login needed ≤ 4.0.5, < 6.7.1 Fixed in 4.0.6 CVE-2022-47424 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only