WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 6,301–6,350 of 6,408 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Link Library | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 7.6 Fixed in 7.6.1 |
CVE-2024-29123 |
Patchstack | |
| 7.1 High | Coupon Affiliates | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.12.7 Fixed in 5.12.8 |
CVE-2024-29125 |
Patchstack | |
| 7.1 High | Specific Content For Mobile – Customize the mobile version without redirections | Cross-Site Scripting No login needed |
≤ 0.1.9.5 Fixed in 0.1.9.6 |
CVE-2024-29126 |
Patchstack | |
| 7.1 High | Advanced Access Manager | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.9.20 Fixed in 6.9.21 |
CVE-2024-29127 |
Patchstack | |
| 7.1 High | POST SMTP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.8.6 Fixed in 2.8.7 |
CVE-2024-29128 |
Patchstack | |
| 7.1 High | OxyExtras | Cross-Site Scripting No login needed |
≤ 1.4.4 Fixed in 1.4.5 |
CVE-2024-29129 |
Patchstack | |
| 7.1 High | Contact Form 7 – PayPal & Stripe Add-on | Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.0 Fixed in 2.1 |
CVE-2024-29130 |
Patchstack | |
| 8.5 High | Tourfic | PHP Object Injection |
≤ 2.11.17 Fixed in 2.11.19 |
CVE-2024-29136 |
Patchstack | |
| 7.1 High | Tourfic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.11.7 Fixed in 2.11.8 |
CVE-2024-29137 |
Patchstack | |
| 7.1 High | Restrict User Access – Membership Plugin with Force | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5 Fixed in 2.6 |
CVE-2024-29138 |
Patchstack | |
| 7.1 High | MyCurator Content Curation | Cross-Site Scripting No login needed |
≤ 3.76 Fixed in 3.77 |
CVE-2024-29139 |
Patchstack | |
| 7.1 High | Better Search – Relevant search results | Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed |
≤ 3.3.0 Fixed in 3.3.1 |
CVE-2024-29142 |
Patchstack | |
| 7.1 High | AntiSpam for Contact Form 7 | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.6.0 Fixed in 0.6.1 |
CVE-2024-27961 |
Patchstack | |
| 7.1 High | Email Subscription Popup | Cross-Site Scripting No login needed |
≤ 1.2.20 Fixed in 1.2.21 |
CVE-2024-27960 |
Patchstack | |
| 7.1 High | WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management | Cross-Site Scripting No login needed |
≤ 4.2.9 Fixed in 4.3 |
CVE-2024-27959 |
Patchstack | |
| 7.1 High | Visualizer | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.10.5 Fixed in 3.10.6 |
CVE-2024-27958 |
Patchstack | |
| 7.1 High | Fontific | Google Fonts | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 0.1.6 |
CVE-2024-27194 |
Patchstack | |
| 7.1 High | Watermark RELOADED | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 1.3.5 Fixed in 1.4.0 |
CVE-2024-27195 |
Patchstack | |
| 7.1 High | BeePress | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 6.9.8 |
CVE-2024-27197 |
Patchstack | |
| 8.8 High | TerraClassifieds | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed |
≤ 2.0.3 |
CVE-2023-51474 |
Patchstack | |
| 7.1 High | Ultimate Reviews | Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed |
≤ 3.2.8 Fixed in 3.2.9 |
CVE-2024-25597 |
Patchstack | |
| 7.1 High | Action Network | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4.2 Fixed in 1.4.3 |
CVE-2024-25921 |
Patchstack | |
| 7.1 High | PayU India | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.8.8 Fixed in 3.8.9 |
CVE-2024-27193 |
Patchstack | |
| 7.1 High | postMash – custom post order | Cross-Site Scripting custom post order plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.0 |
CVE-2024-27196 |
Patchstack | |
| 7.1 High | Configure SMTP | Cross-Site Scripting WordPress Configure SMTP Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.1 |
CVE-2024-27192 |
Patchstack | |
| 7.1 High | GiveWP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.3.1 Fixed in 3.4.0 |
CVE-2024-27987 |
Patchstack | |
| 7.1 High | Advanced Sermons | Cross-Site Scripting No login needed |
≤ 3.2 Fixed in 3.3 |
CVE-2024-27952 |
Patchstack | |
| 8.6 High | Hustle | Information Disclosure Sensitive Information Exposure via Exposed Hubspot API Keys No login needed |
≤ 7.8.3 |
CVE-2024-0368 |
Wordfence | |
| 8.8 High | Academy LMS – eLearning and online course solution | Privilege Escalation eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation |
≤ 1.9.19 |
CVE-2024-1505 |
Wordfence | |
| 8.8 High | Digits: WordPress Mobile Number Signup and Login | Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed |
8.4.1 |
CVE-2024-0203 |
Wordfence | |
| 8.8 High | Vimeography: Vimeo Video Gallery | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 2.3.2 |
CVE-2024-0825 |
Wordfence | |
| 7.1 High | GD Rating System | Cross-Site Scripting WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.5 Fixed in 3.5.1 |
CVE-2024-25093 |
Patchstack | |
| 7.1 High | WP Activity Log | Cross-Site Scripting WordPress WP Activity Log Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.6.1 Fixed in 4.6.2 |
CVE-2023-50905 |
Patchstack | |
| 7.1 High | Ajax Search Lite | Cross-Site Scripting WordPress Ajax Search Lite Plugin <= 4.11.4 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.11.4 Fixed in 4.11.5 |
CVE-2024-21752 |
Patchstack | |
| 7.1 High | Adsmonetizer | Cross-Site Scripting WordPress Adsmonetizer Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.1.2 Fixed in 3.1.3 |
CVE-2024-1437 |
Patchstack | |
| 8.8 High | Avada | Website Builder For WordPress & WooCommerce | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.11.4 |
CVE-2024-1468 |
Wordfence | |
| 8.5 High | SP Project & Document Manager | SQL Injection WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection |
≤ 4.69 Fixed in 4.70 |
CVE-2024-24868 |
Patchstack | |
| 7.6 High | Malware Scanner | SQL Injection WordPress Malware Scanner Plugin <= 4.7.2 is vulnerable to SQL Injection |
≤ 4.7.2 |
CVE-2024-25902 |
Patchstack | |
| 7.2 High | Icons Font Loader | Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2024-24714 |
Patchstack | |
| 7.1 High | Sitepact | SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed |
≤ 1.0.5 Fixed in 3.0.0 |
CVE-2024-25928 |
Patchstack | |
| 7.1 High | PowerPack Pro for Elementor | Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed |
< 2.10.8 Fixed in 2.10.8 |
CVE-2024-24843 |
Patchstack | |
| 7.6 High | Contact Form builder with drag & drop for WordPress – Kali Forms | Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation |
≤ 2.3.41 |
CVE-2024-1217 |
Wordfence | |
| 8.7 High | ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2024-23512 |
Patchstack | |
| 8.7 High | PropertyHive | PHP Object Injection WordPress PropertyHive Plugin <= 2.0.5 is vulnerable to PHP Object Injection No login needed |
≤ 2.0.5 Fixed in 2.0.6 |
CVE-2024-23513 |
Patchstack | |
| 8.2 High | Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – | PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection |
≤ 4.1.1 Fixed in 4.1.2 |
CVE-2024-24796 |
Patchstack | |
| 7.5 High | Brooklyn | Creative Multi-Purpose Responsive | PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection |
≤ 4.9.7.6 |
CVE-2024-24926 |
Patchstack | |
| 7.1 High | Brooklyn | Creative Multi-Purpose Responsive | Cross-Site Scripting WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 4.9.7.6 |
CVE-2024-24927 |
Patchstack | |
| 7.1 High | VK Poster Group | Cross-Site Scripting WordPress VK Poster Group Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 2.0.3 |
CVE-2024-24932 |
Patchstack | |
| 7.1 High | Honeypot for WP Comment | Cross-Site Scripting WordPress Honeypot for WP Comment Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 2.2.3 |
CVE-2024-24933 |
Patchstack | |
| 7.1 High | Crowdsignal Dashboard – Polls, Surveys & more | Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed |
≤ 3.0.11 Fixed in 3.1.0 |
CVE-2023-51488 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.