WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 6,301–6,350 of 6,408 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 127 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6 Fixed in 7.6.1 CVE-2024-29123 Patchstack
7.1 High Coupon Affiliates Plugin woo-coupon-usage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.12.7 Fixed in 5.12.8 CVE-2024-29125 Patchstack
7.1 High Specific Content For Mobile – Customize the mobile version without redirections Plugin specific-content-for-mobile Cross-Site Scripting No login needed ≤ 0.1.9.5 Fixed in 0.1.9.6 CVE-2024-29126 Patchstack
7.1 High Advanced Access Manager Plugin advanced-access-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.9.20 Fixed in 6.9.21 CVE-2024-29127 Patchstack
7.1 High POST SMTP Plugin post-smtp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-29128 Patchstack
7.1 High OxyExtras Plugin Cross-Site Scripting No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-29129 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2024-29130 Patchstack
8.5 High Tourfic Plugin tourfic PHP Object Injection ≤ 2.11.17 Fixed in 2.11.19 CVE-2024-29136 Patchstack
7.1 High Tourfic Plugin tourfic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.11.7 Fixed in 2.11.8 CVE-2024-29137 Patchstack
7.1 High Restrict User Access – Membership Plugin with Force Plugin restrict-user-access Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.6 CVE-2024-29138 Patchstack
7.1 High MyCurator Content Curation Plugin mycurator Cross-Site Scripting No login needed ≤ 3.76 Fixed in 3.77 CVE-2024-29139 Patchstack
7.1 High Better Search – Relevant search results Plugin better-search Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2024-29142 Patchstack
7.1 High AntiSpam for Contact Form 7 Plugin cf7-antispam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.0 Fixed in 0.6.1 CVE-2024-27961 Patchstack
7.1 High Email Subscription Popup Plugin email-subscribe Cross-Site Scripting No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2024-27960 Patchstack
7.1 High WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management Plugin woosquare Cross-Site Scripting No login needed ≤ 4.2.9 Fixed in 4.3 CVE-2024-27959 Patchstack
7.1 High Visualizer Plugin visualizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.10.5 Fixed in 3.10.6 CVE-2024-27958 Patchstack
7.1 High Fontific | Google Fonts Plugin fontific Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.1.6 CVE-2024-27194 Patchstack
7.1 High Watermark RELOADED Plugin watermark-reloaded Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.5 Fixed in 1.4.0 CVE-2024-27195 Patchstack
7.1 High BeePress Plugin beepress Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 6.9.8 CVE-2024-27197 Patchstack
8.8 High TerraClassifieds Plugin terraclassifieds Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.0.3 CVE-2023-51474 Patchstack
7.1 High Ultimate Reviews Plugin ultimate-reviews Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-25597 Patchstack
7.1 High Action Network Plugin wp-action-network Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-25921 Patchstack
7.1 High PayU India Plugin payu-india Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.8 Fixed in 3.8.9 CVE-2024-27193 Patchstack
7.1 High postMash – custom post order Plugin postmash Cross-Site Scripting custom post order plugin <= 1.2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2024-27196 Patchstack
7.1 High Configure SMTP Plugin configure-smtp Cross-Site Scripting WordPress Configure SMTP Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.1 CVE-2024-27192 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.1 Fixed in 3.4.0 CVE-2024-27987 Patchstack
7.1 High Advanced Sermons Plugin advanced-sermons Cross-Site Scripting No login needed ≤ 3.2 Fixed in 3.3 CVE-2024-27952 Patchstack
8.6 High Hustle Plugin wordpress-popup Information Disclosure Sensitive Information Exposure via Exposed Hubspot API Keys No login needed ≤ 7.8.3 CVE-2024-0368 Wordfence
8.8 High Academy LMS – eLearning and online course solution Plugin academy Privilege Escalation eLearning and online course solution for WordPress <= 1.9.19 - Authenticated (Subscriber+) Privilege Escalation ≤ 1.9.19 CVE-2024-1505 Wordfence
8.8 High Digits: WordPress Mobile Number Signup and Login Plugin Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed 8.4.1 CVE-2024-0203 Wordfence
8.8 High Vimeography: Vimeo Video Gallery Plugin vimeography PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.3.2 CVE-2024-0825 Wordfence
7.1 High GD Rating System Plugin gd-rating-system Cross-Site Scripting WordPress GD Rating System Plugin <= 3.5 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.5 Fixed in 3.5.1 CVE-2024-25093 Patchstack
7.1 High WP Activity Log Plugin wp-security-audit-log Cross-Site Scripting WordPress WP Activity Log Plugin <= 4.6.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2023-50905 Patchstack
7.1 High Ajax Search Lite Plugin ajax-search-lite Cross-Site Scripting WordPress Ajax Search Lite Plugin <= 4.11.4 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.11.4 Fixed in 4.11.5 CVE-2024-21752 Patchstack
7.1 High Adsmonetizer Plugin adsensei-b30 Cross-Site Scripting WordPress Adsmonetizer Plugin <= 3.1.2 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-1437 Patchstack
8.8 High Avada | Website Builder For WordPress & WooCommerce Theme Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 7.11.4 CVE-2024-1468 Wordfence
8.5 High SP Project & Document Manager Plugin sp-client-document-manager SQL Injection WordPress SP Project & Document Manager Plugin <= 4.69 is vulnerable to SQL Injection ≤ 4.69 Fixed in 4.70 CVE-2024-24868 Patchstack
7.6 High Malware Scanner Plugin miniorange-malware-protection SQL Injection WordPress Malware Scanner Plugin <= 4.7.2 is vulnerable to SQL Injection ≤ 4.7.2 CVE-2024-25902 Patchstack
7.2 High Icons Font Loader Plugin icons-font-loader Arbitrary File Upload WordPress Icons Font Loader Plugin <= 1.1.4 is vulnerable to Arbitrary File Upload ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-24714 Patchstack
7.1 High Sitepact Plugin sitepact-klaviyo-contact-form-7 SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed ≤ 1.0.5 Fixed in 3.0.0 CVE-2024-25928 Patchstack
7.1 High PowerPack Pro for Elementor Plugin Cross-Site Request Forgery WordPress PowerPack Pro for Elementor Plugin < 2.10.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed < 2.10.8 Fixed in 2.10.8 CVE-2024-24843 Patchstack
7.6 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation ≤ 2.3.41 CVE-2024-1217 Wordfence
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
8.7 High PropertyHive Plugin propertyhive PHP Object Injection WordPress PropertyHive Plugin <= 2.0.5 is vulnerable to PHP Object Injection No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2024-23513 Patchstack
8.2 High Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – Plugin mage-eventpress PHP Object Injection WordPress Event Manager for WooCommerce Plugin <= 4.1.1 is vulnerable to PHP Object Injection ≤ 4.1.1 Fixed in 4.1.2 CVE-2024-24796 Patchstack
7.5 High Brooklyn | Creative Multi-Purpose Responsive Theme PHP Object Injection WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to PHP Object Injection ≤ 4.9.7.6 CVE-2024-24926 Patchstack
7.1 High Brooklyn | Creative Multi-Purpose Responsive Theme Cross-Site Scripting WordPress Brooklyn Theme <= 4.9.7.6 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 4.9.7.6 CVE-2024-24927 Patchstack
7.1 High VK Poster Group Plugin vk-poster-group Cross-Site Scripting WordPress VK Poster Group Plugin <= 2.0.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-24932 Patchstack
7.1 High Honeypot for WP Comment Plugin honeypot-for-wp-comment Cross-Site Scripting WordPress Honeypot for WP Comment Plugin <= 2.2.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2024-24933 Patchstack
7.1 High Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51488 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only