WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,451–6,500 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 130 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium HD Quiz – Save Results Light Plugin hd-quiz-save-results-light Broken Access Control Save Results Light plugin <= 0.5 - Broken Access Control ≤ 0.5 Fixed in 0.6 CVE-2024-49689 Patchstack
4.3 Medium WP VR Plugin wpvr Broken Access Control ≤ 8.5.5 Fixed in 8.5.6 CVE-2024-49680 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-49697 Patchstack
4.3 Medium Easy Accordion Gutenberg Block Plugin easy-accordion-block Broken Access Control ≤ 1.2.3 Fixed in 1.2.5 CVE-2024-51660 Patchstack
4.3 Medium Bold Page Builder Plugin bold-page-builder Broken Access Control ≤ 5.1.3 Fixed in 5.1.4 CVE-2024-50417 Patchstack
5.4 Medium Combo WP Rewrite Slugs Plugin combo-wp-rewrite-slugs Broken Access Control Settings Change ≤ 1.0 CVE-2024-51817 Patchstack
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
6.5 Medium WordPress GDPR Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion No login needed ≤ 2.0.2 CVE-2024-11069 Wordfence
6.5 Medium Stylish Internal Links Plugin stylish-internal-links Cross-Site Scripting ≤ 1.9 CVE-2024-51939 Patchstack
6.5 Medium WP Responsive Video Plugin my-wp-responsive-video Cross-Site Scripting ≤ 1.0 CVE-2024-51940 Patchstack
6.5 Medium Mage Front End Forms Plugin mage-forms Cross-Site Scripting ≤ 1.1.4 CVE-2024-52339 Patchstack
6.5 Medium Photographer Connections Plugin photographer-connections Cross-Site Scripting ≤ 1.3.1 CVE-2024-52340 Patchstack
6.5 Medium OS Our Team Plugin os-our-team Cross-Site Scripting ≤ 1.7 CVE-2024-52341 Patchstack
6.5 Medium OS BXSlider Plugin os-bxslider Cross-Site Scripting ≤ 2.6 CVE-2024-52342 Patchstack
6.5 Medium OS Pricing Tables Plugin os-pricing-tables Cross-Site Scripting ≤ 1.2 CVE-2024-52343 Patchstack
6.5 Medium Provide Forex Signals Plugin provide-forex-signals Cross-Site Scripting ≤ 1.0 CVE-2024-52344 Patchstack
6.5 Medium ra_qrcode Plugin ra-qrcode Cross-Site Scripting ≤ 2.1.0 CVE-2024-52345 Patchstack
6.5 Medium SimpleGMaps Plugin simplegmaps Cross-Site Scripting ≤ 1.0 CVE-2024-52346 Patchstack
6.5 Medium Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera Plugin wp-website-creator Cross-Site Scripting ≤ 4.0 CVE-2024-52347 Patchstack
6.5 Medium AA Audio Player Plugin aa-audio-player Cross-Site Scripting ≤ 1.0 CVE-2024-52348 Patchstack
6.5 Medium Awesome Tool Tip Plugin awesome-tool-tip Cross-Site Scripting ≤ 1.0 CVE-2024-52349 Patchstack
6.5 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-52389 Patchstack
4.9 Medium CYAN Backup Plugin cyan-backup Path Traversal Arbitrary File Download ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-52390 Patchstack
6.5 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.6 Fixed in 1.2.0 CVE-2024-52394 Patchstack
6.5 Medium Copy Anything to Clipboard Plugin copy-the-code Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2024-52419 Patchstack
6.5 Medium WP Githuber MD Plugin wp-githuber-md Cross-Site Scripting ≤ 1.16.3 CVE-2024-52422 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Cross-Site Scripting ≤ 7.6.5 Fixed in 7.6.6 CVE-2024-52423 Patchstack
6.5 Medium Drozd – Addons for Elementor Plugin drozd-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-52425 Patchstack
6.5 Medium Linear Plugin linear Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-52426 Patchstack
5.3 Medium Classified Listing Plugin classified-listing Local File Inclusion ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-52386 Patchstack
6.4 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id and type Parameter ≤ 1.1.1 CVE-2024-10015 Wordfence
5.9 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.8 Fixed in 2.7.8 CVE-2024-10104 WPScan
6.1 Medium LearnPress Export Import – WordPress extension for LearnPress Plugin learnpress-import-export Cross-Site Scripting WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting No login needed ≤ 4.0.4 CVE-2024-9609 Wordfence
4.9 Medium WOLF Plugin bulk-editor Path Traversal CSV Limited Path Traversal ≤ 1.0.8.3 Fixed in 1.0.8.4 CVE-2024-52396 Patchstack
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed ≤ 2.1.7 CVE-2024-10529 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed ≤ 2.1.8 CVE-2024-11143 Wordfence
6.1 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.7 CVE-2024-10684 Wordfence
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Update No login needed ≤ 2.1.7 CVE-2024-10531 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Addition ≤ 2.1.7 CVE-2024-10530 Wordfence
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
6.5 Medium CRM 2go Plugin crm2go Cross-Site Scripting ≤ 1.0 CVE-2024-52350 Patchstack
6.5 Medium BU Slideshow Plugin bu-slideshow Cross-Site Scripting ≤ 2.3.10 CVE-2024-52351 Patchstack
6.5 Medium Postcasa Shortcode Plugin postcasa Cross-Site Scripting ≤ 1.0 CVE-2024-52352 Patchstack
6.5 Medium Christian Science Bible Lesson Subjects Plugin christian-science-bible-lesson-subjects Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-52353 Patchstack
6.5 Medium Web Stories Widgets For Elementor Plugin shortcodes-for-amp-web-stories-and-elementor-widget Cross-Site Scripting ≤ 1.1 Fixed in 1.1.1 CVE-2024-52354 Patchstack
6.5 Medium OSM Plugin osm Cross-Site Scripting OpenStreetMap plugin <= 6.1.2 - Cross Site Scripting (XSS) ≤ 6.1.2 Fixed in 6.1.3 CVE-2024-52355 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-52356 Patchstack
6.5 Medium LIQUID BLOCKS Plugin liquid-blocks Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-52357 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
6.5 Medium MasterBip para Elementor Plugin masterbip-for-elementor Cross-Site Scripting ≤ 1.6.3 CVE-2024-51571 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only