WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,551–6,600 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 132 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Realty by BestWebSoft Plugin realty Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-51786 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51787 Patchstack
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
6.1 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable Cross-Site Scripting Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting No login needed ≤ 1.8.3 CVE-2024-10876 Wordfence
4.9 Medium Poll Maker Plugin poll-maker SQL Injection Authenticated (Administrator+) Time-Based SQL Injection ≤ 5.4.6 CVE-2024-9874 Wordfence
5.3 Medium Quform - WordPress Form Builder Plugin Information Disclosure WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.20.0 CVE-2024-8756 Wordfence
5.5 Medium Anih - Creative Agency Theme Cross-Site Scripting Creative Agency WordPress Theme <= 2024 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2024 CVE-2024-9775 Wordfence
6.4 Medium Pricing Tables WordPress Plugin – Easy Pricing Tables Plugin easy-pricing-tables Cross-Site Scripting Easy Pricing Tables <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fontFamily Attribute ≤ 3.2.6 CVE-2024-8323 Wordfence
6.4 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block ≤ 2.94.1 CVE-2024-10715 Wordfence
6.1 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Cross-Site Scripting Drag & Drop Contact Form Builder for WordPress <= 1.9.244 - Reflected Cross-Site Scripting via URL No login needed ≤ 1.9.244 CVE-2024-10647 Wordfence
6.5 Medium Knowledge Base Plugin knowledgebase Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-51677 Patchstack
6.5 Medium Elo Rating Shortcode Plugin elo-rating-shortcode Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51678 Patchstack
6.5 Medium Cresta Addons for Elementor Plugin cresta-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-51680 Patchstack
6.5 Medium WP Pocket URLs Plugin wp-pocket-urls Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51681 Patchstack
6.5 Medium HT Builder – WordPress Theme Builder for Elementor Plugin ht-builder Cross-Site Scripting WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-51682 Patchstack
6.5 Medium Custom post type templates for Elementor Plugin custom-post-type-templates-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.1 Fixed in 1.1.12 CVE-2024-51683 Patchstack
5.9 Medium Accordion title for Elementor Plugin accordion-title-for-elementor Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-51685 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
6.1 Medium ReCaptcha Integration Plugin wp-recaptcha-integration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-8739 Wordfence
6.5 Medium User Rights Access Manager Plugin user-rights-access-manager Broken Access Control ≤ 1.1.2 CVE-2024-37209 Patchstack
6.5 Medium Htaccess File Editor Plugin htaccess-file-editor Broken Access Control ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-49256 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control ≤ 3.12.3 Fixed in 3.12.4 CVE-2024-48045 Patchstack
5.4 Medium ShortPixel Image Optimizer Plugin shortpixel-image-optimiser Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-48044 Patchstack
4.3 Medium CubeWP Plugin cubewp-framework Broken Access Control ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-48039 Patchstack
5.3 Medium Wheel of Life Plugin wheel-of-life Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-47311 Patchstack
5.3 Medium Fluent Support Plugin fluent-support Broken Access Control Broken Access Control on Email Verification No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47302 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-44038 Patchstack
5.4 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Broken Access Control Subscriber+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37250 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin Broken Access Control Contributor+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37249 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium Popup box Plugin ays-popup-box Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2024-37096 Patchstack
5.3 Medium Ibtana Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder plugin <= 1.2.3.3 - Broken Access Control No login needed ≤ 1.2.3.3 Fixed in 1.2.3.4 CVE-2024-37123 Patchstack
5.3 Medium Uncanny Automator Pro Plugin uncanny-automator-pro Broken Access Control Unauthenticated License Settings Reset No login needed ≤ 5.3.0.0 Fixed in 5.3.0.1 CVE-2024-37119 Patchstack
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-37204 Patchstack
4.3 Medium Laybuy Payment Extension for WooCommerce Plugin laybuy-gateway-for-woocommerce Broken Access Control ≤ 5.3.9 CVE-2024-37203 Patchstack
5.4 Medium Demo Awesome Plugin demo-awesome Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-37207 Patchstack
6.5 Medium Ali2Woo Lite Plugin ali2woo-lite Broken Access Control Broken Access Control to XSS ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37214 Patchstack
5.3 Medium Optinly Plugin optinly Broken Access Control No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-37220 Patchstack
4.3 Medium Page Builder Sandwich – Front-End Page Builder Plugin page-builder-sandwich Broken Access Control ≤ 5.1.0 CVE-2024-37218 Patchstack
5.3 Medium Kanban Boards Plugin kanban Broken Access Control No login needed ≤ 2.5.21 CVE-2024-37226 Patchstack
4.3 Medium File Manager Plugin wp-file-manager Broken Access Control ≤ 7.2.7 Fixed in 7.2.8 CVE-2024-37254 Patchstack
5.3 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-37269 Patchstack
5.3 Medium ElementsKit Elementor addons Lite Plugin elementskit-lite Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 3.1.4 Fixed in 3.2.0 CVE-2024-37255 Patchstack
5.3 Medium Featured Image from URL Plugin featured-image-from-url Broken Access Control No login needed ≤ 4.8.1 Fixed in 4.8.2 CVE-2024-37276 Patchstack
5.3 Medium Progress Planner Plugin progress-planner Broken Access Control No login needed ≤ 0.9.1 Fixed in 0.9.2 CVE-2024-37411 Patchstack
5.4 Medium e2pdf Plugin e2pdf Broken Access Control No login needed ≤ 1.20.27 Fixed in 1.23.00 CVE-2024-37415 Patchstack
5.4 Medium Newspack Blocks Plugin Broken Access Control ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37425 Patchstack
5.4 Medium Uncanny Toolkit Pro for LearnDash Plugin Broken Access Control Subscriber+ Arbitrary Post/Page Duplication ≤ 4.1.4.0 Fixed in 4.1.4.1 CVE-2024-37439 Patchstack
5.3 Medium Timetics Plugin timetics Broken Access Control No login needed ≤ 1.0.21 Fixed in 1.0.22 CVE-2024-37427 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only