WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,751–6,800 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 136 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.15 Fixed in 1.3.18 CVE-2024-50429 Patchstack
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.14 Fixed in 2.1.15 CVE-2024-50431 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.93 Fixed in 2.2.94 CVE-2024-50432 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.15 Fixed in 2.5.16 CVE-2024-50433 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.80 Fixed in 2.3.81 CVE-2024-50437 Patchstack
6.5 Medium Astra Widgets Plugin astra-widgets Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.14 Fixed in 1.2.15 CVE-2024-50439 Patchstack
6.5 Medium CodePen Embedded Pens Shortcode Plugin codepen-embedded-pen-shortcode Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-50440 Patchstack
6.5 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting ≤ 2.0.15 Fixed in 2.0.16 CVE-2024-50441 Patchstack
6.5 Medium Selection Lite Plugin selection-lite Cross-Site Scripting ≤ 1.13 Fixed in 1.14 CVE-2024-50445 Patchstack
6.5 Medium Futurio Extra Plugin futurio-extra Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-50446 Patchstack
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.19 Fixed in 1.4.20 CVE-2024-50447 Patchstack
6.5 Medium PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Cross-Site Scripting ≤ 1.7.4 Fixed in 1.7.5 CVE-2024-50449 Patchstack
6.5 Medium MDTF Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Cross Site Scripting (XSS) ≤ 1.3.3.4 Fixed in 1.3.3.5 CVE-2024-50451 Patchstack
6.5 Medium Advanced Sermons Plugin advanced-sermons Cross-Site Scripting ≤ 3.4 Fixed in 3.5 CVE-2024-50458 Patchstack
5.9 Medium Firelight Lightbox Plugin easy-fancybox Cross-Site Scripting ≤ 2.3.3 Fixed in 2.3.4 CVE-2024-50460 Patchstack
6.5 Medium EmbedPress Plugin embedpress Cross-Site Scripting ≤ 4.0.14 Fixed in 4.1.0 CVE-2024-50461 Patchstack
6.5 Medium Interactive World Map Plugin interactive-world-map Cross-Site Scripting ≤ 3.4.4 Fixed in 3.4.8 CVE-2024-50462 Patchstack
6.5 Medium Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting ≤ 2.5.0 CVE-2024-50464 Patchstack
6.5 Medium Scrollbar by webxapp – Best vertical/horizontal scrollbars Plugin scrollbar-by-webxapp Cross-Site Scripting ≤ 1.3.0 CVE-2024-50467 Patchstack
6.5 Medium Raptor Editor Plugin wp-raptor Cross-Site Scripting ≤ 1.0.20 CVE-2024-50468 Patchstack
6.5 Medium Textboxes Plugin textboxes Cross-Site Scripting ≤ 0.1.3.1 CVE-2024-50469 Patchstack
6.5 Medium PostX Plugin ultimate-post Cross-Site Scripting ≤ 4.1.12 Fixed in 4.1.13 CVE-2024-50443 Patchstack
6.5 Medium Themes4WP YouTube External Subtitles Plugin themes4wp-youtube-external-subtitles Cross-Site Scripting ≤ 1.0 CVE-2024-50470 Patchstack
6.5 Medium Trip Plan Plugin tripplan Cross-Site Scripting ≤ 1.0.10 Fixed in 2.0.0 CVE-2024-50471 Patchstack
6.5 Medium Amilia Store Plugin amilia-store Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.9.8 CVE-2024-50472 Patchstack
6.5 Medium Kata Plus Plugin kata-plus Cross-Site Scripting ≤ 1.4.7 Fixed in 1.5.0 CVE-2024-50501 Patchstack
6.5 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-50502 Patchstack
4.7 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Open Redirect No login needed ≤ 3.2.9 Fixed in 3.2.11 CVE-2024-50463 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons XML External Entity ≤ 1.3.980 Fixed in 1.3.981 CVE-2024-50442 Patchstack
6.1 Medium FormFacade – WordPress plugin for Google Forms Plugin formfacade Cross-Site Scripting WordPress plugin for Google Forms <= 1.3.6 - Reflected Cross-Site Scripting No login needed ≤ 1.3.6 CVE-2024-9613 Wordfence
6.5 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-49693 Patchstack
6.5 Medium WP Flow Plus Plugin wp-imageflow2 Cross-Site Scripting ≤ 5.2.3 Fixed in 5.2.4 CVE-2024-49695 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 3.2.21 Fixed in 3.2.22 CVE-2024-49696 Patchstack
6.5 Medium myCred Elementor Plugin mycred-for-elementor Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-49702 Patchstack
6.5 Medium WpEvently Plugin mage-eventpress Cross-Site Scripting ≤ 4.2.5 Fixed in 4.2.6 CVE-2024-49703 Patchstack
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.5 Fixed in 1.36 CVE-2024-49683 Patchstack
4.7 Medium Simple Membership Plugin simple-membership Open Redirect No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-49682 Patchstack
6.4 Medium WP Adminify – Best WordPress Custom Dashboard Plugin adminify Cross-Site Scripting Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0.1.6 CVE-2024-8959 Wordfence
4.3 Medium HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce Plugin hurrytimer Broken Access Control An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication ≤ 2.10.0 CVE-2024-8667 Wordfence
6.6 Medium Custom Icons for Elementor Plugin custom-icons-for-elementor Arbitrary File Upload ≤ 0.3.3 Fixed in 0.3.4 CVE-2024-49676 Patchstack
5.3 Medium Responsive Lightbox Plugin responsive-lightbox Broken Access Control No login needed ≤ 2.4.7 Fixed in 2.4.8 CVE-2024-43924 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Request Forgery No login needed ≤ 5.9.3 Fixed in 5.9.3.1 CVE-2024-49273 Patchstack
4.3 Medium WP VR Plugin wpvr Broken Access Control ≤ 8.5.4 Fixed in 8.5.5 CVE-2024-49293 Patchstack
4.3 Medium Simple Custom Post Order Plugin simple-custom-post-order Broken Access Control ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-49321 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Request Forgery No login needed ≤ 4.9.91 CVE-2024-43945 Patchstack
4.3 Medium Photo Gallery Builder Plugin photo-gallery-builder Broken Access Control Broken Access Control to Notice Dismissal ≤ 3.0 CVE-2024-49325 Patchstack
5.4 Medium CartBounty – Save and recover abandoned carts for WooCommerce Plugin woo-save-abandoned-carts Cross-Site Request Forgery No login needed ≤ 8.2 Fixed in 8.2.1 CVE-2024-47634 Patchstack
4.3 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Request Forgery No login needed ≤ 2408 Fixed in 2411 CVE-2024-49250 Patchstack
4.3 Medium Social Auto Poster Plugin social-auto-poster Cross-Site Request Forgery No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-49272 Patchstack
5.4 Medium VOD Infomaniak Plugin vod-infomaniak Cross-Site Request Forgery No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-49274 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only