WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,801–6,850 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 137 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium IdeaPush Plugin ideapush Cross-Site Request Forgery No login needed ≤ 8.69 Fixed in 8.71 CVE-2024-49275 Patchstack
4.3 Medium Cooked Pro Plugin Cross-Site Request Forgery No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49290 Patchstack
4.3 Medium WP Content Copy Protection & No Right Click Plugin wp-content-copy-protector Cross-Site Request Forgery No login needed ≤ 3.5.9 Fixed in 3.6.1 CVE-2024-49306 Patchstack
4.3 Medium WordPress Image SEO Plugin wp-image-seo Cross-Site Request Forgery No login needed ≤ 1.1.4 CVE-2024-49627 Patchstack
4.3 Medium Most And Least Read Posts Widget Plugin most-and-least-read-posts-widget Cross-Site Request Forgery No login needed ≤ 2.5.18 Fixed in 2.5.19 CVE-2024-49628 Patchstack
6.5 Medium Mighty Builder Plugin mighty-builder Cross-Site Scripting ≤ 1.0.2 CVE-2024-48049 Patchstack
6.5 Medium WP Education Plugin wp-education Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-49630 Patchstack
6.5 Medium Easy Addons for Elementor Plugin easy-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 CVE-2024-49631 Patchstack
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
6.4 Medium Debrandify · Remove or Replace WordPress Branding Plugin debrandify Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.2 CVE-2024-9674 Wordfence
5.9 Medium Movie Database Plugin movie-database Cross-Site Scripting ≤ 1.0.11 CVE-2024-43300 Patchstack
6.5 Medium wpPricing Builder Plugin wppricing-builder-lite-responsive-pricing-table-builder Cross-Site Scripting ≤ 1.5.0 CVE-2024-49225 Patchstack
6.5 Medium bVerse Convert Plugin bverse-convert Cross-Site Scripting ≤ 1.3.7.1 CVE-2024-49228 Patchstack
6.5 Medium Ajax Custom CSS/JS Plugin ajax-awesome-css Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 2.0.4 CVE-2024-49230 Patchstack
6.5 Medium WordPress Video Plugin wordpress-video Cross-Site Scripting ≤ 1.0 CVE-2024-49231 Patchstack
6.5 Medium El mejor Cluster Plugin mejorcluster Cross-Site Scripting ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-49232 Patchstack
6.5 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-49233 Patchstack
6.5 Medium Plexx Elementor Extension Plugin plexx-elementor-extension Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-49234 Patchstack
6.5 Medium Crazy Call To Action Box Plugin crazy-call-to-action-box Cross-Site Scripting ≤ 1.0.5 CVE-2024-49236 Patchstack
6.5 Medium Tito Plugin tito Cross-Site Scripting ≤ 2.3 CVE-2024-49241 Patchstack
4.3 Medium SendGrid Plugin wp-sendgrid-mailer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 1.4 CVE-2024-9364 Wordfence
6.5 Medium Da Reactions Plugin da-reactions Cross-Site Scripting ≤ 5.1.5 Fixed in 5.2.0 CVE-2024-49255 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-49259 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.23.0 Fixed in 2.27.0 CVE-2024-49261 Patchstack
6.5 Medium Country Flags for Elementor Plugin country-flags-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-49262 Patchstack
6.5 Medium My Favorites Plugin my-favorites Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.3 CVE-2024-49263 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-49264 Patchstack
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting Elementor Addons plugin <= 2.0.2 - Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-49277 Patchstack
6.5 Medium Omnipress Plugin omnipress Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2024-49278 Patchstack
6.5 Medium Hyperlink Group Block Plugin hyperlink-group-block Cross-Site Scripting ≤ 1.17.5 Fixed in 1.17.6 CVE-2024-49279 Patchstack
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
6.5 Medium Click to Chat – WP Support All-in-One Floating Widget Plugin support-chat Cross-Site Scripting WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) ≤ 2.3.3 Fixed in 2.3.4 CVE-2024-49281 Patchstack
5.9 Medium Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2024-49282 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.9.1 Fixed in 1.2.9.2 CVE-2024-49288 Patchstack
6.5 Medium Cooked Pro Plugin Cross-Site Scripting < 1.8.0 Fixed in 1.8.0 CVE-2024-49289 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-49292 Patchstack
5.9 Medium Simple Testimonials Showcase Plugin simple-testimonials-showcase Cross-Site Scripting ≤ 1.1.6 CVE-2024-49295 Patchstack
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.5 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Cross-Site Scripting ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-49298 Patchstack
6.5 Medium G Meta Keywords Plugin g-meta-keywords Cross-Site Scripting ≤ 1.4 CVE-2024-49301 Patchstack
6.5 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-49302 Patchstack
6.5 Medium Admin Management Xtended Plugin admin-management-xtended Cross-Site Scripting ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-49307 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.2 CVE-2024-49310 Patchstack
6.5 Medium Edwiser Bridge Plugin edwiser-bridge Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49311 Patchstack
6.5 Medium Awesome Contact Form7 for Elementor Plugin awesome-contact-form7-for-elementor Cross-Site Scripting ≤ 3.0 Fixed in 3.1 CVE-2024-49319 Patchstack
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
5.3 Medium WP SendFox Plugin wp-sendfox Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.1 CVE-2024-49284 Patchstack
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
6.5 Medium Shortcode For Elementor Templates Plugin shortcode-support-for-elementor-templates Cross-Site Scripting ≤ 1.0.0 CVE-2024-48022 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only