WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,851–6,900 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 138 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Simple Baseball Scoreboard Plugin simple-baseball-scoreboard Cross-Site Scripting ≤ 1.3 CVE-2024-48025 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-48036 Patchstack
5.9 Medium Contact Form by Supsystic Plugin contact-form-by-supsystic Cross-Site Scripting ≤ 1.7.28 Fixed in 1.7.29 CVE-2024-48046 Patchstack
6.5 Medium Featured Posts with Multiple Custom Groups (FPMCG) Plugin featured-posts-with-multiple-custom-groups-fpmcg Cross-Site Request Forgery No login needed ≤ 4.0 CVE-2024-48031 Patchstack
5.4 Medium Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery CSRF No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-48037 Patchstack
4.3 Medium wp-Monalisa Plugin wp-monalisa Cross-Site Request Forgery No login needed ≤ 6.4 Fixed in 6.5 CVE-2024-48038 Patchstack
4.3 Medium Linked Variation for WooCommerce Plugin linked-variation-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 2.0.0 CVE-2024-48047 Patchstack
6.1 Medium Wordpress Photo Album Plus Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 8.8.05.003 CVE-2024-9951 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.9 - Reflected Cross-Site Scripting No login needed ≤ 3.0.9, 2.0.12, 3.0.11 CVE-2024-9347 Wordfence
5.3 Medium advanced-custom-fields Plugin advanced-custom-fields Cross-Site Scripting In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can r… No login needed Not stated CVE-2024-49593 mitre
6.5 Medium Booking.com Banner Creator Plugin bookingcom-banner-creator Cross-Site Scripting ≤ 1.4.6 CVE-2024-49265 Patchstack
5.9 Medium WP-Spreadplugin Plugin wp-spreadplugin Cross-Site Scripting ≤ 4.8.9 CVE-2024-49266 Patchstack
6.5 Medium Unlimited Addon For Elementor Plugin unlimited-addon-for-elementor Cross-Site Scripting ≤ 2.0.0 CVE-2024-49267 Patchstack
6.5 Medium Smart Blocks Plugin smart-blocks Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-49270 Patchstack
5.3 Medium Leyka Plugin leyka Broken Access Control No login needed ≤ 3.31.6 Fixed in 3.31.7 CVE-2024-49252 Patchstack
6.5 Medium WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Path Traversal Arbitrary File Download ≤ 1.5.7 CVE-2024-49258 Patchstack
4.9 Medium WordPress Core Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via use of the_meta(); function ≤ 3.6.1, 3.7 – 3.7.38, 3.8 – 3.8.38, … CVE-2022-4973 Wordfence
6.5 Medium CM Tooltip Glossary Plugin enhanced-tooltipglossary Cross-Site Scripting Stored Cross-Site Scripting ≤ 4.3.9 Fixed in 4.3.11 CVE-2024-48041 Patchstack
4.7 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Open Redirect No login needed ≤ 6.4.2 Fixed in 6.4.3 CVE-2024-47353 Patchstack
6.5 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal ≤ 2.3.7 CVE-2024-7514 Wordfence
4.7 Medium Simple Membership After Login Redirection Plugin simple-membership-after-login-redirection Open Redirect No login needed ≤ 1.6 Fixed in 1.7 CVE-2024-47354 Patchstack
4.7 Medium EventPrime Plugin eventprime-event-calendar-management Open Redirect No login needed ≤ 4.0.4.5 Fixed in 4.0.4.6 CVE-2024-47648 Patchstack
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion ≤ 1.3.0 CVE-2024-9067 Wordfence
6.4 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Cross-Site Scripting BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode ≤ 1.3.0 CVE-2024-8987 Wordfence
6.4 Medium Easy Mega Menu Plugin for WordPress – ThemeHunk Plugin themehunk-megamenu-plus Cross-Site Scripting ThemeHunk <= 1.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-8433 Wordfence
5.3 Medium uListing Plugin ulisting Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-47344 Patchstack
6.5 Medium WP-WebAuthn Plugin wp-webauthn Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-47650 Patchstack
5.1 Medium Full frame Plugin full-frame Cross-Site Scripting ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-44010 Patchstack
6.5 Medium Review & testimonial widgets Plugin trustmary Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.10 CVE-2024-44022 Patchstack
6.5 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Cross-Site Scripting ≤ 1.6.4 CVE-2024-44024 Patchstack
6.5 Medium NiceJob Plugin nicejob Cross-Site Scripting ≤ 3.6.5 Fixed in 3.6.5 CVE-2024-44025 Patchstack
6.5 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.2 CVE-2024-44026 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-44027 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-44032 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-44033 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-44035 Patchstack
5.9 Medium Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting ≤ 2.5.0 CVE-2024-44036 Patchstack
5.9 Medium Multipurpose Ticket Booking Manager Plugin bus-booking-manager Cross-Site Scripting ≤ 4.2.2 Fixed in 4.2.3 CVE-2024-44037 Patchstack
5.9 Medium WP Travel Plugin wp-travel Cross-Site Scripting ≤ 9.3.1 Fixed in 9.4.0 CVE-2024-44039 Patchstack
5.9 Medium ShiftController Employee Shift Scheduling Plugin shiftcontroller Cross-Site Scripting ≤ 4.9.64 Fixed in 4.9.65 CVE-2024-44040 Patchstack
5.9 Medium IdeaPush Plugin ideapush Cross-Site Scripting ≤ 8.66 Fixed in 8.69 CVE-2024-44041 Patchstack
5.9 Medium WP Datepicker Plugin wp-datepicker Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-44042 Patchstack
5.9 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting ≤ 1.8.27 Fixed in 1.8.28 CVE-2024-44043 Patchstack
5.9 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Scripting ≤ 2.6.5 Fixed in 2.7.0 CVE-2024-44045 Patchstack
5.9 Medium Themify – WooCommerce Product Filter Plugin themify-wc-product-filter Cross-Site Scripting ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-44046 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.1.1 Fixed in 5.1.2 CVE-2024-47298 Patchstack
5.9 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Scripting ≤ 6.17.4 Fixed in 6.18.4 CVE-2024-47299 Patchstack
6.5 Medium Meta slider and carousel with lightbox Plugin meta-slider-and-carousel-with-lightbox Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-47307 Patchstack
6.5 Medium ARI Fancy Lightbox Plugin ari-fancy-lightbox Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2024-47310 Patchstack
5.1 Medium Catch Base Plugin catch-base Cross-Site Scripting ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-47313 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only