WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,951–7,000 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 140 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.6 Medium Cities Shipping Zones for WooCommerce Plugin cities-shipping-zones-for-woocommerce Local File Inclusion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-47309 Patchstack
4.9 Medium CSS JS Files Plugin css-js-files Path Traversal Directory Traversal to File Read ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-9146 Patchstack
6.8 Medium Bit File Manager – 100% Free & Open Source File Manager and Code Editor Plugin Arbitrary File Upload Authenticated (Subscriber+) Limited JavaScript File Upload ≤ 6.5.7 CVE-2024-8743 Wordfence
6.1 Medium WordPress Captcha Plugin by Captcha Bank Plugin captcha-bank Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.0.36 CVE-2024-9375 Wordfence
6.4 Medium WordPress Infinite Scroll - Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter ≤ 7.1.2 CVE-2024-8505 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.2.4.4 CVE-2024-8282 Wordfence
5.4 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 5.7.34 CVE-2024-8254 Wordfence
6.4 Medium Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg Plugin guten-post-layout Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.2.4 CVE-2024-8288 Wordfence
6.1 Medium Easy WordPress Subscribe – Optin Hound Plugin opt-in-hound Cross-Site Scripting Optin Hound <= 1.4.3 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 1.4.3 CVE-2024-9267 Wordfence
6.5 Medium KB Support – WordPress Help Desk and Knowledge Base Plugin Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure No login needed ≤ 1.6.6 CVE-2024-8632 Wordfence
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2024-47396 Patchstack
6.5 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-47641 Patchstack
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module ≤ 2.8.3.6 CVE-2024-9049 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 5.7.34 CVE-2024-8771 Wordfence
4.3 Medium Joy Of Text Lite Plugin joy-of-text Broken Access Control ≤ 2.3.1 CVE-2024-47337 Patchstack
4.3 Medium Slider by Supsystic Plugin slider-by-supsystic Broken Access Control Broken Access Control vulnerability on multiple WordPress plugins by Supsystic ≤ 1.8.6, ≤ 2.2.9 Fixed in 1.8.7 CVE-2024-47330 Patchstack
4.3 Medium Use Any Font Plugin use-any-font Cross-Site Request Forgery No login needed ≤ 6.3.08 Fixed in 6.3.09 CVE-2024-47305 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
5.3 Medium WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-43237 Patchstack
5.3 Medium Masterstudy LMS Starter Theme Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-43990 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Cross-Site Scripting ≤ 8.5 Fixed in 8.5.1 CVE-2024-47303 Patchstack
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
6.4 Medium GutenGeek Free Gutenberg Blocks Plugin gtg-advanced-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.3 CVE-2024-9073 Wordfence
6.3 Medium WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 3.8.0 CVE-2024-6590 Wordfence
4.3 Medium Easy Mega Menu Plugin for WordPress – ThemeHunk Plugin themehunk-megamenu-plus Broken Access Control ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates ≤ 1.0.9 CVE-2024-8434 Wordfence
6.4 Medium Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) Plugin graphicsly Cross-Site Scripting The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9069 Wordfence
4.3 Medium WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery Broken Access Control WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation ≤ 4.8.5 CVE-2024-8437 Wordfence
6.4 Medium Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player Plugin radio-player Cross-Site Scripting Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 2.0.78 CVE-2024-8267 Wordfence
6.5 Medium Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated Local File Inclusion ≤ 1.9.10 Fixed in 1.10.0 CVE-2024-44048 Patchstack
6.5 Medium ElementsKit Pro Plugin Local File Inclusion ≤ 3.6.0 Fixed in 3.6.8 CVE-2024-43996 Patchstack
4.4 Medium MailChimp Plugin mailchimp-for-wp Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 4.9.16 CVE-2024-8680 Wordfence
6.1 Medium MC4WP: Mailchimp Plugin mailchimp-for-wp Cross-Site Scripting Reflected Cross-Site Scripting No login needed 4.9.9 – 4.9.16 CVE-2024-8850 Wordfence
5.3 Medium WP Hardening – Fix Your WordPress Security Plugin wp-security-hardening Other Fix Your WordPress Security <= 1.2.6 - Unauthenticated Security Feature Bypass to Username Enumeration No login needed ≤ 1.2.6 CVE-2024-6641 Wordfence
5.9 Medium PageLayer Plugin pagelayer Cross-Site Scripting Drag and Drop website builder plugin <= 1.8.7 - Cross Site Scripting (XSS) ≤ 1.8.7 Fixed in 1.8.8 CVE-2024-43972 Patchstack
6.5 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting ≤ 4.1.13 Fixed in 4.1.14 CVE-2024-43983 Patchstack
6.5 Medium Sliding Door Theme sliding-door Cross-Site Scripting ≤ 3.6 CVE-2024-43987 Patchstack
6.5 Medium Mystique Theme mystique Cross-Site Scripting ≤ 2.5.7 CVE-2024-43988 Patchstack
6.5 Medium Hotel Galaxy Theme hotel-galaxy Cross-Site Scripting ≤ 4.4.24 CVE-2024-43991 Patchstack
6.5 Medium LatePoint Plugin Cross-Site Scripting ≤ 4.9.91 CVE-2024-43992 Patchstack
6.5 Medium Liquido Theme liquido Cross-Site Scripting ≤ 1.0.1.2 CVE-2024-43993 Patchstack
6.5 Medium Kahuna Theme kahuna Cross-Site Scripting ≤ 1.7.0 CVE-2024-43994 Patchstack
6.5 Medium Posterity Theme posterity Cross-Site Scripting ≤ 3.6 CVE-2024-43995 Patchstack
5.9 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting ≤ 3.8.11 Fixed in 3.8.12 CVE-2024-43999 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.982 Fixed in 1.3.985 CVE-2024-44001 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 9.3.7 Fixed in 9.4 CVE-2024-44005 Patchstack
6.5 Medium Geo Mashup Plugin geo-mashup Cross-Site Scripting ≤ 1.13.12 Fixed in 1.13.13 CVE-2024-44008 Patchstack
6.5 Medium IMPress for IDX Broker Plugin idx-broker-platinum Cross-Site Scripting ≤ 3.2.2 Fixed in 3.2.3 CVE-2024-44047 Patchstack
6.5 Medium Gutenberg Blocks Plugin unlimited-blocks Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) ≤ 1.2.8 CVE-2024-44049 Patchstack
5.9 Medium Bus Ticket Booking with Seat Reservation Plugin bus-ticket-booking-with-seat-reservation Cross-Site Scripting ≤ 5.3.5 Fixed in 5.3.6 CVE-2024-43985 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.2 Fixed in 5.6.3 CVE-2024-43977 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only