WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,001–7,050 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 141 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Verbosa Plugin verbosa Cross-Site Scripting ≤ 1.2.3 CVE-2024-44050 Patchstack
6.5 Medium Content Blocks (Custom Post Widget) Plugin custom-post-widget Cross-Site Scripting ≤ 3.3.5 Fixed in 3.3.6 CVE-2024-44051 Patchstack
6.5 Medium Roseta Plugin roseta Cross-Site Scripting ≤ 1.3.0 CVE-2024-45451 Patchstack
6.5 Medium Septera Plugin septera Cross-Site Scripting ≤ 1.5.1 CVE-2024-45452 Patchstack
6.5 Medium Fluida Theme fluida Cross-Site Scripting ≤ 1.8.8 CVE-2024-44054 Patchstack
6.5 Medium Mantra Theme mantra Cross-Site Scripting ≤ 3.3.2 CVE-2024-44056 Patchstack
6.5 Medium Nirvana Theme nirvana Cross-Site Scripting ≤ 1.6.3 CVE-2024-44057 Patchstack
6.5 Medium Parabola Theme parabola Cross-Site Scripting ≤ 2.4.1 CVE-2024-44058 Patchstack
6.5 Medium Custom Query Blocks Plugin post-type-archive-mapping Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4.0 CVE-2024-44059 Patchstack
6.5 Medium Custom Field Template Plugin custom-field-template Cross-Site Scripting ≤ 2.6.5 CVE-2024-44062 Patchstack
6.5 Medium Happyforms Plugin happyforms Cross-Site Scripting ≤ 1.26.0 Fixed in 1.26.1 CVE-2024-44063 Patchstack
5.9 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45455 Patchstack
6.5 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45456 Patchstack
6.5 Medium Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45457 Patchstack
5.9 Medium Flipping Cards Plugin flipping-cards Cross-Site Scripting ≤ 1.30 Fixed in 1.31 CVE-2024-45460 Patchstack
6.1 Medium WordPress Affiliates Plugin — SliceWP Affiliates Plugin slicewp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.20 CVE-2024-8714 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
6.4 Medium Avada | Website Builder For WordPress & eCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode ≤ 3.11.9 CVE-2024-5628 Wordfence
4.8 Medium CM Pop-Up Banners Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.7.3 Fixed in 1.7.3 CVE-2024-5799 WPScan
6.4 Medium Advanced WordPress Backgrounds Plugin advanced-backgrounds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter ≤ 1.12.3 CVE-2024-8045 Wordfence
6.4 Medium Preloader Plus – WordPress Loading Screen Plugin preloader-plus Cross-Site Scripting WordPress Loading Screen Plugin <= 2.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.2.1 CVE-2024-6849 Wordfence
4.3 Medium Frontend Post Submission Manager Lite – Frontend Posting Plugin frontend-post-submission-manager-lite Broken Access Control Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.2.2 CVE-2024-8427 Wordfence
5.3 Medium Ivory Search – WordPress Search Plugin add-search-to-menu Information Disclosure WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form No login needed ≤ 5.5.6 CVE-2024-6835 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change ≤ 3.0.8 CVE-2024-8121 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Insecure Direct Object Reference ≤ 3.0.8 CVE-2024-8123 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page No login needed ≤ 3.0.8 CVE-2024-8119 Wordfence
6.5 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Information Disclosure WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 3.0.8 CVE-2024-8106 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option No login needed ≤ 3.0.8 CVE-2024-8117 Wordfence
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence
5.4 Medium WP Armour Extended Plugin Cross-Site Request Forgery No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43947 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.9.4 - Cross Site Scripting (XSS) ≤ 1.9.4 Fixed in 2.0.0 CVE-2024-43920 Patchstack
6.5 Medium Collapsing Archives Plugin collapsing-archives Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-43934 Patchstack
6.5 Medium Delicious Recipes – WordPress Recipe Plugin delicious-recipes Cross-Site Scripting Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin <= 1.6.7 - Cross Site Scripting (XSS) ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-43935 Patchstack
6.5 Medium EmbedPress Plugin embedpress Cross-Site Scripting ≤ 4.0.8 Fixed in 4.0.9 CVE-2024-43936 Patchstack
6.5 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting ≤ 1.5 CVE-2024-43946 Patchstack
6.5 Medium GHActivity Plugin Cross-Site Scripting ≤ 2.0.0-alpha CVE-2024-43949 Patchstack
6.5 Medium Tempera Theme tempera Cross-Site Scripting ≤ 1.8.2 CVE-2024-43951 Patchstack
6.5 Medium Esotera Theme esotera Cross-Site Scripting ≤ 1.2.5.1 CVE-2024-43952 Patchstack
6.5 Medium Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Cross-Site Scripting WPBakery Page Builder plugin <= 3.5 - Cross Site Scripting (XSS) ≤ 3.5 Fixed in 3.6 CVE-2024-43953 Patchstack
5.9 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.4.6 CVE-2024-43960 Patchstack
6.5 Medium azurecurve Toggle Show/Hide Plugin azurecurve-toggle-showhide Cross-Site Scripting ≤ 2.1.3 CVE-2024-43961 Patchstack
6.5 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Scripting ≤ 4.5 CVE-2024-43964 Patchstack
6.5 Medium Animated Number Counters Plugin animated-number-counters Local File Inclusion Editor+ Limited Local File Inclusion ≤ 1.9 CVE-2024-43957 Patchstack
6.3 Medium Droip Plugin Information Disclosure Subscriber+ Settings Change/Data Exposure ≤ 1.1.1 CVE-2024-43954 Patchstack
6.5 Medium Z Y N I T H Plugin Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 7.4.9 CVE-2024-43940 Patchstack
6.5 Medium Z Y N I T H Plugin Broken Access Control Unauthenticated Arbitrary Option Deletion No login needed ≤ 7.4.9 CVE-2024-43939 Patchstack
4.8 Medium NitroPack Plugin nitropack Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.16.7 Fixed in 1.16.8 CVE-2024-43922 Patchstack
5.9 Medium Taxi Booking Manager for WooCommerce Plugin ecab-taxi-booking-manager Cross-Site Scripting ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-43986 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only