WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,301–7,350 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 147 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-38698 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-38705 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.3 Fixed in 1.3.1 CVE-2024-38712 Patchstack
6.5 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 8.8.02.002 Fixed in 8.8.02.003 CVE-2024-38713 Patchstack
6.5 Medium Download Button for Elementor Plugin download-button-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2024-38718 Patchstack
6.5 Medium EazyDocs Plugin eazydocs Cross-Site Scripting ≤ 2.5.0 CVE-2024-38720 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.57 CVE-2024-38722 Patchstack
5.9 Medium Admin Dashboard RSS Feed Plugin admin-dashboard-rss-feed Cross-Site Scripting ≤ 3.1 CVE-2024-38725 Patchstack
5.9 Medium Change From Email Plugin wp-from-email Cross-Site Scripting ≤ 1.2.1 CVE-2024-38738 Patchstack
5.1 Medium OnePress Theme onepress Cross-Site Scripting ≤ 2.3.8 CVE-2024-38739 Patchstack
6.5 Medium Amazing Hover Effects Plugin amazing-hover-effects Cross-Site Scripting ≤ 2.4.9 CVE-2024-38741 Patchstack
6.5 Medium Advanced post slider Plugin advanced-post-slider Cross-Site Scripting ≤ 3.0.0 CVE-2024-38750 Patchstack
6.5 Medium Typebot Plugin typebot Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2024-38757 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.6 Fixed in 3.6.1 CVE-2024-38767 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack
6.4 Medium Cooked Plugin cooked Content Injection Authenticated (Contributor+) HTML Injection via Recipe Excerpt < 1.8.0 CVE-2024-39682 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Apply Template to All Recipes No login needed < 1.8.0 CVE-2024-39681 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Default Recipe Template Save No login needed < 1.8.0 CVE-2024-39680 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Recipe Template Reset No login needed < 1.8.0 CVE-2024-39679 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Get Recipe IDs No login needed < 1.8.0 CVE-2024-39678 GitHub_M
5.5 Medium AI ChatBot for WordPress – WPBot Plugin chatbot Cross-Site Scripting WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.5.7 CVE-2024-6669 Wordfence
4.3 Medium WordPress File Upload Plugin Arbitrary File Upload Authenticated (Contributor+) Directory Traversal ≤ 4.24.7 CVE-2024-5852 Wordfence
5.4 Medium WordPress Plugin Tournamatch Plugin Cross-Site Scripting Admin+ Stored XSS via Ladders < 4.6.1 Fixed in 4.6.1 CVE-2024-5644 WPScan
5.4 Medium WordPress Plugin Tournamatch Plugin Cross-Site Scripting Subscriber+ Stored XSS < 4.6.1 Fixed in 4.6.1 CVE-2024-5627 WPScan
6.5 Medium CM WordPress Search And Replace Plugin Cross-Site Request Forgery Plugin Reset via CSRF < 1.3.9 Fixed in 1.3.9 CVE-2024-5028 WPScan
4.6 Medium OpenPGP Form Encryption Plugin openpgp-form-encryption Cross-Site Scripting Contributor+ Stored XSS < 1.5.1 Fixed in 1.5.1 CVE-2024-3919 WPScan
5.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Editor+ Stored XSS < 9.7.8 Fixed in 9.7.8 CVE-2024-3026 WPScan
6.5 Medium Events Calendar for Google Plugin events-calendar-for-google Local File Inclusion ≤ 2.1.0 CVE-2024-38716 Patchstack
6.5 Medium ExS Widgets Plugin exs-widgets Local File Inclusion ≤ 0.3.1 CVE-2024-38715 Patchstack
5.3 Medium GD Rating System Plugin gd-rating-system Local File Inclusion ≤ 3.6 Fixed in 3.6.1 CVE-2024-38709 Patchstack
6.5 Medium HT Mega Plugin ht-mega-for-elementor Path Traversal JSON Path Traversal ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-38706 Patchstack
6.5 Medium WordPress Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-38704 Patchstack
6.5 Medium WPCS Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional plugin <= 1.2.0.3 - Arbitrary Shortcode Execution No login needed ≤ 1.2.0.3 CVE-2024-38700 Patchstack
4.3 Medium SociallyViral Theme sociallyviral Cross-Site Request Forgery No login needed ≤ 1.0.10 CVE-2024-37938 Patchstack
4.3 Medium Patricia Lite Theme patricia-lite Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2024-37939 Patchstack
4.3 Medium Internal Link Juicer: SEO Auto Linker Plugin internal-links Cross-Site Request Forgery No login needed ≤ 2.24.3 Fixed in 2.24.4 CVE-2024-37941 Patchstack
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack
4.3 Medium Get Better Reviews for WooCommerce Plugin more-better-reviews-for-woocommerce Broken Access Control ≤ 4.0.6 CVE-2024-37544 Patchstack
5.3 Medium WP Popups – WordPress Popup builder Plugin wp-popups-lite Information Disclosure WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure No login needed ≤ 2.2.0.1 CVE-2024-6555 Wordfence
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence
5.3 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-37205 Patchstack
5.3 Medium TrustedLogin Vendor Plugin Information Disclosure Sensitive Data Exposure No login needed < 1.1.1 Fixed in 1.1.1 CVE-2024-37270 Patchstack
5.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure via API No login needed ≤ 1.0.33 Fixed in 1.0.34 CVE-2024-37498 Patchstack
5.3 Medium FileBird Document Library Plugin filebird-document-library Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.6 Fixed in 2.0.8.1 CVE-2024-37504 Patchstack
5.3 Medium SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer Plugin Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.10.8 CVE-2024-6556 Wordfence
5.4 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution ≤ 3.8.4 Fixed in 3.8.5 CVE-2024-37934 Patchstack
6.5 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Local File Inclusion Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-37520 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Local File Inclusion ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37499 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only