WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,301–7,350 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 147 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Hotlink2Watermark Plugin hotlink2watermark Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2024-53711 Patchstack
7.1 High Continue Shopping From Cart Plugin continue-shopping-from-cart-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2024-53714 Patchstack
7.1 High Silverlight Video Player Plugin smooth-streaming-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-53713 Patchstack
7.1 High wp auto top Plugin wp-auto-top Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.3 CVE-2024-53716 Patchstack
7.1 High Simple Travel Map Plugin simple-travel-map Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-53715 Patchstack
7.1 High Multi Feed Reader Plugin multi-feed-reader Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.4 CVE-2024-53718 Patchstack
7.1 High yPHPlista Plugin yphplista Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-53717 Patchstack
7.1 High Zajax – Ajax Navigation Plugin zajax-ajax-navigation Cross-Site Request Forgery Ajax Navigation plugin <= 0.4 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.4 CVE-2024-53719 Patchstack
7.1 High WP-ISPConfig 3 Plugin wp-ispconfig3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.6 CVE-2024-53720 Patchstack
7.1 High Google Plus Share and +1 Button Plugin google-plus-share-and-plusone-button Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-53723 Patchstack
7.1 High Favicon My Blog Plugin favicon-my-blog Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53722 Patchstack
7.1 High Post Hits Counter Plugin hits-counter Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.23 CVE-2024-53725 Patchstack
7.1 High IceStats Plugin icestats Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-53724 Patchstack
7.1 High LinkLaunder SEO Plugin linklaunder-seo-plugin Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.92.1 CVE-2024-53727 Patchstack
7.1 High RealtyCandy IDX Broker Extended Plugin realtycandy-idx-broker-extended Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2024-53726 Patchstack
7.1 High Protect Your Content Plugin protect-your-content Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53728 Patchstack
7.1 High Blizzard Quotes Plugin blizzard-quotes Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-53729 Patchstack
7.1 High CultBooking Hotel Booking Engine Plugin cultbooking-booking-engine Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2024-53753 Patchstack
7.1 High Third Party Cookie Eraser Plugin third-party-cookie-eraser Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53755 Patchstack
7.1 High Out Of Stock Badge Plugin out-of-stock-badge Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2024-53754 Patchstack
7.1 High ArCa Payment Gateway Plugin arca-payment-gateway Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.3.1 Fixed in 1.3.4 CVE-2024-53759 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
7.1 High Custom Post Type to Map Store Plugin cpt-to-map-store Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2024-53769 Patchstack
7.1 High Mins To Read Plugin mins-to-read Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.2 CVE-2024-53765 Patchstack
7.1 High RingCentral Communications Plugin rccp-free Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.0 CVE-2024-53770 Patchstack
7.1 High Donate Me Plugin donate-me Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.5 CVE-2024-53776 Patchstack
7.1 High Yahoo! WebPlayer Plugin yahoo-media-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.6 CVE-2024-53779 Patchstack
7.1 High Simple Header and Footer Plugin simple-header-and-footer Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-53777 Patchstack
7.1 High SpatialMatch IDX Plugin spatialmatch-free-lifestyle-search Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.9 CVE-2024-53781 Patchstack
7.1 High Load More Posts Plugin load-more-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.0 CVE-2024-53780 Patchstack
7.1 High Photo Video Store Plugin photo-video-store Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 21.07 CVE-2024-53782 Patchstack
7.1 High Advanced What should we write next about Plugin advanced-what-should-we-write-about-next Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2024-53789 Patchstack
8.2 High eDoc Easy Tables Plugin edoc-easy-tables Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.29 CVE-2024-53793 Patchstack
8.5 High Watu Quiz Plugin watu SQL Injection ≤ 3.4.1.2 Fixed in 3.4.1.3 CVE-2024-53792 Patchstack
7.1 High April's Call Posts Plugin aprils-call-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 Fixed in 2.2.0 CVE-2024-53730 Patchstack
7.1 High WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2024-53740 Patchstack
7.7 High WP Project Manager Plugin SQL Injection SQL Injection in WordPress Project Manager Plugin Not stated CVE-2024-12015 tenable
7.1 High Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.27 Fixed in 2.28 CVE-2024-53742 Patchstack
7.1 High PayPal Responder Plugin paypal-responder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53750 Patchstack
7.1 High Essential Breadcrumbs Plugin essential-breadcrumbs Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-53778 Patchstack
7.6 High Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods SQL Injection ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-53783 Patchstack
8.1 High Cryptocurrency Widgets For Elementor Plugin cryptocurrency-widgets-for-elementor Local File Inclusion No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-53739 Patchstack
7.1 High Footer Flyout Widget Plugin footer-flyout-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-53732 Patchstack
7.1 High Fence URL Plugin fence-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 CVE-2024-53733 Patchstack
7.1 High Idealien Category Enhancements Plugin idealien-category-enhancements Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53734 Patchstack
7.1 High Custom Shortcode Sidebars Plugin custom-shortcode-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53736 Patchstack
7.1 High Block Editor Bootstrap Blocks Plugin block-editor-bootstrap-blocks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.1 Fixed in 6.6.2 CVE-2024-11402 Patchstack
8.5 High Distance Based Shipping Calculator Plugin distance-based-shipping-calculator SQL Injection ≤ 2.0.23 Fixed in 2.0.24 CVE-2024-52495 Patchstack
7.5 High Absolute Addons For Elementor Plugin absolute-addons Local File Inclusion ≤ 1.0.14 CVE-2024-52496 Patchstack
7.5 High Shopready Plugin shopready-elementor-addon Local File Inclusion ≤ 3.6 CVE-2024-52497 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only