WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,351–7,400 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 148 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Local File Inclusion ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-37464 Patchstack
6.5 Medium AWSM Team Plugin awsm-team Local File Inclusion Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-37454 Patchstack
5.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Arbitrary SVG File Download ≤ 3.22.1 Fixed in 3.22.2 CVE-2024-37437 Patchstack
5.3 Medium Patreon Plugin patreon-connect Authentication Bypass Image Protection Bypass No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2024-37430 Patchstack
4.9 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Local File Inclusion ≤ 1.3.0.3 Fixed in 1.3.0.4 CVE-2024-37410 Patchstack
4.9 Medium Tutor LMS Plugin tutor Path Traversal ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-37266 Patchstack
5.4 Medium WooCommerce Social Login Plugin woo-social-login PHP Object Injection No login needed ≤ 2.6.3 Fixed in 2.7.0 CVE-2024-37502 Patchstack
5.4 Medium Cliengo – Chatbot Plugin cliengo Cross-Site Request Forgery Chatbot plugin <= 3.0.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2024-37923 Patchstack
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting ≤ 2.0.2 CVE-2024-37554 Patchstack
6.5 Medium Testimonials Widget Plugin testimonials-widget Cross-Site Scripting ≤ 4.0.4 CVE-2024-37553 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Local File Inclusion ≤ 8.4.0 Fixed in 8.4.1 CVE-2024-37547 Patchstack
6.5 Medium Image Hover Effects - Caption Hover with Carousel Plugin image-hover-effects-with-carousel Cross-Site Scripting ≤ 3.0.2 CVE-2024-37546 Patchstack
5.4 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2024-37542 Patchstack
6.5 Medium Elementor Addons, Widgets and Enhancements – Stax Plugin stax-addons-for-elementor Cross-Site Scripting Stax plugin <= 1.5.0 - Cross Site Scripting (XSS) ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-37541 Patchstack
6.5 Medium WP To Do Plugin wp-todo Cross-Site Scripting ≤ 1.3.0 CVE-2024-37539 Patchstack
4.9 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery ≤ 5.7 Fixed in 5.8 CVE-2024-37208 Patchstack
6.5 Medium Newspack Ads Plugin Cross-Site Scripting ≤ 1.47.1 Fixed in 1.47.2 CVE-2024-37474 Patchstack
6.5 Medium Newspack Campaigns Plugin Cross-Site Scripting ≤ 2.31.1 Fixed in 2.31.2 CVE-2024-37476 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Other WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration No login needed ≤ 4.2.6.8.1 CVE-2024-6099 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass No login needed ≤ 4.2.6.8.1 CVE-2024-6088 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 3.1.9 CVE-2024-4268 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via title tag attribute ≤ 3.1.9 CVE-2024-3513 Wordfence
5.4 Medium Basil Theme Cross-Site Scripting WordPress Basil Theme Authenticated (Contributor+) Persistent Cross-Site Scripting < 2.0.5 CVE-2024-39310 GitHub_M
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
6.5 Medium jQuery T(-) Countdown Widget Plugin jquery-t-countdown-widget Cross-Site Scripting ≤ 2.3.25 CVE-2024-37247 Patchstack
6.5 Medium Anima Theme anima Cross-Site Scripting ≤ 1.4.1 CVE-2024-37248 Patchstack
4.4 Medium BlossomThemes Email Newsletter Plugin blossomthemes-email-newsletter Server-Side Request Forgery ≤ 2.2.6 Fixed in 2.2.7 CVE-2024-37098 Patchstack
6.4 Medium The7 — Website and eCommerce Builder Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute ≤ 11.13.0 CVE-2024-5451 Wordfence
5.0 Medium WordPress Core Path Traversal Auth. Arbitrary .html File Read (Windows Only) 6.5 – 6.5.4, 6.4 – 6.4.4, 6.3 – 6.3.4, … Fixed in 6.5.5 CVE-2024-32111 Patchstack
6.5 Medium WordPress Core Cross-Site Scripting 6.5 – 6.5.4, 6.4 – 6.4.4, 6.3 – 6.3.4, … Fixed in 6.5.5 CVE-2024-31111 Patchstack
6.4 Medium WordPress Core Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, … CVE-2024-6307 Wordfence
4.3 Medium Play.ht Plugin play-ht Broken Access Control ≤ 3.6.4 CVE-2024-37233 Patchstack
6.5 Medium Word Balloon Plugin word-balloon Local File Inclusion ≤ 4.21.1 Fixed in 4.22.0 CVE-2024-35781 Patchstack
6.5 Medium Slideshow SE Plugin slideshow-se Local File Inclusion Auth. Limited Local File Inclusion ≤ 2.5.17 Fixed in 2.5.18 CVE-2024-35778 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2022-44587 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Content Injection Auth. HTML Injection ≤ 2.0.9 Fixed in 2.1.0 CVE-2022-38055 Patchstack
5.4 Medium Uncanny Automator Pro Plugin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Leading to License Settings Reset No login needed ≤ 5.3 CVE-2024-37118 Patchstack
4.3 Medium Digital Newspaper Theme digital-newspaper Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-37198 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.9.7 Fixed in 4.9.8 CVE-2024-37227 Patchstack
4.3 Medium Book Landing Page Theme book-landing-page Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-37230 Patchstack
4.3 Medium EmbedPress Plugin embedpress Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2023-51375 Patchstack
6.5 Medium WordPress Form Builder Plugin – Gutenberg Forms Plugin forms-gutenberg Broken Access Control Auth. Broken Access Control ≤ 2.2.8.3 Fixed in 2.2.9 CVE-2022-45803 Patchstack
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
4.3 Medium Customizr Theme customizr Cross-Site Request Forgery No login needed ≤ 4.4.21 Fixed in 4.4.22 CVE-2024-35771 Patchstack
4.3 Medium Hueman Theme hueman Cross-Site Request Forgery No login needed ≤ 3.7.24 Fixed in 3.7.25 CVE-2024-35772 Patchstack
5.3 Medium phpinfo() WP Plugin phpinfo-wp Information Disclosure Unauthenticated Data Exposure No login needed ≤ 5.0 CVE-2024-35776 Patchstack
5.3 Medium Event Management Tickets Booking Plugin event-monster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.0 CVE-2024-5059 Patchstack
5.9 Medium Easy Age Verify Plugin easy-age-verify Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-35757 Patchstack
6.5 Medium Interface Theme interface Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-35758 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35759 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only