WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,751–7,800 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 156 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Bit Form Plugin bit-form SQL Injection ≤ 2.13.11 Fixed in 2.13.12 CVE-2024-47335 Patchstack
8.5 High WPExperts Square For GiveWP Plugin wpexperts-square-for-give SQL Injection ≤ 1.3 Fixed in 1.3.2 CVE-2024-47338 Patchstack
7.1 High NiceJob Plugin nicejob Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.6.5 Fixed in 3.6.5 CVE-2024-44028 Patchstack
7.1 High viala Theme viala Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 CVE-2024-44029 Patchstack
7.1 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.121 Fixed in 1.5.122 CVE-2024-45454 Patchstack
7.1 High CP Polls Plugin cp-polls Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.74 Fixed in 1.0.75 CVE-2024-47297 Patchstack
7.1 High CubeWP Forms Plugin cubewp-forms Cross-Site Scripting No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-47300 Patchstack
7.1 High Bit Form Plugin bit-form Cross-Site Scripting No login needed ≤ 2.13.10 Fixed in 2.13.11 CVE-2024-47301 Patchstack
7.1 High Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection-subscribe-to-view Cross-Site Scripting No login needed ≤ 4.2.3 Fixed in 4.2.4 CVE-2024-47306 Patchstack
7.1 High WS Form LITE Plugin ws-form Cross-Site Scripting No login needed ≤ 1.9.238 Fixed in 1.9.244 CVE-2024-47320 Patchstack
7.1 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47322 Patchstack
7.1 High Share This Image Plugin share-this-image Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.01 Fixed in 2.02 CVE-2024-47326 Patchstack
7.1 High GEO my Plugin geo-my-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.5.0.3 Fixed in 4.5.0.4 CVE-2024-47327 Patchstack
7.1 High Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.4 Fixed in 4.1.5 CVE-2024-47333 Patchstack
7.1 High WP Mail Catcher Plugin wp-mail-catcher Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-47339 Patchstack
7.1 High WP-DownloadManager Plugin wp-downloadmanager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.68.8 Fixed in 1.68.9 CVE-2024-47341 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.9.1 Fixed in 4.9.9.2 CVE-2024-47346 Patchstack
7.1 High Chartify Plugin chart-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2024-47347 Patchstack
7.1 High YellowPencil Visual CSS Style Editor Plugin yellow-pencil-visual-theme-customizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2024-47348 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.50 Fixed in 11.51 CVE-2024-47349 Patchstack
7.1 High WP Bulk Delete Plugin wp-bulk-delete Cross-Site Scripting No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-47352 Patchstack
7.1 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-47360 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.13.0 Fixed in 4.13.1 CVE-2024-47367 Patchstack
7.1 High Social Auto Poster Plugin social-auto-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-47369 Patchstack
7.1 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting No login needed ≤ 6.5.0.2 Fixed in 6.5.1 CVE-2024-47374 Patchstack
7.1 High WPCOM Member Plugin wpcom-member Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 Fixed in 1.5.4.1 CVE-2024-47378 Patchstack
7.1 High Web Directory Free Plugin web-directory-free Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-47379 Patchstack
7.1 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.3 Fixed in 3.6.5 CVE-2024-47380 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.20.13 Fixed in 6.21.01 CVE-2024-47384 Patchstack
7.1 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-47386 Patchstack
7.1 High SliceWP Plugin slicewp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.18 Fixed in 1.1.19 CVE-2024-47388 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.7.3 Fixed in 8.7.4 CVE-2024-47389 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.9 Fixed in 2.6.1 CVE-2024-47394 Patchstack
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-47395 Patchstack
7.1 High BSK Forms Blacklist Plugin bsk-gravityforms-blacklist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.1 Fixed in 3.9 CVE-2024-47624 Patchstack
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.6 Fixed in 4.5 CVE-2024-47638 Patchstack
7.1 High Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-47644 Patchstack
7.5 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Local File Inclusion ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47324 Patchstack
8.1 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Local File Inclusion No login needed ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47323 Patchstack
8.0 High Bit Form Plugin bit-form Arbitrary File Upload ≤ 2.13.10 Fixed in 2.13.11 CVE-2024-47319 Patchstack
7.5 High WPSPX Plugin wpspx Local File Inclusion No login needed ≤ 1.0.2 CVE-2024-44034 Patchstack
8.1 High ABCApp Creator Plugin abcapp-creator Local File Inclusion No login needed ≤ 1.1.2 CVE-2024-44023 Patchstack
7.5 High Instant Chat Floating Button for WordPress Websites Plugin instant-chat-wp Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44018 Patchstack
7.2 High Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math PHP Object Injection AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection ≤ 1.0.228 CVE-2024-9314 Wordfence
7.5 High Podiant Plugin podiant Local File Inclusion No login needed ≤ 1.1 CVE-2024-44016 Patchstack
7.5 High Users Control Plugin users-control Local File Inclusion No login needed ≤ 1.0.16 CVE-2024-44015 Patchstack
7.5 High VR Calendar Plugin vr-calendar-sync Local File Inclusion No login needed ≤ 2.4.0 Fixed in 2.4.5 CVE-2024-44013 Patchstack
7.5 High WP Newsletter Subscription Plugin wp-newsletter-subscription Local File Inclusion No login needed ≤ 1.1 CVE-2024-44012 Patchstack
7.5 High WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44011 Patchstack
7.5 High Social Web Suite – Social Media Auto Post, Social Media Auto Publish Plugin social-web-suite Path Traversal Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File Download No login needed ≤ 4.1.11 CVE-2024-8352 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only