WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 7,851–7,900 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 158 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SchedulePress Plugin wp-scheduled-posts Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2024-32717 Patchstack
5.3 Medium WP Club Manager Plugin wp-club-manager Broken Access Control No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-32719 Patchstack
5.3 Medium WP Job Manager Plugin wp-job-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.2 Fixed in 2.3.0 CVE-2024-34549 Patchstack
5.3 Medium Dynamics 365 Integration Plugin integration-dynamics Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.17 Fixed in 1.3.18 CVE-2024-34550 Patchstack
5.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Information Disclosure Sensitive Data Exposure via Exported File No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34556 Patchstack
4.4 Medium One Click Demo Import Plugin one-click-demo-import PHP Object Injection ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-34433 Patchstack
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
4.3 Medium DS Site Message Plugin ds-site-message Cross-Site Request Forgery No login needed ≤ 1.14.4 CVE-2024-34439 Patchstack
4.3 Medium WP Favorite Posts Plugin wp-favorite-posts Cross-Site Request Forgery No login needed ≤ 1.6.8 CVE-2024-34427 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34557 Patchstack
6.5 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-34415 Patchstack
5.9 Medium Viet Nam Affiliate Plugin viet-nam-affiliate Cross-Site Scripting ≤ 1.0.0 CVE-2024-34417 Patchstack
5.9 Medium WPCS ( WordPress Custom Search ) Plugin wpcs-wp-custom-search Cross-Site Scripting ≤ 1.1 CVE-2024-34418 Patchstack
5.9 Medium Configure Login Timeout Plugin configure-login-timeout Cross-Site Scripting ≤ 1.0 CVE-2024-34419 Patchstack
5.9 Medium Comments Evolved Plugin gplus-comments Cross-Site Scripting ≤ 1.6.3 CVE-2024-34420 Patchstack
6.5 Medium BlogLentor Plugin bloglentor-for-elementor Cross-Site Scripting Blog Designer Pack for Elementor plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 CVE-2024-34421 Patchstack
5.9 Medium Viet Affiliate Link Plugin viet-affiliate-link Cross-Site Scripting ≤ 1.2 CVE-2024-34422 Patchstack
5.9 Medium Forty Four – 404 Plugin forty-four Cross-Site Scripting ≤ 1.4 CVE-2024-34423 Patchstack
5.9 Medium Featured Content Gallery Plugin featured-content-gallery Cross-Site Scripting ≤ 3.2.0 CVE-2024-34424 Patchstack
5.9 Medium QuickieBar Plugin quickiebar Cross-Site Scripting ≤ 1.8.4 CVE-2024-34425 Patchstack
5.9 Medium Brozzme Scroll Top Plugin brozzme-scroll-top Cross-Site Scripting ≤ 1.8.5 CVE-2024-34426 Patchstack
5.9 Medium AWSOM News Announcement Plugin awsom-news-announcement Cross-Site Scripting ≤ 1.6.0 CVE-2024-34428 Patchstack
5.9 Medium Corona Virus (COVID-19) Banner & Live Data Plugin corona-virus-covid-19-banner Cross-Site Scripting ≤ 1.8.0.2 CVE-2024-34429 Patchstack
5.9 Medium TT Custom Post Type Creator Plugin tt-custom-post-type-creator Cross-Site Scripting ≤ 1.0 CVE-2024-34430 Patchstack
6.5 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-34432 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34436 Patchstack
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.24 Fixed in 1.15.25 CVE-2024-34437 Patchstack
6.5 Medium Easy Affiliate Links Plugin easy-affiliate-links Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-34441 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34445 Patchstack
4.3 Medium EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-33573 Patchstack
4.3 Medium Vitepos Plugin vitepos-lite Broken Access Control ≤ 3.0.1 Fixed in 3.0.2 CVE-2024-33574 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Broken Access Control on Post Clone ≤ 3.10.1 Fixed in 3.10.2 CVE-2024-24833 Patchstack
5.3 Medium AI WP Writer Plugin ai-wp-writer Broken Access Control No login needed ≤ 3.6.5 Fixed in 3.6.5.6 CVE-2024-30459 Patchstack
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares ≤ 4.8.1, ≤ 2.1.10, ≤ 1.9.3 Fixed in 4.9.0 CVE-2024-4233 Patchstack
6.5 Medium Advance WordPress Search Plugin th-advance-product-search Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2022-40218 Patchstack
6.5 Medium raindrops Theme raindrops Cross-Site Scripting ≤ 1.600 Fixed in 1.700 CVE-2024-34414 Patchstack
5.9 Medium Sticky Social Link Plugin sticky-social-link Cross-Site Scripting ≤ 2.0.1 CVE-2024-34546 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.1.34 Fixed in 1.1.35 CVE-2024-34547 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit plugin <= 2.4.8 - Cross Site Scripting (XSS) ≤ 2.4.8 Fixed in 2.5.0 CVE-2024-34548 Patchstack
5.9 Medium WOLF Plugin bulk-editor Cross-Site Scripting ≤ 1.0.8.2 Fixed in 1.0.8.3 CVE-2024-34558 Patchstack
5.9 Medium gee Search Plus Plugin gsearch-plus Cross-Site Scripting ≤ 1.4.4 CVE-2024-34560 Patchstack
5.9 Medium 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 3.71 Fixed in 3.72 CVE-2024-34561 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34562 Patchstack
6.5 Medium Gold Addons for Elementor Plugin gold-addons-for-elementor Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-34563 Patchstack
6.5 Medium Counter Up Plugin wp-counter-up Cross-Site Scripting ≤ 2.2.1 Fixed in 2.3.0 CVE-2024-34564 Patchstack
5.9 Medium Debug Info Plugin debug-info Cross-Site Scripting ≤ 1.3.10 CVE-2024-34565 Patchstack
6.5 Medium Content Blocks (Custom Post Widget) Plugin custom-post-widget Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2024-34566 Patchstack
5.9 Medium LetterPress Plugin letterpress Cross-Site Scripting ≤ 1.2.1 CVE-2024-34568 Patchstack
6.5 Medium Zotpress Plugin zotpress Cross-Site Scripting ≤ 7.3.9 Fixed in 7.3.10 CVE-2024-34569 Patchstack
5.9 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.3 CVE-2024-34570 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only