WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,151–8,200 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 164 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Contact Form to DB by BestWebSoft Plugin contact-form-to-db SQL Injection ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-35678 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.12.0 Fixed in 3.12.1 CVE-2024-35679 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross-Site Scripting (XSS) No login needed ≤ 7.6.3 Fixed in 7.6.4 CVE-2024-35687 Patchstack
7.1 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting No login needed ≤ 3.14.33 Fixed in 3.14.34 CVE-2024-35693 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting No login needed ≤ 11.41 Fixed in 11.42 CVE-2024-35694 Patchstack
7.1 High WP Docs Plugin wp-docs Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35696 Patchstack
7.1 High Eduma Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.7 Fixed in 5.4.8 CVE-2024-35697 Patchstack
7.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Scripting No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2024-35706 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-35718 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2024-35730 Patchstack
7.1 High Auto Coupons for WooCommerce Plugin woo-auto-coupons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.14 Fixed in 3.0.15 CVE-2024-35733 Patchstack
7.1 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Scripting No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-35734 Patchstack
8.5 High Visualizer Plugin visualizer SQL Injection ≤ 3.11.1 Fixed in 3.11.2 CVE-2024-35736 Patchstack
7.1 High WP Visitors Tracker Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.4 CVE-2024-35737 Patchstack
8.5 High Responsive Image Gallery, Gallery Album Plugin gallery-album SQL Injection Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 CVE-2024-35750 Patchstack
7.4 High SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate and Creative Slider Widgets ≤ 2.0 CVE-2024-5091 Wordfence
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 2.10.17 CVE-2024-3668 Wordfence
7.5 High FileOrganizer Plugin fileorganizer Information Disclosure Sensitive Information Exposure via Directory Listing No login needed ≤ 1.0.7 CVE-2024-5599 Wordfence
7.2 High Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed ≤ 2.0.6.1 CVE-2024-5542 Wordfence
7.5 High Market Exporter Plugin market-exporter Broken Access Control Missing Authorization to Arbitrary File Deletion No login needed ≤ 2.0.19 CVE-2024-5637 Wordfence
7.2 High Tutor LMS – eLearning and online course solution Plugin tutor SQL Injection eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection ≤ 2.7.1 CVE-2024-4902 Wordfence
7.5 High Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.7.2 CVE-2024-4887 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter ≤ 1.5.109 CVE-2024-5329 Wordfence
8.8 High Cowidgets – Elementor Addons Plugin Local File Inclusion Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion ≤ 1.1.2 CVE-2024-5179 Wordfence
8.1 High The Moneytizer Plugin the-moneytizer Broken Access Control Missing Authorization via multiple AJAX actions ≤ 9.6.3 CVE-2023-6966 Wordfence
8.1 High The Moneytizer Plugin the-moneytizer Cross-Site Request Forgery Cross-Site Request Forgery via multiple AJAX actions ≤ 9.6.3 CVE-2023-6968 Wordfence
8.8 High XootiX Framework <= Various Plugin Versions Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Update ≤ 2.6, ≤ 2.6.1, 2.5, … CVE-2024-5324 Wordfence
8.8 High LifterLMS – WordPress LMS Plugin for eLearning Plugin SQL Injection WordPress LMS Plugin for eLearning <= 7.6.2 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 7.6.2 CVE-2024-4743 Wordfence
7.4 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.43 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget Link To URL ≤ 2.4.43 CVE-2024-3667 Wordfence
7.2 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form No login needed ≤ 2.4.43 CVE-2024-2087 Wordfence
7.1 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.41 - Authenticated(Contributor+) Stored Cross-Site Scripting ≤ 2.4.41 CVE-2024-1940 Wordfence
7.5 High Netgsm Plugin netgsm Broken Access Control No login needed ≤ 2.9.19 Fixed in 2.9.20 CVE-2024-35672 Patchstack
7.5 High Easy Forms for Mailchimp Plugin yikes-inc-easy-mailchimp-extender Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 6.9.0 CVE-2024-25095 Patchstack
7.1 High Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-35652 Patchstack
7.1 High WPvivid Backup for MainWP Plugin wpvivid-backup-mainwp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.32 Fixed in 0.9.33 CVE-2024-35664 Patchstack
7.1 High Newsletter, SMTP, Email marketing and Subscribe forms by Sendinblue Plugin mailin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.77 Fixed in 3.1.78 CVE-2024-35668 Patchstack
8.5 High Stockholm Core Plugin Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-34554 Patchstack
8.5 High Stockholm Theme Local File Inclusion ≤ 9.6 Fixed in 9.7 CVE-2024-34552 Patchstack
8.8 High XforWooCommerce Plugin Local File Inclusion Authenticated Local File Inclusion ≤ 2.0.2 CVE-2024-33628 Patchstack
8.5 High Element Pack Pro Plugin Path Traversal Arbitrary File Read and Phar Deserialization < 7.19.3 Fixed in 7.19.3 CVE-2024-33568 Patchstack
8.5 High XStore Core Plugin Local File Inclusion ≤ 5.3.8 Fixed in 5.3.9 CVE-2024-33557 Patchstack
8.3 High ARMember Plugin armember-membership Privilege Escalation Membership Plan Bypass ≤ 4.0.10 Fixed in 4.0.11 CVE-2023-47837 Patchstack
7.5 High Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Authentication Bypass Password Protected View Bypass Vulnerability No login needed ≤ 5.7.1 Fixed in 5.8.0 CVE-2023-46630 Patchstack
8.2 High FS Product Inquiry Plugin fs-product-inquiry Cross-Site Scripting Reflected XSS No login needed ≤ 1.1.1 CVE-2024-4856 WPScan
8.3 High WP eMember Plugin Cross-Site Scripting Reflected XSS No login needed < 10.3.9 Fixed in 10.3.9 CVE-2024-4749 WPScan
7.5 High WP-DB-Table-Editor Plugin wp-db-table-editor Broken Access Control Missing Authorization to Authenticated(Contributor+) Database Access ≤ 1.8.4 CVE-2024-2019 Wordfence
7.2 High Social Link Pages: link-in-bio landing pages for your social media profiles Plugin social-link-pages Broken Access Control Missing Authorization to Arbitrary Page Creation and Cross-Site Scripting No login needed ≤ 1.6.9 CVE-2024-3555 Wordfence
7.2 High Frontend Registration – Contact Form 7 Plugin frontend-registration-contact-form-7 Privilege Escalation Contact Form 7 <= 5.1 - Authenticated (Editor+) Privilege Escalation ≤ 5.1 CVE-2024-4870 Wordfence
7.1 High Tainacan Plugin tainacan Cross-Site Scripting No login needed ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34794 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting No login needed ≤ 7.5.45.7212 Fixed in 7.5.46.7212 CVE-2024-35631 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only