WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 8,351–8,400 of 8,931 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 168 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS ≤ 2.10.3 CVE-2023-6486 Wordfence
6.4 Medium WordPress File Upload Plugin Arbitrary File Upload Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.24.5 CVE-2024-2847 Wordfence
5.3 Medium WordPress Gallery Plugin – NextGEN Gallery Plugin nextgen-gallery Broken Access Control NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 3.59 CVE-2024-3097 Wordfence
6.4 Medium GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin Cross-Site Scripting The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.9.0 CVE-2024-2783 Wordfence
4.4 Medium FancyBox Plugin fancybox-for-wordpress Cross-Site Scripting The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization a… 3.0.2 – 3.3.3 CVE-2024-0662 Wordfence
5.4 Medium Soledad Theme Cross-Site Request Forgery No login needed ≤ 8.4.2 CVE-2024-31369 Patchstack
6.5 Medium Soledad Theme Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 8.4.2 CVE-2024-31368 Patchstack
5.4 Medium WP2LEADS Plugin wp2leads Broken Access Control ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-31375 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.5.2 Fixed in 1.6.0 CVE-2024-31357 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control IDOR on Friend Request ≤ 5.7.6 Fixed in 5.7.7 CVE-2024-31291 Patchstack
4.3 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0.81 Fixed in 1.0.82 CVE-2024-31296 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery No login needed ≤ 8.5.2 Fixed in 8.6.0 CVE-2024-22155 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-31236 Patchstack
6.5 Medium Formsite | Embed online forms to collect orders, registrations, leads, and surveys Plugin formsite Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-31257 Patchstack
6.5 Medium Form to Chat App Plugin form-to-chat Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-31258 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-31306 Patchstack
5.9 Medium Easy Login Styler – White Label Admin Login Page Plugin easy-login-styler Cross-Site Scripting ≤ 1.0.6 CVE-2024-31344 Patchstack
6.5 Medium Gradient Text Widget for Elementor Plugin gradient-text-widget-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-31346 Patchstack
6.5 Medium Testimonials Plugin super-testimonial Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-31348 Patchstack
6.5 Medium MailMunch – Grow your Email List Plugin mailmunch Cross-Site Scripting Grow your Email List plugin <= 3.1.6 - Cross Site Scripting (XSS) ≤ 3.1.6 Fixed in 3.1.7 CVE-2024-31349 Patchstack
4.4 Medium WP Import Export Lite Plugin wp-import-export-lite PHP Object Injection ≤ 3.9.26 Fixed in 3.9.27 CVE-2024-31308 Patchstack
6.4 Medium Powerkit – Supercharge your WordPress Site Plugin powerkit Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.9.1 CVE-2024-2458 Wordfence
5.3 Medium WordPress Core Information Disclosure Sensitive Information Exposure via redirect_guess_404_permalink No login needed ≤ 6.4.3 CVE-2023-5692 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-30531 Patchstack
4.9 Medium Builderall Builder Plugin builderall-cheetah-for-wp Server-Side Request Forgery ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-30532 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.25 Fixed in 3.2.26 CVE-2024-24888 Patchstack
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button ≤ 2.8.0.5 CVE-2024-2925 Wordfence
4.3 Medium SecuPress Free — WordPress Security Plugin secupress Cross-Site Request Forgery Cross-Site Request Forgery to Banned IP Address No login needed ≤ 2.2.5.1 CVE-2024-1504 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.15.7 Fixed in 2.15.8 CVE-2024-31099 Patchstack
6.5 Medium PDF Viewer for Elementor Plugin pdf-viewer-for-elementor Cross-Site Scripting ≤ 2.9.3 CVE-2024-30524 Patchstack
6.5 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting ≤ 5.1 Fixed in 5.1.1 CVE-2024-30530 Patchstack
5.9 Medium underConstruction Plugin underconstruction Cross-Site Scripting ≤ 1.21 Fixed in 1.22 CVE-2024-30548 Patchstack
5.9 Medium Contact Forms by Cimatti Plugin contact-forms Cross-Site Scripting ≤ 1.8.0 Fixed in 1.9.1 CVE-2024-30549 Patchstack
6.5 Medium Responsive flipbook Plugin wppdf Cross-Site Scripting ≤ 1.0.0 CVE-2024-30552 Patchstack
5.9 Medium WP Twitter Mega Fan Box Widget Plugin wp-twitter-mega-fan-box Cross-Site Scripting ≤ 1.0 CVE-2024-30553 Patchstack
5.9 Medium DD Rating Plugin dd-rating Cross-Site Scripting ≤ 1.7.1 CVE-2024-30554 Patchstack
6.5 Medium Ultimate Social Comments – Email Notification & Lazy Load Plugin ultimate-facebook-comments Cross-Site Scripting ≤ 1.4.8 CVE-2024-30555 Patchstack
6.5 Medium Mighty Classic Pros And Cons Plugin joomdev-wp-pros-cons Cross-Site Scripting ≤ 2.0.9 CVE-2024-30556 Patchstack
6.5 Medium Aesop Story Engine Plugin aesop-story-engine Cross-Site Scripting ≤ 2.3.2 CVE-2024-30557 Patchstack
6.5 Medium Spin 360 deg and 3D Model Viewer Plugin spin360 Cross-Site Scripting ≤ 1.2.7 CVE-2024-30559 Patchstack
5.9 Medium Platinum SEO Plugin platinum-seo-pack Cross-Site Scripting ≤ 2.4.0 CVE-2024-31089 Patchstack
6.5 Medium AI Twitter Feeds (Twitter widget & shortcode) Plugin ai-twitter-feeds Cross-Site Scripting ≤ 2.4 CVE-2024-31101 Patchstack
5.9 Medium Prenotazioni Plugin prenotazioni Cross-Site Scripting ≤ 1.7.4 CVE-2024-31102 Patchstack
6.5 Medium GetResponse Plugin getresponse-integration Cross-Site Scripting ≤ 5.5.33 CVE-2024-31104 Patchstack
6.5 Medium iFlyChat – WordPress Chat Plugin iflychat Cross-Site Scripting ≤ 4.7.2 CVE-2024-31108 Patchstack
6.5 Medium WooCommerce Bookings Calendar Plugin woo-bookings-calendar Cross-Site Scripting ≤ 1.0.36 CVE-2024-31117 Patchstack
6.5 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) ≤ 2.0.3 CVE-2024-31120 Patchstack
6.5 Medium HeartThis Plugin heart-this Cross-Site Scripting ≤ 0.1.0 CVE-2024-31121 Patchstack
5.8 Medium User Rights Access Manager Plugin user-rights-access-manager Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-31122 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only