WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 801–850 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 29
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Request Forgery Settings update via CSRF No login needed < 3.2.43 Fixed in 3.2.43 CVE-2024-10892 WPScan
6.4 Medium Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.30 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.30 CVE-2024-12449 Wordfence
6.1 Medium Learning Management System, eLearning, Course Builder, WordPress LMS Plugin – Sikshya LMS Plugin sikshya Cross-Site Scripting Sikshya LMS <= 0.0.21 - Reflected Cross-Site Scripting via page Parameter No login needed ≤ 0.0.21 CVE-2024-12127 Wordfence
6.1 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting Reflected Cross-Site Scripting via Navigate Parameter No login needed ≤ 1.3.0.5 CVE-2024-12239 Wordfence
9.1 Critical Zita Site Builder Plugin ai-site-builder Broken Access Control Arbitrary Plugin Installation and Activation No login needed ≤ 1.0.2 CVE-2024-54369 Patchstack
4.9 Medium Bold Page Builder Plugin bold-page-builder Path Traversal ≤ 5.1.5 Fixed in 5.1.6 CVE-2024-54382 Patchstack
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
6.5 Medium Poll Builder Plugin poll-builder Cross-Site Scripting ≤ 1.3.5 CVE-2024-54276 Patchstack
5.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control ≤ 3.1.42 Fixed in 3.1.43 CVE-2023-40011 Patchstack
5.3 Medium Gutenverse Plugin gutenverse Broken Access Control Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.8.5 - Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.6 CVE-2023-35875 Patchstack
6.4 Medium Beaver Builder – WordPress Page Builder Plugin Cross-Site Scripting WordPress Page Builder <= 2.8.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.4.4 CVE-2024-11832 Wordfence
5.4 Medium Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder Plugin Cross-Site Scripting Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.20.2 CVE-2024-10583 Wordfence
4.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Disclosure ≤ 9.9.9.3 CVE-2024-11181 Wordfence
4.8 Medium Popup Builder Plugin popup-builder Cross-Site Scripting Admin+ Stored XSS < 4.3.5 Fixed in 4.3.5 CVE-2024-9428 WPScan
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed ≤ 3.8.19 CVE-2024-11052 Wordfence
7.5 High WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Plugin wp-courses Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed ≤ 3.2.21 CVE-2024-12172 Wordfence
6.5 Medium SQL Chart Builder Plugin sql-chart-builder SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3.6 CVE-2024-11430 Wordfence
5.3 Medium ARForms Form Builder Plugin arforms-form-builder Content Injection HTML Injection No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-54223 Patchstack
5.3 Medium FormCraft Plugin formcraft-form-builder Broken Access Control Contact Form Builder for WordPress plugin <= 1.2.7 - Broken Access Control No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2023-47823 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Broken Access Control No login needed ≤ 2.1.10 Fixed in 2.2 CVE-2023-48750 Patchstack
5.3 Medium Button Generator – easily Button Builder Plugin button-generation Broken Access Control easily Button Builder plugin <= 2.3.8 - Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2023-49154 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ 5.2.3.0 Fixed in 5.2.3.1 CVE-2023-49831 Patchstack
5.3 Medium Metform Plugin metform Broken Access Control No login needed ≤ 3.4.0 Fixed in 3.4.1 CVE-2023-50903 Patchstack
6.1 Medium Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.19 CVE-2024-11436 Wordfence
6.4 Medium Depicter — Popup & Slider Builder Plugin depicter Cross-Site Scripting Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.2.1- Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.2.1 CVE-2024-4633 Wordfence
6.5 Medium Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting ≤ 2.8.4.3 Fixed in 2.8.4.4 CVE-2024-53797 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.2.1 Fixed in 5.2.2 CVE-2024-53801 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.14 Fixed in 6.0.1 CVE-2024-53823 Patchstack
6.5 Medium ZionBuilder Plugin zionbuilder Cross-Site Scripting Zion Builder plugin <= 3.6.16 - Cross Site Scripting (XSS) ≤ 3.6.16 Fixed in 3.6.17 CVE-2024-54213 Patchstack
8.5 High NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection ≤ 8.7.8 Fixed in 8.7.9 CVE-2024-53808 Patchstack
4.3 Medium XLTab – Accordions and Tabs for Elementor Page Builder Plugin xl-tab Information Disclosure Accordions and Tabs for Elementor Page Builder <= 1.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.4 CVE-2024-10689 Wordfence
6.1 Medium PDF Builder for WooCommerce. Create invoices,packing slips and more Plugin woo-pdf-invoice-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.136 CVE-2024-11276 Wordfence
6.4 Medium Contact Form Builder Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via livesite-pay Shortcode ≤ 4.10.4 CVE-2024-10056 Wordfence
6.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.3.9 CVE-2024-10178 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.5.2 CVE-2024-8962 Wordfence
7.5 High Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Local File Inclusion WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion ≤ 3.0 CVE-2024-11952 Wordfence
4.3 Medium Dollie Hub – Build Your Own WordPress Cloud Platform Plugin Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure ≤ 6.2.0 CVE-2024-12099 Wordfence
6.4 Medium Contact Form, Survey & Form Builder – MightyForms Plugin mightyforms Cross-Site Scripting MightyForms <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.9 CVE-2024-11897 Wordfence
6.5 Medium Elementor Portfolio Builder Plugin portfolio-builder-elementor Cross-Site Scripting ≤ 1.0.0 CVE-2024-52486 Patchstack
5.4 Medium Build App Online Plugin build-app-online Cross-Site Request Forgery No login needed ≤ 1.0.23 CVE-2024-53751 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
6.1 Medium FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-11458 Wordfence
6.4 Medium Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Plugin pricing-tables-for-visual-composer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wdo_pricing_tables Shortcode ≤ 1.4 CVE-2024-10175 Wordfence
5.3 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Path Traversal Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View No login needed ≤ 3.0.6 CVE-2024-11219 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.25.7 CVE-2024-8236 Wordfence
6.1 Medium Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder Plugin formidable Cross-Site Scripting Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter No login needed ≤ 6.16.1.2 CVE-2024-11188 Wordfence
6.4 Medium HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents Plugin hipaatizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.4 CVE-2024-11332 Wordfence
4.3 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Information Disclosure Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post Disclosure ≤ 2.1.9 CVE-2024-10868 Wordfence
4.3 Medium WP User Manager – User Profile Builder & Membership Plugin wp-user-manager Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration ≤ 2.9.11 CVE-2024-10537 Wordfence
4.3 Medium WP User Manager – User Profile Builder & Membership Plugin wp-user-manager Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal ≤ 2.9.11 CVE-2024-10216 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only