WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,501–8,550 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 171 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Networker - Tech News WordPress Theme with Dark Mode Theme Broken Access Control Tech News WordPress Theme with Dark Mode <= 1.1.9 - Missing Authorization No login needed ≤ 1.1.9 CVE-2024-2962 Wordfence
6.5 Medium WishSuite Plugin wishsuite Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-29927 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-29926 Patchstack
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Cross-Site Scripting ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-29925 Patchstack
5.9 Medium Slider Hero Plugin slider-hero Cross-Site Scripting ≤ 8.6.1 Fixed in 8.7.0 CVE-2024-29922 Patchstack
5.9 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Scripting ≤ 1.15.16 Fixed in 1.15.17 CVE-2024-29921 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-29920 Patchstack
6.5 Medium Compact WP Audio Player Plugin compact-wp-audio-player Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2024-29917 Patchstack
6.5 Medium Stratum Plugin stratum Cross-Site Scripting Elementor Widgets plugin <= 1.3.15 - Cross Site Scripting (XSS) ≤ 1.3.15 Fixed in 1.3.16 CVE-2024-29914 Patchstack
6.5 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-29913 Patchstack
6.5 Medium iCalendrier Plugin icalendrier Cross-Site Scripting ≤ 1.80 Fixed in 1.81 CVE-2024-29912 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-29911 Patchstack
6.5 Medium Dropdown Multisite selector Plugin dropdown-multisite-selector Cross-Site Scripting ≤ 0.9.2 Fixed in 0.9.2.1 CVE-2024-29910 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-29909 Patchstack
6.5 Medium Co-marquage service-public.fr Plugin co-marquage-service-public Cross-Site Scripting ≤ 0.5.71 Fixed in 0.5.72 CVE-2024-29908 Patchstack
6.5 Medium PDF Builder for WPForms Plugin pdf-builder-for-wpforms Cross-Site Scripting ≤ 1.2.88 Fixed in 1.2.89 CVE-2024-29820 Patchstack
5.9 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting Meta Data and Taxonomies Filter plugin <= 1.3.2 - Cross Site Scripting (XSS) ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-29906 Patchstack
6.5 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-30192 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.1.17 Fixed in 4.1.18 CVE-2024-30193 Patchstack
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-27188 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30197 Patchstack
5.8 Medium BuddyForms Plugin buddyforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2024-30198 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.24 Fixed in 2.0.25 CVE-2023-52228 Patchstack
6.5 Medium WP SMS Plugin wp-sms Cross-Site Scripting ≤ 6.3.4 Fixed in 6.4 CVE-2024-25920 Patchstack
5.3 Medium Community by PeepSo Plugin peepso-core Information Disclosure Server Information Disclosure No login needed ≤ 6.0.9.0 Fixed in 6.1.0.0 CVE-2023-27630 Patchstack
5.9 Medium Upload Resume Plugin resume-upload-form Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.0 CVE-2023-25965 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck
4.3 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2023-52214 Patchstack
6.5 Medium SalesKing Plugin Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22156 Patchstack
6.5 Medium Radio Player Plugin radio-player Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-2906 Patchstack
4.3 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Broken Access Control MPG plugin <= 3.4.0 - Broken Access Control ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-30235 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30234 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Information Disclosure Sensitive Data Exposure on User Export ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30233 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9 Fixed in 2.6.9.1 CVE-2024-30232 Patchstack
4.3 Medium PopupAlly Plugin popupally Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-23520 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-24711 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control Missing Authorization to Non-Arbitrary Plugin Installation ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-24718 Patchstack
4.3 Medium Location Picker at Checkout for WooCommerce Plugin map-location-picker-at-checkout-for-woocommerce Broken Access Control ≤ 1.8.9 Fixed in 1.9.0 CVE-2024-24719 Patchstack
6.5 Medium WooCommerce Box Office Plugin woocommerce-box-office Broken Access Control ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-24799 Patchstack
4.3 Medium Calliope Theme calliope Cross-Site Request Forgery No login needed ≤ 1.0.33 Fixed in 1.0.35 CVE-2024-2904 Patchstack
4.3 Medium WP Dummy Content Generator Plugin wp-dummy-content-generator Broken Access Control No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2024-24805 Patchstack
6.5 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting ≤ 20230901 Fixed in 20230902 CVE-2023-7251 Patchstack
6.5 Medium EnvíaloSimple Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery No login needed ≤ 2.2 Fixed in 2.3 CVE-2023-51416 Patchstack
5.9 Medium WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting ≤ 2.6.11 Fixed in 2.6.12 CVE-2024-2889 Patchstack
6.5 Medium Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Plugin post-and-page-builder Cross-Site Scripting ≤ 1.26.2 Fixed in 1.26.3 CVE-2024-2888 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only