WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,551–8,600 of 8,917 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 172 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Comic Easel Plugin comic-easel Cross-Site Scripting No login needed ≤ 1.15 CVE-2024-31092 Patchstack
7.1 High SEO Title Tag Plugin seo-title-tag Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.9 CVE-2024-31097 Patchstack
7.1 High Kanban Boards Plugin kanban Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.21 CVE-2024-31103 Patchstack
7.1 High Yoo Slider Plugin yoo-slider Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2024-31106 Patchstack
7.1 High OpenID Plugin openid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.1 CVE-2024-31107 Patchstack
7.1 High Contact Form 7 Newsletter Plugin contact-form-7-newsletter Cross-Site Scripting No login needed ≤ 2.2 CVE-2024-31110 Patchstack
7.1 High Convert Post Types Plugin convert-post-types Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-31112 Patchstack
7.1 High SpiderFAQ Plugin spider-faq Cross-Site Scripting No login needed ≤ 1.3.2 CVE-2024-31123 Patchstack
8.5 High WP Cost Estimation & Payment Forms Builder Plugin SQL Injection ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-30489 Patchstack
8.5 High Easy Form Builder Plugin easy-form-builder SQL Injection ≤ 3.7.4 Fixed in 3.7.5 CVE-2024-30535 Patchstack
7.6 High 10Web Map Builder for Google Maps Plugin wd-google-maps SQL Injection ≤ 1.0.74 CVE-2024-31116 Patchstack
7.5 High Layouts for Elementor Plugin layouts-for-elementor Arbitrary File Upload No login needed < 1.8 Fixed in 1.8 CVE-2024-30533 Patchstack
8.5 High Filter Custom Fields & Taxonomies Light Plugin filter-custom-fields-taxonomies-light PHP Object Injection ≤ 1.05 CVE-2024-31094 Patchstack
8.8 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite PHP Object Injection Authenticated (Author+) PHP Object Injection via error_resetpassword ≤ 5.9.13 CVE-2024-3018 Wordfence
8.8 High ElementsKit Elementor addons Plugin elementskit-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion in render_raw ≤ 3.0.6 CVE-2024-2047 Wordfence
7.1 High Mang Board WP Plugin mangboard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-30431 Patchstack
7.1 High Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.2.5 Fixed in 3.2.6 CVE-2024-30435 Patchstack
7.1 High Limit Attempts by BestWebSoft Plugin limit-attempts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-30439 Patchstack
7.1 High Post Grid Plugin post-grid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.74 Fixed in 2.2.76 CVE-2024-30441 Patchstack
7.1 High Creative Image Slider – Responsive Slider Plugin creative-image-slider Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.5.0 CVE-2024-30447 Patchstack
7.1 High Booking Activities Plugin booking-activities Cross-Site Scripting No login needed ≤ 1.15.19 Fixed in 1.15.20 CVE-2024-30449 Patchstack
7.1 High All In One Redirection Plugin all-in-one-redirection-404-pages-list Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-30506 Patchstack
7.6 High WP Travel Engine Plugin wp-travel-engine SQL Injection ≤ 5.7.9 Fixed in 5.8.0 CVE-2024-30504 Patchstack
7.6 High Download Monitor Plugin download-monitor SQL Injection Auth. SQL Injection ≤ 4.9.4 Fixed in 4.9.5 CVE-2024-30501 Patchstack
8.5 High CRM Perks Forms Plugin crm-perks-forms SQL Injection ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-30499 Patchstack
8.5 High WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs SQL Injection ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-30497 Patchstack
8.5 High Element Pack Elementor Addons Plugin bdthemes-element-pack-lite SQL Injection ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-30496 Patchstack
7.6 High Falang multilanguage Plugin falang SQL Injection ≤ 1.3.47 Fixed in 1.3.48 CVE-2024-30495 Patchstack
7.6 High OSS Aliyun Plugin oss-aliyun SQL Injection ≤ 1.4.10 Fixed in 1.4.11 CVE-2024-30494 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - SQL Injection ≤ 5.7.8 Fixed in 5.7.9 CVE-2024-30491 Patchstack
8.5 High Zotpress Plugin zotpress SQL Injection ≤ 7.3.7 Fixed in 7.3.8 CVE-2024-30488 Patchstack
7.6 High MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.1 Fixed in 5.1.1 CVE-2024-30487 Patchstack
8.5 High Media Library Folders Plugin media-library-plus SQL Injection Auth. SQL Injection ≤ 8.1.7 Fixed in 8.1.8 CVE-2024-30486 Patchstack
7.6 High WordPress Announcement & Notification Banner Plugin – Bulletin Plugin bulletin-announcements SQL Injection Bulletin plugin <= 3.8.5 - SQL Injection ≤ 3.8.5 Fixed in 3.9.0 CVE-2024-30478 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-30428 Patchstack
7.1 High Jobeleon Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2022-47153 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2024-30503 Patchstack
7.5 High Responsive Theme responsive Broken Access Control Missing Authorization to HTML Injection No login needed ≤ 5.0.2 CVE-2024-2848 Wordfence
7.2 High HUSKY – Products Filter Professional for WooCommerce Plugin Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion ≤ 1.3.5.2 CVE-2024-3061 Wordfence
8.8 High Button Plugin button PHP Object Injection Authenticated (Contributor+) PHP Object Injection in button_shortcode ≤ 1.1.27 CVE-2024-1872 Wordfence
7.2 High WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting Plugin erp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.13.1 CVE-2024-0609 Wordfence
7.2 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection ≤ 1.13.0 CVE-2024-0913 Wordfence
7.1 High Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2024-25599 Patchstack
7.1 High Preview E-mails for WooCommerce Plugin woo-preview-emails Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2024-27999 Patchstack
7.1 High Favicon Rotator Plugin favicon-rotator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-28001 Patchstack
7.1 High Cornerstone Plugin cornerstone Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.8.0 Fixed in 0.8.1 CVE-2024-28002 Patchstack
8.5 High Fusion Builder Plugin SQL Injection Auth. SQL Injection ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39309 Patchstack
7.6 High WP Testimonials Plugin testimonial-widgets SQL Injection Auth. SQL Injection ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-25924 Patchstack
8.1 High MainWP Links Manager Extension Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.1 CVE-2023-23649 Patchstack
7.1 High Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-34370 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only