WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 8,551–8,600 of 8,917 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | Comic Easel | Cross-Site Scripting No login needed |
≤ 1.15 |
CVE-2024-31092 |
Patchstack | |
| 7.1 High | SEO Title Tag | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.5.9 |
CVE-2024-31097 |
Patchstack | |
| 7.1 High | Kanban Boards | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.5.21 |
CVE-2024-31103 |
Patchstack | |
| 7.1 High | Yoo Slider | Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.1 |
CVE-2024-31106 |
Patchstack | |
| 7.1 High | OpenID | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.6.1 |
CVE-2024-31107 |
Patchstack | |
| 7.1 High | Contact Form 7 Newsletter | Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2024-31110 |
Patchstack | |
| 7.1 High | Convert Post Types | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.4 |
CVE-2024-31112 |
Patchstack | |
| 7.1 High | SpiderFAQ | Cross-Site Scripting No login needed |
≤ 1.3.2 |
CVE-2024-31123 |
Patchstack | |
| 8.5 High | WP Cost Estimation & Payment Forms Builder | SQL Injection |
≤ 10.1.75 Fixed in 10.1.76 |
CVE-2024-30489 |
Patchstack | |
| 8.5 High | Easy Form Builder | SQL Injection |
≤ 3.7.4 Fixed in 3.7.5 |
CVE-2024-30535 |
Patchstack | |
| 7.6 High | 10Web Map Builder for Google Maps | SQL Injection |
≤ 1.0.74 |
CVE-2024-31116 |
Patchstack | |
| 7.5 High | Layouts for Elementor | Arbitrary File Upload No login needed |
< 1.8 Fixed in 1.8 |
CVE-2024-30533 |
Patchstack | |
| 8.5 High | Filter Custom Fields & Taxonomies Light | PHP Object Injection |
≤ 1.05 |
CVE-2024-31094 |
Patchstack | |
| 8.8 High | Essential Addons for Elementor | PHP Object Injection Authenticated (Author+) PHP Object Injection via error_resetpassword |
≤ 5.9.13 |
CVE-2024-3018 |
Wordfence | |
| 8.8 High | ElementsKit Elementor addons | Local File Inclusion Authenticated (Contributor+) Local File Inclusion in render_raw |
≤ 3.0.6 |
CVE-2024-2047 |
Wordfence | |
| 7.1 High | Mang Board WP | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.8.0 Fixed in 1.8.1 |
CVE-2024-30431 |
Patchstack | |
| 7.1 High | Nexter Blocks | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.2.5 Fixed in 3.2.6 |
CVE-2024-30435 |
Patchstack | |
| 7.1 High | Limit Attempts by BestWebSoft | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.9 Fixed in 1.3.0 |
CVE-2024-30439 |
Patchstack | |
| 7.1 High | Post Grid | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.74 Fixed in 2.2.76 |
CVE-2024-30441 |
Patchstack | |
| 7.1 High | Creative Image Slider – Responsive Slider | Cross-Site Scripting No login needed |
≤ 2.1.3 Fixed in 2.5.0 |
CVE-2024-30447 |
Patchstack | |
| 7.1 High | Booking Activities | Cross-Site Scripting No login needed |
≤ 1.15.19 Fixed in 1.15.20 |
CVE-2024-30449 |
Patchstack | |
| 7.1 High | All In One Redirection | Cross-Site Scripting No login needed |
≤ 2.2.0 |
CVE-2024-30506 |
Patchstack | |
| 7.6 High | WP Travel Engine | SQL Injection |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-30504 |
Patchstack | |
| 7.6 High | Download Monitor | SQL Injection Auth. SQL Injection |
≤ 4.9.4 Fixed in 4.9.5 |
CVE-2024-30501 |
Patchstack | |
| 8.5 High | CRM Perks Forms | SQL Injection |
≤ 1.1.4 Fixed in 1.1.5 |
CVE-2024-30499 |
Patchstack | |
| 8.5 High | WP Responsive Tabs horizontal vertical and accordion Tabs | SQL Injection |
≤ 1.1.17 Fixed in 1.1.18 |
CVE-2024-30497 |
Patchstack | |
| 8.5 High | Element Pack Elementor Addons | SQL Injection |
≤ 5.5.3 Fixed in 5.5.4 |
CVE-2024-30496 |
Patchstack | |
| 7.6 High | Falang multilanguage | SQL Injection |
≤ 1.3.47 Fixed in 1.3.48 |
CVE-2024-30495 |
Patchstack | |
| 7.6 High | OSS Aliyun | SQL Injection |
≤ 1.4.10 Fixed in 1.4.11 |
CVE-2024-30494 |
Patchstack | |
| 8.5 High | ProfileGrid | SQL Injection User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - SQL Injection |
≤ 5.7.8 Fixed in 5.7.9 |
CVE-2024-30491 |
Patchstack | |
| 8.5 High | Zotpress | SQL Injection |
≤ 7.3.7 Fixed in 7.3.8 |
CVE-2024-30488 |
Patchstack | |
| 7.6 High | MP3 Audio Player for Music, Radio & Podcast by Sonaar | Broken Access Control |
≤ 5.1 Fixed in 5.1.1 |
CVE-2024-30487 |
Patchstack | |
| 8.5 High | Media Library Folders | SQL Injection Auth. SQL Injection |
≤ 8.1.7 Fixed in 8.1.8 |
CVE-2024-30486 |
Patchstack | |
| 7.6 High | WordPress Announcement & Notification Banner Plugin – Bulletin | SQL Injection Bulletin plugin <= 3.8.5 - SQL Injection |
≤ 3.8.5 Fixed in 3.9.0 |
CVE-2024-30478 |
Patchstack | |
| 7.1 High | Contest Gallery | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 24.0.3 Fixed in 24.0.4 |
CVE-2024-30428 |
Patchstack | |
| 7.1 High | Jobeleon | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.9.1 Fixed in 1.9.2 |
CVE-2022-47153 |
Patchstack | |
| 7.1 High | Mailster | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.0.6 Fixed in 4.0.7 |
CVE-2024-30503 |
Patchstack | |
| 7.5 High | Responsive | Broken Access Control Missing Authorization to HTML Injection No login needed |
≤ 5.0.2 |
CVE-2024-2848 |
Wordfence | |
| 7.2 High | HUSKY – Products Filter Professional for WooCommerce | Local File Inclusion Products Filter Professional for WooCommerce <= 1.3.5.2 - Authenticated (Admin+) Local File Inclusion |
≤ 1.3.5.2 |
CVE-2024-3061 |
Wordfence | |
| 8.8 High | Button | PHP Object Injection Authenticated (Contributor+) PHP Object Injection in button_shortcode |
≤ 1.1.27 |
CVE-2024-1872 |
Wordfence | |
| 7.2 High | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.13.1 |
CVE-2024-0609 |
Wordfence | |
| 7.2 High | WP ERP | SQL Injection Authenticated (Accounting Manager+) SQL Injection |
≤ 1.13.0 |
CVE-2024-0913 |
Wordfence | |
| 7.1 High | Seriously Simple Podcasting | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.0.2 Fixed in 3.1.0 |
CVE-2024-25599 |
Patchstack | |
| 7.1 High | Preview E-mails for WooCommerce | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.1 Fixed in 2.2.2 |
CVE-2024-27999 |
Patchstack | |
| 7.1 High | Favicon Rotator | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.2.10 Fixed in 1.2.11 |
CVE-2024-28001 |
Patchstack | |
| 7.1 High | Cornerstone | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 0.8.0 Fixed in 0.8.1 |
CVE-2024-28002 |
Patchstack | |
| 8.5 High | Fusion Builder | SQL Injection Auth. SQL Injection |
≤ 3.11.1 Fixed in 3.11.2 |
CVE-2023-39309 |
Patchstack | |
| 7.6 High | WP Testimonials | SQL Injection Auth. SQL Injection |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2024-25924 |
Patchstack | |
| 8.1 High | MainWP Links Manager Extension | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 2.1 |
CVE-2023-23649 |
Patchstack | |
| 7.1 High | Starter Templates — Elementor, WordPress & Beaver Builder Templates | Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins |
≤ 3.2.4 Fixed in 3.2.5 |
CVE-2023-34370 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.