WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 8,801–8,850 of 8,907 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 177 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Product Code for WooCommerce Plugin product-code-for-woocommerce Cross-Site Scripting WordPress Product Code for WooCommerce Plugin <= 1.4.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.4 Fixed in 1.4.5 CVE-2023-51669 Patchstack
6.5 Medium Related Post Plugin related-post Cross-Site Scripting WordPress Related Post Plugin <= 2.0.53 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.53 Fixed in 2.0.54 CVE-2023-51666 Patchstack
5.9 Medium SlickNav Mobile Menu Plugin slicknav-mobile-menu Cross-Site Scripting WordPress SlickNav Mobile Menu Plugin <= 1.9.2 is vulnerable to Cross Site Scripting (XSS) ≤ 1.9.2 Fixed in 1.9.3 CVE-2023-51548 Patchstack
6.5 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Cross-Site Scripting WordPress WP User Profile Avatar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 Fixed in 1.0.1 CVE-2023-52118 Patchstack
6.5 Medium Auto Amazon Links – Amazon Associates Affiliate Plugin amazon-auto-links Cross-Site Scripting WordPress Auto Amazon Links Plugin <= 5.1.1 is vulnerable to Cross Site Scripting (XSS) ≤ 5.1.1 Fixed in 5.1.2 CVE-2023-52175 Patchstack
6.5 Medium Footer Putter Plugin footer-putter Cross-Site Scripting WordPress Footer Putter Plugin <= 1.17 is vulnerable to Cross Site Scripting (XSS) ≤ 1.17 CVE-2023-52188 Patchstack
6.5 Medium Ideal Interactive Map Plugin ideal-interactive-map Cross-Site Scripting WordPress Ideal Interactive Map Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.4 CVE-2023-52189 Patchstack
6.5 Medium Infogram – Add charts, maps and infographics Plugin infogram Cross-Site Scripting WordPress Infogram Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.1 CVE-2023-52191 Patchstack
6.5 Medium Keap Official Opt-in Forms Plugin infusionsoft-official-opt-in-forms Cross-Site Scripting WordPress Keap Official Opt-in Forms Plugin <= 1.0.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2023-52192 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting WordPress Page Builder: Live Composer Plugin <= 1.5.23 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.23 Fixed in 1.5.24 CVE-2023-52193 Patchstack
6.5 Medium oEmbed Gist Plugin oembed-gist Cross-Site Scripting WordPress oEmbed Gist Plugin <= 4.9.1 is vulnerable to Cross Site Scripting (XSS) ≤ 4.9.1 CVE-2023-52194 Patchstack
6.5 Medium Kerry James Plugin posts-to-page Cross-Site Scripting WordPress Posts to Page Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7 CVE-2023-52195 Patchstack
6.5 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting WordPress Schema & Structured Data for WP & AMP Plugin <= 1.25 is vulnerable to Cross Site Scripting (XSS) ≤ 1.25 Fixed in 1.26 CVE-2024-22146 Patchstack
5.9 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Cross-Site Scripting WordPress Stock Locations for WooCommerce Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) ≤ 2.5.9 Fixed in 2.6.0 CVE-2024-22153 Patchstack
6.5 Medium Portfolio & Image Gallery for WordPress | PowerFolio Plugin portfolio-elementor Cross-Site Scripting WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) ≤ 3.1 Fixed in 3.1.1 CVE-2024-22150 Patchstack
6.5 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Cross-Site Scripting WordPress PeepSo Core: Photos Plugin < 6.3.1.0 is vulnerable to Cross Site Scripting (XSS) < 6.3.1.0 Fixed in 6.3.1.0 CVE-2024-22158 Patchstack
5.9 Medium HD Quiz Plugin hd-quiz Cross-Site Scripting WordPress HD Quiz Plugin <= 1.8.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.8.11 Fixed in 1.8.12 CVE-2024-22161 Patchstack
6.5 Medium WP To Do Plugin wp-todo Cross-Site Scripting WordPress WP To Do Plugin <= 1.2.8 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.8 CVE-2024-22292 Patchstack
5.9 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting WordPress Robo Gallery Plugin <= 3.2.17 is vulnerable to Cross Site Scripting (XSS) ≤ 3.2.17 Fixed in 3.2.18 CVE-2024-22295 Patchstack
6.5 Medium CBX Map for Google Map & OpenStreetMap Plugin cbxgooglemap Cross-Site Scripting WordPress CBX Map for Google Map & OpenStreetMap Plugin <= 1.1.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.11 CVE-2024-22297 Patchstack
6.5 Medium Albo Pretorio On line Plugin albo-pretorio-on-line Cross-Site Scripting WordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Cross Site Scripting (XSS) ≤ 4.6.6 CVE-2024-22302 Patchstack
5.9 Medium Mang Board WP Plugin mangboard Cross-Site Scripting WordPress Mang Board WP Plugin <= 1.7.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7.7 CVE-2024-22306 Patchstack
6.5 Medium Formzu WP Plugin formzu-wp Cross-Site Scripting WordPress Formzu WP Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-22310 Patchstack
6.5 Medium Posts List Designer by Category – List Category Posts Or Recent Posts Plugin post-list-designer Cross-Site Scripting List Category Posts Or Recent Posts Plugin <= 3.3.2 is vulnerable to Cross Site Scripting (XSS) ≤ 3.3.2 CVE-2024-23502 Patchstack
6.5 Medium PDF Viewer & 3D PDF Flipbook – DearPDF Plugin dearpdf-lite Cross-Site Scripting DearPDF Plugin <= 2.0.38 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.38 CVE-2024-23505 Patchstack
4.3 Medium Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder Plugin droit-elementor-addons Cross-Site Request Forgery WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.5 CVE-2024-22136 Patchstack
5.4 Medium WP Spell Check Plugin wp-spell-check Cross-Site Request Forgery WordPress WP Spell Check Plugin <= 9.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 9.17 Fixed in 9.18 CVE-2024-22143 Patchstack
5.4 Medium Frontpage Manager Plugin frontpage-manager Cross-Site Request Forgery WordPress Frontpage Manager Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2024-22285 Patchstack
4.3 Medium Browser Theme Color Plugin browser-theme-color Cross-Site Request Forgery WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2024-22291 Patchstack
5.4 Medium FreshMail Plugin freshmail-integration Cross-Site Request Forgery WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.2 CVE-2024-22304 Patchstack
4.3 Medium WordPress Review & Structure Data Schema Plugin – Review Schema Plugin review-schema Broken Access Control Review Schema <= 2.1.14 - Missing Authorization to Arbitrary Review Update ≤ 2.1.14 CVE-2024-0836 Wordfence
6.4 Medium UserPro - Community and User Profile Plugin Cross-Site Scripting The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitiz… 5.1.5 CVE-2023-2439 Wordfence
6.4 Medium MapPress Plugin mappress-google-maps-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings ≤ 2.88.16 CVE-2023-7225 Wordfence
6.1 Medium WordPress Toolbar Plugin Open Redirect No login needed ≤ 2.2.6 CVE-2023-6389 WPScan
4.4 Medium WordPress Simple Shopping Cart Plugin Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting ≤ 4.7.1 CVE-2023-6497 Wordfence
5.3 Medium Image Source Control Lite – Show Image Credits and Captions Plugin image-source-control-isc Information Disclosure WordPress Image Source Control Plugin <= 2.17.0 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.17.0 Fixed in 2.17.1 CVE-2023-52187 Patchstack
6.5 Medium Profile Builder Pro Plugin Information Disclosure WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Sensitive Data Exposure ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22141 Patchstack
5.3 Medium IP2Location Country Blocker Plugin ip2location-country-blocker Information Disclosure WordPress Download IP2Location Country Blocker Plugin <= 2.33.3 is vulnerable to Sensitive Data Exposure No login needed ≤ 2.33.3 Fixed in 2.33.4 CVE-2024-22294 Patchstack
5.3 Medium Albo Pretorio On line Plugin albo-pretorio-on-line Information Disclosure WordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Sensitive Data Exposure No login needed ≤ 4.6.6 CVE-2024-22301 Patchstack
4.9 Medium Contact Form 7 Extension For Mailchimp Plugin contact-form-7-mailchimp-extension Server-Side Request Forgery WordPress Contact Form 7 Extension For Mailchimp Plugin <= 0.5.70 is vulnerable to Server Side Request Forgery (SSRF) ≤ 0.5.70 CVE-2024-22134 Patchstack
6.5 Medium Wp Social Login and Register Social Counter Plugin wp-social Information Disclosure WordPress Wp Social Plugin <= 1.9.0 is vulnerable to Sensitive Data Exposure ≤ 1.9.0 Fixed in 2.0 CVE-2022-47160 Patchstack
4.3 Medium Smart Slider 3 Plugin smart-slider-3 PHP Object Injection WordPress Smart Slider 3 Plugin <= 3.5.1.9 is vulnerable to PHP Object Injection ≤ 3.5.1.9 Fixed in 3.5.1.11 CVE-2022-45845 Patchstack
6.6 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar PHP Object Injection WordPress ProfilePress Plugin <= 4.3.2 is vulnerable to PHP Object Injection ≤ 4.3.2 Fixed in 4.4.0 CVE-2022-45083 Patchstack
5.4 Medium WIP Custom Login Plugin wip-custom-login Broken Access Control WordPress WIP Custom Login Plugin <= 1.2.7 is vulnerable to Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2022-42884 Patchstack
4.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control WordPress WP Time Slots Booking Form Plugin <= 1.1.76 is vulnerable to Broken Access Control ≤ 1.1.76 Fixed in 1.1.77 CVE-2022-41790 Patchstack
5.4 Medium WP Job Portal – A Complete Job Board Plugin wp-job-portal Broken Access Control WordPress WP Job Portal Plugin <= 2.0.1 is vulnerable to Broken Access Control No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2022-41786 Patchstack
5.4 Medium Traffic Manager Plugin traffic-manager Broken Access Control WordPress Traffic Manager Plugin <= 1.4.5 is vulnerable to Broken Access Control ≤ 1.4.5 CVE-2022-41695 Patchstack
5.4 Medium Image Zoom Plugin image-zoom Broken Access Control WordPress Image Zoom Plugin <= 1.8.8 is vulnerable to Broken Access Control ≤ 1.8.8 CVE-2022-41619 Patchstack
5.4 Medium Advanced Local Pickup for WooCommerce Plugin advanced-local-pickup-for-woocommerce Broken Access Control WordPress Advanced Local Pickup for WooCommerce Plugin <= 1.5.2 is vulnerable to Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2022-40702 Patchstack
4.3 Medium Ultimate Addons for Beaver Builder – Lite Plugin ultimate-addons-for-beaver-builder-lite Broken Access Control Lite Plugin <= 1.5.5 is vulnerable to Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2023-23882 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only