WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–92 of 92 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Animated Counters Plugin animated-counters Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-11905 Wordfence
7.1 High Go Animate Plugin goanimate Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54397 Patchstack
4.3 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Information Disclosure animation and page builder blocks <= 9.9.9.3 - Authenticated (Contributor+) Post Disclosure ≤ 9.9.9.3 CVE-2024-11181 Wordfence
9.9 Critical Tumult Hype Animations Plugin tumult-hype-animations Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload via hypeanimations_panel Function ≤ 1.9.15 CVE-2024-11082 Wordfence
6.4 Medium Counter Up – Animated Number Counter & Milestone Showcase Plugin Cross-Site Scripting Animated Number Counter & Milestone Showcase <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2024-10895 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Limited Arbitrary Options Update No login needed ≤ 2.6.1 CVE-2024-11601 Wordfence
8.1 High Sky Addons – Elementor Addons with Widgets & Templates Plugin sky-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.6.2 CVE-2024-11104 Wordfence
4.3 Medium Tumult Hype Animations Plugin tumult-hype-animations Broken Access Control Missing Authorization ≤ 1.9.14 CVE-2024-10543 Wordfence
5.4 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 9.7 Fixed in 9.8 CVE-2024-50419 Patchstack
7.1 High Animator Plugin scroll-triggered-animations Cross-Site Scripting Scroll Triggered Animations plugin <= 3.0.15 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2024-49308 Patchstack
6.4 Medium R Animated Icon Plugin r-animated-icon Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9272 Wordfence
6.5 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-47641 Patchstack
6.4 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via confetti-fall-animation Shortcode ≤ 1.3.1 CVE-2024-8919 Wordfence
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 9.3.7 Fixed in 9.4 CVE-2024-44005 Patchstack
5.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element ≤ 2.0.6.4 CVE-2024-6282 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters ≤ 1.13.5 CVE-2024-4401 Wordfence
6.5 Medium Animated Number Counters Plugin animated-number-counters Local File Inclusion Editor+ Limited Local File Inclusion ≤ 1.9 CVE-2024-43957 Patchstack
3.7 Low Maintenance & Coming Soon Redirect Animation Plugin maintenance-coming-soon-redirect-animation Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3.3 CVE-2024-43944 Patchstack
6.5 Medium Animated Typed JS Shortcode Plugin animated-typed-js-shortcode Cross-Site Scripting ≤ 2.0 CVE-2024-38679 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
5.4 Medium Animated AL List Plugin animated-al-list Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.6 CVE-2024-5728 WPScan
6.5 Medium Anima Theme anima Cross-Site Scripting ≤ 1.4.1 CVE-2024-37248 Patchstack
6.5 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) ≤ 8.8.9.1 Fixed in 8.9.4 CVE-2024-35765 Patchstack
6.5 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification No login needed ≤ 2.0.6.1 CVE-2024-5382 Wordfence
7.2 High Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed ≤ 2.0.6.1 CVE-2024-5542 Wordfence
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
6.4 Medium LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Plugin include-lottie-animation-for-elementor Cross-Site Scripting JSON Based Animation Lottie & Bodymovin for Elementor <= 1.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.10.9 CVE-2024-5060 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-4580 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animation Title widget img tag ≤ 2.1.5 CVE-2024-3680 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting ≤ 2.0.5.9 CVE-2024-4265 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget ≤ 5.6.0 CVE-2024-1429 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget ≤ 5.6.0 CVE-2024-1426 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget ≤ 1.0.15 CVE-2024-2138 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget ≤ 8.3.4 CVE-2024-1458 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
4.3 Medium Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30460 Patchstack
6.5 Medium Lordicon Animated Icons Plugin lordicon-interactive-icons Cross-Site Scripting ≤ 2.0.1 CVE-2024-30519 Patchstack
9.1 Critical Tumult Hype Animations Plugin tumult-hype-animations Arbitrary File Upload ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-2890 Patchstack
6.4 Medium Animated Headline Plugin animated-headline Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.0 CVE-2024-2304 Wordfence
7.2 High Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload ≤ 7.6.2 CVE-2023-6636 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only