WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 51–78 of 78 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 2 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium R Animated Icon Plugin r-animated-icon Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9272 Wordfence
6.5 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-47641 Patchstack
6.4 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via confetti-fall-animation Shortcode ≤ 1.3.1 CVE-2024-8919 Wordfence
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 9.3.7 Fixed in 9.4 CVE-2024-44005 Patchstack
5.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element ≤ 2.0.6.4 CVE-2024-6282 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id and eae_slider_animation Parameters ≤ 1.13.5 CVE-2024-4401 Wordfence
6.5 Medium Animated Number Counters Plugin animated-number-counters Local File Inclusion Editor+ Limited Local File Inclusion ≤ 1.9 CVE-2024-43957 Patchstack
6.5 Medium Animated Typed JS Shortcode Plugin animated-typed-js-shortcode Cross-Site Scripting ≤ 2.0 CVE-2024-38679 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
5.4 Medium Animated AL List Plugin animated-al-list Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.6 CVE-2024-5728 WPScan
6.5 Medium Anima Theme anima Cross-Site Scripting ≤ 1.4.1 CVE-2024-37248 Patchstack
6.5 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) ≤ 8.8.9.1 Fixed in 8.9.4 CVE-2024-35765 Patchstack
6.5 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification No login needed ≤ 2.0.6.1 CVE-2024-5382 Wordfence
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
6.4 Medium LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor Plugin include-lottie-animation-for-elementor Cross-Site Scripting JSON Based Animation Lottie & Bodymovin for Elementor <= 1.10.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.10.9 CVE-2024-5060 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-4580 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animation Title widget img tag ≤ 2.1.5 CVE-2024-3680 Wordfence
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.5.9 - Contributor+ Stored Cross-Site Scripting ≤ 2.0.5.9 CVE-2024-4265 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget ≤ 5.6.0 CVE-2024-1429 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget ≤ 5.6.0 CVE-2024-1426 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget ≤ 1.0.15 CVE-2024-2138 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget ≤ 8.3.4 CVE-2024-1458 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
4.3 Medium Tumult Hype Animations Plugin tumult-hype-animations Cross-Site Request Forgery No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2024-30460 Patchstack
6.5 Medium Lordicon Animated Icons Plugin lordicon-interactive-icons Cross-Site Scripting ≤ 2.0.1 CVE-2024-30519 Patchstack
6.4 Medium Animated Headline Plugin animated-headline Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.0 CVE-2024-2304 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only