WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 951–1,000 of 1,457 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 20 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Auto iFrame Plugin auto-iframe Cross-Site Scripting Contributor+ XSS via Shortcode < 2.0 Fixed in 2.0 CVE-2024-10151 WPScan
7.1 High Smoothness Slider Shortcode Plugin smoothness-slider-shortcode Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ v1.2.2 CVE-2025-22555 Patchstack
6.5 Medium mcjh button shortcode Plugin mcjh-button-shortcode Cross-Site Scripting ≤ 1.6.4 CVE-2025-22558 Patchstack
6.4 Medium Marketplace Items Plugin marketplace-items Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.5 CVE-2024-12437 Wordfence
5.3 Medium Tabs Shortcode Plugin Cross-Site Scripting Contributor+ XSS via Shortcode No login needed ≤ 2.0.2 CVE-2024-11606 WPScan
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
6.4 Medium Social Rocket Plugin social-rocket Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.4 CVE-2024-9702 Wordfence
6.4 Medium Marketplace Items Plugin marketplace-items Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'marketplace' Shortcode ≤ 1.5.5 CVE-2024-12439 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
4.4 Medium Toggles Shortcode and Widget Plugin toggles-shortcode-and-widget Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.14 CVE-2024-12207 Wordfence
6.5 Medium Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler Plugin cf7-styler Arbitrary Shortcode Execution CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-12419 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
6.4 Medium Taskbuilder – WordPress Project & Task Management Plugin taskbuilder Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode ≤ 3.0.6 CVE-2024-11930 Wordfence
7.3 High WordPress Popular Posts Plugin wordpress-popular-posts Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 7.1.0 CVE-2024-11733 Wordfence
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.14 Fixed in 2.1.15 CVE-2024-56242 Patchstack
7.1 High My Shortcodes Plugin my-shortcodes Broken Access Control ≤ 2.3 CVE-2023-46632 Patchstack
6.5 Medium Category Post Shortcode Plugin category-post-shortcode Cross-Site Scripting ≤ 2.4 CVE-2024-56021 Patchstack
6.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Arbitrary Shortcode Execution The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.8.22 CVE-2024-12238 Wordfence
5.9 Medium WP-SVG Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 0.9 CVE-2024-11644 WPScan
6.4 Medium MagicPost Plugin magicpost Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wb_share_social Shortcode ≤ 1.2.1 CVE-2024-12591 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget ≤ 2.17.2 CVE-2024-12588 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes ≤ 2.17.0 CVE-2024-9545 Wordfence
6.4 Medium Multi-column Tag Map Plugin multi-column-tag-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mctagmap Shortcode ≤ 17.0.33 CVE-2024-11196 Wordfence
6.4 Medium One Click Upsell Funnel for WooCommerce Plugin woo-one-click-upsell-funnel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wps_wocuf_pro_yes Shortcode ≤ 3.4.9 CVE-2024-11938 Wordfence
7.3 High kk Star Ratings – Rate Post & Collect User Feedbacks Plugin kk-star-ratings Arbitrary Shortcode Execution Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.4.10 CVE-2024-11977 Wordfence
5.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 1.2.7 Fixed in 1.2.7 CVE-2024-11108 WPScan
7.3 High Download Manager Plugin download-manager Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.3.03 CVE-2024-11740 Wordfence
7.1 High Geoportail Shortcode Plugin geoportail-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.4.4 CVE-2024-54414 Patchstack
5.4 Medium Tithe.ly Giving Button Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1 CVE-2024-11841 WPScan
6.4 Medium Ganohrs Toggle Shortcode Plugin ganohrs-toggle-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2.4 CVE-2024-12459 Wordfence
4.3 Medium Shortcodes for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.4 CVE-2024-10690 Wordfence
4.3 Medium Get Post Content Shortcode Plugin get-post-content-shortcode Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via post_content Shortcode ≤ 0.4 CVE-2024-12447 Wordfence
6.4 Medium WooCommerce Cart Count Shortcode Plugin woo-cart-count-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-12517 Wordfence
6.5 Medium Quran Phrases About Most People Shortcodes Plugin quran-phrases-about-most-people-shortcodes Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2024-54334 Patchstack
7.1 High Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-54264 Patchstack
6.4 Medium Out of the Block: OpenStreetMap Plugin ootb-openstreetmap Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ootb_query Shortcode ≤ 2.8.3 CVE-2024-11827 Wordfence
6.3 Medium Notibar – Notification Bar Plugin notibar Arbitrary Shortcode Execution Notification Bar for WordPress <= 2.1.4 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via njt_nofi_text ≤ 2.1.4 CVE-2024-11012 Wordfence
6.5 Medium Simple Link Directory Plugin simple-link-directory Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.4.5 CVE-2024-12417 Wordfence
6.5 Medium Coupon Affiliates – Affiliate Plugin for WooCommerce Plugin woo-coupon-usage Arbitrary Shortcode Execution Affiliate Plugin for WooCommerce <= 5.16.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 5.16.7.1 CVE-2024-12421 Wordfence
6.5 Medium WPMobile.App — Android and iOS Mobile Application Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 11.52 CVE-2024-12420 Wordfence
5.4 Medium SVG Shortcode Plugin svg-shortcode Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.0.1 CVE-2024-12574 Wordfence
6.5 Medium WoodMart Theme Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 8.0.3 CVE-2024-12333 Wordfence
6.4 Medium Social Media Shortcodes Plugin social-media-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.0 CVE-2024-11871 Wordfence
4.3 Medium Snippet Shortcodes Plugin shortcode-variables Broken Access Control Authenticated (Subscriber+) Shortcode Deletion ≤ 4.1.6 CVE-2024-12018 Wordfence
6.4 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode ≤ 0.4.1 CVE-2024-12463 Wordfence
7.3 High Grid Plus – Unlimited grid layout Plugin grid-plus Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed ≤ 1.3.5 CVE-2024-10910 Wordfence
6.4 Medium Surbma | SalesAutopilot Shortcode Plugin surbma-salesautopilot-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5 CVE-2024-11433 Wordfence
7.3 High Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via woot_get_smth No login needed ≤ 1.0.6.5 CVE-2024-10959 Wordfence
4.7 Medium Login Widget With Shortcode Plugin login-sidebar-widget Open Redirect No login needed ≤ 6.1.2 CVE-2024-54255 Patchstack
4.3 Medium Shortcodes Plugin wc-shortcodes Broken Access Control No login needed ≤ 3.46 CVE-2023-23725 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only