WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,451–10,500 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 210 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium ElementsKit Elementor addons Plugin elementskit-lite Information Disclosure Unauthenticated Information Exposure via get_megamenu_content Function No login needed ≤ 3.4.0 CVE-2025-0968 Wordfence
6.1 Medium Raptive Ads Plugin adthrive-ads Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.6.3 CVE-2024-13363 Wordfence
5.3 Medium Raptive Ads Plugin adthrive-ads Broken Access Control Missing Authorization to Unauthenticated Data/Settings Reset No login needed ≤ 3.6.3 CVE-2024-13364 Wordfence
6.1 Medium DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 5.8.0 CVE-2024-13339 Wordfence
4.3 Medium Disable Auto Updates Plugin disable-auto-updates Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed ≤ 1.4 CVE-2024-13336 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.4 Medium Widget BUY.BOX Plugin buybox-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.5 CVE-2024-13679 Wordfence
4.3 Medium Apptivo Business Site CRM Plugin apptivo-business-site Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed ≤ 5.3 CVE-2024-13405 Wordfence
6.1 Medium Pure Chat – Live Chat & More! Plugin pure-chat Cross-Site Scripting Live Chat & More! <= 2.4 - Reflected Cross-Site Scripting via purechatWidgetName Parameter No login needed ≤ 2.4 Fixed in 2.31 CVE-2024-13736 Wordfence
6.4 Medium Store Locator Widget Plugin store-locator-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2025r1 CVE-2024-13657 Wordfence
6.4 Medium Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-13591 Wordfence
6.5 Medium Categorized Gallery Plugin categorized-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.0 CVE-2024-13676 Wordfence
6.4 Medium UMich OIDC Login Plugin umich-oidc-login Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.0 CVE-2024-11753 Wordfence
6.4 Medium WP Wiki Tooltip Plugin wp-wiki-tooltip Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 Fixed in 2.1.0 CVE-2024-13462 Wordfence
6.4 Medium CanadaHelps Embedded Donation Plugin embedded-cdn Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2024-11778 Wordfence
6.4 Medium UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included Plugin ultraembed-advanced-iframe Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11335 Wordfence
6.4 Medium Responsive Flickr Slideshow Plugin mobile-friendly-flickr-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13660 Wordfence
6.1 Medium Digihood HTML Sitemap Plugin wedesin-html-sitemap Cross-Site Scripting Reflected Cross-Site Scripting via 'channel' No login needed ≤ 3.1.1 CVE-2024-12339 Wordfence
6.4 Medium Cosmic Blocks (40+) Content Editor Blocks Collection Plugin cosmic-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.0 CVE-2024-13674 Wordfence
6.1 Medium Lexicata Plugin lexicata Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.16 CVE-2024-12069 Wordfence
4.3 Medium Education Addon for Elementor Plugin education-addon Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode ≤ 1.3.1 CVE-2024-13854 Wordfence
6.1 Medium Pollin Plugin pollin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.01.1 CVE-2024-13711 Wordfence
6.4 Medium Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily Plugin yayforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.1 Fixed in 1.4 CVE-2024-12522 Wordfence
5.3 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control Insecure Direct Object Reference to Unauthenticated Order Information Exposure No login needed ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-13719 Wordfence
6.4 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Scripting Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.1 CVE-2024-13390 Wordfence
4.9 Medium Pollin Plugin pollin SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.01.1 CVE-2024-13712 Wordfence
6.4 Medium YouTube Playlists with Schema Plugin jma-youtube-playlists-with-schema Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13589 Wordfence
6.5 Medium WP Media Category Management Plugin wp-media-category-management Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 2.0 – 2.3.3 Fixed in 2.3.4 CVE-2025-0865 Wordfence
6.4 Medium Coaching Staffs Plugin coaching-staffs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.1 CVE-2024-13663 Wordfence
6.4 Medium User Private Files – File Upload & Download Manager with Secure File Sharing Plugin user-private-files Cross-Site Scripting File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.1.3 CVE-2024-13799 Wordfence
6.4 Medium Visualizer: Tables and Charts Manager Plugin visualizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File ≤ 3.11.8 Fixed in 3.11.9 CVE-2025-1065 Wordfence
6.1 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.7.1007 Fixed in 1.7.1008 CVE-2025-1441 Wordfence
4.3 Medium Age Verification Plugin agecheckernet Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed 1.20.0 CVE-2025-22622 Fluid Attacks
6.4 Medium Easypromos Plugin easypromos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.8 CVE-2024-13443 Wordfence
6.1 Medium Booking Package Plugin booking-package Cross-Site Scripting Reflected Cross-Site Scripting via Locale Parameter No login needed ≤ 1.6.72 CVE-2024-13508 Wordfence
6.4 Medium Wonder Video Embed Plugin wonderplugin-video-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.2 CVE-2024-13743 Wordfence
6.5 Medium Smartarget Plugin smartarget-contact-us Cross-Site Scripting ≤ 1.5.3 CVE-2025-22650 Patchstack
5.3 Medium Real Estate Manager Plugin real-estate-manager Authentication Bypass Captcha Bypass Vulnerability No login needed ≤ 7.3 CVE-2025-22645 Patchstack
6.5 Medium Drivr Lite – Google Drive Plugin drivr-google-drive-file-picker Cross-Site Scripting Google Drive Plugin plugin <= 1.0.1 - Stored Cross Site Scripting (XSS) ≤ 1.0.1 CVE-2025-27016 Patchstack
5.3 Medium MediCenter - Health Medical Clinic Plugin medicenter Information Disclosure Sensitive Data Exposure No login needed ≤ 14.7 Fixed in 14.7 CVE-2025-27013 Patchstack
6.3 Medium Uncode Core Plugin Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_medias ≤ 2.9.1.6 CVE-2024-13689 Wordfence
4.3 Medium FormCraft Plugin formcraft-form-builder Broken Access Control Missing Authorization to Plugin Data Export in formcraft-main.php ≤ 3.9.11 CVE-2024-13783 Wordfence
6.5 Medium Uncode Theme Path Traversal Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia ≤ 2.9.1.6 CVE-2024-13691 Wordfence
5.4 Medium Uncode Theme Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description ≤ 2.9.1.6 CVE-2024-13667 Wordfence
6.5 Medium Tour Master - Tour Booking, Travel, Hotel Plugin SQL Injection Tour Booking, Travel, Hotel <= 5.3.7 - Authenticated (Subscriber+) SQL Injection via review_id Parameter ≤ 5.3.7 CVE-2024-13369 Wordfence
6.4 Medium Threepress Plugin threepress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-13395 Wordfence
5.3 Medium Scratch & Win – Giveaways and Contests Plugin scratch-win-giveaways-for-website-facebook Broken Access Control Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation No login needed ≤ 2.8.0 Fixed in 2.9.0 CVE-2024-13316 Wordfence
4.3 Medium Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later Plugin flexible-wishlist Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed ≤ 1.2.26 CVE-2024-13718 Wordfence
6.4 Medium Web Stories Enhancer – Level Up Your Web Stories Plugin web-stories-enhancer Cross-Site Scripting Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3 Fixed in 1.4 CVE-2024-13575 Wordfence
6.1 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6.6 Fixed in 1.1.1 CVE-2025-0864 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only