WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 10,451–10,500 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | ElementsKit Elementor addons | Information Disclosure Unauthenticated Information Exposure via get_megamenu_content Function No login needed |
≤ 3.4.0 |
CVE-2025-0968 |
Wordfence | |
| 6.1 Medium | Raptive Ads | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.6.3 |
CVE-2024-13363 |
Wordfence | |
| 5.3 Medium | Raptive Ads | Broken Access Control Missing Authorization to Unauthenticated Data/Settings Reset No login needed |
≤ 3.6.3 |
CVE-2024-13364 |
Wordfence | |
| 6.1 Medium | DeBounce Email Validator | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 5.8.0 |
CVE-2024-13339 |
Wordfence | |
| 4.3 Medium | Disable Auto Updates | Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed |
≤ 1.4 |
CVE-2024-13336 |
Wordfence | |
| 5.3 Medium | WordPress Portfolio Builder – Portfolio Gallery | Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed |
≤ 1.1.7 |
CVE-2024-13231 |
Wordfence | |
| 6.4 Medium | Widget BUY.BOX | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.1.5 |
CVE-2024-13679 |
Wordfence | |
| 4.3 Medium | Apptivo Business Site CRM | Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed |
≤ 5.3 |
CVE-2024-13405 |
Wordfence | |
| 6.1 Medium | Pure Chat – Live Chat & More! | Cross-Site Scripting Live Chat & More! <= 2.4 - Reflected Cross-Site Scripting via purechatWidgetName Parameter No login needed |
≤ 2.4 Fixed in 2.31 |
CVE-2024-13736 |
Wordfence | |
| 6.4 Medium | Store Locator Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2025r1 |
CVE-2024-13657 |
Wordfence | |
| 6.4 Medium | Team Builder For WPBakery Page Builder(Formerly Visual Composer) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2024-13591 |
Wordfence | |
| 6.5 Medium | Categorized Gallery | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.0 |
CVE-2024-13676 |
Wordfence | |
| 6.4 Medium | UMich OIDC Login | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.0 |
CVE-2024-11753 |
Wordfence | |
| 6.4 Medium | WP Wiki Tooltip | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.2 Fixed in 2.1.0 |
CVE-2024-13462 |
Wordfence | |
| 6.4 Medium | CanadaHelps Embedded Donation | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.1 |
CVE-2024-11778 |
Wordfence | |
| 6.4 Medium | UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included | Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.3 |
CVE-2024-11335 |
Wordfence | |
| 6.4 Medium | Responsive Flickr Slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13660 |
Wordfence | |
| 6.1 Medium | Digihood HTML Sitemap | Cross-Site Scripting Reflected Cross-Site Scripting via 'channel' No login needed |
≤ 3.1.1 |
CVE-2024-12339 |
Wordfence | |
| 6.4 Medium | Cosmic Blocks (40+) Content Editor Blocks Collection | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-13674 |
Wordfence | |
| 6.1 Medium | Lexicata | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.16 |
CVE-2024-12069 |
Wordfence | |
| 4.3 Medium | Education Addon for Elementor | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode |
≤ 1.3.1 |
CVE-2024-13854 |
Wordfence | |
| 6.1 Medium | Pollin | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.01.1 |
CVE-2024-13711 |
Wordfence | |
| 6.4 Medium | Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.1 Fixed in 1.4 |
CVE-2024-12522 |
Wordfence | |
| 5.3 Medium | PeproDev Ultimate Invoice | Broken Access Control Insecure Direct Object Reference to Unauthenticated Order Information Exposure No login needed |
≤ 2.0.9 Fixed in 2.1.0 |
CVE-2024-13719 |
Wordfence | |
| 6.4 Medium | ADFO – Custom data in admin dashboard | Cross-Site Scripting Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.1 |
CVE-2024-13390 |
Wordfence | |
| 4.9 Medium | Pollin | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.01.1 |
CVE-2024-13712 |
Wordfence | |
| 6.4 Medium | YouTube Playlists with Schema | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13589 |
Wordfence | |
| 6.5 Medium | WP Media Category Management | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
2.0 – 2.3.3 Fixed in 2.3.4 |
CVE-2025-0865 |
Wordfence | |
| 6.4 Medium | Coaching Staffs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.1 |
CVE-2024-13663 |
Wordfence | |
| 6.4 Medium | User Private Files – File Upload & Download Manager with Secure File Sharing | Cross-Site Scripting File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.1.3 |
CVE-2024-13799 |
Wordfence | |
| 6.4 Medium | Visualizer: Tables and Charts Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File |
≤ 3.11.8 Fixed in 3.11.9 |
CVE-2025-1065 |
Wordfence | |
| 6.1 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.7.1007 Fixed in 1.7.1008 |
CVE-2025-1441 |
Wordfence | |
| 4.3 Medium | Age Verification | Cross-Site Scripting Reflected cross-site scripting (XSS) No login needed |
1.20.0 |
CVE-2025-22622 |
Fluid Attacks | |
| 6.4 Medium | Easypromos | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3.8 |
CVE-2024-13443 |
Wordfence | |
| 6.1 Medium | Booking Package | Cross-Site Scripting Reflected Cross-Site Scripting via Locale Parameter No login needed |
≤ 1.6.72 |
CVE-2024-13508 |
Wordfence | |
| 6.4 Medium | Wonder Video Embed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.2 |
CVE-2024-13743 |
Wordfence | |
| 6.5 Medium | Smartarget | Cross-Site Scripting |
≤ 1.5.3 |
CVE-2025-22650 |
Patchstack | |
| 5.3 Medium | Real Estate Manager | Authentication Bypass Captcha Bypass Vulnerability No login needed |
≤ 7.3 |
CVE-2025-22645 |
Patchstack | |
| 6.5 Medium | Drivr Lite – Google Drive | Cross-Site Scripting Google Drive Plugin plugin <= 1.0.1 - Stored Cross Site Scripting (XSS) |
≤ 1.0.1 |
CVE-2025-27016 |
Patchstack | |
| 5.3 Medium | MediCenter - Health Medical Clinic | Information Disclosure Sensitive Data Exposure No login needed |
≤ 14.7 Fixed in 14.7 |
CVE-2025-27013 |
Patchstack | |
| 6.3 Medium | Uncode Core | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution in uncode_get_medias |
≤ 2.9.1.6 |
CVE-2024-13689 |
Wordfence | |
| 4.3 Medium | FormCraft | Broken Access Control Missing Authorization to Plugin Data Export in formcraft-main.php |
≤ 3.9.11 |
CVE-2024-13783 |
Wordfence | |
| 6.5 Medium | Uncode | Path Traversal Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia |
≤ 2.9.1.6 |
CVE-2024-13691 |
Wordfence | |
| 5.4 Medium | Uncode | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via mle-description |
≤ 2.9.1.6 |
CVE-2024-13667 |
Wordfence | |
| 6.5 Medium | Tour Master - Tour Booking, Travel, Hotel | SQL Injection Tour Booking, Travel, Hotel <= 5.3.7 - Authenticated (Subscriber+) SQL Injection via review_id Parameter |
≤ 5.3.7 |
CVE-2024-13369 |
Wordfence | |
| 6.4 Medium | Threepress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.1 Fixed in 1.7.2 |
CVE-2024-13395 |
Wordfence | |
| 5.3 Medium | Scratch & Win – Giveaways and Contests | Broken Access Control Giveaways and Contests <= 2.8.0 - Missing Authorization to Unauthenticated Coupon Creation No login needed |
≤ 2.8.0 Fixed in 2.9.0 |
CVE-2024-13316 |
Wordfence | |
| 4.3 Medium | Flexible Wishlist for WooCommerce – Ecommerce Wishlist & Save for later | Cross-Site Request Forgery Ecommerce Wishlist & Save for later <= 1.2.26 - Cross-Site Request Forgery to Wishlist Creation/Modification No login needed |
≤ 1.2.26 |
CVE-2024-13718 |
Wordfence | |
| 6.4 Medium | Web Stories Enhancer – Level Up Your Web Stories | Cross-Site Scripting Level Up Your Web Stories <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3 Fixed in 1.4 |
CVE-2024-13575 |
Wordfence | |
| 6.1 Medium | Active Products Tables for WooCommerce. Use constructor to create tables | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6.6 Fixed in 1.1.1 |
CVE-2025-0864 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.