WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,751–10,800 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 216 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium WP DataTable Plugin wp-datatable Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 0.2.6 CVE-2024-13566 Wordfence
6.4 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting Music Player, Podcast Player & Radio by Sonaar <= 5.9.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Podcast RSS Feed ≤ 5.9.3 CVE-2024-13157 Wordfence
4.3 Medium Custom Login Page Styler Plugin login-page-styler Broken Access Control Missing Authorization to Authenticated (Subsciber+) Log Deletion and Session Termination ≤ 7.1.1 CVE-2024-13530 Wordfence
5.9 Medium Order Export for WooCommerce Plugin order-export-and-more-for-woocommerce Information Disclosure Unauthenticated Sensitive Information Exposure Through Unprotected Directory No login needed ≤ 3.24 CVE-2024-13623 Wordfence
6.1 Medium A5 Custom Login Page Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.8.1 CVE-2024-13226 WPScan
6.1 Medium ECT Home Page Products Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.9 CVE-2024-13225 WPScan
6.1 Medium SlideDeck 1 Lite Content Slider Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.4.8 CVE-2024-13224 WPScan
6.1 Medium Tabulate Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.10.3 CVE-2024-13223 WPScan
6.1 Medium User Messages Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2.4 CVE-2024-13222 WPScan
6.1 Medium Fantastic Elasticsearch Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 4.1.0 CVE-2024-13221 WPScan
6.1 Medium Google Map Professional Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13220 WPScan
6.1 Medium Policy Genius Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.4 CVE-2024-13219 WPScan
6.1 Medium Fast Tube Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.3.1 CVE-2024-13218 WPScan
6.1 Medium WP MediaTagger Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 4.1.1 CVE-2024-13112 WPScan
5.4 Medium WP MediaTagger Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 4.1.1 CVE-2024-13101 WPScan
6.1 Medium Woo UPS Pickup Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.6.3 CVE-2024-13100 WPScan
4.8 Medium Zalomení Plugin zalomeni Cross-Site Scripting Admin+ Stored XSS ≤ 1.5 CVE-2024-12872 WPScan
6.1 Medium Ninja Tables Plugin ninja-tables Cross-Site Scripting Admin+ Stored XSS No login needed < 5.0.17 Fixed in 5.0.17 CVE-2024-12772 WPScan
6.1 Medium CanvasFlow Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.5.5 CVE-2024-12275 WPScan
4.3 Medium Ni Sales Commission For WooCommerce Plugin ni-woo-sales-commission Broken Access Control Missing Authorization to Authenticated (Subscriber+) Commission Update ≤ 1.2.4 CVE-2024-13424 Wordfence
4.3 Medium Contact Form and Calls To Action by vcita Plugin lead-capturing-call-to-actions-by-vcita Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contact/Widget Toggle ≤ 2.7.1 CVE-2024-13717 Wordfence
4.3 Medium Food Menu – Restaurant Menu & Online Ordering for WooCommerce Plugin tlp-food-menu Broken Access Control Restaurant Menu & Online Ordering for WooCommerce <= 5.1.4 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 5.1.4 CVE-2024-13415 Wordfence
6.4 Medium Contact Form and Calls To Action by vcita Plugin lead-capturing-call-to-actions-by-vcita Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.1 CVE-2024-11886 Wordfence
4.3 Medium HT Event – WordPress Event Manager Plugin for Elementor Plugin Information Disclosure WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: Sponsor ≤ 1.4.7 CVE-2024-13216 Wordfence
5.4 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.6.2 CVE-2024-10867 Wordfence
6.4 Medium Ticketmeo – Sell Tickets – Event Ticketing Plugin ploxel Cross-Site Scripting Sell Tickets – Event Ticketing <= 2.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.3.6 CVE-2025-0507 Wordfence
6.1 Medium Forminator Plugin forminator Cross-Site Scripting Reflected Cross-Site Scripting via Title Parameter No login needed ≤ 1.38.2 CVE-2025-0470 Wordfence
6.4 Medium SeatReg Plugin seatreg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.56.0 CVE-2024-13463 Wordfence
6.4 Medium WPRadio – WordPress Radio Streaming Plugin wpradio Cross-Site Scripting WordPress Radio Streaming Plugin <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-13397 Wordfence
6.4 Medium Frictionless Plugin frictionless Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.0.23 CVE-2024-13396 Wordfence
6.4 Medium Gosign – Posts Slider Block Plugin gosign-posts-slider-block Cross-Site Scripting Posts Slider Block <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-13399 Wordfence
6.4 Medium Stockdio Historical Chart Plugin stockdio-historical-chart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.18 CVE-2024-13349 Wordfence
6.4 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13400 Wordfence
4.3 Medium Typer Core Plugin typer-core Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.9.6 CVE-2024-12102 Wordfence
6.4 Medium WP Post List Table Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-13664 Wordfence
6.4 Medium Storely Theme storely Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 18 CVE-2024-10847 Wordfence
6.5 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll SQL Injection Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) SQL Injection ≤ 1.7.5 CVE-2024-13596 Wordfence
6.4 Medium HTML5 chat Plugin html5-chat Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.07 CVE-2024-12451 Wordfence
6.1 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting Reflected Cross-Site Scripting via Filename Parameter No login needed ≤ 2.8.17 CVE-2024-12299 Wordfence
4.3 Medium zStore Manager Basic Plugin zstore-manager-basic Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cache Clearing ≤ 3.311 CVE-2024-13715 Wordfence
6.1 Medium Ai Image Alt Text Generator for WP Plugin ai-image-alt-text-generator-for-wp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2024-12177 Wordfence
4.3 Medium Elementor Website Builder Pro – More than Just a Page Builder Plugin Information Disclosure More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 3.25.10 CVE-2024-8494 Wordfence
6.4 Medium Music Sheet Viewer Plugin music-sheet-viewer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1 CVE-2024-13670 Wordfence
6.5 Medium W2S – Migrate WooCommerce to Shopify Plugin w2s-migrate-woo-to-shopify Broken Access Control Migrate WooCommerce to Shopify <= 1.2.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read ≤ 1.2.1 CVE-2024-12861 Wordfence
6.4 Medium All Bootstrap Blocks Plugin all-bootstrap-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.26 CVE-2024-13549 Wordfence
6.1 Medium Team Rosters Plugin team-rosters Cross-Site Scripting Reflected Cross-Site Scripting via 'tab' No login needed ≤ 4.7 CVE-2024-12320 Wordfence
6.4 Medium WE – Testimonial Slider Plugin we-testimonial-slider Cross-Site Scripting Testimonial Slider <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5 CVE-2024-13460 Wordfence
4.3 Medium ECPay Ecommerce for WooCommerce Plugin ecpay-ecommerce-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 1.1.2411060 CVE-2024-13652 Wordfence
6.1 Medium StageShow Plugin stageshow Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 9.8.6 CVE-2024-13705 Wordfence
6.4 Medium Embed Swagger UI Plugin embed-swagger-ui Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2024-13700 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only