WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 10,851–10,900 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 218 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Minterpress Plugin minterpress Broken Access Control Arbitrary Content Deletion ≤ 1.0.5 CVE-2025-23529 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 3.4.0 Fixed in 3.4.2 CVE-2025-24754 Patchstack
4.3 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Broken Access Control ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-24584 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
6.5 Medium Social Share Buttons Plugin share-button Path Traversal Unauthenticated Image Upload & Path Traversal No login needed ≤ 2.7 CVE-2024-13117 WPScan
4.8 Medium WP Triggers Lite Plugin SQL Injection Admin+ SQL Injection ≤ 2.5.3 CVE-2024-13095 WPScan
6.5 Medium Altra Side Menu Plugin Cross-Site Request Forgery Abitrary Menu Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12774 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Bulk Delete via CSRF No login needed ≤ 8.2.4 CVE-2024-12436 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Event Log Deletion via CSRF No login needed ≤ 8.2.4 CVE-2024-12280 WPScan
5.5 Medium Survey Maker Plugin survey-maker Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Survey Question ≤ 5.1.3.3 CVE-2024-13505 Wordfence
6.1 Medium WC Affiliate – A Complete WooCommerce Affiliate Plugin wc-affiliate Cross-Site Scripting A Complete WooCommerce Affiliate Plugin <= 2.4 - Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2024-12334 Wordfence
5.4 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Server-Side Request Forgery MPG <= 4.0.5 - Authenticated (Editor+) Server-Side Request Forgery via fileUrl ≤ 4.0.5 CVE-2024-10705 Wordfence
5.3 Medium Membership Plugin – Restrict Content Plugin restrict-content Information Disclosure Restrict Content <= 3.2.13 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 3.2.13 CVE-2024-11090 Wordfence
6.1 Medium Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10636 Wordfence
6.4 Medium Divi Carousel Lite Plugin wow-carousel-for-divi-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Carousel and Logo Carousel Widgets ≤ 2.0.4 CVE-2025-0350 Wordfence
4.3 Medium Boom Fest Plugin boom-fest Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update ≤ 2.2.1 CVE-2024-13449 Wordfence
4.3 Medium GoHero Store Customizer for WooCommerce Plugin personalize-woocommerce-cart-page Broken Access Control Missing Authorization to Unuthenticated Settings Update ≤ 3.5 CVE-2024-12826 Wordfence
6.4 Medium ABC Notation Plugin abc-notation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.3 CVE-2024-13551 Wordfence
6.5 Medium ABC Notation Plugin abc-notation Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 6.1.3 CVE-2024-13550 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.3 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update (save_addon_key_license) ≤ 1.3.3 CVE-2024-13370 Wordfence
6.4 Medium Bilingual Linker Plugin bilingual-linker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4 CVE-2024-13441 Wordfence
6.4 Medium Etsy Importer Plugin etsy-importer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.2 CVE-2024-12817 Wordfence
6.4 Medium Masy Gallery Plugin masy-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13586 Wordfence
6.1 Medium WP Contact Form7 Email Spam Blocker Plugin wp-contact-form7-email-spam-blocker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2024-13467 Wordfence
6.4 Medium Broadstreet Plugin broadstreet Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via zone Parameter ≤ 1.51.0 CVE-2024-11825 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 1.3.4 CVE-2024-13368 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress By KaineLabs <= 1.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Review Deletion ≤ 1.3.2 CVE-2024-12113 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin learnpress Cross-Site Scripting WordPress LMS Plugin <= 4.2.7.5 - Authenticated (LP Instructor+) Stored Cross-Site Scripting via Lesson Name ≤ 4.2.7.5 CVE-2024-13599 Wordfence
6.4 Medium Power Ups for Elementor Plugin power-ups-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-13548 Wordfence
6.4 Medium WordPress SEO Friendly Accordion FAQ with AI assisted content generation Plugin notice-faq Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-13458 Wordfence
6.5 Medium Connections Business Directory Plugin connections Arbitrary File Deletion Authenticated (Admin+) Arbitrary Directory Deletion ≤ 10.4.66 CVE-2024-12885 Wordfence
6.4 Medium brodos.net Onlineshop Plugin brodos-net-onlineshop Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 CVE-2024-12529 Wordfence
6.4 Medium Ask Me Anything (Anonymously) Plugin ask-me-anything-anonymously Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6 CVE-2024-12512 Wordfence
6.1 Medium Target Video Easy Publish Plugin brid-video-easy-publish Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.8.3 CVE-2024-12076 Wordfence
6.4 Medium NOTICE BOARD BY TOWKIR Plugin notice-board-by-towkir Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1 CVE-2024-12816 Wordfence
6.4 Medium Flexmls® IDX Plugin flexmls-idx Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via API parameters ≤ 3.14.26 CVE-2024-10552 Wordfence
6.4 Medium Plethora Plugins Tabs + Accordions Plugin plethora-tabs-accordions Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via anchor ≤ 1.1.8 CVE-2024-13721 Wordfence
4.3 Medium Linear Plugin linear Cross-Site Request Forgery Cross-Site Request Forgery to Cache Reset No login needed ≤ 2.8.1 CVE-2024-13709 Wordfence
6.5 Medium Popup Maker Plugin popup-maker Cross-Site Scripting ≤ 1.20.2 Fixed in 1.20.3 CVE-2025-24746 Patchstack
4.3 Medium Post Duplicator Plugin post-duplicator Broken Access Control ≤ 2.35 Fixed in 2.36 CVE-2025-24736 Patchstack
6.5 Medium PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce Cross-Site Scripting ≤ 4.6.0 Fixed in 4.7.0 CVE-2025-24755 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-24753 Patchstack
4.3 Medium CoBlocks Plugin coblocks Broken Access Control ≤ 3.1.13 Fixed in 3.1.14 CVE-2025-24751 Patchstack
5.4 Medium ExactMetrics Plugin google-analytics-dashboard-for-wp Broken Access Control ≤ 8.1.0 Fixed in 8.2.0 CVE-2025-24750 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-24729 Patchstack
6.5 Medium Post Grid Master Plugin ajax-filter-posts Local File Inclusion ≤ 3.4.12 Fixed in 3.4.13 CVE-2025-24733 Patchstack
6.5 Medium Easy YouTube Gallery Plugin easy-youtube-gallery Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-24721 Patchstack
6.5 Medium HT Contact Form 7 Plugin ht-contactform Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-24726 Patchstack
6.5 Medium WP VR Plugin wpvr Cross-Site Scripting ≤ 8.5.14 Fixed in 8.5.15 CVE-2025-24730 Patchstack
4.3 Medium Thim Elementor Kit Plugin thim-elementor-kit Broken Access Control ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-24725 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only