WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 1,051–1,100 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 22 of 29
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Local File Inclusion ≤ 1.3.0.3 Fixed in 1.3.0.4 CVE-2024-37410 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 5.6.1 CVE-2024-4482 Wordfence
4.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation ≤ 3.2.12 CVE-2024-6012 Wordfence
4.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.2.12 CVE-2024-6011 Wordfence
6.4 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute ≤ 2.4 CVE-2024-5419 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes ≤ 3.2.45 CVE-2024-5819 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.13.1 CVE-2024-6296 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.0- Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.0 CVE-2024-4983 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.13.5 CVE-2024-4570 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.13.5 CVE-2024-4569 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.42 - Authenticated (Contributor+) Stored Cross-Site Scripting in Google Maps Widget ≤ 3.2.42 CVE-2024-5289 Wordfence
6.4 Medium The7 — Website and eCommerce Builder Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute ≤ 11.13.0 CVE-2024-5451 Wordfence
4.3 Medium Bricks Builder Plugin Broken Access Control Insecure Direct Object Reference ≤ 1.9.8 CVE-2024-4874 Wordfence
6.5 Medium WordPress Form Builder Plugin – Gutenberg Forms Plugin forms-gutenberg Broken Access Control Auth. Broken Access Control ≤ 2.2.8.3 Fixed in 2.2.9 CVE-2022-45803 Patchstack
5.9 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting ≤ 2.1.22 CVE-2024-35768 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting Contributor+ Shortcode Cross Site Scripting (XSS) ≤ 1.5.42 CVE-2024-35779 Patchstack
6.1 Medium The Plus Addons for Elementor Page Builder Plugin Cross-Site Scripting Reflected Cross-Site Scripting via WP Login and Register Widget No login needed ≤ 5.5.6 CVE-2024-5344 Wordfence
4.3 Medium Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer Plugin promolayer-popup-builder Broken Access Control Promolayer <= 1.1.0 - Missing Authorization ≤ 1.1.0 CVE-2024-3602 Wordfence
5.4 Medium Fusion Builder Plugin Broken Access Control Authenticated Broken Access Control ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39310 Patchstack
8.3 High Thrive Theme Builder Theme Broken Access Control Multiple Authenticated Broken Access Control < 3.24.0 Fixed in 3.24.0 CVE-2023-47783 Patchstack
6.5 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) ≤ 8.8.9.1 Fixed in 8.9.4 CVE-2024-35765 Patchstack
8.5 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection Contributor+ PHP Object Injection ≤ 1.5.42 CVE-2024-35780 Patchstack
6.4 Medium WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce Plugin cartflows Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.7 CVE-2024-4632 Wordfence
5.3 Medium Ibtana - WordPress Website Builder Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder <= 1.2.3.3 - Unauthenticated reCAPTCHA Settings Update No login needed ≤ 1.2.3.3 CVE-2024-5541 Wordfence
4.3 Medium Infographic Maker iList Plugin infographic-and-list-builder-ilist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Title Update ≤ 4.7.4 CVE-2024-5858 Wordfence
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
7.4 High Popup Builder Plugin popup-builder Broken Access Control Missing Authorization in Multiple AJAX Actions ≤ 4.3.0 CVE-2024-2544 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter ≤ 3.2.38 CVE-2024-4863 Wordfence
9.0 Critical CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin PHP Object Injection Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Unauthenticated PHP Object Injection No login needed ≤ 4.4.1 CVE-2024-4371 Wordfence
6.4 Medium EleSpare – News, Magazine and Blog Addons for Elementor Plugin elespare Cross-Site Scripting Blog, Magazine and Newspaper Addons for Elementor with Templates, Widgets, Kits, and Header/Footer Builder. One Click Import: No Coding Required! <= 3.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Horizontal Nav Menu Widget ≤ 3.1.2 CVE-2024-4615 Wordfence
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via VC Single Image link attribute ≤ 7.6 CVE-2024-5265 Wordfence
6.1 Medium Themify Builder Plugin themify-builder Open Redirect No login needed < 7.5.8 Fixed in 7.5.8 CVE-2024-3032 WPScan
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Site Title Widget ≤ 1.6.35 CVE-2024-5757 Wordfence
5.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Widget ≤ 1.13.3 CVE-2024-2092 Wordfence
6.5 Medium WordPress Header Builder Plugin – Pearl Plugin pearl-header-builder Broken Access Control Pearl <= 1.3.7 - Missing Authorization to Unauthenticated Arbitrary Site Options Deletion No login needed ≤ 1.3.7 CVE-2024-5468 Wordfence
6.4 Medium CoDesigner WooCommerce Builder for Elementor – Customize Checkout, Shop, Email, Products & More Plugin woolementor Cross-Site Scripting Customize Checkout, Shop, Email, Products & More <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 4.4.1 CVE-2024-4564 Wordfence
5.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Broken Access Control ReviewShort plugin <= 1.01.5 - Broken Access Control No login needed ≤ 1.01.5 Fixed in 1.01.6 CVE-2024-34763 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.23 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.23 CVE-2024-5189 Wordfence
4.3 Medium Elementor Website Builder Plugin elementor Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2023-33922 Patchstack
5.3 Medium MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor Plugin metform Information Disclosure Contact Form, Survey, Quiz, & Custom Form Builder for Elementor <= 3.8.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.8.8 CVE-2024-4266 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Product Horizontal Filter Widget ≤ 2.9.0 CVE-2024-5530 Wordfence
8.1 High Build App Online Plugin build-app-online Privilege Escalation Account Takeover via Weak Password Reset Mechanism No login needed ≤ 1.0.22 CVE-2023-7264 Wordfence
5.3 Medium Contact Form Builder, Contact Widget Plugin contact-forms-builder Other Bypass Vulnerability No login needed ≤ 2.1.7 CVE-2024-35747 Patchstack
5.3 Medium Vision Interactive Plugin vision Broken Access Control Image Map Builder plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-32779 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.5.4 Fixed in 5.5.5 CVE-2024-35709 Patchstack
6.4 Medium Cards for Beaver Builder Plugin bb-bootstrap-cards Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Cards Widget ≤ 1.1.3 CVE-2024-5663 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode ≤ 1.0.276 CVE-2024-4451 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget ≤ 5.8.15 CVE-2024-5612 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.22 CVE-2024-5188 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only