WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 11,001–11,050 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Avada Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets |
≤ 3.11.11 |
CVE-2024-12477 |
Wordfence | |
| 5.9 Medium | Toocheke Companion | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.166 Fixed in 1.167 |
CVE-2025-23992 |
Patchstack | |
| 6.5 Medium | Database Sync | Information Disclosure Sensitive Data Exposure |
≤ 0.5.1 |
CVE-2025-23486 |
Patchstack | |
| 4.3 Medium | Debug Tool | Broken Access Control |
≤ 2.2 |
CVE-2025-23684 |
Patchstack | |
| 4.3 Medium | WP Hotel Booking | Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Retrieval |
≤ 2.1.6 |
CVE-2024-13447 |
Wordfence | |
| 6.1 Medium | Themify Builder | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.6.5 |
CVE-2024-13319 |
Wordfence | |
| 5.4 Medium | AI Power: Complete AI Pack | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 1.8.96 |
CVE-2024-13360 |
Wordfence | |
| 6.3 Medium | AI Power: Complete AI Pack | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.8.96 |
CVE-2024-13361 |
Wordfence | |
| 6.4 Medium | Stackable – Page Builder Gutenberg Blocks | Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.13.11 |
CVE-2024-12117 |
Wordfence | |
| 6.1 Medium | XML for Google Merchant Center | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.0.11 |
CVE-2024-13406 |
Wordfence | |
| 4.3 Medium | WPBot Pro Wordpress Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation |
≤ 13.5.5 |
CVE-2024-12879 |
Wordfence | |
| 6.4 Medium | Ketchup Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1.2 |
CVE-2024-13590 |
Wordfence | |
| 6.4 Medium | Picture Gallery – Frontend Image Uploads, AJAX Photo List | Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.19 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.19 |
CVE-2024-13584 |
Wordfence | |
| 5.4 Medium | WP-Polls | SQL Injection Unauthenticated SQL Injection to Stored Cross-Site Scripting No login needed |
≤ 2.77.2 |
CVE-2024-13426 |
Wordfence | |
| 4.3 Medium | AnyRoad | Cross-Site Request Forgery No login needed |
≤ 1.3.2 |
CVE-2025-23996 |
Patchstack | |
| 4.3 Medium | Widget Options | Broken Access Control Broken Access Control to Notice Dimissal |
≤ 4.0.8 Fixed in 4.0.9 |
CVE-2025-22722 |
Patchstack | |
| 4.3 Medium | ApplyOnline | Broken Access Control |
≤ 2.6.7.1 Fixed in 2.6.7.2 |
CVE-2025-22721 |
Patchstack | |
| 6.5 Medium | Online Payments – Get Paid with PayPal, Square & Stripe | Cross-Site Scripting |
≤ 3.20.0 Fixed in 3.30.0 |
CVE-2025-22661 |
Patchstack | |
| 5.9 Medium | Related Post Shortcode | Cross-Site Scripting |
≤ 1.2 |
CVE-2025-22276 |
Patchstack | |
| 6.5 Medium | Weaver Themes Shortcode Compatibility | Cross-Site Scripting |
≤ 1.0.4 |
CVE-2025-22267 |
Patchstack | |
| 6.5 Medium | Tamara Checkout | Cross-Site Scripting |
≤ 1.9.9.1 Fixed in 1.9.9.1 |
CVE-2025-23997 |
Patchstack | |
| 6.5 Medium | Flexible PDF Coupons | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.10.3 Fixed in 1.10.3 |
CVE-2025-22825 |
Patchstack | |
| 6.5 Medium | Ad Blocking Detector | Cross-Site Scripting |
≤ 3.6.0 |
CVE-2025-22732 |
Patchstack | |
| 6.5 Medium | MailChimp Subscribe Forms | Cross-Site Scripting |
≤ 4.1 Fixed in 4.2 |
CVE-2025-22727 |
Patchstack | |
| 6.5 Medium | FAT Event Lite | Cross-Site Scripting |
≤ 1.1 |
CVE-2025-22718 |
Patchstack | |
| 5.9 Medium | Bonjour Bar | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-22262 |
Patchstack | |
| 5.3 Medium | Poll Maker | Content Injection HTML Injection No login needed |
≤ 5.5.5 Fixed in 5.5.5 |
CVE-2024-56277 |
Patchstack | |
| 6.1 Medium | wp-greet | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 6.2 |
CVE-2024-13444 |
Wordfence | |
| 5.3 Medium | Social Share, Social Login and Social Comments Plugin – Super Socializer | SQL Injection Super Socializer <= 7.14 - Unauthenticated Limited SQL Injection via 'SuperSocializerKey' No login needed |
≤ 7.14 |
CVE-2024-13230 |
Wordfence | |
| 6.4 Medium | FireCask Like & Share Button | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 1.2 |
CVE-2024-11226 |
Wordfence | |
| 6.4 Medium | Betheme | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS |
≤ 27.6.1 |
CVE-2025-0450 |
Wordfence | |
| 6.1 Medium | Link Library | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.7.2 |
CVE-2024-13404 |
Wordfence | |
| 5.3 Medium | Visual Website Collaboration, Feedback & Project Management – Atarim | Broken Access Control Atarim <= 4.0.9 - Missing Authorization to Authenticated (Subscriber+) Project Page/File Deletion No login needed |
≤ 4.0.9 |
CVE-2024-12104 |
Wordfence | |
| 6.1 Medium | WP-BibTeX | Cross-Site Request Forgery Cross-Site Request Forgery to Stored and Reflected Cross-Site Scripting No login needed |
≤ 3.0.1 |
CVE-2024-12005 |
Wordfence | |
| 6.4 Medium | Jet Elements | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 2.7.2.1 |
CVE-2025-0371 |
Wordfence | |
| 5.3 Medium | 1003 Mortgage Application | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 1.87 |
CVE-2024-13536 |
Wordfence | |
| 5.5 Medium | WP All Import Pro | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.9.7 |
CVE-2024-8722 |
Wordfence | |
| 6.4 Medium | Rate Star Review Vote – AJAX Reviews, Votes, Star Ratings | Cross-Site Scripting AJAX Reviews, Votes, Star Ratings <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.3 |
CVE-2024-13392 |
Wordfence | |
| 6.4 Medium | Utilities for MTG | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-13433 |
Wordfence | |
| 6.4 Medium | Jet Engine | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via list_tag Parameter |
≤ 3.6.2 |
CVE-2025-0369 |
Wordfence | |
| 6.4 Medium | Video Share VOD – Turnkey Video Site Builder Script | Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.31 |
CVE-2024-13393 |
Wordfence | |
| 6.4 Medium | Picture Gallery – Frontend Image Uploads, AJAX Photo List | Cross-Site Scripting Frontend Image Uploads, AJAX Photo List <= 1.5.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via videowhisper_picture_upload_guest Shortcode |
≤ 1.5.22 |
CVE-2024-12696 |
Wordfence | |
| 4.4 Medium | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) | Cross-Site Scripting Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Title |
≤ 3.3.2 |
CVE-2024-13517 |
Wordfence | |
| 6.4 Medium | JSM Screenshot Machine Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.0 |
CVE-2024-13385 |
Wordfence | |
| 4.4 Medium | MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting |
≤ 1.9.80 |
CVE-2024-13519 |
Wordfence | |
| 6.1 Medium | WP Abstracts | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 2.7.2 |
CVE-2024-12385 |
Wordfence | |
| 4.3 Medium | Buzz Club – Night Club, DJ and Music Festival Event | Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update |
≤ 2.0.4 |
CVE-2025-0515 |
Wordfence | |
| 4.3 Medium | ShipWorks Connector for Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Service Password/Username Update No login needed |
≤ 5.2.5 |
CVE-2024-13317 |
Wordfence | |
| 6.1 Medium | Webcamconsult | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.5.0 |
CVE-2024-13432 |
Wordfence | |
| 6.4 Medium | MicroPayments – Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet | Cross-Site Scripting Fans Paysite: Paid Creator Subscriptions, Digital Assets, Tokens Wallet <= 2.9.29 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.9.29 |
CVE-2024-13391 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.