WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 11,451–11,500 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords | Information Disclosure Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure No login needed |
≤ 3.1 |
CVE-2024-12159 |
Wordfence | |
| 6.5 Medium | School Management System – WPSchoolPress | SQL Injection WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection |
≤ 2.2.14 |
CVE-2024-12332 |
Wordfence | |
| 4.3 Medium | Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements | Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure |
≤ 2.2.1 |
CVE-2024-12140 |
Wordfence | |
| 6.1 Medium | Automate Hub Free by Sperse.IO | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.7.0 |
CVE-2024-11377 |
Wordfence | |
| 5.3 Medium | Member Access | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 1.1.6 |
CVE-2024-11290 |
Wordfence | |
| 5.3 Medium | Popup – MailChimp, GetResponse and ActiveCampaign Intergrations | Broken Access Control MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table Truncation No login needed |
≤ 3.2.6 |
CVE-2024-12158 |
Wordfence | |
| 6.1 Medium | GDY Modular Content | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.9.92 |
CVE-2024-12153 |
Wordfence | |
| 6.4 Medium | Uptodown APK Download Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1.10 |
CVE-2024-12453 |
Wordfence | |
| 6.1 Medium | Same but Different – Related Posts by Taxonomy | Cross-Site Scripting Related Posts by Taxonomy <= 1.0.16 - Reflected Cross-Site Scripting No login needed |
≤ 1.0.16 |
CVE-2024-11363 |
Wordfence | |
| 6.4 Medium | Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode | Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.3 |
CVE-2024-12457 |
Wordfence | |
| 4.4 Medium | Toggles Shortcode and Widget | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.14 |
CVE-2024-12207 |
Wordfence | |
| 6.4 Medium | Horoscope And Tarot | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-11337 |
Wordfence | |
| 6.1 Medium | ViewMedica 9 | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.4.17 |
CVE-2024-12291 |
Wordfence | |
| 6.1 Medium | Infility Global | Cross-Site Scripting Reflected Cross-Site Scripting via set_type Parameter No login needed |
≤ 2.9.8 |
CVE-2024-12290 |
Wordfence | |
| 5.4 Medium | ViewMedica Embed | Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed |
≤ 1.4.17 |
CVE-2024-12170 |
Wordfence | |
| 6.1 Medium | Simple add pages or posts | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 2.0.0 |
CVE-2024-12288 |
Wordfence | |
| 6.4 Medium | Image Magnify | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2024-11445 |
Wordfence | |
| 6.1 Medium | WC1C | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.23.0 |
CVE-2024-11375 |
Wordfence | |
| 6.1 Medium | Bizapp for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.8 |
CVE-2024-11378 |
Wordfence | |
| 6.1 Medium | WooCommerce HSS Extension for Streaming Video | Cross-Site Scripting Reflected Cross-Site Scripting via videolink Parameter No login needed |
≤ 3.31 |
CVE-2024-12214 |
Wordfence | |
| 6.1 Medium | SEO Keywords | Cross-Site Scripting Reflected Cross-Site Scripting via google_error Parameter No login needed |
≤ 1.1.3 |
CVE-2024-12126 |
Wordfence | |
| 6.1 Medium | Financial Stocks & Crypto Market Data | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.10.3 |
CVE-2024-11690 |
Wordfence | |
| 6.1 Medium | WP – Bulk SMS – by SMS.to | Cross-Site Scripting Bulk SMS – by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting No login needed |
≤ 1.0.12 |
CVE-2024-11434 |
Wordfence | |
| 6.4 Medium | PIXNET | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.9.10 |
CVE-2024-11338 |
Wordfence | |
| 6.4 Medium | YOGO Booking | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.2 |
CVE-2024-12462 |
Wordfence | |
| 6.1 Medium | Woo Ukrposhta | Cross-Site Scripting Reflected Cross-Site Scripting via order, post, and idd Parameters No login needed |
≤ 1.17.11 |
CVE-2024-12049 |
Wordfence | |
| 6.4 Medium | CC Canadian Mortgage Calculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.0 |
CVE-2024-11383 |
Wordfence | |
| 4.3 Medium | Duplicate Post, Page and Any Custom Post | Information Disclosure Authenticated (Contributor+) Post Disclosure via Post Duplication |
≤ 3.5.5 |
CVE-2024-12538 |
Wordfence | |
| 5.3 Medium | ClickDesigns | Broken Access Control Missing Authorization to API Key Modification or Removal No login needed |
≤ 1.8.0 |
CVE-2024-12559 |
Wordfence | |
| 6.4 Medium | Slider Pro Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-11899 |
Wordfence | |
| 6.4 Medium | Sellsy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.3 |
CVE-2024-12592 |
Wordfence | |
| 6.1 Medium | ARS Affiliate Page | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.2 |
CVE-2024-12098 |
Wordfence | |
| 6.4 Medium | Sell Media | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.5.8.5 |
CVE-2024-11777 |
Wordfence | |
| 5.4 Medium | Chative Live chat and Chatbot | Cross-Site Request Forgery Cross-Site Request Forgery via add_chative_widget_action Function No login needed |
≤ 1.1 |
CVE-2024-12541 |
Wordfence | |
| 6.4 Medium | WordPress Survey & Poll – Quiz, Survey and Poll | Cross-Site Scripting Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.5 |
CVE-2024-12528 |
Wordfence | |
| 6.5 Medium | Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler | Arbitrary Shortcode Execution CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed |
≤ 1.7.1 |
CVE-2024-12419 |
Wordfence | |
| 6.1 Medium | Transporters.io | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.1.1 |
CVE-2024-12557 |
Wordfence | |
| 6.4 Medium | Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.1.3.2 |
CVE-2024-11934 |
Wordfence | |
| 4.9 Medium | Timeline Designer | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.4 |
CVE-2024-11437 |
Wordfence | |
| 6.4 Medium | WP Youtube Gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 1.9 |
CVE-2024-12590 |
Wordfence | |
| 6.5 Medium | Email Subscribers | SQL Injection Admin+ SQL Injection |
< 5.7.44 Fixed in 5.7.44 |
CVE-2024-12311 |
WPScan | |
| 6.1 Medium | Icegram Engage | Cross-Site Scripting Author+ Stored XSS No login needed |
< 3.1.32 Fixed in 3.1.32 |
CVE-2024-12302 |
WPScan | |
| 6.1 Medium | Pods – Custom Content Types and Fields | Cross-Site Scripting Custom Content Types and Fields < 3.2.8.1 - Admin+ Stored XSS No login needed |
< 3.2.8.1 Fixed in 3.2.8.1 |
CVE-2024-11849 |
WPScan | |
| 6.1 Medium | Tourmaster | Cross-Site Scripting Unauthenticated Stored XSS via Room Booking No login needed |
< 5.3.4 Fixed in 5.3.4 |
CVE-2024-11356 |
WPScan | |
| 6.5 Medium | WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts | SQL Injection Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection |
≤ 2.6.16 |
CVE-2024-12195 |
Wordfence | |
| 6.4 Medium | WP Multi Store Locator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4.1 |
CVE-2024-12475 |
Wordfence | |
| 6.1 Medium | WP Social AutoConnect | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 4.6.2 |
CVE-2024-12279 |
Wordfence | |
| 6.1 Medium | Turnkey bbPress by WeaverTheme | Cross-Site Scripting Reflected Cross-Site Scripting via _wpnonce Parameter No login needed |
≤ 1.6.3 |
CVE-2024-12221 |
Wordfence | |
| 6.4 Medium | Taskbuilder – WordPress Project & Task Management | Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode |
≤ 3.0.6 |
CVE-2024-11930 |
Wordfence | |
| 6.1 Medium | WP Smart Import : Import any XML File to | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.2 |
CVE-2024-12701 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.