WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 11,451–11,500 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 230 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords Plugin muzaara-adwords-optimize-dashboard Information Disclosure Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure No login needed ≤ 3.1 CVE-2024-12159 Wordfence
6.5 Medium School Management System – WPSchoolPress Plugin wpschoolpress SQL Injection WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection ≤ 2.2.14 CVE-2024-12332 Wordfence
4.3 Medium Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements Plugin ai-addons-for-elementor Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure ≤ 2.2.1 CVE-2024-12140 Wordfence
6.1 Medium Automate Hub Free by Sperse.IO Plugin automate-hub-free-by-sperse-io Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2024-11377 Wordfence
5.3 Medium Member Access Plugin member-access Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 1.1.6 CVE-2024-11290 Wordfence
5.3 Medium Popup – MailChimp, GetResponse and ActiveCampaign Intergrations Plugin ultimate-popup-creator Broken Access Control MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table Truncation No login needed ≤ 3.2.6 CVE-2024-12158 Wordfence
6.1 Medium GDY Modular Content Plugin gdy-modular-content Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.9.92 CVE-2024-12153 Wordfence
6.4 Medium Uptodown APK Download Widget Plugin uptodown-apk-download-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1.10 CVE-2024-12453 Wordfence
6.1 Medium Same but Different – Related Posts by Taxonomy Plugin same-but-different Cross-Site Scripting Related Posts by Taxonomy <= 1.0.16 - Reflected Cross-Site Scripting No login needed ≤ 1.0.16 CVE-2024-11363 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
4.4 Medium Toggles Shortcode and Widget Plugin toggles-shortcode-and-widget Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.14 CVE-2024-12207 Wordfence
6.4 Medium Horoscope And Tarot Plugin horoscope-and-tarot Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.0 CVE-2024-11337 Wordfence
6.1 Medium ViewMedica 9 Plugin viewmedica Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.4.17 CVE-2024-12291 Wordfence
6.1 Medium Infility Global Plugin infility-global Cross-Site Scripting Reflected Cross-Site Scripting via set_type Parameter No login needed ≤ 2.9.8 CVE-2024-12290 Wordfence
5.4 Medium ViewMedica Embed Plugin viewmedica Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed ≤ 1.4.17 CVE-2024-12170 Wordfence
6.1 Medium Simple add pages or posts Plugin simple-add-pages-or-posts Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.0.0 CVE-2024-12288 Wordfence
6.4 Medium Image Magnify Plugin image-magnify Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2024-11445 Wordfence
6.1 Medium WC1C Plugin wc1c-main Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.23.0 CVE-2024-11375 Wordfence
6.1 Medium Bizapp for WooCommerce Plugin bizapp-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2024-11378 Wordfence
6.1 Medium WooCommerce HSS Extension for Streaming Video Plugin woocommerce-hss-extension-for-streaming-video Cross-Site Scripting Reflected Cross-Site Scripting via videolink Parameter No login needed ≤ 3.31 CVE-2024-12214 Wordfence
6.1 Medium SEO Keywords Plugin seo-keywords Cross-Site Scripting Reflected Cross-Site Scripting via google_error Parameter No login needed ≤ 1.1.3 CVE-2024-12126 Wordfence
6.1 Medium Financial Stocks & Crypto Market Data Plugin live-stock-prices-for-wordpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.10.3 CVE-2024-11690 Wordfence
6.1 Medium WP – Bulk SMS – by SMS.to Plugin wp-bulk-sms Cross-Site Scripting Bulk SMS – by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting No login needed ≤ 1.0.12 CVE-2024-11434 Wordfence
6.4 Medium PIXNET Plugin pixnet Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.9.10 CVE-2024-11338 Wordfence
6.4 Medium YOGO Booking Plugin yogo-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.2 CVE-2024-12462 Wordfence
6.1 Medium Woo Ukrposhta Plugin woo-ukrposhta Cross-Site Scripting Reflected Cross-Site Scripting via order, post, and idd Parameters No login needed ≤ 1.17.11 CVE-2024-12049 Wordfence
6.4 Medium CC Canadian Mortgage Calculator Plugin cc-canadian-mortgage-calculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.0 CVE-2024-11383 Wordfence
4.3 Medium Duplicate Post, Page and Any Custom Post Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure via Post Duplication ≤ 3.5.5 CVE-2024-12538 Wordfence
5.3 Medium ClickDesigns Plugin clickdesigns Broken Access Control Missing Authorization to API Key Modification or Removal No login needed ≤ 1.8.0 CVE-2024-12559 Wordfence
6.4 Medium Slider Pro Lite Plugin slider-pro-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-11899 Wordfence
6.4 Medium Sellsy Plugin sellsy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.3 CVE-2024-12592 Wordfence
6.1 Medium ARS Affiliate Page Plugin ars-affiliate-page Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.2 CVE-2024-12098 Wordfence
6.4 Medium Sell Media Plugin sell-media Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.5.8.5 CVE-2024-11777 Wordfence
5.4 Medium Chative Live chat and Chatbot Plugin chative-live-chat-and-chatbot Cross-Site Request Forgery Cross-Site Request Forgery via add_chative_widget_action Function No login needed ≤ 1.1 CVE-2024-12541 Wordfence
6.4 Medium WordPress Survey & Poll – Quiz, Survey and Poll Plugin wp-survey-and-poll Cross-Site Scripting Quiz, Survey and Poll Plugin for WordPress <= 1.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.5 CVE-2024-12528 Wordfence
6.5 Medium Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler Plugin cf7-styler Arbitrary Shortcode Execution CF7 WOW Styler <= 1.7.1 - Unauthenticated Arbitrary Shortcode Execution and Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-12419 Wordfence
6.1 Medium Transporters.io Plugin transportersio Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.1.1 CVE-2024-12557 Wordfence
6.4 Medium Formaloo Form Maker & Customer Analytics for WordPress & WooCommerce Plugin formaloo-form-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3.2 CVE-2024-11934 Wordfence
4.9 Medium Timeline Designer Plugin timeline-designer SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.4 CVE-2024-11437 Wordfence
6.4 Medium WP Youtube Gallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9 CVE-2024-12590 Wordfence
6.5 Medium Email Subscribers Plugin SQL Injection Admin+ SQL Injection < 5.7.44 Fixed in 5.7.44 CVE-2024-12311 WPScan
6.1 Medium Icegram Engage Plugin icegram Cross-Site Scripting Author+ Stored XSS No login needed < 3.1.32 Fixed in 3.1.32 CVE-2024-12302 WPScan
6.1 Medium Pods – Custom Content Types and Fields Plugin pods Cross-Site Scripting Custom Content Types and Fields < 3.2.8.1 - Admin+ Stored XSS No login needed < 3.2.8.1 Fixed in 3.2.8.1 CVE-2024-11849 WPScan
6.1 Medium Tourmaster Plugin Cross-Site Scripting Unauthenticated Stored XSS via Room Booking No login needed < 5.3.4 Fixed in 5.3.4 CVE-2024-11356 WPScan
6.5 Medium WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts Plugin wedevs-project-manager SQL Injection Task, team, and project management plugin featuring kanban board and gantt charts <= 2.6.16 - Authenticated (Subscriber+) SQL Injection ≤ 2.6.16 CVE-2024-12195 Wordfence
6.4 Medium WP Multi Store Locator Plugin wp-multi-store-locator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2024-12475 Wordfence
6.1 Medium WP Social AutoConnect Plugin wp-fb-autoconnect Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 4.6.2 CVE-2024-12279 Wordfence
6.1 Medium Turnkey bbPress by WeaverTheme Plugin weaver-for-bbpress Cross-Site Scripting Reflected Cross-Site Scripting via _wpnonce Parameter No login needed ≤ 1.6.3 CVE-2024-12221 Wordfence
6.4 Medium Taskbuilder – WordPress Project & Task Management Plugin taskbuilder Cross-Site Scripting WordPress Project & Task Management plugin <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via wppm_tasks Shortcode ≤ 3.0.6 CVE-2024-11930 Wordfence
6.1 Medium WP Smart Import : Import any XML File to Plugin wp-smart-import Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-12701 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only