WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,151–1,200 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 24 of 29
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Royal Elementor Addons and Templates Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget ≤ 1.3.974 CVE-2024-3887 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Cross-Site Scripting Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect ≤ 3.2.37 CVE-2024-4208 Wordfence
5.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.37 CVE-2024-3189 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.20 CVE-2024-4624 Wordfence
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-34812 Patchstack
6.4 Medium Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2.1 CVE-2024-4630 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Timer ≤ 3.2.36 CVE-2024-4209 Wordfence
6.4 Medium Beaver Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via photo widget crop attribute ≤ 2.8.1.2 CVE-2024-4430 Wordfence
6.4 Medium Elegant Themes Divi Theme, Extra Theme, Divi Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 4.25.0 CVE-2024-4490 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' ≤ 5.9.19 CVE-2024-4275 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' ≤ 5.9.19 CVE-2024-4448 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.4.2 CVE-2024-2785 Wordfence
4.3 Medium Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 4.1.6 CVE-2024-1467 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.4.2 CVE-2024-0445 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1.1 CVE-2024-3923 Wordfence
6.4 Medium Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Text Effect Widget ≤ 1.1.37 CVE-2024-2923 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading widget ≤ 2.1.5 CVE-2024-3831 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animation Title widget img tag ≤ 2.1.5 CVE-2024-3680 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.21.0 CVE-2024-4107 Wordfence
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
7.6 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31270 Patchstack
6.5 Medium Pootle Pagebuilder – WordPress Page builder Plugin pootle-page-builder Cross-Site Scripting ≤ 5.7.1 CVE-2024-34573 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.4.2 Fixed in 5.5.0 CVE-2024-34373 Patchstack
5.3 Medium iPanorama 360 WordPress Virtual Tour Builder Plugin ipanorama-360-virtual-tour-builder-lite Broken Access Control No login needed ≤ 1.8.1 Fixed in 1.8.2 CVE-2024-33941 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 5.3.2.0 Fixed in 5.3.2.1 CVE-2024-33947 Patchstack
6.1 Medium Responsive Contact Form Builder & Lead Generation Plugin Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 1.8.9 CVE-2024-3637 WPScan
7.2 High Cost Calculator Builder Pro Plugin Cross-Site Scripting Unauthenticated Cross-Site Scripting via SVG Upload No login needed ≤ 3.1.67 CVE-2024-4097 Wordfence
5.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri-gallery-slideshow' Shortcode ≤ 1.0.272 CVE-2024-3340 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.13.3 CVE-2024-3743 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Cross-Site Scripting Page Builder Features <= 3.2.34 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.34 CVE-2024-2273 Wordfence
4.3 Medium Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Cross-Site Request Forgery No login needed ≤ 1.8.9 CVE-2024-1415 Wordfence
4.3 Medium Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Broken Access Control Missing Authorization No login needed ≤ 1.8.9 CVE-2024-1416 Wordfence
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleTag' ≤ 2.6.9 CVE-2024-3725 Wordfence
6.4 Medium WordPress Header Builder Plugin – Pearl Plugin Cross-Site Scripting Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.6 CVE-2024-4000 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'colibri_breadcrumb_element' Shortcode ≤ 1.0.272 CVE-2024-3337 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes ≤ 5.4.2 CVE-2024-3197 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 5.4.2 CVE-2024-3199 Wordfence
5.3 Medium Contact Form by WPForms – Drag & Drop Form Builder Plugin wpforms-lite Price Manipulation Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation No login needed ≤ 1.8.7.2 CVE-2024-3649 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id ≤ 2.8.7 CVE-2024-3991 Wordfence
4.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.0.262 CVE-2024-3338 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.17 CVE-2024-4156 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.15 CVE-2024-4003 Wordfence
6.4 Medium Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder Plugin supreme-modules-for-divi Cross-Site Scripting Divi Theme, Extra Theme and Divi Builder <= 2.5.3 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting ≤ 2.5.3 CVE-2024-4334 Wordfence
7.1 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion ≤ 1.6.4 CVE-2024-1945 Wordfence
4.3 Medium OptinMonster Plugin optinmonster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Notice Dismissal No login needed ≤ 2.15.3 Fixed in 2.16.0 CVE-2024-33691 Patchstack
4.7 Medium Page Builder: Live Composer Plugin live-composer-page-builder Broken Access Control ≤ 1.5.38 Fixed in 1.5.39 CVE-2024-32957 Patchstack
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure No login needed ≤ 5.9.15 CVE-2024-3733 Wordfence
9.8 Critical Build App Online Plugin build-app-online Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 1.0.19 CVE-2023-51478 Patchstack
5.3 Medium JetFormBuilder Plugin jetformbuilder Content Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2023-48763 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only