WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 12,101–12,150 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Analytics Cat – Google Analytics Made Easy | Cross-Site Scripting Google Analytics Made Easy <= 1.1.2 - Reflected Cross-Site Scripting No login needed |
≤ 1.1.2 |
CVE-2024-12072 |
Wordfence | |
| 4.3 Medium | Snippet Shortcodes | Broken Access Control Authenticated (Subscriber+) Shortcode Deletion |
≤ 4.1.6 |
CVE-2024-12018 |
Wordfence | |
| 6.1 Medium | Library Bookshelves | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.8 |
CVE-2024-11359 |
Wordfence | |
| 6.4 Medium | Smart Agenda – Prise de rendez-vous en ligne | Cross-Site Scripting Prise de rendez-vous en ligne <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.6 |
CVE-2024-11781 |
Wordfence | |
| 6.4 Medium | FAQ And Answers – Create Frequently Asked Questions Area on WP Sites | Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11882 |
Wordfence | |
| 4.3 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Request Forgery Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 0.4.1 |
CVE-2024-12526 |
Wordfence | |
| 6.1 Medium | BP Email Assign Templates | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5 |
CVE-2024-12441 |
Wordfence | |
| 4.3 Medium | AI Post Generator | AutoWriter | Broken Access Control Missing Authorization to Authenticated (Contributor+) Post/Page Deletion |
≤ 3.5 |
CVE-2024-11709 |
Wordfence | |
| 6.1 Medium | Video & Photo Gallery for Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.1 |
CVE-2024-12162 |
Wordfence | |
| 6.1 Medium | AI Content Writer, RSS Feed to Post, Autoblogging SEO Help | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 6.1.3 |
CVE-2024-12156 |
Wordfence | |
| 6.1 Medium | Planaday API | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 11.4 |
CVE-2024-11804 |
Wordfence | |
| 6.1 Medium | Country Blocker | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2 |
CVE-2024-11459 |
Wordfence | |
| 6.4 Medium | Cognito Forms | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.7 |
CVE-2024-10182 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode |
≤ 0.4.1 |
CVE-2024-12463 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.3.0 |
CVE-2024-11384 |
Wordfence | |
| 6.4 Medium | Top and footer bars for announcements, notifications, advertisements, promotions – YooBar | Cross-Site Scripting YooBar <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.6 |
CVE-2024-11410 |
Wordfence | |
| 6.4 Medium | Add infos to the events calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-11875 |
Wordfence | |
| 6.5 Medium | Library Management System | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 3.2.0 |
CVE-2024-12406 |
Wordfence | |
| 6.4 Medium | Perfect Font Awesome Integration | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3 |
CVE-2024-11891 |
Wordfence | |
| 6.4 Medium | ONLYOFFICE DocSpace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.1 |
CVE-2024-11750 |
Wordfence | |
| 6.1 Medium | kvCORE IDX | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3.35 |
CVE-2024-11723 |
Wordfence | |
| 6.1 Medium | WP Service Payment Form With Authorize.net | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.6.3 |
CVE-2024-12258 |
Wordfence | |
| 6.1 Medium | Newsletter Subscriptions | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2024-11683 |
Wordfence | |
| 6.1 Medium | Website Toolbox Community | Cross-Site Scripting Reflected Cross-Site Scripting via websitetoolbox_username No login needed |
≤ 2.0.1 |
CVE-2024-12338 |
Wordfence | |
| 6.1 Medium | Ultimate Endpoints With Rest Api | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.2 |
CVE-2024-12260 |
Wordfence | |
| 6.4 Medium | PowerBI Embed Reports | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.7 |
CVE-2024-11901 |
Wordfence | |
| 6.1 Medium | dejure.org Vernetzungsfunktion | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.97.5 |
CVE-2024-11417 |
Wordfence | |
| 6.1 Medium | Password for WP | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.5 |
CVE-2024-11419 |
Wordfence | |
| 6.4 Medium | WP-Revive Adserver | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.1 |
CVE-2024-12461 |
Wordfence | |
| 6.4 Medium | Surbma | SalesAutopilot Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.5 |
CVE-2024-11433 |
Wordfence | |
| 6.4 Medium | Gutenberg Blocks and Page Layouts – Attire Blocks | Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.5 |
CVE-2024-11914 |
Wordfence | |
| 6.4 Medium | Catch Popup | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.4 |
CVE-2024-11427 |
Wordfence | |
| 6.1 Medium | Schema App Structured Data | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.4 |
CVE-2024-11279 |
Wordfence | |
| 6.4 Medium | HostFact bestelformulier integratie | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2024-11413 |
Wordfence | |
| 4.3 Medium | Custom Skins Contact Form 7 | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update and Skin Creation |
≤ 1.0 |
CVE-2024-12341 |
Wordfence | |
| 6.5 Medium | SQL Chart Builder | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.3.6 |
CVE-2024-11430 |
Wordfence | |
| 6.4 Medium | Horizontal scroll image slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.1 |
CVE-2024-11442 |
Wordfence | |
| 5.3 Medium | Restrict – membership, site, content and user access restrictions | Information Disclosure membership, site, content and user access restrictions for WordPress <= 2.2.8 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 2.2.8 |
CVE-2024-11351 |
Wordfence | |
| 6.1 Medium | Waymark | Cross-Site Scripting Reflected Cross-Site Scripting via 'content' No login needed |
≤ 1.4.1 |
CVE-2024-12325 |
Wordfence | |
| 5.3 Medium | Last Viewed Posts by WPBeginner | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.0.1 |
CVE-2024-12294 |
Wordfence | |
| 5.3 Medium | Members | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 3.2.10 |
CVE-2024-11008 |
Wordfence | |
| 4.3 Medium | Notibar | Broken Access Control |
≤ 2.1.4 Fixed in 2.1.5 |
CVE-2024-54269 |
Patchstack | |
| 6.1 Medium | WP Pipes | Cross-Site Scripting Reflected Cross-Site Scripting via x1 Parameter No login needed |
≤ 1.4.1 |
CVE-2024-12283 |
Wordfence | |
| 6.1 Medium | WPC Order Notes for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.5.2 |
CVE-2024-12004 |
Wordfence | |
| 6.1 Medium | turboSMTP | Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed |
≤ 4.6 |
CVE-2024-12323 |
Wordfence | |
| 5.3 Medium | LearnPress – WordPress LMS | Information Disclosure WordPress LMS Plugin <= 4.2.7.3 - Course Material Sensitive Information Exposure via REST API No login needed |
≤ 4.2.7.3 |
CVE-2024-11868 |
Wordfence | |
| 6.4 Medium | iChart – Easy Charts and Graphs | Cross-Site Scripting Easy Charts and Graphs <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 2.1.0 |
CVE-2024-11928 |
Wordfence | |
| 5.3 Medium | Simple Restrict | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 1.2.7 |
CVE-2024-11106 |
Wordfence | |
| 6.4 Medium | Email Reminders | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.4 |
CVE-2024-11945 |
Wordfence | |
| 6.1 Medium | Quran multilanguage Text & Audio | Cross-Site Scripting Reflected Cross-Site Scripting via sourate and lang Parameters No login needed |
≤ 2.3.21 |
CVE-2024-11973 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.