WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 12,401–12,450 of 17,806 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Pixobe Cartography | Cross-Site Scripting |
≤ 1.0.1 |
CVE-2024-53767 |
Patchstack | |
| 6.5 Medium | SimpleSchema | Cross-Site Scripting |
≤ 1.7.6.9 |
CVE-2024-53771 |
Patchstack | |
| 6.5 Medium | Mail Picker | Cross-Site Scripting |
≤ 1.0.15 Fixed in 1.0.16 |
CVE-2024-53772 |
Patchstack | |
| 6.5 Medium | Znajdź Pracę z Praca.pl | Cross-Site Scripting |
≤ 2.2.3 |
CVE-2024-53773 |
Patchstack | |
| 6.5 Medium | Sparkle Elementor Kit | Cross-Site Scripting |
≤ 2.0.9 |
CVE-2024-53774 |
Patchstack | |
| 6.5 Medium | Cowidgets – Elementor Addons | Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) |
≤ 1.2.0 |
CVE-2024-53786 |
Patchstack | |
| 6.5 Medium | Random Banner | Cross-Site Scripting |
≤ 4.2.12 |
CVE-2024-53787 |
Patchstack | |
| 5.9 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-53788 |
Patchstack | |
| 5.3 Medium | Content Audit Exporter | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.1 |
CVE-2024-53768 |
Patchstack | |
| 4.4 Medium | Asset CleanUp: Page Speed Booster | Server-Side Request Forgery |
≤ 1.3.9.8 Fixed in 1.3.9.9 |
CVE-2024-53738 |
Patchstack | |
| 6.1 Medium | Social Sharing Plugin – Sassy Social Share | Cross-Site Scripting Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter No login needed |
≤ 3.3.69 |
CVE-2024-11252 |
Wordfence | |
| 5.4 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS |
< 5.10.3 Fixed in 5.10.3 |
CVE-2024-10980 |
WPScan | |
| 4.8 Medium | Photo Gallery by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.8.31 Fixed in 1.8.31 |
CVE-2024-10704 |
WPScan | |
| 6.5 Medium | Wallet for WooCommerce | Other Authenticated (Subscriber+) Incorrect Conversion between Numeric Types |
≤ 1.5.6 |
CVE-2024-7747 |
Wordfence | |
| 6.5 Medium | Fintelligence Calculator | Cross-Site Scripting |
≤ 1.0.3 |
CVE-2024-53731 |
Patchstack | |
| 6.5 Medium | WP Mailster | Cross-Site Scripting |
≤ 1.8.16.0 Fixed in 1.8.17.0 |
CVE-2024-53737 |
Patchstack | |
| 4.3 Medium | Restaurant & Cafe Addon for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.5.9 |
CVE-2024-10780 |
Wordfence | |
| 4.3 Medium | Primary Addon for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.6.2 |
CVE-2024-10670 |
Wordfence | |
| 4.3 Medium | Royal Elementor Addons and Templates | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.7.1003 |
CVE-2024-10798 |
Wordfence | |
| 6.4 Medium | Login with Vipps and MobilePay | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.3 |
CVE-2024-11786 |
Wordfence | |
| 6.1 Medium | Kudos Donations – Easy donations and payments with Mollie | Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting No login needed |
≤ 3.2.9 |
CVE-2024-11684 |
Wordfence | |
| 6.1 Medium | Kudos Donations – Easy donations and payments with Mollie | Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg' No login needed |
≤ 3.2.9 |
CVE-2024-11685 |
Wordfence | |
| 6.1 Medium | FAQ Builder AYS | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.7.1 |
CVE-2024-11458 |
Wordfence | |
| 6.1 Medium | SEO Landing Page Generator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.66.2 |
CVE-2024-11366 |
Wordfence | |
| 6.4 Medium | HLS Player | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.10 |
CVE-2024-11333 |
Wordfence | |
| 6.4 Medium | Ragic Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2 |
CVE-2024-11431 |
Wordfence | |
| 6.4 Medium | StreamWeasels YouTube Integration | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.6 |
CVE-2024-11788 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' |
≤ 4.1.3 |
CVE-2024-11203 |
Wordfence | |
| 6.4 Medium | LegalWeb Cloud | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.2 |
CVE-2024-11761 |
Wordfence | |
| 5.4 Medium | Logo Slider | Cross-Site Scripting Contributor+ Stored XSS |
< 4.5.0 Fixed in 4.5.0 |
CVE-2024-10896 |
WPScan | |
| 4.8 Medium | adBuddy+ (AdBlocker Detection) by NetfunkDesign | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.1.3 |
CVE-2024-10510 |
WPScan | |
| 5.4 Medium | Element Pack Elementor Addons | Cross-Site Scripting Contributor+ Stored XSS |
< 5.10.3 Fixed in 5.10.3 |
CVE-2024-10493 |
WPScan | |
| 5.4 Medium | Logo Slider | Cross-Site Scripting Author+ Stored XSS |
< 4.5.0 Fixed in 4.5.0 |
CVE-2024-10473 |
WPScan | |
| 4.3 Medium | Image Alt Text | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Image Alt Text Update |
≤ 2.0.0 |
CVE-2024-11918 |
Wordfence | |
| 4.9 Medium | Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) | SQL Injection Auto internal links (100% automatic) <= 1.2.1 - Authenticated (Administrator+) SQL Injection via post_id Parameter |
≤ 1.2.1 |
CVE-2024-11009 |
Wordfence | |
| 4.3 Medium | WordPress Contact Forms by Cimatti | Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed |
≤ 1.9.2 |
CVE-2024-10521 |
Wordfence | |
| 5.3 Medium | Hustle – Email Marketing, Lead Generation, Optins, Popups | Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission No login needed |
≤ 7.8.5 |
CVE-2024-10580 |
Wordfence | |
| 6.4 Medium | Pricing Tables For WPBakery Page Builder (formerly Visual Composer) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wdo_pricing_tables Shortcode |
≤ 1.4 |
CVE-2024-10175 |
Wordfence | |
| 6.4 Medium | Counter Up – Animated Number Counter & Milestone Showcase | Cross-Site Scripting Animated Number Counter & Milestone Showcase <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4.0 |
CVE-2024-10895 |
Wordfence | |
| 5.3 Medium | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Path Traversal Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View No login needed |
≤ 3.0.6 |
CVE-2024-11219 |
Wordfence | |
| 5.3 Medium | ProfilePress | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 4.15.18 |
CVE-2024-11083 |
Wordfence | |
| 6.1 Medium | Sugar Calendar (Lite) | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.3.0 |
CVE-2024-10878 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder – More than Just a Page Builder | Cross-Site Scripting More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.25.7 |
CVE-2024-8236 |
Wordfence | |
| 4.3 Medium | Hustle – Email Marketing, Lead Generation, Optins, Popups | Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure |
≤ 7.8.5 |
CVE-2024-10579 |
Wordfence | |
| 6.4 Medium | Jeg Elementor Kit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget |
≤ 2.6.9 |
CVE-2024-10308 |
Wordfence | |
| 4.3 Medium | Jeg Elementor Kit | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template |
≤ 2.6.9 |
CVE-2024-8899 |
Wordfence | |
| 6.1 Medium | Parsi Date | Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed |
≤ 5.1.1 |
CVE-2024-11032 |
Wordfence | |
| 6.4 Medium | Spotify Play Button | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode |
≤ 2.11 |
CVE-2024-11192 |
Wordfence | |
| 6.4 Medium | Support SVG – Upload svg files in wordpress without hassle | Cross-Site Scripting Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload |
≤ 1.1.0 |
CVE-2024-11091 |
Wordfence | |
| 6.4 Medium | BNE Gallery Extended | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode |
≤ 1.2.1 |
CVE-2024-11119 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.