WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 12,401–12,450 of 17,806 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 249 of 357
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting ≤ 1.0.1 CVE-2024-53767 Patchstack
6.5 Medium SimpleSchema Plugin simpleschema-free Cross-Site Scripting ≤ 1.7.6.9 CVE-2024-53771 Patchstack
6.5 Medium Mail Picker Plugin mail-picker Cross-Site Scripting ≤ 1.0.15 Fixed in 1.0.16 CVE-2024-53772 Patchstack
6.5 Medium Znajdź Pracę z Praca.pl Plugin znajdz-prace-z-pracapl Cross-Site Scripting ≤ 2.2.3 CVE-2024-53773 Patchstack
6.5 Medium Sparkle Elementor Kit Plugin sparkle-elementor-kit Cross-Site Scripting ≤ 2.0.9 CVE-2024-53774 Patchstack
6.5 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2024-53786 Patchstack
6.5 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-53787 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack
5.3 Medium Content Audit Exporter Plugin content-audit-exporter Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-53768 Patchstack
4.4 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery ≤ 1.3.9.8 Fixed in 1.3.9.9 CVE-2024-53738 Patchstack
6.1 Medium Social Sharing Plugin – Sassy Social Share Plugin sassy-social-share Cross-Site Scripting Sassy Social Share <= 3.3.69 - Reflected Cross-Site Scripting via heateor_mastodon_share Parameter No login needed ≤ 3.3.69 CVE-2024-11252 Wordfence
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10980 WPScan
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.31 Fixed in 1.8.31 CVE-2024-10704 WPScan
6.5 Medium Wallet for WooCommerce Plugin woo-wallet Other Authenticated (Subscriber+) Incorrect Conversion between Numeric Types ≤ 1.5.6 CVE-2024-7747 Wordfence
6.5 Medium Fintelligence Calculator Plugin fintelligence-calculator Cross-Site Scripting ≤ 1.0.3 CVE-2024-53731 Patchstack
6.5 Medium WP Mailster Plugin wp-mailster Cross-Site Scripting ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53737 Patchstack
4.3 Medium Restaurant & Cafe Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.5.9 CVE-2024-10780 Wordfence
4.3 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.6.2 CVE-2024-10670 Wordfence
4.3 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.7.1003 CVE-2024-10798 Wordfence
6.4 Medium Login with Vipps and MobilePay Plugin login-with-vipps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.3 CVE-2024-11786 Wordfence
6.1 Medium Kudos Donations – Easy donations and payments with Mollie Plugin kudos-donations Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting No login needed ≤ 3.2.9 CVE-2024-11684 Wordfence
6.1 Medium Kudos Donations – Easy donations and payments with Mollie Plugin kudos-donations Cross-Site Scripting Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting via 'add_query_arg' No login needed ≤ 3.2.9 CVE-2024-11685 Wordfence
6.1 Medium FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.1 CVE-2024-11458 Wordfence
6.1 Medium SEO Landing Page Generator Plugin seo-landing-page-generator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.66.2 CVE-2024-11366 Wordfence
6.4 Medium HLS Player Plugin hls-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.10 CVE-2024-11333 Wordfence
6.4 Medium Ragic Shortcode Plugin ragic-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2024-11431 Wordfence
6.4 Medium StreamWeasels YouTube Integration Plugin streamweasels-youtube-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.6 CVE-2024-11788 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' ≤ 4.1.3 CVE-2024-11203 Wordfence
6.4 Medium LegalWeb Cloud Plugin legalweb-cloud Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.2 CVE-2024-11761 Wordfence
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.5.0 Fixed in 4.5.0 CVE-2024-10896 WPScan
4.8 Medium adBuddy+ (AdBlocker Detection) by NetfunkDesign Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.1.3 CVE-2024-10510 WPScan
5.4 Medium Element Pack Elementor Addons Plugin Cross-Site Scripting Contributor+ Stored XSS < 5.10.3 Fixed in 5.10.3 CVE-2024-10493 WPScan
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Author+ Stored XSS < 4.5.0 Fixed in 4.5.0 CVE-2024-10473 WPScan
4.3 Medium Image Alt Text Plugin image-alt-text Broken Access Control Missing Authorization to Authenticated (Subscriber+) Image Alt Text Update ≤ 2.0.0 CVE-2024-11918 Wordfence
4.9 Medium Internal Linking for SEO traffic & Ranking – Auto internal links (100% automatic) Plugin automatic-internal-links-for-seo SQL Injection Auto internal links (100% automatic) <= 1.2.1 - Authenticated (Administrator+) SQL Injection via post_id Parameter ≤ 1.2.1 CVE-2024-11009 Wordfence
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission No login needed ≤ 7.8.5 CVE-2024-10580 Wordfence
6.4 Medium Pricing Tables For WPBakery Page Builder (formerly Visual Composer) Plugin pricing-tables-for-visual-composer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wdo_pricing_tables Shortcode ≤ 1.4 CVE-2024-10175 Wordfence
6.4 Medium Counter Up – Animated Number Counter & Milestone Showcase Plugin Cross-Site Scripting Animated Number Counter & Milestone Showcase <= 2.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2024-10895 Wordfence
5.3 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Path Traversal Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View No login needed ≤ 3.0.6 CVE-2024-11219 Wordfence
5.3 Medium ProfilePress Plugin wp-user-avatar Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed ≤ 4.15.18 CVE-2024-11083 Wordfence
6.1 Medium Sugar Calendar (Lite) Plugin sugar-calendar-lite Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.3.0 CVE-2024-10878 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.25.7 CVE-2024-8236 Wordfence
4.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure ≤ 7.8.5 CVE-2024-10579 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Countdown Widget ≤ 2.6.9 CVE-2024-10308 Wordfence
4.3 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via sg_content_template ≤ 2.6.9 CVE-2024-8899 Wordfence
6.1 Medium Parsi Date Plugin wp-parsidate Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 5.1.1 CVE-2024-11032 Wordfence
6.4 Medium Spotify Play Button Plugin spotify-play-button-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode ≤ 2.11 CVE-2024-11192 Wordfence
6.4 Medium Support SVG – Upload svg files in wordpress without hassle Plugin support-svg Cross-Site Scripting Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload ≤ 1.1.0 CVE-2024-11091 Wordfence
6.4 Medium BNE Gallery Extended Plugin bne-gallery-extended Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via gallery Shortcode ≤ 1.2.1 CVE-2024-11119 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only