WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,201–1,250 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 25 of 29
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Elementor Website Builder Plugin elementor Authentication Bypass Auth. Arbitrary Attachment Read ≤ 3.16.4 Fixed in 3.16.5 CVE-2023-47504 Patchstack
5.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Content Injection No login needed ≤ 5.1.9.2 Fixed in 5.1.9.3 CVE-2023-23989 Patchstack
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Other Arbitrary Price Change No login needed ≤ 5.1.9.2 Fixed in 5.1.9.3 CVE-2023-23976 Patchstack
4.3 Medium EleSpare – News, Magazine and Blog Addons for Elementor Plugin elespare Broken Access Control Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation ≤ 2.1.2 CVE-2024-0900 Wordfence
6.5 Medium Infographic Maker – iList Plugin infographic-and-list-builder-ilist Cross-Site Scripting ≤ 4.6.6 Fixed in 4.6.8 CVE-2024-32696 Patchstack
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1 CVE-2024-1057 Wordfence
5.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block ≤ 4.5.9 CVE-2024-3818 Wordfence
6.5 Medium App Builder Plugin app-builder Cross-Site Scripting ≤ 3.8.8 Fixed in 3.8.9 CVE-2024-32565 Patchstack
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0 Fixed in 2.0.1 CVE-2024-32592 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.3.4.2 Fixed in 1.4 CVE-2024-32593 Patchstack
7.1 High WP Cost Estimation & Payment Forms Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-32510 Patchstack
6.5 Medium WP Cost Estimation & Payment Forms Builder Plugin Broken Access Control No login needed ≤ 10.1.76 Fixed in 10.1.77 CVE-2024-32509 Patchstack
5.4 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Request Forgery No login needed ≤ 1.5.35 Fixed in 1.5.36 CVE-2024-31933 Patchstack
4.3 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.2.104 Fixed in 1.2.105 CVE-2024-31940 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.15.20 Fixed in 6.15.21 CVE-2024-32088 Patchstack
6.3 Medium ARForms Form Builder Plugin arforms-form-builder Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31272 Patchstack
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Arbitrary File Upload Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Author+) Limited File Upload to Stored Cross-Site Scripting ≤ 2.6.8 CVE-2024-3344 Wordfence
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 2.6.8 CVE-2024-3343 Wordfence
4.7 Medium App Builder Plugin app-builder Open Redirect No login needed ≤ 3.8.7 Fixed in 3.8.8 CVE-2024-31282 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 4.8.8 CVE-2024-2736 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via "Price List" Element ≤ 4.8.8 CVE-2024-2735 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via AI Features ≤ 4.8.8 CVE-2024-2734 Wordfence
5.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Separator Element ≤ 4.8.8 CVE-2024-2733 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list Shortcode ≤ 4.8.8 CVE-2024-3267 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Text Separator' and 'Image Compare' Widget ≤ 1.13.2 CVE-2024-2792 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Posts Block ≤ 3.12.11 CVE-2024-2039 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget ≤ 2.8.4 CVE-2024-2946 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget ≤ 3.20.2 CVE-2024-2117 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes ≤ 1.8.4 CVE-2024-2504 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.11 CVE-2024-2623 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget ≤ 3.2.25 CVE-2024-1999 Wordfence
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
6.4 Medium Cards for Beaver Builder Plugin bb-bootstrap-cards Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via bootstrapcard link ≤ 1.1.2 CVE-2024-2305 Wordfence
6.4 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via element link ≤ 1.3.0 CVE-2024-2289 Wordfence
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure No login needed ≤ 5.9.13 CVE-2024-2974 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Widget ≤ 1.3.4 CVE-2024-2183 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 5.3.0.0 CVE-2024-1991 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget ≤ 1.3.4 CVE-2024-2186 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.11 CVE-2024-2650 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 1.3.4 CVE-2024-2181 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 5.3.1.0 CVE-2024-1990 Wordfence
5.9 Medium Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker Information Disclosure Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure No login needed ≤ 1.15.22 CVE-2024-2112 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget URL Attribute ≤ 4.8.8 CVE-2024-3266 Wordfence
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.4 CVE-2024-2226 Wordfence
6.4 Medium Forminator – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Scripting Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode ≤ 1.29.2 CVE-2024-3053 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget ≤ 1.3.4 CVE-2024-2185 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget ≤ 1.3.4 CVE-2024-2187 Wordfence
7.1 High Post Type Builder (PTB) Plugin Broken Access Control Auth. Arbitrary Post/Page Creation ≤ 2.0.8 CVE-2024-31366 Patchstack
7.1 High Post Type Builder (PTB) Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-31365 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget ≤ 3.2.31 CVE-2024-2919 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only