WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 12,451–12,500 of 17,806 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.5 Medium | Booster for WooCommerce | Cross-Site Scripting Authenticated (ShopManager+) Stored Cross-Site Scripting via wcj_product_meta Shortcode |
≤ 7.2.3 |
CVE-2024-9170 |
Wordfence | |
| 6.1 Medium | Multiple Plugins <= (Various Versions) | Cross-Site Scripting Reflected Cross-Site Scripting via cminds_free_guide Shortcode No login needed |
≤ 1.2.1, ≤ 1.4.1, ≤ 1.4.2, … |
CVE-2024-11202 |
Wordfence | |
| 6.5 Medium | Product Input Fields for WooCommerce | Path Traversal Authenticated (Contributor+) Arbitrary File Read |
≤ 1.9 |
CVE-2024-10857 |
Wordfence | |
| 6.3 Medium | InPost Gallery | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via inpost_gallery_get_shortcode_template |
≤ 2.1.4.2 |
CVE-2024-11002 |
Wordfence | |
| 4.8 Medium | Everest Forms | Cross-Site Scripting Admin+ Stored XSS |
< 3.0.4.2 Fixed in 3.0.4.2 |
CVE-2024-10471 |
WPScan | |
| 4.8 Medium | WP Admin UI Customize | Cross-Site Scripting Cross-site scripting vulnerability exists in WP Admin UI Customize versions prior to ver 1.5.14. If a malicious admin user customizes the admin screen with some malicious contents… |
prior to ver 1.5.14 |
CVE-2024-53278 |
jpcert | |
| 6.1 Medium | Additional Order Filters for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.21 |
CVE-2024-11418 |
Wordfence | |
| 6.1 Medium | Skt NURCaptcha | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 3.5.0 |
CVE-2024-11342 |
Wordfence | |
| 4.8 Medium | NextGEN Gallery | Cross-Site Scripting Admin+ Stored XSS |
< 3.59.5 Fixed in 3.59.5 |
CVE-2024-6393 |
WPScan | |
| 6.8 Medium | YaDisk Files | Cross-Site Scripting Contributor+ Stored XSS via Shortcode |
≤ 1.2.5 |
CVE-2024-10709 |
WPScan | |
| 6.4 Medium | 워드프레스 결제 심플페이 – 우커머스 결제 플러그인 | Cross-Site Scripting 우커머스 결제 플러그인 <= 5.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting pafw_instant_payment Shortcode |
≤ 5.1.4 |
CVE-2024-11228 |
Wordfence | |
| 6.4 Medium | 코드엠샵 소셜톡 | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via add_plus_friends and add_plus_talk Shortcodes |
≤ 1.1.18 |
CVE-2024-11229 |
Wordfence | |
| 6.4 Medium | 우커머스 네이버페이 | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mnp_purchase Shortcode |
≤ 3.3.7 |
CVE-2024-11231 |
Wordfence | |
| 6.1 Medium | Wishlist for WooCommerce: Multi Wishlists Per Customer PRO | Cross-Site Scripting Reflected Cross-Site Scripting via wtab Parameter No login needed |
3.0.8, 3.0.9, 3.1.0, … |
CVE-2024-10519 |
Wordfence | |
| 6.4 Medium | Rescue Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via rescue_progressbar Shortcode |
≤ 2.9 |
CVE-2024-11199 |
Wordfence | |
| 6.4 Medium | Memberlite Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via memberlite_accordion Shortcode |
≤ 1.3.9 |
CVE-2024-11227 |
Wordfence | |
| 6.1 Medium | Checkout with Cash App on WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 6.0.2 |
CVE-2024-9635 |
Wordfence | |
| 6.1 Medium | Chessgame Shizzle | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.3.0 |
CVE-2024-11446 |
Wordfence | |
| 6.1 Medium | Custom CSS, JS & PHP | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3.0 |
CVE-2024-11330 |
Wordfence | |
| 4.3 Medium | Wp Maximum Upload File Size | Information Disclosure Authenticated (Author+) Full Path Disclosure |
≤ 1.1.3 |
CVE-2024-11265 |
Wordfence | |
| 6.1 Medium | Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder | Cross-Site Scripting Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder <= 6.16.1.2 - Reflected Cross-Site Scripting via Custom HTML Form Parameter No login needed |
≤ 6.16.1.2 |
CVE-2024-11188 |
Wordfence | |
| 6.4 Medium | AutoListicle: Automatically Update Numbered List Articles | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.3 |
CVE-2024-11426 |
Wordfence | |
| 6.1 Medium | PDF Invoices & Packing Slips Generator for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.1 |
CVE-2024-11361 |
Wordfence | |
| 6.4 Medium | HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.4 |
CVE-2024-11332 |
Wordfence | |
| 4.3 Medium | WP Travel Engine | Broken Access Control Missing Authorization to Authenticated (Contributor+) Plugin Settings Update |
≤ 6.2.1 |
CVE-2024-10606 |
Wordfence | |
| 6.4 Medium | Slotti Ajanvaraus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-11408 |
Wordfence | |
| 6.4 Medium | Easy Liveblogs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.5 |
CVE-2024-11387 |
Wordfence | |
| 6.1 Medium | JobBoardWP – Job Board Listings and Submissions | Cross-Site Scripting Job Board Listings and Submissions <= 1.3.0 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.0 |
CVE-2024-10880 |
Wordfence | |
| 4.3 Medium | Enter Addons – Ultimate Template Builder for Elementor | Information Disclosure Ultimate Template Builder for Elementor <= 2.1.9 - Authenticated (Contributor+) Post Disclosure |
≤ 2.1.9 |
CVE-2024-10868 |
Wordfence | |
| 6.4 Medium | Twitter Follow Button | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter |
≤ 0.2 |
CVE-2024-10116 |
Wordfence | |
| 5.3 Medium | Product Table for WooCommerce by CodeAstrology (wooproducttable.com) | Information Disclosure Information Exposure No login needed |
≤ 3.5.1 |
CVE-2024-10813 |
Wordfence | |
| 6.4 Medium | Tribute Testimonials – WordPress Testimonial Grid/Slider | Cross-Site Scripting WordPress Testimonial Grid/Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.4 |
CVE-2024-10886 |
Wordfence | |
| 4.3 Medium | WP User Manager – User Profile Builder & Membership | Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration |
≤ 2.9.11 |
CVE-2024-10537 |
Wordfence | |
| 6.1 Medium | Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.112.0 |
CVE-2024-11362 |
Wordfence | |
| 6.4 Medium | Quotes llama | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.0.0 |
CVE-2024-10874 |
Wordfence | |
| 4.3 Medium | WPDash Notes | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 1.3.5 |
CVE-2024-9223 |
Wordfence | |
| 6.1 Medium | DeBounce Email Validator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.6.5 |
CVE-2024-11463 |
Wordfence | |
| 4.3 Medium | WP User Manager – User Profile Builder & Membership | Broken Access Control User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal |
≤ 2.9.11 |
CVE-2024-10216 |
Wordfence | |
| 6.1 Medium | GuardGiant Brute Force Protection | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.6 |
CVE-2024-10869 |
Wordfence | |
| 6.6 Medium | GEO My | Arbitrary File Upload Admin+ Arbitrary File Upload |
4.0 – < 4.5, < 3.1 Fixed in 4.5 |
CVE-2024-9422 |
WPScan | |
| 4.3 Medium | Easy Twitter Feed – Twitter feeds plugin for WP | Information Disclosure Twitter feeds plugin for WP <= 1.2.6 - Authenticated (Contributor+) Post Exposure |
≤ 1.2.6 |
CVE-2024-10666 |
Wordfence | |
| 6.1 Medium | Premium Packages – Sell Digital Products Securely | Cross-Site Scripting Sell Digital Products Securely <= 5.9.3 - Reflected Cross-Site Scripting via add_query_arg No login needed |
≤ 5.9.3 |
CVE-2024-11225 |
Wordfence | |
| 6.1 Medium | MailMunch – Grow your Email List | Cross-Site Scripting Grow your Email List <= 3.1.8 - Reflected Cross-Site Scripting No login needed |
≤ 3.1.8 |
CVE-2024-8735 |
Wordfence | |
| 5.5 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 3.2.4.2 |
CVE-2024-10034 |
Wordfence | |
| 4.3 Medium | Ultimate YouTube Video & Shorts Player With Vimeo | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Setting Exposure |
≤ 3.3 |
CVE-2024-11355 |
Wordfence | |
| 6.4 Medium | Control horas | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.1 |
CVE-2024-11381 |
Wordfence | |
| 5.3 Medium | Anonymous Restricted Content | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 1.6.5 |
CVE-2024-11089 |
Wordfence | |
| 5.3 Medium | Simple Membership | Information Disclosure Exposure of Private Personal Information to an Unauthorized Actor No login needed |
≤ 4.5.5 |
CVE-2024-11088 |
Wordfence | |
| 4.3 Medium | Stratum – Elementor Widgets | Information Disclosure Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates |
≤ 1.4.4 |
CVE-2024-10316 |
Wordfence | |
| 4.3 Medium | Sky Addons for Elementor | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor Template |
≤ 2.6.1 |
CVE-2024-9542 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.