WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 12,651–12,700 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 254 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.7 Medium Filebird Plugin filebird Broken Access Control ≤ 6.3.2 Fixed in 6.3.4 CVE-2024-53825 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-53796 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.27.0 Fixed in 2.27.1 CVE-2024-53794 Patchstack
6.5 Medium Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting ≤ 2.8.4.3 Fixed in 2.8.4.4 CVE-2024-53797 Patchstack
6.5 Medium Futurio Extra Plugin futurio-extra Cross-Site Scripting ≤ 2.0.14 Fixed in 2.0.15 CVE-2024-53802 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.2.1 Fixed in 5.2.2 CVE-2024-53801 Patchstack
6.5 Medium Captivate Sync Plugin captivatesync-trade Cross-Site Scripting ≤ 2.0.22 Fixed in 2.0.26 CVE-2024-53820 Patchstack
7.1 High WP GeoNames Plugin wp-geonames Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 Fixed in 1.9 CVE-2024-53812 Patchstack
7.1 High Pie Register Premium Plugin pie-register-premium Cross-Site Scripting No login needed < 3.8.3.3 Fixed in 3.8.3.3 CVE-2024-53821 Patchstack
5.9 Medium Z-Downloads Plugin z-downloads Cross-Site Scripting ≤ 1.11.7 Fixed in 1.11.8 CVE-2024-54206 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.6.14 Fixed in 6.0.1 CVE-2024-53823 Patchstack
7.1 High Block Controller Plugin block-controller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.3 CVE-2024-54208 Patchstack
5.9 Medium Auction Plugin wp-auctions Cross-Site Scripting ≤ 3.7 CVE-2024-54207 Patchstack
7.1 High Awesome Shortcodes Plugin awesome-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-54209 Patchstack
5.9 Medium Borderless Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin <= 1.5.8 - Cross Site Scripting (XSS) ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54211 Patchstack
6.5 Medium Advanced Element Bucket Addons for Elementor Plugin cs-element-bucket Cross-Site Scripting ≤ 1.0.2 CVE-2024-54210 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54212 Patchstack
6.5 Medium ZionBuilder Plugin zionbuilder Cross-Site Scripting Zion Builder plugin <= 3.6.16 - Cross Site Scripting (XSS) ≤ 3.6.16 Fixed in 3.6.17 CVE-2024-54213 Patchstack
7.1 High Paloma Widget Plugin postman-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.14 CVE-2024-54205 Patchstack
9.3 Critical Auction Plugin wp-auctions SQL Injection No login needed ≤ 3.7 CVE-2024-51615 Patchstack
10.0 Critical Revy Plugin revy Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.18 CVE-2024-54214 Patchstack
7.7 High ARForms Plugin arforms Path Traversal < 7.0.2 Fixed in 7.0.2 CVE-2024-54216 Patchstack
9.0 Critical s2Member Plugin s2member Remote Code Execution No login needed ≤ 241114 Fixed in 241216 CVE-2024-51815 Patchstack
5.4 Medium Maspik – Spam blacklist Plugin contact-forms-anti-spam Cross-Site Request Forgery CSRF to Settings Change ≤ 2.2.7 Fixed in 2.2.8 CVE-2024-53806 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.4.1 Fixed in 2.6.5 CVE-2024-53809 Patchstack
8.5 High WP Mailster Plugin wp-mailster SQL Injection ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53807 Patchstack
8.5 High NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection ≤ 8.7.8 Fixed in 8.7.9 CVE-2024-53808 Patchstack
8.5 High Pinpoint Booking System Plugin booking-system SQL Injection ≤ 2.9.9.5.1 Fixed in 2.9.9.5.2 CVE-2024-53815 Patchstack
7.6 High Product Labels For Woocommerce Plugin aco-product-labels-for-woocommerce SQL Injection ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-53817 Patchstack
7.5 High WP Mailster Plugin wp-mailster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53804 Patchstack
6.6 Medium WDesignkit Plugin wdesignkit Arbitrary File Upload ≤ 1.0.40 Fixed in 1.1.0 CVE-2024-53811 Patchstack
7.5 High All Bootstrap Blocks Plugin all-bootstrap-blocks Local File Inclusion ≤ 1.3.19 Fixed in 1.3.20 CVE-2024-53824 Patchstack
7.5 High WP Mailster Plugin wp-mailster Broken Access Control No login needed ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53805 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.5.1 CVE-2024-9872 Wordfence
6.1 Medium Clickbank WordPress Plugin (Storefront) Plugin clickbank-storefront Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.7 CVE-2024-11336 Wordfence
9.3 Critical FAT Services Booking Plugin fat-services-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 5.6 CVE-2024-54221 Patchstack
6.4 Medium Listdom – Business Directory and Classified Ads Listings Plugin listdom Cross-Site Scripting Business Directory and Classified Ads Listings WordPress Plugin <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode Parameter ≤ 3.7.0 CVE-2024-11854 Wordfence
8.1 High Pie Register - Social Sites Login (Add on) Plugin Authentication Bypass User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login <= 1.7.9 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 1.7.9 CVE-2024-11293 Wordfence
4.3 Medium Dollie Hub – Build Your Own WordPress Cloud Platform Plugin Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure ≤ 6.2.0 CVE-2024-12099 Wordfence
6.4 Medium WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout Plugin gs-pinterest-portfolio Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.8 CVE-2024-11453 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget ≤ 2.16.2 CVE-2024-10484 Wordfence
7.1 High Open edX LMS Plugin edunext-openedx-integrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.1 CVE-2024-52452 Patchstack
5.9 Medium What Would Seth Godin Do Plugin what-would-seth-godin-do Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-51900 Patchstack
7.1 High Library Bookshelves Plugin library-bookshelves Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.8 Fixed in 5.9 CVE-2024-52453 Patchstack
7.1 High GoQSmile Plugin goqsmile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52455 Patchstack
7.1 High GoQMieruca Plugin goqmieruca Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2024-52454 Patchstack
7.1 High Youneeq Recommendations Plugin youneeq-panel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.7 CVE-2024-52457 Patchstack
7.1 High Awesome Studio Plugin awesome-studio Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.4 CVE-2024-52456 Patchstack
7.1 High Chameleoni Jobs Plugin chameleon-jobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-52459 Patchstack
7.1 High TM Islamic Helper Plugin tm-islamic-helper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52458 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only