WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 12,751–12,800 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 256 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High CultBooking Hotel Booking Engine Plugin cultbooking-booking-engine Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2024-53753 Patchstack
5.4 Medium Build App Online Plugin build-app-online Cross-Site Request Forgery No login needed ≤ 1.0.23 CVE-2024-53751 Patchstack
7.1 High Third Party Cookie Eraser Plugin third-party-cookie-eraser Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53755 Patchstack
7.1 High Out Of Stock Badge Plugin out-of-stock-badge Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2024-53754 Patchstack
7.1 High ArCa Payment Gateway Plugin arca-payment-gateway Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.3.1 Fixed in 1.3.4 CVE-2024-53759 Patchstack
7.1 High FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-53762 Patchstack
5.4 Medium WP Revisions Manager Plugin wp-revisions-manager Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2024-53761 Patchstack
7.1 High Custom Post Type to Map Store Plugin cpt-to-map-store Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2024-53769 Patchstack
7.1 High Mins To Read Plugin mins-to-read Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.2 CVE-2024-53765 Patchstack
4.3 Medium DancePress (TRWA) Plugin dancepress-trwa Cross-Site Request Forgery No login needed ≤ 3.1.11 CVE-2024-53775 Patchstack
7.1 High RingCentral Communications Plugin rccp-free Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7.0 CVE-2024-53770 Patchstack
7.1 High Donate Me Plugin donate-me Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.5 CVE-2024-53776 Patchstack
7.1 High Yahoo! WebPlayer Plugin yahoo-media-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.6 CVE-2024-53779 Patchstack
7.1 High Simple Header and Footer Plugin simple-header-and-footer Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-53777 Patchstack
7.1 High SpatialMatch IDX Plugin spatialmatch-free-lifestyle-search Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.9 CVE-2024-53781 Patchstack
7.1 High Load More Posts Plugin load-more-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.0 CVE-2024-53780 Patchstack
7.1 High Photo Video Store Plugin photo-video-store Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 21.07 CVE-2024-53782 Patchstack
7.1 High Advanced What should we write next about Plugin advanced-what-should-we-write-about-next Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2024-53789 Patchstack
4.3 Medium Smart Marketing SMS and Newsletters Forms Plugin smart-marketing-for-wp Broken Access Control ≤ 5.0.4 Fixed in 5.0.5 CVE-2024-53784 Patchstack
8.2 High eDoc Easy Tables Plugin edoc-easy-tables Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.29 CVE-2024-53793 Patchstack
8.5 High Watu Quiz Plugin watu SQL Injection ≤ 3.4.1.2 Fixed in 3.4.1.3 CVE-2024-53792 Patchstack
7.1 High April's Call Posts Plugin aprils-call-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 Fixed in 2.2.0 CVE-2024-53730 Patchstack
7.1 High WooCommerce Ultimate Gift Card Plugin woocommerce-ultimate-gift-card Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.1 Fixed in 2.9.1 CVE-2024-53740 Patchstack
7.7 High WP Project Manager Plugin SQL Injection SQL Injection in WordPress Project Manager Plugin Not stated CVE-2024-12015 tenable
7.1 High Multilevel Referral Affiliate Plugin for WooCommerce Plugin multilevel-referral-plugin-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.27 Fixed in 2.28 CVE-2024-53742 Patchstack
6.5 Medium Countdown Timer for Elementor Plugin countdown-timer-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-53743 Patchstack
6.5 Medium Elementor Image Gallery Plugin skyboot-portfolio-gallery Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-53744 Patchstack
6.5 Medium 소셜 공유 버튼 By 코스모스팜 Plugin cosmosfarm-share-buttons Cross-Site Scripting ≤ 1.9 CVE-2024-53745 Patchstack
6.5 Medium Elementor Button Plus Plugin fd-elementor-button-plus Cross-Site Scripting ≤ 1.3.9 CVE-2024-53746 Patchstack
6.5 Medium Video Player for WPBakery Plugin video-player-for-wpbakery Cross-Site Scripting ≤ 1.0.1 Fixed in 1.0.2 CVE-2024-53747 Patchstack
6.5 Medium WP Mermaid Plugin wp-mermaid Cross-Site Scripting ≤ 1.0.2 CVE-2024-53748 Patchstack
6.5 Medium Post Carousel Slider for Elementor Plugin post-carousel-slider-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-53749 Patchstack
7.1 High PayPal Responder Plugin paypal-responder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53750 Patchstack
6.5 Medium Stripe Donation Plugin bin-stripe-donation Cross-Site Scripting ≤ 1.2.5 CVE-2024-53752 Patchstack
6.5 Medium Vertical Carousel Plugin vertical-carousel-slider Cross-Site Scripting ≤ 1.0.2 CVE-2024-53756 Patchstack
6.5 Medium WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Scripting ≤ 0.3.1 CVE-2024-53757 Patchstack
6.5 Medium WP MathJax Plugin wp-mathjax-plus Cross-Site Scripting ≤ 1.0.1 CVE-2024-53758 Patchstack
6.5 Medium Capitalize My Title Plugin capitalize-my-title Cross-Site Scripting ≤ 0.5.3 CVE-2024-53760 Patchstack
6.5 Medium Best Addons for Elementor Plugin best-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.5 CVE-2024-53763 Patchstack
6.5 Medium Softtemplates For Elementor Plugin softtemplates-for-elementor Cross-Site Scripting ≤ 1.0.8 CVE-2024-53764 Patchstack
6.5 Medium Devnex Addons For Elementor Plugin devnex-addons-for-elementor Cross-Site Scripting ≤ 1.0.9 CVE-2024-53766 Patchstack
6.5 Medium Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting ≤ 1.0.1 CVE-2024-53767 Patchstack
6.5 Medium SimpleSchema Plugin simpleschema-free Cross-Site Scripting ≤ 1.7.6.9 CVE-2024-53771 Patchstack
6.5 Medium Mail Picker Plugin mail-picker Cross-Site Scripting ≤ 1.0.15 Fixed in 1.0.16 CVE-2024-53772 Patchstack
6.5 Medium Znajdź Pracę z Praca.pl Plugin znajdz-prace-z-pracapl Cross-Site Scripting ≤ 2.2.3 CVE-2024-53773 Patchstack
6.5 Medium Sparkle Elementor Kit Plugin sparkle-elementor-kit Cross-Site Scripting ≤ 2.0.9 CVE-2024-53774 Patchstack
7.1 High Essential Breadcrumbs Plugin essential-breadcrumbs Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-53778 Patchstack
6.5 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons plugin <= 1.2.0 - Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2024-53786 Patchstack
6.5 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-53787 Patchstack
5.9 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-53788 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only