WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 12,751–12,800 of 17,767 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | SimpleForm Contact Form Submissions | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.0 |
CVE-2024-10884 |
Wordfence | |
| 6.1 Medium | SimpleForm – Contact form made simple | Cross-Site Scripting Contact form made simple <= 2.2.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.2.0 |
CVE-2024-10883 |
Wordfence | |
| 4.3 Medium | Simple Local Avatars | Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Cache Clearing |
≤ 2.7.11 |
CVE-2024-10786 |
Wordfence | |
| 5.3 Medium | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed |
≤ 4.9.7 |
CVE-2024-10861 |
Wordfence | |
| 4.3 Medium | Popularis Extra | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.2.7 |
CVE-2024-10795 |
Wordfence | |
| 5.7 Medium | Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders | Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure |
≤ 6.0.9 |
CVE-2024-8978 |
Wordfence | |
| 6.1 Medium | Hide My WP Ghost – Security & Firewall | Cross-Site Scripting Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL No login needed |
≤ 5.3.01 |
CVE-2024-10825 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.0.7 |
CVE-2024-8961 |
Wordfence | |
| 6.6 Medium | Secure Custom Fields | Remote Code Execution Admin+ Remote Code Execution |
6.3.7 – < 6.3.9, < 6.3.6.3, < 6.3.9 Fixed in 6.3.9 |
CVE-2024-9529 |
WPScan | |
| 5.9 Medium | Jobs | Cross-Site Scripting Contributor+ Stored XSS |
< 2.7.8 Fixed in 2.7.8 |
CVE-2024-10104 |
WPScan | |
| 4.3 Medium | Music Player for Elementor – Audio Player & Podcast Player | Broken Access Control Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Template Import |
≤ 2.4.1 |
CVE-2024-10582 |
Wordfence | |
| 6.1 Medium | Yotpo: Product & Photo Reviews for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.7.9 |
CVE-2024-9356 |
Wordfence | |
| 6.4 Medium | WP AdCenter – Ad Manager & Adsense Ads | Cross-Site Scripting Ad Manager & Adsense Ads <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpadcenter_ad Shortcode |
≤ 2.5.7 |
CVE-2024-10113 |
Wordfence | |
| 6.1 Medium | LearnPress Export Import – WordPress extension for LearnPress | Cross-Site Scripting WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting No login needed |
≤ 4.0.4 |
CVE-2024-9609 |
Wordfence | |
| 4.3 Medium | Tutor LMS Elementor Addons | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation |
≤ 2.1.5 |
CVE-2024-10897 |
Wordfence | |
| 4.9 Medium | WOLF | Path Traversal CSV Limited Path Traversal |
≤ 1.0.8.3 Fixed in 1.0.8.4 |
CVE-2024-52396 |
Patchstack | |
| 5.4 Medium | Simple File List | Cross-Site Scripting Reflected Cross-Site Scripting |
< 6.1.13 Fixed in 6.1.13 |
CVE-2024-10146 |
WPScan | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget |
≤ 1.7.1001 |
CVE-2024-9682 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget |
≤ 1.7.1001 |
CVE-2024-9668 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Template | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget |
≤ 1.7.1001 |
CVE-2024-9059 |
Wordfence | |
| 6.1 Medium | AFI – The Easiest Integration | Cross-Site Scripting The Easiest Integration Plugin <= 1.92.0 - Reflected Cross-Site Scripting No login needed |
≤ 1.92.0 |
CVE-2024-10877 |
Wordfence | |
| 4.3 Medium | Boostify Header Footer Builder for Elementor | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 1.3.6 |
CVE-2024-10794 |
Wordfence | |
| 5.3 Medium | Hash Elements | Broken Access Control Missing Authorization to Unauthenticated Draft Post Title Exposure No login needed |
≤ 1.4.7 |
CVE-2024-10802 |
Wordfence | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed |
≤ 2.1.7 |
CVE-2024-10529 |
Wordfence | |
| 4.3 Medium | Kognetiks Chatbot | Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed |
≤ 2.1.8 |
CVE-2024-11143 |
Wordfence | |
| 6.1 Medium | Kognetiks Chatbot | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.7 |
CVE-2024-10684 |
Wordfence | |
| 5.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Update No login needed |
≤ 2.1.7 |
CVE-2024-10531 |
Wordfence | |
| 4.3 Medium | Kognetiks Chatbot | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Addition |
≤ 2.1.7 |
CVE-2024-10530 |
Wordfence | |
| 4.3 Medium | WPForms – Easy Form Builder | Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed |
≤ 1.9.1.6 |
CVE-2024-10593 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce - Lite | Cross-Site Scripting Lite <= 2.8.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.8.0 |
CVE-2024-10882 |
Wordfence | |
| 6.4 Medium | Aqua SVG Sprite | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 3.0.14 |
CVE-2024-9426 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Import |
≤ 2.2.9 |
CVE-2024-10854 |
Wordfence | |
| 6.1 Medium | AJAX Login and Registration modal popup + inline form | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.24 |
CVE-2024-8874 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Deletion |
≤ 2.2.9 |
CVE-2024-10853 |
Wordfence | |
| 6.5 Medium | Styler for Ninja Forms | Broken Access Control Authenticated (Subscriber+) Arbitrary Option Deletion via deactivate_license |
≤ 3.3.4 |
CVE-2024-10717 |
Wordfence | |
| 6.1 Medium | Razorpay Payment Button for Elementor | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.5 |
CVE-2024-10850 |
Wordfence | |
| 6.1 Medium | WP-Strava | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting No login needed |
≤ 2.12.1 |
CVE-2024-10038 |
Wordfence | |
| 6.1 Medium | Constant Contact Forms by MailMunch | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.2 |
CVE-2024-9614 |
Wordfence | |
| 6.4 Medium | NiceJob | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.7.1 |
CVE-2024-10887 |
Wordfence | |
| 6.1 Medium | Fat Rat Collect | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-10577 |
Wordfence | |
| 6.1 Medium | Razorpay Payment Button | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.4.6 |
CVE-2024-10851 |
Wordfence | |
| 6.4 Medium | Social Proof (Testimonials) Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spslider-block Shortcode |
≤ 2.2.4 |
CVE-2024-8985 |
Wordfence | |
| 5.3 Medium | Hide Links | Arbitrary Shortcode Execution Unauthenticated Shortcode Execution No login needed |
≤ 1.4.2 |
CVE-2024-9578 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Export |
≤ 2.2.9 |
CVE-2024-10852 |
Wordfence | |
| 4.3 Medium | BuddyPress Builder for Elementor – BuddyBuilder | Information Disclosure BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclosure |
≤ 1.7.4 |
CVE-2024-10778 |
Wordfence | |
| 6.4 Medium | JetWidgets For Elementor | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.18 |
CVE-2024-10323 |
Wordfence | |
| 6.4 Medium | Slickstream: Engagement and Conversions | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slick-grid Shortcode |
≤ 1.4.4 |
CVE-2024-10179 |
Wordfence | |
| 5.9 Medium | RSS Feed Widget | Cross-Site Scripting Contributor+ Stored XSS |
< 3.0.0 Fixed in 3.0.0 |
CVE-2024-9836 |
WPScan | |
| 4.8 Medium | RSS Feed Widget | Cross-Site Scripting Reflected XSS |
< 3.0.1 Fixed in 3.0.1 |
CVE-2024-9835 |
WPScan | |
| 5.4 Medium | Admin and Site Enhancements (ASE) | Cross-Site Scripting Authenticated Stored Cross-Site Scripting via SVG |
≤ 7.5.1 |
CVE-2024-10790 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.