WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 12,801–12,850 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 257 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.6 High Ni WooCommerce Cost Of Goods Plugin ni-woocommerce-cost-of-goods SQL Injection ≤ 3.2.8 Fixed in 3.2.9 CVE-2024-53783 Patchstack
5.3 Medium Content Audit Exporter Plugin content-audit-exporter Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-53768 Patchstack
8.1 High Cryptocurrency Widgets For Elementor Plugin cryptocurrency-widgets-for-elementor Local File Inclusion No login needed ≤ 1.6.4 Fixed in 1.6.5 CVE-2024-53739 Patchstack
4.4 Medium Asset CleanUp: Page Speed Booster Plugin wp-asset-clean-up Server-Side Request Forgery ≤ 1.3.9.8 Fixed in 1.3.9.9 CVE-2024-53738 Patchstack
6.5 Medium Fintelligence Calculator Plugin fintelligence-calculator Cross-Site Scripting ≤ 1.0.3 CVE-2024-53731 Patchstack
7.1 High Footer Flyout Widget Plugin footer-flyout-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-53732 Patchstack
7.1 High Fence URL Plugin fence-url Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 CVE-2024-53733 Patchstack
7.1 High Idealien Category Enhancements Plugin idealien-category-enhancements Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53734 Patchstack
7.1 High Custom Shortcode Sidebars Plugin custom-shortcode-sidebars Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-53736 Patchstack
7.1 High Block Editor Bootstrap Blocks Plugin block-editor-bootstrap-blocks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.1 Fixed in 6.6.2 CVE-2024-11402 Patchstack
6.5 Medium WP Mailster Plugin wp-mailster Cross-Site Scripting ≤ 1.8.16.0 Fixed in 1.8.17.0 CVE-2024-53737 Patchstack
9.3 Critical Express Payments Module Plugin express-pay SQL Injection No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-52474 Patchstack
8.5 High Distance Based Shipping Calculator Plugin distance-based-shipping-calculator SQL Injection ≤ 2.0.23 Fixed in 2.0.24 CVE-2024-52495 Patchstack
10.0 Critical Pathomation Plugin pathomation Arbitrary File Upload No login needed ≤ 2.5.1 CVE-2024-52490 Patchstack
7.5 High Absolute Addons For Elementor Plugin absolute-addons Local File Inclusion ≤ 1.0.14 CVE-2024-52496 Patchstack
7.5 High Shopready Plugin shopready-elementor-addon Local File Inclusion ≤ 3.6 CVE-2024-52497 Patchstack
7.5 High SP Blog Designer Plugin sp-blog-designer Local File Inclusion ≤ 1.0.0 CVE-2024-52498 Patchstack
7.5 High Pricing table addon for elementor Plugin pricing-table-addon-for-elementor Local File Inclusion ≤ 1.0.0 CVE-2024-52499 Patchstack
7.5 High Office Locator Plugin office-locator Local File Inclusion ≤ 1.3.0 CVE-2024-52501 Patchstack
7.5 High Jobify Theme jobify Path Traversal Unauthenticated Arbitrary File Read No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52481 Patchstack
7.2 High Rank Math SEO Plugin seo-by-rank-math Remote Code Execution Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) ≤ 1.0.231 Fixed in 1.0.232 CVE-2024-11620 Patchstack
9.8 Critical Wawp Plugin automation-web-platform Privilege Escalation Account Takeover No login needed ≤ 3.0.18 Fixed in 3.0.18 CVE-2024-52475 Patchstack
9.9 Critical Widget Options – The #1 WordPress Widget & Block Control Plugin widget-options Remote Code Execution The #1 WordPress Widget & Block Control Plugin <= 4.0.7 - Authenticated (Contributor+) Remote Code Execution ≤ 4.0.7 CVE-2024-8672 Wordfence
4.3 Medium WordPress Contact Forms by Cimatti Plugin contact-forms Cross-Site Request Forgery Cross-Site Request Forgery via process_bulk_action Function No login needed ≤ 1.9.2 CVE-2024-10521 Wordfence
5.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unauthorized Form Submission No login needed ≤ 7.8.5 CVE-2024-10580 Wordfence
4.3 Medium Hustle – Email Marketing, Lead Generation, Optins, Popups Plugin wordpress-popup Broken Access Control Email Marketing, Lead Generation, Optins, Popups <= 7.8.5 - Missing Authorization to Unpublished Form Exposure ≤ 7.8.5 CVE-2024-10579 Wordfence
6.4 Medium Spotify Play Button Plugin spotify-play-button-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode ≤ 2.11 CVE-2024-11192 Wordfence
6.4 Medium Support SVG – Upload svg files in wordpress without hassle Plugin support-svg Cross-Site Scripting Upload svg files in wordpress without hassle <= 1.1.0 - Authenticated (Author+) Stored Cross-site Scripting via SVG File Upload ≤ 1.1.0 CVE-2024-11091 Wordfence
6.4 Medium Tribute Testimonials – WordPress Testimonial Grid/Slider Plugin tribute-testimonial-gridslider Cross-Site Scripting WordPress Testimonial Grid/Slider <= 1.0.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-10886 Wordfence
6.6 Medium GEO My Plugin Arbitrary File Upload Admin+ Arbitrary File Upload 4.0 – < 4.5, < 3.1 Fixed in 4.5 CVE-2024-9422 WPScan
6.1 Medium Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels Plugin wpfunnels Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.5 CVE-2024-10792 Wordfence
6.1 Medium Theater Plugin theatre Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.18.6.2 CVE-2024-11371 Wordfence
4.8 Medium CM Table Of Contents – WordPress TOC Plugin Cross-Site Scripting WordPress TOC Plugin < 1.2.4 - Stored XSS via CSRF < 1.2.4 Fixed in 1.2.4 CVE-2024-5029 WPScan
6.4 Medium Dino Game – Embed Google Chrome Dinosaur Game in Plugin dino-game Cross-Site Scripting Embed Google Chrome Dinosaur Game in WordPress <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11388 Wordfence
7.1 High Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Scripting No login needed ≤ 1.0 Fixed in 1.2 CVE-2024-52470 Patchstack
7.1 High Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.37 CVE-2024-52471 Patchstack
7.1 High Weather Atlas Widget Plugin weather-atlas Cross-Site Scripting No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-52472 Patchstack
7.1 High HTML5 Lyrics Karaoke Player Plugin html5-lyrics-karaoke-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4 CVE-2024-52473 Patchstack
8.8 High Banner System Plugin banner-system Privilege Escalation ≤ 1.0.0 CVE-2024-52437 Patchstack
8.8 High de:branding Plugin debranding Privilege Escalation ≤ 1.0.2 CVE-2024-52438 Patchstack
9.8 Critical UserPlus Plugin userplus Privilege Escalation No login needed ≤ 2.0 CVE-2024-52442 Patchstack
8.2 High Post Ideas Plugin post-ideas Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 2 CVE-2024-52451 Patchstack
7.5 High Ultimate Classified Listings Plugin ultimate-classified-listings Local File Inclusion ≤ 1.7 CVE-2024-52448 Patchstack
7.5 High Bootscraper Plugin wp-bootscraper Local File Inclusion No login needed ≤ 2.1.0 Fixed in 4.0.0 CVE-2024-52449 Patchstack
7.5 High nBlocks Plugin nblocks Local File Inclusion ≤ 1.0.2 CVE-2024-52450 Patchstack
9.8 Critical Team Rosters Plugin team-rosters PHP Object Injection No login needed ≤ 4.8.2 CVE-2024-52439 Patchstack
9.8 Critical Xpresslane Fast Checkout Plugin xpresslane-integration-for-woocommerce PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-52440 Patchstack
9.8 Critical Quick Learn Plugin quick-learn PHP Object Injection No login needed ≤ 1.0.1 CVE-2024-52441 Patchstack
9.8 Critical Geolocator Plugin geolocator PHP Object Injection No login needed ≤ 1.1 CVE-2024-52443 Patchstack
8.8 High QRMenu Restaurant QR Menu Lite Plugin qrmenu-lite PHP Object Injection ≤ 1.0.4 CVE-2024-52445 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only