WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 12,851–12,900 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 258 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium AwesomePress Plugin awesomepress Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2024-51616 Patchstack
6.5 Medium Custom Admin Menu Plugin custom-admin-menu Cross-Site Scripting ≤ 1.0.0 CVE-2024-51618 Patchstack
6.5 Medium WP EASY RECIPE Plugin wp-easy-recipe Cross-Site Scripting ≤ 1.6 CVE-2024-51622 Patchstack
6.5 Medium Audio Comparison Lite Plugin audio-comparison-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.4 Fixed in 3.5 CVE-2024-51627 Patchstack
6.5 Medium EzyOnlineBookings Online Booking System Widget Plugin ezyonlinebookings-online-booking-system Cross-Site Scripting ≤ 1.3 CVE-2024-51628 Patchstack
6.5 Medium Header Footer Composer for Elementor Plugin header-footer-composer Cross-Site Scripting ≤ 1.0.4 CVE-2024-51629 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-51662 Patchstack
5.9 Medium Bricksable for Bricks Builder Plugin bricksable Cross-Site Scripting ≤ 1.6.59 Fixed in 1.6.60 CVE-2024-51663 Patchstack
5.9 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.25 Fixed in 2.0.26 CVE-2024-51664 Patchstack
5.9 Medium MyCurator Content Curation Plugin mycurator Cross-Site Scripting ≤ 3.78 Fixed in 3.79 CVE-2024-51668 Patchstack
5.9 Medium JS Help Desk Plugin js-support-ticket Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-51670 Patchstack
6.5 Medium HT Politic Plugin wp-politic Cross-Site Scripting ≤ 2.4.4 Fixed in 2.4.5 CVE-2024-51673 Patchstack
6.5 Medium Sastra Essential Addons for Elementor Plugin sastra-essential-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51674 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-51675 Patchstack
6.5 Medium Delisho Plugin dr-widgets-blocks Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-51676 Patchstack
6.1 Medium SysBasics Customize My Account for WooCommerce Plugin customize-my-account-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via tab Parameter No login needed ≤ 2.7.29 CVE-2024-10837 Wordfence
4.3 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 1.2.4 CVE-2024-10352 Wordfence
6.5 Medium Realty by BestWebSoft Plugin realty Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-51786 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.3 Fixed in 6.4.4 CVE-2024-51787 Patchstack
4.4 Medium Responsive Filterable Portfolio Plugin responsive-filterable-portfolio Server-Side Request Forgery ≤ 1.0.22 Fixed in 1.0.23 CVE-2024-51785 Patchstack
6.1 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable Cross-Site Scripting Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.3 - Reflected Cross-Site Scripting No login needed ≤ 1.8.3 CVE-2024-10876 Wordfence
4.3 Medium Attesa Extra Plugin attesa-extra Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.4.2 CVE-2024-10688 Wordfence
4.9 Medium Poll Maker Plugin poll-maker SQL Injection Authenticated (Administrator+) Time-Based SQL Injection ≤ 5.4.6 CVE-2024-9874 Wordfence
6.1 Medium Contact Form 7 - PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on <= 2.3.1 - Reflected Cross-Site Scripting No login needed ≤ 2.3.1 CVE-2024-10683 Wordfence
5.3 Medium Quform - WordPress Form Builder Plugin Information Disclosure WordPress Form Builder <= 2.20.0 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.20.0 CVE-2024-8756 Wordfence
4.3 Medium Content Slider Block – Create fully functional slider with Gutenberg block Plugin content-slider-block Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure ≤ 3.1.5 CVE-2024-10667 Wordfence
6.4 Medium Code Embed Plugin simple-embed-code Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 2.5 CVE-2024-10814 Wordfence
4.3 Medium Countdown Timer block – Display the event's date into a timer. Plugin Information Disclosure Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.2.4 CVE-2024-10669 Wordfence
4.3 Medium Envo Extra Plugin envo-extra Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.9.3 CVE-2024-10770 Wordfence
4.3 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 3.3 CVE-2024-10693 Wordfence
6.1 Medium Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages Plugin landing-page-cat Cross-Site Scripting Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Site Scripting No login needed ≤ 1.7.6 CVE-2024-9226 Wordfence
6.4 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Cross-Site Scripting Elementor Addons <= 1.2.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.0 CVE-2024-8960 Wordfence
5.3 Medium Cowidgets – Elementor Addons Plugin cowidgets-elementor-addons Information Disclosure Elementor Addons <= 1.2.0 - Authenticated (Contributor+) Post Disclosure No login needed ≤ 1.2.0 CVE-2024-10779 Wordfence
6.5 Medium CE21 Suite Plugin ce21-suite Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Change No login needed ≤ 2.2.0 CVE-2024-10294 Wordfence
5.5 Medium Anih - Creative Agency Theme Cross-Site Scripting Creative Agency WordPress Theme <= 2024 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 2024 CVE-2024-9775 Wordfence
4.3 Medium Debug Tool Plugin debug-tool Broken Access Control Missing Authorization to Information Exposure ≤ 2.2 CVE-2024-10588 Wordfence
6.5 Medium User Meta – User Profile Builder and User management Plugin user-meta Broken Access Control User Profile Builder and User management plugin <= 3.1.1 - Insecure Direct Object Reference to Sensitive Information Exposure ≤ 3.1.1 CVE-2024-9262 Wordfence
6.4 Medium Lenxel Core for Lenxel(LNX) LMS Plugin lenxel-core Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.3 CVE-2024-9270 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.6.45 CVE-2024-10325 Wordfence
6.4 Medium myCred Plugin mycred Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode ≤ 2.7.4 CVE-2024-10187 Wordfence
6.4 Medium Easy SVG Support Plugin easy-svg Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.7 CVE-2024-10269 Wordfence
6.4 Medium Simple Shortcode for Google Maps Plugin simple-google-maps-short-code Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.4 CVE-2024-10621 Wordfence
4.8 Medium Safe SVG Plugin safe-svg Cross-Site Scripting Author+ SVG Sanitisation Bypass < 2.2.6 Fixed in 2.2.6 CVE-2024-8378 WPScan
4.3 Medium Jetpack Plugin jetpack Broken Access Control Subscriber+ Arbitrary Feedback Access 13.9 – < 13.9.1, 13.8 – < 13.8.2, 13.7 – < 13.7.1, … Fixed in 13.9.1 CVE-2024-9926 WPScan
6.4 Medium Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.18 - Authenticated (Contributor+) Stored Cross-Site Scripting via Blog Widget ≤ 3.15.18 CVE-2024-8442 Wordfence
4.8 Medium WP Booking Calendar Plugin Cross-Site Scripting Admin+ Stored XSS < 10.6.3 Fixed in 10.6.3 CVE-2024-10027 WPScan
6.4 Medium Event Post Plugin event-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via events_cal Shortcode ≤ 5.9.6 CVE-2024-10186 Wordfence
6.4 Medium Pricing Tables WordPress Plugin – Easy Pricing Tables Plugin easy-pricing-tables Cross-Site Scripting Easy Pricing Tables <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fontFamily Attribute ≤ 3.2.6 CVE-2024-8323 Wordfence
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
6.4 Medium MapPress Maps Plugin mappress-google-maps-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Block ≤ 2.94.1 CVE-2024-10715 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only