WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 12,901–12,950 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 259 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Alley Elementor Widget Plugin alley-elementor-widget Cross-Site Scripting ≤ 1.0.7 CVE-2024-50521 Patchstack
6.5 Medium Ancient World Linked Data Plugin ancient-world-linked-data-for-wordpress Cross-Site Scripting ≤ 0.2.1 CVE-2024-50520 Patchstack
6.5 Medium Step by Step Plugin step-by-step Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.4.5 CVE-2024-50535 Patchstack
7.1 High WeChat Subscribers Lite Plugin wechat-subscribers-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.6 CVE-2024-50522 Patchstack
6.5 Medium GDReseller Plugin gdreseller Cross-Site Scripting ≤ 1.6 CVE-2024-50536 Patchstack
6.5 Medium Show Visitor IP Address Plugin show-visitor-ip-address Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2 CVE-2024-50538 Patchstack
6.5 Medium Smart Mockups Plugin smart-mockups Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.0 CVE-2024-50537 Patchstack
6.5 Medium Advanced Control Manager for WordPress by ItalyStrap Plugin advanced-control-manager Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.16.0 CVE-2024-50541 Patchstack
6.5 Medium (dp) AddThis Plugin dp-addthis Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-50540 Patchstack
6.5 Medium amazing neo icon font for elementor Plugin amazing-neo-icon-font-for-elementor Cross-Site Scripting ≤ 2.0.1 CVE-2024-50543 Patchstack
6.5 Medium RLM Elementor Widgets Pack Plugin rlm-elementor-widgets-pack Cross-Site Scripting ≤ 1.3.1 Fixed in 1.4.0 CVE-2024-50542 Patchstack
6.5 Medium MyOrderDesk Plugin myorderdesk Cross-Site Scripting ≤ 3.2.6 Fixed in 3.3.0 CVE-2024-50546 Patchstack
6.5 Medium DataMentor Plugin datamentor Cross-Site Scripting ≤ 1.7 CVE-2024-50545 Patchstack
6.5 Medium Themedy Toolbox Plugin themedy-toolbox Cross-Site Scripting ≤ 1.0.16 CVE-2024-50547 Patchstack
6.5 Medium Bonway Static Block Editor Plugin bonway-static-block-editor Cross-Site Scripting ≤ 1.1.0 CVE-2024-50549 Patchstack
6.5 Medium Awesome Progress Bar Plugin awesome-progess-bar Cross-Site Scripting ≤ 1.0.13 Fixed in 1.1.0 CVE-2024-50548 Patchstack
6.5 Medium Hover Video Preview Plugin hover-video-preview Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-50552 Patchstack
6.5 Medium EndomondoWP Plugin endomondowp Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.1 CVE-2024-50551 Patchstack
6.5 Medium Sided Plugin sided Cross-Site Scripting ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-50554 Patchstack
6.5 Medium Classy Addons for Elementor Plugin classy-addons-for-elementor Cross-Site Scripting ≤ 1.2.7 CVE-2024-50553 Patchstack
6.5 Medium Clyp Plugin clyp Cross-Site Scripting ≤ 1.3 CVE-2024-51617 Patchstack
6.5 Medium WM Zoom Plugin wm-zoom Cross-Site Scripting ≤ 1.0 CVE-2024-50556 Patchstack
6.5 Medium Pdf Embedder Fay Plugin pdf-embedder-fay Cross-Site Scripting ≤ 1.10.1 CVE-2024-51795 Patchstack
6.5 Medium Storely Plugin storely Cross-Site Scripting ≤ 14.7 CVE-2024-51794 Patchstack
6.5 Medium Trendy Restaurant Menu Plugin trendy-restaurant-menu Cross-Site Scripting ≤ 1.0.0 CVE-2024-51796 Patchstack
6.5 Medium Surbma | Font Awesome Plugin surbma-font-awesome Cross-Site Scripting ≤ 3.0 Fixed in 3.1 CVE-2024-51798 Patchstack
6.5 Medium Ultimate Accordion Plugin ultimate-accordion Cross-Site Scripting ≤ 1.0 CVE-2024-51797 Patchstack
6.5 Medium Brand my Footer Plugin brand-my-footer Cross-Site Scripting ≤ 1.1 CVE-2024-51801 Patchstack
6.5 Medium Bg Patriarchia BU Plugin bg-patriarchia-bu Cross-Site Scripting ≤ 2.2.3 CVE-2024-51799 Patchstack
6.5 Medium Inline Click To Tweet Plugin inline-click-to-tweet Cross-Site Scripting ≤ 1.0.0 CVE-2024-51803 Patchstack
6.5 Medium Bread & Butter Plugin bread-butter Cross-Site Scripting ≤ 7.4.857 Fixed in 7.5.880 CVE-2024-51802 Patchstack
6.5 Medium yPHPlista Plugin yphplista Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-51805 Patchstack
6.5 Medium Moka Get Posts Shortcode Plugin moka-get-posts Cross-Site Scripting ≤ 1.0 CVE-2024-51804 Patchstack
6.5 Medium Awesome Fitness Testimonials Plugin awesome-fitness-testimonials Cross-Site Scripting ≤ 1.0.1 CVE-2024-51806 Patchstack
6.5 Medium codeSnips Plugin codesnips Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2 CVE-2024-51808 Patchstack
6.5 Medium AgendaPress – Easily Publish Meeting Agendas and Programs on Plugin agendapress Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.8 CVE-2024-51807 Patchstack
6.5 Medium Lewe Bootstrap Visuals Plugin shortcode-bootstrap-visuals Cross-Site Scripting ≤ 3.0.1 CVE-2024-51810 Patchstack
6.5 Medium Keymaster Chord Notation Free Plugin keymaster-chord-notation-free Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-51809 Patchstack
6.5 Medium Pro Addons For Elementor Plugin pro-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-51812 Patchstack
6.5 Medium Popup Image Plugin popup-image Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.1 CVE-2024-51811 Patchstack
6.5 Medium Anant Addons for Elementor Plugin anant-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51813 Patchstack
6.5 Medium Banner System Plugin banner-system Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2024-51816 Patchstack
6.5 Medium 活动链接推广插件 Plugin yr-activity-link Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.4 CVE-2024-51814 Patchstack
6.5 Medium WE – Client Logo Carousel Plugin we-client-logo-carousel Cross-Site Scripting Client Logo Carousel plugin <= 1.4 - Cross Site Scripting (XSS) ≤ 1.4 CVE-2024-51821 Patchstack
6.5 Medium Tigris Flexplatform Plugin tigris-flexplatform Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.2 CVE-2024-51819 Patchstack
6.5 Medium Add Ribbon Shortcode Plugin add-ribbon Cross-Site Scripting ≤ 1.0.1 CVE-2024-51823 Patchstack
6.5 Medium Creative Blocks Plugin creative-blocks Cross-Site Scripting ≤ 1.0.1 CVE-2024-51822 Patchstack
6.5 Medium Alert Me! Plugin alert-me Cross-Site Scripting ≤ 0.4.0 CVE-2024-51825 Patchstack
6.5 Medium Advanced Video Player with Analytics Plugin advanced-video-player-with-analytics Cross-Site Scripting ≤ 1 CVE-2024-51824 Patchstack
6.5 Medium Boombox Shortcode Plugin boombox-shortcode Cross-Site Scripting ≤ 1.0.0 CVE-2024-51827 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only