WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 12,901–12,950 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 259 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Broken Access Control All In One Form Integration including DB for Elementor <= 2.9.9.9 - Missing Authorization No login needed ≤ 2.9.9.9 CVE-2024-6626 Wordfence
4.3 Medium Tumult Hype Animations Plugin tumult-hype-animations Broken Access Control Missing Authorization ≤ 1.9.14 CVE-2024-10543 Wordfence
5.3 Medium Video Gallery for WooCommerce Plugin video-wc-gallery Broken Access Control Missing Authorization to Unauthenticated Limited File Deletion No login needed ≤ 1.31 CVE-2024-10535 Wordfence
6.1 Medium Wp-ImageZoom Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1.0 CVE-2024-9934 WPScan
4.8 Medium WP ULike Plugin wp-ulike Cross-Site Scripting Admin+ Stored XSS via Widgets < 4.7.5 Fixed in 4.7.5 CVE-2024-7879 WPScan
6.1 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Cross-Site Scripting Drag & Drop Contact Form Builder for WordPress <= 1.9.244 - Reflected Cross-Site Scripting via URL No login needed ≤ 1.9.244 CVE-2024-10647 Wordfence
4.3 Medium Contact Form 7 – Dynamic Text Extension Plugin contact-form-7-dynamic-text-extension Information Disclosure Dynamic Text Extension <= 4.5 - Information Disclosure via Shortcode ≤ 4.5 CVE-2024-10084 Wordfence
4.3 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 1.4.6 CVE-2024-10329 Wordfence
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget ≤ 5.10.2 CVE-2024-9867 Wordfence
6.5 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.2 CVE-2024-9657 Wordfence
6.4 Medium XT Floating Cart for WooCommerce Plugin woo-floating-cart-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.8.2 CVE-2024-9178 Wordfence
4.3 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Information Disclosure FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Template ≤ 1.4.6 CVE-2024-10319 Wordfence
4.4 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.8.30 CVE-2024-9878 Wordfence
4.3 Medium Zotpress Plugin zotpress Broken Access Control Missing Authorization ≤ 7.3.12 CVE-2024-7429 Wordfence
6.1 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 3.5.0 CVE-2024-9667 Wordfence
6.4 Medium Basticom Framework Plugin basticom-framework Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.5.0 CVE-2024-9443 Wordfence
4.8 Medium Pods Plugin pods Cross-Site Scripting Admin+ Stored XSS < 3.2.7.1 Fixed in 3.2.7.1 CVE-2024-9883 WPScan
4.1 Medium Post From Frontend Plugin Cross-Site Request Forgery Post Deletion via CSRF ≤ 1.0.0 CVE-2024-9689 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7877 WPScan
4.8 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Cross-Site Scripting Admin+ Stored XSS < 1.6.7.55 Fixed in 1.6.7.55 CVE-2024-7876 WPScan
4.8 Medium Table of Contents Plus Plugin table-of-contents-plus Cross-Site Scripting Editor+ Stored XSS ≤ 2408 CVE-2024-5578 WPScan
6.4 Medium Shortcodes Blocks Creator Ultimate Plugin ultimate-shortcodes-creator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3 CVE-2024-10340 Wordfence
6.5 Medium Knowledge Base Plugin knowledgebase Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-51677 Patchstack
6.5 Medium Elo Rating Shortcode Plugin elo-rating-shortcode Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51678 Patchstack
6.5 Medium Cresta Addons for Elementor Plugin cresta-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-51680 Patchstack
6.5 Medium WP Pocket URLs Plugin wp-pocket-urls Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-51681 Patchstack
6.5 Medium HT Builder – WordPress Theme Builder for Elementor Plugin ht-builder Cross-Site Scripting WordPress Theme Builder for Elementor plugin <= 1.3.0 - Stored Cross Site Scripting (XSS) ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-51682 Patchstack
6.5 Medium Custom post type templates for Elementor Plugin custom-post-type-templates-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.10.1 Fixed in 1.1.12 CVE-2024-51683 Patchstack
5.9 Medium Accordion title for Elementor Plugin accordion-title-for-elementor Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-51685 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.2.1 Fixed in 1.2.3 CVE-2024-51665 Patchstack
6.1 Medium BBP Core – Expand bbPress powered forums with useful features Plugin bbp-core Cross-Site Scripting Expand bbPress powered forums with useful features <= 1.2.5 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 1.2.5 CVE-2024-9896 Wordfence
5.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.10.1 CVE-2024-9868 Wordfence
6.1 Medium ReCaptcha Integration Plugin wp-recaptcha-integration Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-8739 Wordfence
5.3 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.16 - Authenticated (Subscriber+) SQL Injection ≤ 1.1.16 CVE-2024-10540 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
6.5 Medium User Rights Access Manager Plugin user-rights-access-manager Broken Access Control ≤ 1.1.2 CVE-2024-37209 Patchstack
6.5 Medium Htaccess File Editor Plugin htaccess-file-editor Broken Access Control ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-49256 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control ≤ 3.12.3 Fixed in 3.12.4 CVE-2024-48045 Patchstack
5.4 Medium ShortPixel Image Optimizer Plugin shortpixel-image-optimiser Broken Access Control ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-48044 Patchstack
4.3 Medium CubeWP Plugin cubewp-framework Broken Access Control ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-48039 Patchstack
5.3 Medium Wheel of Life Plugin wheel-of-life Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-47311 Patchstack
5.3 Medium Fluent Support Plugin fluent-support Broken Access Control Broken Access Control on Email Verification No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47302 Patchstack
5.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control No login needed ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-44038 Patchstack
5.4 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Broken Access Control Subscriber+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37250 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin Broken Access Control Contributor+ Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-37249 Patchstack
4.3 Medium Envira Photo Gallery Plugin envira-gallery-lite Cross-Site Request Forgery CSRF leading to notice dismissal ≤ 1.8.7.3 Fixed in 1.8.8 CVE-2024-37095 Patchstack
4.3 Medium Popup box Plugin ays-popup-box Broken Access Control ≤ 4.5.1 Fixed in 4.5.2 CVE-2024-37096 Patchstack
5.3 Medium Ibtana Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder plugin <= 1.2.3.3 - Broken Access Control No login needed ≤ 1.2.3.3 Fixed in 1.2.3.4 CVE-2024-37123 Patchstack
5.3 Medium Uncanny Automator Pro Plugin uncanny-automator-pro Broken Access Control Unauthenticated License Settings Reset No login needed ≤ 5.3.0.0 Fixed in 5.3.0.1 CVE-2024-37119 Patchstack
4.3 Medium Woocommerce Customers Order History Plugin woo-customers-order-history Broken Access Control ≤ 5.2.2 CVE-2024-37201 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only