WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 1,251–1,300 of 1,456 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode |
≤ 3.2.90 |
CVE-2024-4160 |
Wordfence | |
| 6.4 Medium | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | Cross-Site Scripting Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode |
≤ 2.2.24 |
CVE-2024-5427 |
Wordfence | |
| 6.4 Medium | Simple Like Page | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.5.2 |
CVE-2024-3583 |
Wordfence | |
| 5.4 Medium | Remote Content Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5 |
CVE-2024-2089 |
Wordfence | |
| 6.4 Medium | List categories | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 0.4 |
CVE-2024-4356 |
Wordfence | |
| 6.4 Medium | Login Logout Register Menu | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'llrmloginlogout' Shortcode |
≤ 2.0 |
CVE-2024-3726 |
Wordfence | |
| 6.4 Medium | HUSKY – Products Filter Professional for WooCommerce | Cross-Site Scripting Products Filter Professional for WooCommerce <= 1.3.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3.5.3 |
CVE-2024-5039 |
Wordfence | |
| 6.4 Medium | ND Shortcodes | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 7.5 |
CVE-2024-5220 |
Wordfence | |
| 6.5 Medium | WP Photo Album Plus | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 8.7.00.003 |
CVE-2024-4037 |
Wordfence | |
| 6.4 Medium | WP Go Maps (formerly WP Google Maps) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 9.0.36 |
CVE-2024-3557 |
Wordfence | |
| 6.4 Medium | Videojs HTML5 Player | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via videojs_video Shortcode |
≤ 1.1.11 |
CVE-2024-5205 |
Wordfence | |
| 6.4 Medium | LayerSlider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ls_search_form Shortcode |
7.11.0 |
CVE-2024-4575 |
Wordfence | |
| 6.4 Medium | WordPress + Microsoft Office 365 / Azure AD | LOGIN | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode |
≤ 27.2 |
CVE-2024-4706 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode |
≤ 3.9.1 |
CVE-2024-4043 |
Wordfence | |
| 6.4 Medium | ShareThis Share Buttons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sharethis-inline-buttons Shortcode |
≤ 2.3.0 |
CVE-2024-3648 |
Wordfence | |
| 6.4 Medium | WP DSGVO Tools (GDPR) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.1.32 |
CVE-2024-3201 |
Wordfence | |
| 4.4 Medium | PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.7 |
CVE-2024-3065 |
Wordfence | |
| 5.0 Medium | iframe | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode |
≤ 5.0 |
CVE-2023-6844 |
Wordfence | |
| 6.4 Medium | jQuery T(-) Countdown Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via tminus Shortcode |
≤ 2.3.25 |
CVE-2024-4783 |
Wordfence | |
| 5.4 Medium | Responsive Contact Form Builder & Lead Generation | Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.9.1 |
CVE-2024-4261 |
Wordfence | |
| 8.5 High | MemberPress | Server-Side Request Forgery Authenticated (Contributor+) Blind Server-Side Request Forgery via mepr-user-file Shortcode |
≤ 1.11.29 |
CVE-2024-5031 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting - Authenticated (Contributor+) Stored Cross-Site Scripting via 'siteorigin_widget' Shortcode |
≤ 1.60.0 |
CVE-2024-4362 |
Wordfence | |
| 6.4 Medium | Print-O-Matic | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.1.10 |
CVE-2024-3671 |
Wordfence | |
| 6.4 Medium | WP Font Awesome Share Icons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.1.1 |
CVE-2024-3198 |
Wordfence | |
| 8.8 High | Media Library Assistant | SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 3.15 |
CVE-2024-3518 |
Wordfence | |
| 6.4 Medium | Page Builder by SiteOrigin | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'siteorigin_widget' Shortcode |
≤ 2.29.15 |
CVE-2024-4361 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via su_members Shortcode |
≤ 7.1.5 |
CVE-2024-4553 |
Wordfence | |
| 6.4 Medium | ShopLentor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woolentorsearch Shortcode |
≤ 2.8.8 |
CVE-2024-3345 |
Wordfence | |
| 6.4 Medium | Uber Menu | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes |
≤ 3.8.2 |
CVE-2024-4710 |
Wordfence | |
| 7.5 High | Salient Core | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 2.0.7 |
CVE-2024-3812 |
Wordfence | |
| 6.4 Medium | Salient Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.5.3 |
CVE-2024-3811 |
Wordfence | |
| 8.8 High | Salient Shortcodes | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 1.5.3 |
CVE-2024-3810 |
Wordfence | |
| 6.5 Medium | Remote Content Shortcode | Local File Inclusion |
≤ 1.5 |
CVE-2023-45652 |
Patchstack | |
| 6.5 Medium | WordPress Meta Data and Taxonomies Filter (MDTF) | Arbitrary Shortcode Execution Meta Data and Taxonomies Filter plugin <= 1.3.3.2 - Arbitrary Shortcode Execution No login needed |
≤ 1.3.3.2 Fixed in 1.3.3.3 |
CVE-2024-34434 |
Patchstack | |
| 7.6 High | Shortcodes and extra features for Phlox | Local File Inclusion Unauthenticated Local File Inclusion |
≤ 2.14.0 Fixed in 2.15.0 |
CVE-2023-37888 |
Patchstack | |
| 7.1 High | Shortcodes Ultimate | Path Traversal Arbitrary File Download |
≤ 5.12.6 Fixed in 5.12.7 |
CVE-2023-25050 |
Patchstack | |
| 6.5 Medium | Swift Framework | Cross-Site Scripting Contributor+ Stored XSS via Shortcode |
< 2024.0.0 Fixed in 2024.0.0 |
CVE-2024-2697 |
WPScan | |
| 6.4 Medium | Custom Post Type Attachment | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via pdf_attachment Shortcode |
≤ 3.4.5 |
CVE-2024-4546 |
Wordfence | |
| 8.8 High | All-in-One Video Gallery | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via aiovg_search_form Shortcode |
≤ 3.6.5 |
CVE-2024-4670 |
Wordfence | |
| 6.1 Medium | Shortcodes Ultimate | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 7.1.2 Fixed in 7.1.2 |
CVE-2024-3548 |
WPScan | |
| 6.4 Medium | Jetpack – WP Security, Backup, Speed, & Growth | Cross-Site Scripting WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode |
≤ 13.3.1 |
CVE-2024-4392 |
Wordfence | |
| 6.5 Medium | Simple Basic Contact Form | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 20240502 |
CVE-2024-4144 |
Wordfence | |
| 6.5 Medium | Orders Tracking for WooCommerce | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.2.10 |
CVE-2024-4039 |
Wordfence | |
| 8.8 High | Porto Theme - Functionality | Local File Inclusion Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 3.1.0 |
CVE-2024-3808 |
Wordfence | |
| 6.5 Medium | Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 5.3.1 |
CVE-2024-4038 |
Wordfence | |
| 4.3 Medium | Squelch Tabs and Accordions Shortcodes | Cross-Site Request Forgery No login needed |
≤ 0.4.7 |
CVE-2024-4463 |
Wordfence | |
| 6.4 Medium | Themify Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode |
≤ 2.0.9 |
CVE-2024-4567 |
Wordfence | |
| 6.4 Medium | Mihdan: Yandex Turbo Feed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.6.5.1 |
CVE-2024-4411 |
Wordfence | |
| 6.4 Medium | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter |
≤ 3.7.1 |
CVE-2024-4446 |
Wordfence | |
| 6.4 Medium | Swift Framework | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes |
≤ 2.7.31 |
CVE-2024-3916 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.