WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,151–13,200 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 264 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WordPress User Extra Fields Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 16.6 CVE-2024-10800 Wordfence
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Deletion No login needed ≤ 2.1.7 CVE-2024-10529 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Assistant Modification No login needed ≤ 2.1.8 CVE-2024-11143 Wordfence
6.1 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.7 CVE-2024-10684 Wordfence
5.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Update No login needed ≤ 2.1.7 CVE-2024-10531 Wordfence
4.3 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Broken Access Control Missing Authorization to Authenticated (Subscriber+) Assistant Addition ≤ 2.1.7 CVE-2024-10530 Wordfence
4.3 Medium WPForms – Easy Form Builder Plugin wpforms-lite Cross-Site Request Forgery Easy Form Builder for WordPress <= 1.9.1.6 - Cross-Site Request Forgery (CSRF) to Plugin's Log Deletion No login needed ≤ 1.9.1.6 CVE-2024-10593 Wordfence
6.5 Medium CRM 2go Plugin crm2go Cross-Site Scripting ≤ 1.0 CVE-2024-52350 Patchstack
6.5 Medium BU Slideshow Plugin bu-slideshow Cross-Site Scripting ≤ 2.3.10 CVE-2024-52351 Patchstack
6.5 Medium Postcasa Shortcode Plugin postcasa Cross-Site Scripting ≤ 1.0 CVE-2024-52352 Patchstack
6.5 Medium Christian Science Bible Lesson Subjects Plugin christian-science-bible-lesson-subjects Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-52353 Patchstack
6.5 Medium Web Stories Widgets For Elementor Plugin shortcodes-for-amp-web-stories-and-elementor-widget Cross-Site Scripting ≤ 1.1 Fixed in 1.1.1 CVE-2024-52354 Patchstack
6.5 Medium OSM Plugin osm Cross-Site Scripting OpenStreetMap plugin <= 6.1.2 - Cross Site Scripting (XSS) ≤ 6.1.2 Fixed in 6.1.3 CVE-2024-52355 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-52356 Patchstack
6.5 Medium LIQUID BLOCKS Plugin liquid-blocks Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-52357 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
8.5 High L Squared Hub WP Plugin l-squared-hub-wp-virtual-device SQL Injection ≤ 1.0 CVE-2024-51820 Patchstack
8.5 High WP Contest Plugin wp-contest SQL Injection ≤ 1.0.0 CVE-2024-51837 Patchstack
8.5 High Horsemanager Plugin fruitcake-horsemanager SQL Injection ≤ 1.3 CVE-2024-51843 Patchstack
8.5 High Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection ≤ 1.0.2 CVE-2024-51845 Patchstack
8.5 High Gboy Custom Google Map Plugin gboy-custom-google-map SQL Injection ≤ 1.2 CVE-2024-51882 Patchstack
10.0 Critical The Novel Design Store Directory Plugin noveldesign-store-directory Arbitrary File Upload No login needed ≤ 4.3.0 CVE-2024-51788 Patchstack
10.0 Critical Image Classify Plugin image-classify Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-51789 Patchstack
10.0 Critical HB AUDIO GALLERY Plugin hb-audio-gallery Arbitrary File Upload No login needed ≤ 3.0 CVE-2024-51790 Patchstack
10.0 Critical Forms Plugin forms-by-made-it Arbitrary File Upload No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-51791 Patchstack
10.0 Critical Audio Record Plugin audio-record Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-51792 Patchstack
10.0 Critical RepairBuddy Plugin computer-repair-shop Arbitrary File Upload No login needed ≤ 3.8115 Fixed in 3.8116 CVE-2024-51793 Patchstack
6.5 Medium MasterBip para Elementor Plugin masterbip-for-elementor Cross-Site Scripting ≤ 1.6.3 CVE-2024-51571 Patchstack
6.5 Medium LH QR Codes Plugin lh-qr-codes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.06 CVE-2024-51572 Patchstack
6.5 Medium ML Responsive Audio player with playlist Shortcode Plugin mlr-audio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2 CVE-2024-51573 Patchstack
6.5 Medium Simple Goods Plugin simple-goods Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.3 CVE-2024-51574 Patchstack
6.5 Medium Extender All In One For Elementor Plugin extender-all-in-one-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.3 CVE-2024-51575 Patchstack
6.5 Medium AMP Img Shortcode Plugin amp-img-shortcode Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.1 CVE-2024-51576 Patchstack
6.5 Medium bpmn.io Plugin bpmnio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2024-51577 Patchstack
6.5 Medium 3D Presentation Plugin 3d-presentation Cross-Site Scripting ≤ 1.0 CVE-2024-51578 Patchstack
6.5 Medium Clever Addons for Elementor Plugin cafe-lite Cross-Site Scripting ≤ 2.2.1 CVE-2024-51580 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-51581 Patchstack
6.5 Medium Kento Ads Rotator Plugin kento-ads-rotator Cross-Site Scripting ≤ 1.3 CVE-2024-51583 Patchstack
6.5 Medium Marquee Elementor with Posts Plugin marquee-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2024-51584 Patchstack
6.5 Medium Sales Page Addon – Elementor & Beaver Builder Plugin sales-page-addon Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.4.5 CVE-2024-51585 Patchstack
6.5 Medium Elementary Addons Plugin elementary-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.4 CVE-2024-51586 Patchstack
6.5 Medium Definitive Addons for Elementor Plugin definitive-addons-for-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.5.16 CVE-2024-51587 Patchstack
6.5 Medium Super Addons for Elementor Plugin super-addons-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2024-51588 Patchstack
6.5 Medium Bigmart Elements Plugin bigmart-elements Cross-Site Scripting ≤ 1.0.3 CVE-2024-51589 Patchstack
6.5 Medium Hoo Addons for Elementor Plugin hoo-addons-for-elementor Cross-Site Scripting ≤ 1.0.6 CVE-2024-51590 Patchstack
6.5 Medium Slicko Plugin slicko-for-elementor Cross-Site Scripting ≤ 1.2.0 CVE-2024-51591 Patchstack
6.5 Medium Meta Store Elements Plugin meta-store-elements Cross-Site Scripting ≤ 1.0.9 CVE-2024-51592 Patchstack
6.5 Medium Курс валют UAH Plugin ukrainian-currency Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0 CVE-2024-51593 Patchstack
6.5 Medium Gmap Point List Plugin gmap-point-list Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.2 CVE-2024-51594 Patchstack
6.5 Medium SKSDEV Toolkit Plugin sksdev-toolkit Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2024-51595 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only