WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,201–13,250 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 265 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Business Plugin business Cross-Site Scripting ≤ 1.3 CVE-2024-51596 Patchstack
6.5 Medium ThemeShark Templates & Widgets for Elementor Plugin themeshark-elementor Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-51597 Patchstack
6.5 Medium Selar.co Widget Plugin selar-co-widget Cross-Site Scripting ≤ 1.2 CVE-2024-51598 Patchstack
6.5 Medium Simple Business Manager Plugin simple-business-manager Cross-Site Scripting ≤ 4.6.7.4 CVE-2024-51599 Patchstack
6.5 Medium NMR Strava activities Plugin nmr-strava-activities Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-51603 Patchstack
6.5 Medium Media Modal Plugin media-modal Cross-Site Scripting ≤ 1.0.2 CVE-2024-51604 Patchstack
6.5 Medium Genoo Plugin genoo Cross-Site Scripting ≤ 6.0.10 Fixed in 6.0.13 CVE-2024-51605 Patchstack
8.5 High Blrt WP Embed Plugin blrt-wp-embed SQL Injection ≤ 1.6.9 CVE-2024-51606 Patchstack
8.5 High AmaDiscount Plugin amadiscount SQL Injection ≤ 1.0 CVE-2024-51608 Patchstack
6.5 Medium Emoji Shortcode Plugin emoji-shortcode Cross-Site Scripting ≤ 1.0.0 CVE-2024-51609 Patchstack
6.5 Medium Display Terms Shortcode Plugin display-terms-shortcode Cross-Site Scripting ≤ 1.0.4 CVE-2024-51610 Patchstack
6.5 Medium WP Feature Box Plugin wp-feature-box Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.3 CVE-2024-51611 Patchstack
6.5 Medium Reftagger Shortcode Plugin reftagger-shortcode Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2024-51612 Patchstack
6.5 Medium TradeMe widgets Plugin trademe-widget Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2 CVE-2024-51613 Patchstack
6.5 Medium Aajoda Testimonials Plugin aajoda-testimonials Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.2.2 CVE-2024-51614 Patchstack
6.5 Medium AwesomePress Plugin awesomepress Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2024-51616 Patchstack
6.5 Medium Custom Admin Menu Plugin custom-admin-menu Cross-Site Scripting ≤ 1.0.0 CVE-2024-51618 Patchstack
6.5 Medium WP EASY RECIPE Plugin wp-easy-recipe Cross-Site Scripting ≤ 1.6 CVE-2024-51622 Patchstack
8.5 High WP EIS Plugin wp-eis SQL Injection ≤ 1.3.3 CVE-2024-51623 Patchstack
6.5 Medium Audio Comparison Lite Plugin audio-comparison-lite Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 3.4 Fixed in 3.5 CVE-2024-51627 Patchstack
6.5 Medium EzyOnlineBookings Online Booking System Widget Plugin ezyonlinebookings-online-booking-system Cross-Site Scripting ≤ 1.3 CVE-2024-51628 Patchstack
6.5 Medium Header Footer Composer for Elementor Plugin header-footer-composer Cross-Site Scripting ≤ 1.0.4 CVE-2024-51629 Patchstack
7.1 High Responsive Flickr Gallery Plugin responsive-flickr-gallery Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.1 CVE-2024-51630 Patchstack
7.1 High Featured Posts Scroll Plugin featured-posts-scroll Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.25 CVE-2024-51647 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-51662 Patchstack
5.9 Medium Bricksable for Bricks Builder Plugin bricksable Cross-Site Scripting ≤ 1.6.59 Fixed in 1.6.60 CVE-2024-51663 Patchstack
5.9 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.25 Fixed in 2.0.26 CVE-2024-51664 Patchstack
5.9 Medium MyCurator Content Curation Plugin mycurator Cross-Site Scripting ≤ 3.78 Fixed in 3.79 CVE-2024-51668 Patchstack
5.9 Medium JS Help Desk Plugin js-support-ticket Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-51670 Patchstack
6.5 Medium HT Politic Plugin wp-politic Cross-Site Scripting ≤ 2.4.4 Fixed in 2.4.5 CVE-2024-51673 Patchstack
6.5 Medium Sastra Essential Addons for Elementor Plugin sastra-essential-addons-for-elementor Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.6 CVE-2024-51674 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting ≤ 1.0.7 Fixed in 1.0.8 CVE-2024-51675 Patchstack
6.5 Medium Delisho Plugin dr-widgets-blocks Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-51676 Patchstack
7.1 High CF7 WOW Styler Plugin cf7-styler Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.8 Fixed in 1.6.9 CVE-2024-51689 Patchstack
7.1 High Wp Slide Categorywise Plugin wp-slide-categorywise Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-51690 Patchstack
7.1 High Admin Amplify Plugin wpr-admin-amplify Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-51691 Patchstack
7.1 High Bing Search API Integration Plugin abbs-bing-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.3 CVE-2024-51692 Patchstack
7.1 High Search order by product SKU for WooCommerce Plugin search-order-by-product-sku-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2024-51693 Patchstack
7.1 High Geotagged Media Plugin geotagged-media Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.3.0 CVE-2024-51694 Patchstack
7.1 High Fabrica Synced Pattern Instances Plugin fabrica-reusable-block-instances Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 Fixed in 1.0.9 CVE-2024-51695 Patchstack
7.1 High Content Syndication Toolkit Reader Plugin content-syndication-toolkit-reader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2024-51696 Patchstack
7.1 High Doofinder Plugin doofinder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.4 CVE-2024-51697 Patchstack
7.1 High Master Bar Plugin master-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-51698 Patchstack
7.1 High Buooy Sticky Header Plugin buooy-sticky-header Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5.2 CVE-2024-51699 Patchstack
7.1 High MG Post Contributors Plugin mg-post-contributors Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3. CVE-2024-51701 Patchstack
7.1 High SrcSet Responsive Images Plugin truenorth-srcset Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-51702 Patchstack
7.1 High WP-Basics Plugin wp-basics Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2024-51703 Patchstack
7.1 High imPress Plugin wp-js-impress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.4 CVE-2024-51704 Patchstack
7.1 High WP MMenu Lite Plugin wp-mmenu-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-51705 Patchstack
7.1 High UW Freelancer Plugin uw-freelancer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-51706 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only