WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,401–13,450 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 269 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.7 Medium Simple Membership After Login Redirection Plugin simple-membership-after-login-redirection Open Redirect No login needed ≤ 1.6 Fixed in 1.7 CVE-2024-47354 Patchstack
4.7 Medium EventPrime Plugin eventprime-event-calendar-management Open Redirect No login needed ≤ 4.0.4.5 Fixed in 4.0.4.6 CVE-2024-47648 Patchstack
5.9 Medium WP-Advanced-Search Plugin SQL Injection Unauthenticated SQL Injection No login needed < 3.3.9.2 Fixed in 3.3.9.2 CVE-2024-9796 WPScan
5.9 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection Unauthenticated SQL Injection via lang parameters No login needed ≤ 2.8.2 CVE-2024-9156 WPScan
6.3 Medium UserPlus Plugin userplus Broken Access Control Missing Authorization via Multiple Functions ≤ 2.0 CVE-2024-9520 Wordfence
6.4 Medium Advanced Blocks Pro Plugin advanced-blocks-pro Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.0 CVE-2024-9074 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion ≤ 1.3.0 CVE-2024-9067 Wordfence
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.87 CVE-2024-8477 Wordfence
4.3 Medium Notification for Telegram Plugin notification-for-telegram Broken Access Control Missing Authorization to Authenticated (Subscriber+) Send Telegram Test Message ≤ 3.3.1 CVE-2024-9685 Wordfence
6.1 Medium Easy Social Share Buttons Plugin easy-social-share-buttons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-8729 Wordfence
6.4 Medium Curator.io: Show all your social media posts in a beautiful feed. Plugin curatorio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute ≤ 1.9.1 CVE-2024-9057 Wordfence
6.1 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.15 CVE-2024-9377 Wordfence
5.3 Medium WP Helper Premium Plugin wp-helper-lite Broken Access Control Missing Authorization in whp_smtp_send_mail_test No login needed ≤ 4.6.1 CVE-2024-9065 Wordfence
6.4 Medium Elementor Inline SVG Plugin inline-svg-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.0 CVE-2024-9064 Wordfence
6.4 Medium Marketing and SEO Booster Plugin marketing-and-seo-booster Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.9.10 CVE-2024-9066 Wordfence
6.4 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Cross-Site Scripting BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode ≤ 1.3.0 CVE-2024-8987 Wordfence
6.1 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.8 CVE-2024-9205 Wordfence
5.3 Medium QA Analytics Plugin qa-heatmap-analytics Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 4.1.1.1 CVE-2024-8513 Wordfence
6.4 Medium GDPR-Extensions-com – Consent Manager Plugin gdpr-consent-manager Cross-Site Scripting Consent Manager <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.0 CVE-2024-9072 Wordfence
6.4 Medium WP Builder Plugin cssjockey-add-ons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.0.7 CVE-2024-9457 Wordfence
6.4 Medium Embed PDF Viewer Plugin embed-pdf-viewer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via height and width Parameters ≤ 2.4.4 CVE-2024-9451 Wordfence
6.4 Medium Auto iFrame Plugin auto-iframe Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via tag Parameter ≤ 1.7 CVE-2024-9449 Wordfence
4.8 Medium Photo Gallery by 10Web Plugin photo-gallery Cross-Site Scripting Admin+ Stored XSS < 1.8.28 Fixed in 1.8.28 CVE-2024-5968 WPScan
6.4 Medium CMSMasters Content Composer Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.8.8 CVE-2024-7963 Wordfence
4.3 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Broken Access Control Missing Authorization to Authenticated (Subscriber+) Private Gallery Title Disclosure ≤ 3.2.21 CVE-2024-8431 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget ≤ 1.3.986 CVE-2024-8482 Wordfence
6.1 Medium BuddyPress Docs Plugin buddypress-docs Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.3 CVE-2024-9207 Wordfence
4.4 Medium Survey Maker – Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms Plugin survey-maker Cross-Site Scripting Customer Satisfaction Questionnaire, Chat Survey, Calculation Form, Payment Forms <= 4.9.7 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.9.5 CVE-2024-8488 Wordfence
6.4 Medium Easy Mega Menu Plugin for WordPress – ThemeHunk Plugin themehunk-megamenu-plus Cross-Site Scripting ThemeHunk <= 1.1.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-8433 Wordfence
6.1 Medium WooCommerce Multilingual & Multicurrency with WPML Plugin woocommerce-multilingual Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.3.7 CVE-2024-8629 Wordfence
5.3 Medium Limit Login Attempts (Spam Protection) Plugin wp-limit-failed-login-attempts Other IP Address Spoofing to Protection Mechanism Bypass No login needed ≤ 5.3 CVE-2022-4534 Wordfence
6.4 Medium Image Optimizer, Resizer and CDN – Sirv Plugin sirv Cross-Site Scripting Sirv <= 7.2.9 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 7.2.9 CVE-2024-8964 Wordfence
5.4 Medium Relevanssi Plugin relevanssi Cross-Site Scripting Contributor+ Stored XSS < 4.23.1 Fixed in 4.23.1 CVE-2024-9021 WPScan
4.8 Medium Custom Twitter Feeds Plugin custom-twitter-feeds Cross-Site Scripting Admin+ Stored XSS < 2.2.3 Fixed in 2.2.3 CVE-2024-8983 WPScan
6.4 Medium Bridge Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.0 CVE-2024-9292 Wordfence
5.3 Medium uListing Plugin ulisting Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-47344 Patchstack
6.5 Medium WP-WebAuthn Plugin wp-webauthn Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-47650 Patchstack
5.1 Medium Full frame Plugin full-frame Cross-Site Scripting ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-44010 Patchstack
6.5 Medium Review & testimonial widgets Plugin trustmary Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.10 CVE-2024-44022 Patchstack
6.5 Medium Medical Addon for Elementor Plugin medical-addon-for-elementor Cross-Site Scripting ≤ 1.6.4 CVE-2024-44024 Patchstack
6.5 Medium NiceJob Plugin nicejob Cross-Site Scripting ≤ 3.6.5 Fixed in 3.6.5 CVE-2024-44025 Patchstack
6.5 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.2 CVE-2024-44026 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-44027 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-44032 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.5.7 Fixed in 1.5.8 CVE-2024-44033 Patchstack
6.5 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-44035 Patchstack
5.9 Medium Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting ≤ 2.5.0 CVE-2024-44036 Patchstack
5.9 Medium Multipurpose Ticket Booking Manager Plugin bus-booking-manager Cross-Site Scripting ≤ 4.2.2 Fixed in 4.2.3 CVE-2024-44037 Patchstack
5.9 Medium WP Travel Plugin wp-travel Cross-Site Scripting ≤ 9.3.1 Fixed in 9.4.0 CVE-2024-44039 Patchstack
5.9 Medium ShiftController Employee Shift Scheduling Plugin shiftcontroller Cross-Site Scripting ≤ 4.9.64 Fixed in 4.9.65 CVE-2024-44040 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only