WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 13,501–13,550 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Logo Carousel – Clients logo carousel for WP | Cross-Site Scripting Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) |
≤ 1.2 Fixed in 1.3.0 |
CVE-2024-47631 |
Patchstack | |
| 6.5 Medium | DethemeKit For Elementor | Cross-Site Scripting |
≤ 2.1.7 Fixed in 2.1.8 |
CVE-2024-47632 |
Patchstack | |
| 6.5 Medium | Zoho Forms | Cross-Site Scripting |
≤ 4.0 Fixed in 4.0.1 |
CVE-2024-47633 |
Patchstack | |
| 5.4 Medium | TinyPNG | Cross-Site Request Forgery No login needed |
≤ 3.4.3 Fixed in 3.4.4 |
CVE-2024-47635 |
Patchstack | |
| 6.5 Medium | VdoCipher | Cross-Site Scripting |
≤ 1.29 Fixed in 1.30 |
CVE-2024-47639 |
Patchstack | |
| 6.5 Medium | Keap Official Opt-in Forms | Cross-Site Scripting |
≤ 2.0.3 |
CVE-2024-47642 |
Patchstack | |
| 6.5 Medium | Include Fussball.de Widgets | Cross-Site Scripting |
≤ 4.0.0 |
CVE-2024-47643 |
Patchstack | |
| 4.7 Medium | Payflex Payment Gateway | Open Redirect No login needed |
≤ 2.6.1 Fixed in 2.6.2 |
CVE-2024-47646 |
Patchstack | |
| 5.9 Medium | Helpie FAQ | Cross-Site Scripting Helpie WordPress FAQ Accordion plugin plugin <= 1.27 - Cross Site Scripting (XSS) |
≤ 1.27 Fixed in 1.28 |
CVE-2024-47647 |
Patchstack | |
| 4.3 Medium | Salon booking system | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 10.9 Fixed in 10.9.1 |
CVE-2024-47316 |
Patchstack | |
| 6.6 Medium | Cities Shipping Zones for WooCommerce | Local File Inclusion |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2024-47309 |
Patchstack | |
| 6.5 Medium | Rank Math SEO – AI SEO Tools to Dominate SEO Rankings | Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete No login needed |
≤ 1.0.228 |
CVE-2024-9161 |
Wordfence | |
| 4.9 Medium | CSS JS Files | Path Traversal Directory Traversal to File Read |
≤ 1.5.0 Fixed in 1.5.1 |
CVE-2024-9146 |
Patchstack | |
| 6.1 Medium | Hash Form - Drag & Drop Form Builder | Arbitrary File Upload Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload No login needed |
≤ 1.1.9 |
CVE-2024-9417 |
Wordfence | |
| 6.4 Medium | Shortcodes and extra features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets |
≤ 2.16.3 |
CVE-2024-8486 |
Wordfence | |
| 6.8 Medium | Bit File Manager – 100% Free & Open Source File Manager and Code Editor | Arbitrary File Upload Authenticated (Subscriber+) Limited JavaScript File Upload |
≤ 6.5.7 |
CVE-2024-8743 |
Wordfence | |
| 4.9 Medium | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | Cross-Site Scripting Authenticated (Form Manager+) Stored Cross-Site Scripting |
≤ 5.1.19 |
CVE-2024-9528 |
Wordfence | |
| 6.1 Medium | Themify Builder | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.6.2 |
CVE-2024-9385 |
Wordfence | |
| 6.4 Medium | WP Cleanup and Basic Functions | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.2.1 |
CVE-2024-9455 |
Wordfence | |
| 4.7 Medium | Checkout Field Editor (Checkout Manager) for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed |
≤ 2.0.3 |
CVE-2024-8499 |
Wordfence | |
| 6.4 Medium | Re:WP | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.1 |
CVE-2024-9271 |
Wordfence | |
| 6.4 Medium | Easy Demo Importer – A Modern One-Click Demo Import Solution | Cross-Site Scripting A Modern One-Click Demo Import Solution <= 1.1.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.1.2 |
CVE-2024-9071 |
Wordfence | |
| 6.1 Medium | ShiftController Employee Shift Scheduling | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.9.66 |
CVE-2024-9435 |
Wordfence | |
| 4.4 Medium | WP Booking Calendar | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 10.6 |
CVE-2024-9306 |
Wordfence | |
| 6.4 Medium | Memberful – Membership | Cross-Site Scripting Membership Plugin <= 1.73.7 - Authenticated (contributor+) Stored Cross-Site Scripting |
≤ 1.73.7 |
CVE-2024-9242 |
Wordfence | |
| 6.4 Medium | Code Embed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4 |
CVE-2024-8804 |
Wordfence | |
| 6.1 Medium | Fish and Ships | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5.9 |
CVE-2024-9237 |
Wordfence | |
| 6.4 Medium | Ultimate Member | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.6 |
CVE-2024-8519 |
Wordfence | |
| 5.3 Medium | Ultimate Member | Cross-Site Request Forgery Cross-Site Request Forgery to Membership Status Change No login needed |
≤ 2.8.6 |
CVE-2024-8520 |
Wordfence | |
| 6.1 Medium | Quantity Dynamic Pricing & Bulk Discounts for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.8.0 |
CVE-2024-9384 |
Wordfence | |
| 6.4 Medium | Display Medium Posts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via display_medium_posts Shortcode |
≤ 5.0.1 |
CVE-2024-9445 |
Wordfence | |
| 6.1 Medium | WordPress Captcha Plugin by Captcha Bank | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.0.36 |
CVE-2024-9375 |
Wordfence | |
| 6.1 Medium | Smart Custom 404 Error Page | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 11.4.7 |
CVE-2024-9204 |
Wordfence | |
| 6.4 Medium | Login Logout Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class Parameter |
≤ 1.1.0 |
CVE-2024-9421 |
Wordfence | |
| 6.4 Medium | Aggregator Advanced Settings | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.2.1 |
CVE-2024-9368 |
Wordfence | |
| 6.4 Medium | WP Blocks Hub | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.2 |
CVE-2024-9372 |
Wordfence | |
| 6.1 Medium | Auto Amazon Links – Amazon Associates Affiliate | Cross-Site Scripting Amazon Associates Affiliate Plugin <= 5.4.2 - Reflected Cross-Site Scripting No login needed |
≤ 5.4.2 |
CVE-2024-9349 |
Wordfence | |
| 6.1 Medium | Popularis Extra | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.6 |
CVE-2024-9353 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce – Lite | Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-9345 |
Wordfence | |
| 6.1 Medium | Clio Grow | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.2 |
CVE-2024-8802 |
Wordfence | |
| 6.4 Medium | WordPress Infinite Scroll - Ajax Load More | Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter |
≤ 7.1.2 |
CVE-2024-8505 |
Wordfence | |
| 6.4 Medium | Ibtana – WordPress Website Builder | Cross-Site Scripting WordPress Website Builder <= 1.2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 1.2.4.4 |
CVE-2024-8282 |
Wordfence | |
| 6.1 Medium | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | Cross-Site Scripting Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.14 |
CVE-2024-9218 |
Wordfence | |
| 6.1 Medium | YML for Yandex Market | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.7.2 |
CVE-2024-9378 |
Wordfence | |
| 6.1 Medium | BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | Cross-Site Scripting Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript <= 2.1.1 - Reflected Cross-Site Scripting No login needed |
≤ 2.1.1 |
CVE-2024-9344 |
Wordfence | |
| 6.1 Medium | RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more | Cross-Site Scripting Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more <= 2.21.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.21.0 |
CVE-2024-8800 |
Wordfence | |
| 6.1 Medium | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | Cross-Site Scripting Effortless Memberships, Recurring Payments & Content Restriction <= 2.12.8 - Reflected Cross-Site Scripting No login needed |
≤ 2.12.8 |
CVE-2024-9222 |
Wordfence | |
| 6.1 Medium | MC4WP: Mailchimp Top Bar | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.0 |
CVE-2024-9210 |
Wordfence | |
| 6.1 Medium | SEOPress – On-site SEO | Cross-Site Scripting On-site SEO <= 8.1.1 - Reflected Cross-Site Scripting No login needed |
≤ 8.1.1 |
CVE-2024-9225 |
Wordfence | |
| 6.4 Medium | Demo Importer Plus | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.0.1 |
CVE-2024-9172 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.