WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,551–13,600 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 272 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High js paper Theme js-paper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.7 CVE-2024-49678 Patchstack
5.9 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-49679 Patchstack
6.5 Medium AffiliateX Plugin affiliatex Cross-Site Scripting ≤ 1.2.9 Fixed in 1.2.9.1 CVE-2024-49692 Patchstack
7.1 High Namaste! LMS Plugin namaste-lms Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-50407 Patchstack
6.5 Medium Namaste! LMS Plugin namaste-lms Cross-Site Scripting ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-50409 Patchstack
6.5 Medium Namaste! LMS Plugin namaste-lms Cross-Site Scripting ≤ 2.6.4 Fixed in 2.6.4.1 CVE-2024-50410 Patchstack
8.1 High LiteSpeed Cache Plugin litespeed-cache Privilege Escalation No login needed ≤ 6.5.1 Fixed in 6.5.2 CVE-2024-50550 Patchstack
7.1 High Todo Custom Field Plugin todo-custom-field Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.4 CVE-2024-49642 Patchstack
5.9 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-50411 Patchstack
5.9 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Cross-Site Scripting ≤ 2.4.15 Fixed in 2.5 CVE-2024-50412 Patchstack
5.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting ≤ 1.27.5 Fixed in 1.27.6 CVE-2024-50413 Patchstack
5.9 Medium Button contact VR Plugin button-contact-vr Cross-Site Scripting ≤ 4.7.9.1 Fixed in 4.7.10 CVE-2024-50414 Patchstack
5.9 Medium Ads.txt & App-ads.txt Manager Plugin app-ads-txt Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2024-50415 Patchstack
6.5 Medium Time Slot Plugin timeslot Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-50418 Patchstack
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2024-50426 Patchstack
9.8 Critical Signup Page Plugin signup-page Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0 CVE-2024-50475 Patchstack
9.8 Critical GRÜN spendino Spendenformular Plugin spendino Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0.1 CVE-2024-50476 Patchstack
8.8 High Bstone Demo Importer Plugin bstone-demo-importer Privilege Escalation ≤ 1.0.1 CVE-2024-50481 Patchstack
9.8 Critical Exam Matrix Plugin exam-matrix Privilege Escalation No login needed ≤ 1.5 CVE-2024-50485 Patchstack
9.8 Critical PegaPoll Plugin pegapoll Privilege Escalation Arbitrary Option Update to Privilege Escalation No login needed ≤ 1.0.2 CVE-2024-50490 Patchstack
10.0 Critical aDirectory Plugin adirectory Arbitrary File Upload No login needed ≤ 1.3 Fixed in 1.3.1 CVE-2024-50420 Patchstack
9.9 Critical SurveyJS Plugin surveyjs Arbitrary File Upload ≤ 1.9.136 Fixed in 1.12.4 CVE-2024-50427 Patchstack
10.0 Critical Ajar in5 Embed Plugin ajar-productions-in5-embed Arbitrary File Upload No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-50473 Patchstack
9.9 Critical Marketing Automation by AZEXO Plugin marketing-automation-by-azexo Arbitrary File Upload ≤ 1.27.80 CVE-2024-50480 Patchstack
10.0 Critical Woocommerce Product Design Plugin woo-product-design Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-50482 Patchstack
10.0 Critical Multi Purpose Mail Form Plugin multi-purpose-mail-form Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-50484 Patchstack
10.0 Critical Automatic Translation Plugin automatic-translation Arbitrary File Upload No login needed ≤ 1.0.4 CVE-2024-50493 Patchstack
10.0 Critical Sudan Payment Gateway for WooCommerce Plugin wc-sudan-payment-gateway Arbitrary File Upload No login needed ≤ 1.2.2 CVE-2024-50494 Patchstack
6.4 Medium Masteriyo LMS – eLearning and Online Course Builder Plugin learning-management-system Cross-Site Scripting eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Stored Cross-Site Scripting via Ask a Question Functionality ≤ 1.13.3 CVE-2024-10000 Wordfence
8.8 High Masteriyo LMS – eLearning and Online Course Builder Plugin learning-management-system Broken Access Control eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation ≤ 1.13.3 CVE-2024-10008 Wordfence
10.0 Critical Plugin Propagator Plugin wp-propagator Arbitrary File Upload No login needed ≤ 0.1 CVE-2024-50495 Patchstack
10.0 Critical AR Plugin ar-for-wordpress Arbitrary File Upload No login needed ≤ 6.6 Fixed in 7.0 CVE-2024-50496 Patchstack
7.5 High NewsCard Plugin newscard Local File Inclusion No login needed ≤ 1.3 Fixed in 1.4 CVE-2024-50434 Patchstack
7.5 High Meta News Plugin meta-news Local File Inclusion No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-50435 Patchstack
7.5 High Clean Retina Plugin clean-retina Local File Inclusion No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-50436 Patchstack
7.5 High The Pack Elementor addons Plugin the-pack-addon Local File Inclusion ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-50453 Patchstack
7.5 High Qode Essential Addons Plugin qode-essential-addons Local File Inclusion ≤ 1.6.3 Fixed in 1.6.4 CVE-2024-50457 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.15 Fixed in 1.3.18 CVE-2024-50429 Patchstack
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.14 Fixed in 2.1.15 CVE-2024-50431 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.93 Fixed in 2.2.94 CVE-2024-50432 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.15 Fixed in 2.5.16 CVE-2024-50433 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.80 Fixed in 2.3.81 CVE-2024-50437 Patchstack
7.1 High Church Admin Plugin church-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.0.0 Fixed in 5.0.0 CVE-2024-50438 Patchstack
6.5 Medium Astra Widgets Plugin astra-widgets Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.14 Fixed in 1.2.15 CVE-2024-50439 Patchstack
6.5 Medium CodePen Embedded Pens Shortcode Plugin codepen-embedded-pen-shortcode Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-50440 Patchstack
6.5 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting ≤ 2.0.15 Fixed in 2.0.16 CVE-2024-50441 Patchstack
6.5 Medium Selection Lite Plugin selection-lite Cross-Site Scripting ≤ 1.13 Fixed in 1.14 CVE-2024-50445 Patchstack
6.5 Medium Futurio Extra Plugin futurio-extra Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-50446 Patchstack
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.19 Fixed in 1.4.20 CVE-2024-50447 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.14.1 Fixed in 4.14.2 CVE-2024-50448 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only