WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,601–13,650 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 273 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.5 Medium Form Maker Plugin form-maker Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.15.27 CVE-2024-8633 Wordfence
6.8 Medium Advanced File Manager Theme file-manager-advanced Arbitrary File Upload Authenticated (Subscriber+) Limited File Upload ≤ 5.2.8 CVE-2024-8725 Wordfence
6.4 Medium Mapplic Lite Plugin mapplic-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9117 Wordfence
6.4 Medium Common Tools for Site Plugin common-tools-for-site Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9115 Wordfence
6.4 Medium GF Custom Style Plugin gf-custom-style Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.0 CVE-2024-9173 Wordfence
6.4 Medium Super Testimonials Plugin sola-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via alignment Parameter ≤ 3.0.0 CVE-2024-9127 Wordfence
6.4 Medium king_IE Plugin king-ie Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9125 Wordfence
4.3 Medium Joy Of Text Lite Plugin joy-of-text Broken Access Control ≤ 2.3.1 CVE-2024-47337 Patchstack
5.3 Medium Sight – Professional Image Gallery and Portfolio Plugin sight Broken Access Control Professional Image Gallery and Portfolio <= 1.1.2 - Missing Authorization to Sensitive Information Exposure in handler_post_title No login needed ≤ 1.1.2 CVE-2024-9025 Wordfence
6.1 Medium Store Hours for WooCommerce Plugin order-hours-scheduler-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.3.20 CVE-2024-8872 Wordfence
6.4 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.3.2 CVE-2024-8861 Wordfence
6.1 Medium Contact Form 7 Math Captcha Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.1 CVE-2024-6517 WPScan
4.3 Medium Slider by Supsystic Plugin slider-by-supsystic Broken Access Control Broken Access Control vulnerability on multiple WordPress plugins by Supsystic ≤ 1.8.6, ≤ 2.2.9 Fixed in 1.8.7 CVE-2024-47330 Patchstack
6.1 Medium Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.15 CVE-2024-8803 Wordfence
4.3 Medium Download Monitor Plugin download-monitor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Shop Enable ≤ 5.0.9 CVE-2024-8552 Wordfence
6.4 Medium 012 PS Multi Languages Plugin 012-ps-multi-languages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6 CVE-2024-8723 Wordfence
4.3 Medium Use Any Font Plugin use-any-font Cross-Site Request Forgery No login needed ≤ 6.3.08 Fixed in 6.3.09 CVE-2024-47305 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery Donation Plugin and Fundraising Platform plugin <= 3.15.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.15.1 Fixed in 3.16.0 CVE-2024-47315 Patchstack
5.3 Medium WordPress Tag Cloud Plugin – Tag Groups Plugin tag-groups Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-43237 Patchstack
5.3 Medium Masterstudy LMS Starter Theme Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-43990 Patchstack
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget ≤ 3.2.7 CVE-2024-8546 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via piechart_settings Parameter ≤ 8.5 CVE-2024-8858 Wordfence
5.5 Medium litespeed cache Plugin litespeed-cache Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 6.4.1 CVE-2024-9169 Wordfence
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Cross-Site Scripting ≤ 8.5 Fixed in 8.5.1 CVE-2024-47303 Patchstack
4.7 Medium Ninja Forms Contact Form Plugin ninja-forms Cross-Site Scripting Reflected Self-Based Cross-Site Scripting via Referer No login needed ≤ 3.8.15 CVE-2024-3866 Wordfence
5.3 Medium Revolut Gateway for WooCommerce Plugin revolut-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed ≤ 4.17.3 CVE-2024-8678 Wordfence
4.3 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Information Disclosure Absolute Addons For Elementor <= 2.6.5 - Authenticated (Contributor+) Sensitive Information Exposure via template_id ≤ 2.6.5 CVE-2024-8910 Wordfence
4.3 Medium adstxt Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0.0 CVE-2024-7892 WPScan
4.8 Medium WP ULike Plugin wp-ulike Cross-Site Scripting Admin+ Stored XSS < 4.7.4 Fixed in 4.7.4 CVE-2024-7878 WPScan
5.3 Medium SmartSearchWP Plugin Information Disclosure Unauthenticated OpenAI Key Disclosure No login needed < 2.4.6 Fixed in 2.4.6 CVE-2024-6845 WPScan
5.3 Medium Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred Plugin mycred Broken Access Control Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 - Missing Authorization to Unauthenticated Database Upgrade No login needed ≤ 2.7.3 CVE-2024-8658 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
4.3 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Information Disclosure Authenticated (Contributor+) Information Exposure ≤ 2.2.1 CVE-2024-8516 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-8515 Wordfence
6.4 Medium GutenGeek Free Gutenberg Blocks Plugin gtg-advanced-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.3 CVE-2024-9073 Wordfence
5.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed ≤ 1.3.6.1 CVE-2024-7491 Wordfence
6.3 Medium WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 3.8.0 CVE-2024-6590 Wordfence
4.3 Medium Easy Mega Menu Plugin for WordPress – ThemeHunk Plugin themehunk-megamenu-plus Broken Access Control ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates ≤ 1.0.9 CVE-2024-8434 Wordfence
6.4 Medium Material Design Icons Plugin material-design-icons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mdi-icon Shortcode ≤ 0.0.5 CVE-2024-9024 Wordfence
6.4 Medium WP GPX Maps Plugin wp-gpx-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sgpx Shortcode ≤ 1.7.08 CVE-2024-9028 Wordfence
4.3 Medium MAS Static Content Plugin mas-static-content Information Disclosure Authenticated (Contributor+) Private Static Content Page Disclosure ≤ 1.0.8 CVE-2024-8483 Wordfence
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2024-8476 Wordfence
6.1 Medium Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.5.0 CVE-2024-8713 Wordfence
6.4 Medium OneElements – Best Elementor Addons Plugin oneelements-ultimate-addons-for-elementor Cross-Site Scripting Best Elementor Addons <= 1.3.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.3.7 CVE-2024-9068 Wordfence
6.4 Medium Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) Plugin graphicsly Cross-Site Scripting The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9069 Wordfence
6.1 Medium Beam me up Scotty – Back to Top Button Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting No login needed ≤ 1.0.21 CVE-2024-8741 Wordfence
5.3 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Information Disclosure Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path Disclosure No login needed ≤ 6.4.6.0 CVE-2024-7426 Wordfence
6.4 Medium WPZOOM Shortcodes Plugin wpzoom-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via box Shortcode ≤ 1.0.5 CVE-2024-9027 Wordfence
6.1 Medium Simple Calendar – Google Calendar Plugin google-calendar-events Cross-Site Scripting Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting No login needed ≤ 3.4.2 CVE-2024-8549 Wordfence
4.3 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Cross-Site Request Forgery Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery No login needed ≤ 5.9.1 CVE-2024-7386 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only