WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,701–13,750 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 275 of 1
Severity Component Vulnerability Affected versions Published CVE Source
10.0 Critical Woostagram Connect Plugin woostagram-connect Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-49327 Patchstack
10.0 Critical WP REST API FNS Plugin rest-api-fns Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49329 Patchstack
10.0 Critical Nice Backgrounds Plugin nicebackgrounds Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49330 Patchstack
9.9 Critical Property Lot Management System Plugin plms Arbitrary File Upload ≤ 4.2.38 CVE-2024-49331 Patchstack
10.0 Critical WP Dropbox Dropins Plugin wp-dropbox-dropins Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49607 Patchstack
10.0 Critical photokit Plugin photokit Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49610 Patchstack
9.8 Critical Giveaway Boost Plugin giveaway-boost PHP Object Injection No login needed ≤ 2.1.4 CVE-2024-49332 Patchstack
9.8 Critical Advanced Advertising System Plugin advanced-advertising-system PHP Object Injection No login needed ≤ 1.3.1 CVE-2024-49624 Patchstack
9.8 Critical SiteBuilder Dynamic Components Plugin sitebuilder-dynamic-components PHP Object Injection No login needed ≤ 1.0 CVE-2024-49625 Patchstack
9.8 Critical Shipyaari Shipping Management Plugin shipyaari-shipping-managment PHP Object Injection No login needed ≤ 1.2 CVE-2024-49626 Patchstack
9.6 Critical SSV Events Plugin ssv-events Local File Inclusion Local File Inclusion to RCE No login needed ≤ 3.2.7 CVE-2024-49286 Patchstack
10.0 Critical Product Website Showcase Plugin product-websites-showcase Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49611 Patchstack
9.8 Critical WP REST API FNS Plugin rest-api-fns Privilege Escalation Account Takeover No login needed ≤ 1.0.0 CVE-2024-49328 Patchstack
9.8 Critical Simple User Registration Plugin wp-registration Authentication Bypass Broken Authentication No login needed ≤ 6.7 Fixed in 6.8 CVE-2024-49604 Patchstack
6.5 Medium Mighty Builder Plugin mighty-builder Cross-Site Scripting ≤ 1.0.2 CVE-2024-48049 Patchstack
7.1 High All in One Slider Plugin all-in-one-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-49323 Patchstack
7.1 High jLayer Parallax Slider Plugin jlayer-parallax-slider-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49334 Patchstack
7.1 High Google Map Locations Plugin google-map-locations Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49606 Patchstack
6.5 Medium WP Education Plugin wp-education Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-49630 Patchstack
6.5 Medium Easy Addons for Elementor Plugin easy-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 CVE-2024-49631 Patchstack
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
6.4 Medium Debrandify · Remove or Replace WordPress Branding Plugin debrandify Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.2 CVE-2024-9674 Wordfence
5.9 Medium Movie Database Plugin movie-database Cross-Site Scripting ≤ 1.0.11 CVE-2024-43300 Patchstack
7.1 High Mitm Bug Tracker Plugin mitm-bug-tracker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49224 Patchstack
6.5 Medium wpPricing Builder Plugin wppricing-builder-lite-responsive-pricing-table-builder Cross-Site Scripting ≤ 1.5.0 CVE-2024-49225 Patchstack
6.5 Medium bVerse Convert Plugin bverse-convert Cross-Site Scripting ≤ 1.3.7.1 CVE-2024-49228 Patchstack
6.5 Medium Ajax Custom CSS/JS Plugin ajax-awesome-css Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 2.0.4 CVE-2024-49230 Patchstack
6.5 Medium WordPress Video Plugin wordpress-video Cross-Site Scripting ≤ 1.0 CVE-2024-49231 Patchstack
6.5 Medium El mejor Cluster Plugin mejorcluster Cross-Site Scripting ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-49232 Patchstack
6.5 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-49233 Patchstack
6.5 Medium Plexx Elementor Extension Plugin plexx-elementor-extension Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-49234 Patchstack
6.5 Medium Crazy Call To Action Box Plugin crazy-call-to-action-box Cross-Site Scripting ≤ 1.0.5 CVE-2024-49236 Patchstack
7.1 High ADIF Log Search Widget Plugin adif-log-search-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0f CVE-2024-49238 Patchstack
7.1 High Add Categories Post Footer Plugin add-categories-post-footer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.2 CVE-2024-49239 Patchstack
7.1 High AB Categories Search Widget Plugin ab-categories-search-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.5 CVE-2024-49240 Patchstack
6.5 Medium Tito Plugin tito Cross-Site Scripting ≤ 2.3 CVE-2024-49241 Patchstack
7.5 High Dynamic Elementor Addons Plugin dynamic-elementor-addons Local File Inclusion ≤ 1.0.0 CVE-2024-49243 Patchstack
4.3 Medium SendGrid Plugin wp-sendgrid-mailer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion ≤ 1.4 CVE-2024-9364 Wordfence
7.1 High Ad Inserter Plugin ad-inserter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.37 Fixed in 2.7.38 CVE-2024-49248 Patchstack
6.5 Medium Da Reactions Plugin da-reactions Cross-Site Scripting ≤ 5.1.5 Fixed in 5.2.0 CVE-2024-49255 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-49259 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.23.0 Fixed in 2.27.0 CVE-2024-49261 Patchstack
6.5 Medium Country Flags for Elementor Plugin country-flags-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-49262 Patchstack
6.5 Medium My Favorites Plugin my-favorites Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.3 CVE-2024-49263 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-49264 Patchstack
7.1 High Clio Grow Plugin clio-grow-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-49276 Patchstack
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting Elementor Addons plugin <= 2.0.2 - Cross Site Scripting (XSS) ≤ 2.0.2 CVE-2024-49277 Patchstack
6.5 Medium Omnipress Plugin omnipress Cross-Site Scripting No login needed ≤ 1.4.3 Fixed in 1.5.0 CVE-2024-49278 Patchstack
6.5 Medium Hyperlink Group Block Plugin hyperlink-group-block Cross-Site Scripting ≤ 1.17.5 Fixed in 1.17.6 CVE-2024-49279 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only