WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 13,751–13,800 of 16,945 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Lightbox slider – Responsive Lightbox Gallery | Cross-Site Scripting |
≤ 1.10.6 |
CVE-2024-49280 |
Patchstack | |
| 6.5 Medium | Click to Chat – WP Support All-in-One Floating Widget | Cross-Site Scripting WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) |
≤ 2.3.3 Fixed in 2.3.4 |
CVE-2024-49281 |
Patchstack | |
| 5.9 Medium | Responsive Lightbox | Cross-Site Scripting |
≤ 2.4.8 Fixed in 2.4.9 |
CVE-2024-49282 |
Patchstack | |
| 7.1 High | CURCY | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.2.3 Fixed in 2.2.4 |
CVE-2024-49283 |
Patchstack | |
| 5.9 Medium | Email Template Customizer for WooCommerce | Cross-Site Scripting |
≤ 1.2.9.1 Fixed in 1.2.9.2 |
CVE-2024-49288 |
Patchstack | |
| 6.5 Medium | Cooked Pro | Cross-Site Scripting |
< 1.8.0 Fixed in 1.8.0 |
CVE-2024-49289 |
Patchstack | |
| 6.5 Medium | Exclusive Addons Elementor | Cross-Site Scripting |
≤ 2.7.1 Fixed in 2.7.2 |
CVE-2024-49292 |
Patchstack | |
| 5.9 Medium | Simple Testimonials Showcase | Cross-Site Scripting |
≤ 1.1.6 |
CVE-2024-49295 |
Patchstack | |
| 6.5 Medium | Custom Add to Cart Button Label and Link | Cross-Site Scripting |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-49296 |
Patchstack | |
| 6.5 Medium | PeproDev Ultimate Invoice | Cross-Site Scripting |
≤ 2.0.6 Fixed in 2.0.7 |
CVE-2024-49298 |
Patchstack | |
| 6.5 Medium | G Meta Keywords | Cross-Site Scripting |
≤ 1.4 |
CVE-2024-49301 |
Patchstack | |
| 6.5 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-49302 |
Patchstack | |
| 6.5 Medium | Admin Management Xtended | Cross-Site Scripting |
≤ 2.4.6 Fixed in 2.4.7 |
CVE-2024-49307 |
Patchstack | |
| 7.1 High | Animator | Cross-Site Scripting Scroll Triggered Animations plugin <= 3.0.15 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.0.15 Fixed in 3.0.16 |
CVE-2024-49308 |
Patchstack | |
| 7.1 High | Digitally | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.8 |
CVE-2024-49309 |
Patchstack | |
| 6.5 Medium | themesflat-addons-for-elementor | Cross-Site Scripting |
≤ 2.2.0 Fixed in 2.2.2 |
CVE-2024-49310 |
Patchstack | |
| 6.5 Medium | Edwiser Bridge | Cross-Site Scripting |
≤ 3.0.7 Fixed in 3.0.8 |
CVE-2024-49311 |
Patchstack | |
| 7.1 High | Akismet htaccess writer | Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2024-49316 |
Patchstack | |
| 6.5 Medium | Awesome Contact Form7 for Elementor | Cross-Site Scripting |
≤ 3.0 Fixed in 3.1 |
CVE-2024-49319 |
Patchstack | |
| 7.1 High | EasyJobs | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.4.14 Fixed in 2.4.15 |
CVE-2024-43997 |
Patchstack | |
| 7.1 High | Cookie Scanner | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1 |
CVE-2024-49220 |
Patchstack | |
| 7.1 High | cSlider | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 2.4.2 |
CVE-2024-49221 |
Patchstack | |
| 7.1 High | CJ Change Howdy | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 3.3.1 |
CVE-2024-49223 |
Patchstack | |
| 7.1 High | Better Author Bio | Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed |
≤ 2.7.10.11 |
CVE-2024-49229 |
Patchstack | |
| 7.1 High | Ahmeti Wp Timeline | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 5.1 |
CVE-2024-49237 |
Patchstack | |
| 5.4 Medium | Pinpoint Booking System | Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 |
CVE-2024-49304 |
Patchstack | |
| 7.1 High | VKontakte Wall Post | Cross-Site Scripting No login needed |
≤ 2.0 |
CVE-2024-49313 |
Patchstack | |
| 9.8 Critical | Adding drop down roles in registration | Privilege Escalation No login needed |
≤ 1.1 |
CVE-2024-49217 |
Patchstack | |
| 8.8 High | RS-Members | Privilege Escalation |
≤ 1.0.3 |
CVE-2024-49219 |
Patchstack | |
| 9.8 Critical | Job Board Manager | Privilege Escalation No login needed |
≤ 1.0 |
CVE-2024-49322 |
Patchstack | |
| 8.5 High | Fluent Support | SQL Injection |
≤ 1.8.0 Fixed in 1.8.1 |
CVE-2024-47304 |
Patchstack | |
| 8.5 High | Classic Editor and Classic Widgets | SQL Injection |
≤ 1.4.1 Fixed in 1.4.2 |
CVE-2024-47312 |
Patchstack | |
| 8.5 High | CSV Product Import Export for WooCommerce | SQL Injection |
≤ 1.0.0 |
CVE-2024-49244 |
Patchstack | |
| 9.3 Critical | Ajax Rating with Custom Login | SQL Injection No login needed |
≤ 1.1 |
CVE-2024-49246 |
Patchstack | |
| 8.5 High | Zoho CRM Lead Magnet | SQL Injection |
≤ 1.7.9.7 Fixed in 1.7.9.8 |
CVE-2024-49297 |
Patchstack | |
| 7.6 High | Surfer | SQL Injection |
≤ 1.5.0.502 Fixed in 1.6.0.523 |
CVE-2024-49299 |
Patchstack | |
| 9.3 Critical | Email Verification for WooCommerce | SQL Injection No login needed |
≤ 2.8.10 Fixed in 2.9.0 |
CVE-2024-49305 |
Patchstack | |
| 7.5 High | Contact Forms, Live Support, CRM, Video Messages | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.10.2 Fixed in 1.11.1 |
CVE-2024-49235 |
Patchstack | |
| 5.3 Medium | WP SendFox | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.3.1 |
CVE-2024-49284 |
Patchstack | |
| 10.0 Critical | Cooked Pro | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
< 1.8.0 Fixed in 1.8.0 |
CVE-2024-49291 |
Patchstack | |
| 10.0 Critical | JiangQie Free Mini Program | Arbitrary File Upload No login needed |
≤ 2.5.2 |
CVE-2024-49314 |
Patchstack | |
| 7.5 High | SSV MailChimp | Local File Inclusion No login needed |
≤ 3.1.5 |
CVE-2024-49285 |
Patchstack | |
| 7.5 High | PDF-Rechnungsverwaltung | Local File Inclusion No login needed |
≤ 0.0.1 |
CVE-2024-49287 |
Patchstack | |
| 7.5 High | Point Maker | Local File Inclusion |
≤ 0.1.4 Fixed in 0.1.5 |
CVE-2024-49317 |
Patchstack | |
| 9.8 Critical | My Reading Library | PHP Object Injection No login needed |
≤ 1.0 |
CVE-2024-49318 |
Patchstack | |
| 4.9 Medium | Edwiser Bridge | Server-Side Request Forgery |
≤ 3.0.7 Fixed in 3.0.8 |
CVE-2024-49312 |
Patchstack | |
| 8.6 High | FREE DOWNLOAD MANAGER | Arbitrary File Deletion No login needed |
≤ 1.0.0 |
CVE-2024-49315 |
Patchstack | |
| 7.1 High | Contact Form 7 – PayPal & Stripe Add-on | Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.3 Fixed in 2.3.1 |
CVE-2024-48021 |
Patchstack | |
| 6.5 Medium | Shortcode For Elementor Templates | Cross-Site Scripting |
≤ 1.0.0 |
CVE-2024-48022 |
Patchstack | |
| 7.1 High | Restaurant Reservations Widget | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2024-48023 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.