WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,751–13,800 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 276 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery Cross-Site Scripting ≤ 1.10.6 CVE-2024-49280 Patchstack
6.5 Medium Click to Chat – WP Support All-in-One Floating Widget Plugin support-chat Cross-Site Scripting WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) ≤ 2.3.3 Fixed in 2.3.4 CVE-2024-49281 Patchstack
5.9 Medium Responsive Lightbox Plugin responsive-lightbox Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2024-49282 Patchstack
7.1 High CURCY Plugin woo-multi-currency Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 Fixed in 2.2.4 CVE-2024-49283 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.9.1 Fixed in 1.2.9.2 CVE-2024-49288 Patchstack
6.5 Medium Cooked Pro Plugin Cross-Site Scripting < 1.8.0 Fixed in 1.8.0 CVE-2024-49289 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-49292 Patchstack
5.9 Medium Simple Testimonials Showcase Plugin simple-testimonials-showcase Cross-Site Scripting ≤ 1.1.6 CVE-2024-49295 Patchstack
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.5 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Cross-Site Scripting ≤ 2.0.6 Fixed in 2.0.7 CVE-2024-49298 Patchstack
6.5 Medium G Meta Keywords Plugin g-meta-keywords Cross-Site Scripting ≤ 1.4 CVE-2024-49301 Patchstack
6.5 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2024-49302 Patchstack
6.5 Medium Admin Management Xtended Plugin admin-management-xtended Cross-Site Scripting ≤ 2.4.6 Fixed in 2.4.7 CVE-2024-49307 Patchstack
7.1 High Animator Plugin scroll-triggered-animations Cross-Site Scripting Scroll Triggered Animations plugin <= 3.0.15 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.15 Fixed in 3.0.16 CVE-2024-49308 Patchstack
7.1 High Digitally Plugin digitally Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.8 CVE-2024-49309 Patchstack
6.5 Medium themesflat-addons-for-elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.2 CVE-2024-49310 Patchstack
6.5 Medium Edwiser Bridge Plugin edwiser-bridge Cross-Site Scripting ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49311 Patchstack
7.1 High Akismet htaccess writer Plugin akismet-htaccess-writer Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2024-49316 Patchstack
6.5 Medium Awesome Contact Form7 for Elementor Plugin awesome-contact-form7-for-elementor Cross-Site Scripting ≤ 3.0 Fixed in 3.1 CVE-2024-49319 Patchstack
7.1 High EasyJobs Plugin easyjobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-43997 Patchstack
7.1 High Cookie Scanner Plugin cookie-scanner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-49220 Patchstack
7.1 High cSlider Plugin cslider Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4.2 CVE-2024-49221 Patchstack
7.1 High CJ Change Howdy Plugin cj-change-howdy Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.1 CVE-2024-49223 Patchstack
7.1 High Better Author Bio Plugin better-author-bio Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.7.10.11 CVE-2024-49229 Patchstack
7.1 High Ahmeti Wp Timeline Plugin ahmeti-wp-timeline Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.1 CVE-2024-49237 Patchstack
5.4 Medium Pinpoint Booking System Plugin booking-system Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.9.5.7 Fixed in 2.9.9.5.8 CVE-2024-49304 Patchstack
7.1 High VKontakte Wall Post Plugin vkontakte-wall-post Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-49313 Patchstack
9.8 Critical Adding drop down roles in registration Plugin user-drop-down-roles-in-registration Privilege Escalation No login needed ≤ 1.1 CVE-2024-49217 Patchstack
8.8 High RS-Members Plugin rs-members Privilege Escalation ≤ 1.0.3 CVE-2024-49219 Patchstack
9.8 Critical Job Board Manager Plugin jemployee Privilege Escalation No login needed ≤ 1.0 CVE-2024-49322 Patchstack
8.5 High Fluent Support Plugin fluent-support SQL Injection ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-47304 Patchstack
8.5 High Classic Editor and Classic Widgets Plugin classic-editor-and-classic-widgets SQL Injection ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-47312 Patchstack
8.5 High CSV Product Import Export for WooCommerce Plugin csv-wc-product-import-export SQL Injection ≤ 1.0.0 CVE-2024-49244 Patchstack
9.3 Critical Ajax Rating with Custom Login Plugin ajax-rating-with-custom-login SQL Injection No login needed ≤ 1.1 CVE-2024-49246 Patchstack
8.5 High Zoho CRM Lead Magnet Plugin zoho-crm-forms SQL Injection ≤ 1.7.9.7 Fixed in 1.7.9.8 CVE-2024-49297 Patchstack
7.6 High Surfer Plugin surferseo SQL Injection ≤ 1.5.0.502 Fixed in 1.6.0.523 CVE-2024-49299 Patchstack
9.3 Critical Email Verification for WooCommerce Plugin emails-verification-for-woocommerce SQL Injection No login needed ≤ 2.8.10 Fixed in 2.9.0 CVE-2024-49305 Patchstack
7.5 High Contact Forms, Live Support, CRM, Video Messages Plugin live-support-tickets Information Disclosure Sensitive Data Exposure No login needed ≤ 1.10.2 Fixed in 1.11.1 CVE-2024-49235 Patchstack
5.3 Medium WP SendFox Plugin wp-sendfox Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.1 CVE-2024-49284 Patchstack
10.0 Critical Cooked Pro Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed < 1.8.0 Fixed in 1.8.0 CVE-2024-49291 Patchstack
10.0 Critical JiangQie Free Mini Program Plugin jiangqie-free-mini-program Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2024-49314 Patchstack
7.5 High SSV MailChimp Plugin ssv-mailchimp Local File Inclusion No login needed ≤ 3.1.5 CVE-2024-49285 Patchstack
7.5 High PDF-Rechnungsverwaltung Plugin pdf-rechnungsverwaltung Local File Inclusion No login needed ≤ 0.0.1 CVE-2024-49287 Patchstack
7.5 High Point Maker Plugin point-maker Local File Inclusion ≤ 0.1.4 Fixed in 0.1.5 CVE-2024-49317 Patchstack
9.8 Critical My Reading Library Plugin my-reading-library PHP Object Injection No login needed ≤ 1.0 CVE-2024-49318 Patchstack
4.9 Medium Edwiser Bridge Plugin edwiser-bridge Server-Side Request Forgery ≤ 3.0.7 Fixed in 3.0.8 CVE-2024-49312 Patchstack
8.6 High FREE DOWNLOAD MANAGER Plugin free-download-manager Arbitrary File Deletion No login needed ≤ 1.0.0 CVE-2024-49315 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.3.1 CVE-2024-48021 Patchstack
6.5 Medium Shortcode For Elementor Templates Plugin shortcode-support-for-elementor-templates Cross-Site Scripting ≤ 1.0.0 CVE-2024-48022 Patchstack
7.1 High Restaurant Reservations Widget Plugin restaurantconnect-reswidget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-48023 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only