WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,751–13,800 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 276 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Simple Headline Rotator Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7860 WPScan
6.5 Medium Visual Sound Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.03 CVE-2024-7859 WPScan
6.1 Medium Quick Code Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7822 WPScan
4.3 Medium ILC Thickbox Plugin Cross-Site Request Forgery Settings update via CSRF No login needed ≤ 1.0 CVE-2024-7820 WPScan
6.1 Medium Misiek Photo Album Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.4.3 CVE-2024-7818 WPScan
6.5 Medium Misiek Photo Album Plugin Cross-Site Request Forgery Album Deletion via CSRF No login needed ≤ 1.4.3 CVE-2024-7817 WPScan
6.1 Medium Gixaw Chat Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7816 WPScan
4.8 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Scripting Editor+ Stored XSS < 1.12.16 Fixed in 1.12.16 CVE-2024-6887 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.3 CVE-2024-6019 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.3 CVE-2024-6018 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.3 CVE-2024-6017 WPScan
4.8 Medium CM Pop-Up Banners Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.7.3 Fixed in 1.7.3 CVE-2024-5799 WPScan
4.3 Medium Easy Property Listings Plugin easy-property-listings Cross-Site Request Forgery Arbitrary Contact Deletion via CSRF No login needed < 3.5.4 Fixed in 3.5.4 CVE-2024-3163 WPScan
5.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets ≤ 3.23.4 CVE-2024-5416 Wordfence
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
6.4 Medium Advanced WordPress Backgrounds Plugin advanced-backgrounds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter ≤ 1.12.3 CVE-2024-8045 Wordfence
6.4 Medium Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget ≤ 6.0.3 CVE-2024-8440 Wordfence
4.8 Medium GS Logo Slider Lite Plugin Cross-Site Scripting Admin+ Stored XSS < 3.6.9 Fixed in 3.6.9 CVE-2024-7716 WPScan
4.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS < 1.8.15 Fixed in 1.8.15 CVE-2024-3899 WPScan
5.3 Medium HTML5 Video Player – mp4 Video Player Plugin and Block Plugin html5-video-player Broken Access Control mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler No login needed ≤ 2.5.32 CVE-2024-7727 Wordfence
4.3 Medium HTML5 Video Player – mp4 Video Player Plugin and Block Plugin html5-video-player Broken Access Control mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 2.5.34 CVE-2024-7721 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed ≤ 4.0.4.3 CVE-2024-8369 Wordfence
5.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element ≤ 2.0.6.4 CVE-2024-6282 Wordfence
4.3 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery Cross-Site Request Forgery via 'addon_enable_disable' No login needed ≤ 2.7.4 CVE-2023-2919 Wordfence
6.4 Medium Slider comparison image before and after Plugin slider-comparison-image-before-and-after Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.8.3 CVE-2024-8543 Wordfence
6.4 Medium Nova Blocks by Pixelgrade Plugin nova-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 2.1.7 CVE-2024-8241 Wordfence
4.4 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Cross-Site Scripting Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via content Parameter ≤ 6.4.5.0 CVE-2024-7618 Wordfence
4.4 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Cross-Site Scripting Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 6.4.5.0 CVE-2024-7655 Wordfence
4.8 Medium Starbox Plugin starbox Cross-Site Scripting Admin+ Stored XSS < 3.5.2 Fixed in 3.5.2 CVE-2024-7955 WPScan
4.8 Medium Floating Contact Button Plugin floating-contact Cross-Site Scripting Admin+ Stored XSS < 2.8 Fixed in 2.8 CVE-2024-7891 WPScan
4.8 Medium Pocket Widget Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 0.1.3 CVE-2024-7918 WPScan
4.7 Medium Snapshot Backup Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 2.1.1 CVE-2024-7689 WPScan
6.5 Medium AZIndex Plugin Cross-Site Request Forgery Index Deletion via CSRF No login needed ≤ 0.8.1 CVE-2024-7688 WPScan
6.1 Medium AZIndex Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.8.1 CVE-2024-7687 WPScan
4.8 Medium EventON Plugin eventon-lite Cross-Site Scripting Admin+ Stored XSS < 2.2.17 Fixed in 2.2.17 CVE-2024-6910 WPScan
4.8 Medium Popup Maker Plugin popup-maker Cross-Site Scripting Admin+ Stored XSS < 1.19.1 Fixed in 1.19.1 CVE-2024-5561 WPScan
6.1 Medium Forminator Plugin forminator Cross-Site Scripting Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the… No login needed prior to 1.34.1 CVE-2024-45625 jpcert
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery Settings Update via CSRF No login needed < 1.0.3 Fixed in 1.0.3 CVE-2024-6925 WPScan
5.4 Medium WP MultiTasking Plugin Cross-Site Scripting Reflected XSS via Shortcode ≤ 0.1.12 CVE-2024-6859 WPScan
6.5 Medium WP MultiTasking Plugin Cross-Site Request Forgery SMTP Settings Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6856 WPScan
6.5 Medium WP MultiTasking Plugin Cross-Site Request Forgery Exit Popup Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6855 WPScan
6.5 Medium WP MultiTasking Plugin Cross-Site Request Forgery Welcome Popup Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6853 WPScan
6.5 Medium WP MultiTasking Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.1.12 CVE-2024-6852 WPScan
5.3 Medium Cost Calculator Builder PRO Plugin cost-calculator-builder Price Manipulation Unauthenticated Price Manipulation No login needed ≤ 3.2.1 CVE-2024-6010 Wordfence
6.6 Medium Customizer Export/Import Plugin customizer-export-import Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload via Customization Settings Import ≤ 0.9.7 CVE-2024-7620 Wordfence
6.4 Medium Preloader Plus – WordPress Loading Screen Plugin preloader-plus Cross-Site Scripting WordPress Loading Screen Plugin <= 2.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.2.1 CVE-2024-6849 Wordfence
4.3 Medium Big File Uploads Plugin tuxedo-big-file-uploads Arbitrary File Upload Authenticated (Author+) Full Path Disclosure ≤ 2.1.2 CVE-2024-8538 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget ≤ 2.1.8 CVE-2024-7611 Wordfence
6.4 Medium Advanced Sermons Plugin advanced-sermons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.3 CVE-2024-7599 Wordfence
4.3 Medium Revision Manager TMC Plugin revision-manager-tmc Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 2.8.19 CVE-2024-7622 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only