WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,901–13,950 of 16,945 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 279 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium ARI Fancy Lightbox Plugin ari-fancy-lightbox Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2024-47310 Patchstack
5.1 Medium Catch Base Plugin catch-base Cross-Site Scripting ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-47313 Patchstack
7.1 High WS Form LITE Plugin ws-form Cross-Site Scripting No login needed ≤ 1.9.238 Fixed in 1.9.244 CVE-2024-47320 Patchstack
7.1 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47322 Patchstack
7.1 High Share This Image Plugin share-this-image Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.01 Fixed in 2.02 CVE-2024-47326 Patchstack
7.1 High GEO my Plugin geo-my-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.5.0.3 Fixed in 4.5.0.4 CVE-2024-47327 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 6.4.0 Fixed in 6.4.1 CVE-2024-47329 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.11 Fixed in 2.5.12 CVE-2024-47332 Patchstack
7.1 High Loops & Logic Plugin tangible-loops-and-logic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.4 Fixed in 4.1.5 CVE-2024-47333 Patchstack
5.9 Medium Terms descriptions Plugin terms-descriptions Cross-Site Scripting ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-47336 Patchstack
7.1 High WP Mail Catcher Plugin wp-mail-catcher Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-47339 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.89 Fixed in 2.2.90 CVE-2024-47340 Patchstack
7.1 High WP-DownloadManager Plugin wp-downloadmanager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.68.8 Fixed in 1.68.9 CVE-2024-47341 Patchstack
6.5 Medium Accordion Plugin accordions Cross-Site Scripting ≤ 2.2.99 Fixed in 2.2.100 CVE-2024-47342 Patchstack
6.5 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.2.4 - Cross Site Scripting (XSS) ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-47343 Patchstack
5.9 Medium Starter Templates Plugin astra-sites Cross-Site Scripting ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-47345 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.9.1 Fixed in 4.9.9.2 CVE-2024-47346 Patchstack
7.1 High Chartify Plugin chart-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2024-47347 Patchstack
7.1 High YellowPencil Visual CSS Style Editor Plugin yellow-pencil-visual-theme-customizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6.4 Fixed in 7.6.5 CVE-2024-47348 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 11.50 Fixed in 11.51 CVE-2024-47349 Patchstack
7.1 High WP Bulk Delete Plugin wp-bulk-delete Cross-Site Scripting No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-47352 Patchstack
6.5 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-47355 Patchstack
5.1 Medium Create Plugin create Cross-Site Scripting ≤ 2.9.1 Fixed in 2.9.2 CVE-2024-47356 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.12.0 Fixed in 3.12.1 CVE-2024-47357 Patchstack
7.1 High BA Book Everything Plugin ba-book-everything Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-47360 Patchstack
6.5 Medium Blockspare Plugin blockspare Cross-Site Scripting ≤ 3.2.4 Fixed in 3.2.5 CVE-2024-47363 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-47364 Patchstack
6.5 Medium Automatically Hierarchic Categories in Menu Plugin automatically-hierarchic-categories-in-menu Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2024-47365 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting ≤ 1.13.6 Fixed in 1.13.7 CVE-2024-47366 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.13.0 Fixed in 4.13.1 CVE-2024-47367 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.33 Fixed in 2.1.34 CVE-2024-47368 Patchstack
7.1 High Social Auto Poster Plugin social-auto-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.15 Fixed in 5.3.16 CVE-2024-47369 Patchstack
6.5 Medium Author Avatars List/Block Plugin author-avatars Cross-Site Scripting ≤ 2.1.21 Fixed in 2.1.22 CVE-2024-47370 Patchstack
5.9 Medium WP MyLinks Plugin wp-mylinks Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-47371 Patchstack
5.9 Medium TNC PDF viewer Plugin pdf-viewer-by-themencode Cross-Site Scripting ≤ 3.1.0 Fixed in 3.2.0 CVE-2024-47372 Patchstack
6.5 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting ≤ 6.5.0.2 Fixed in 6.5.1 CVE-2024-47373 Patchstack
7.1 High LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting No login needed ≤ 6.5.0.2 Fixed in 6.5.1 CVE-2024-47374 Patchstack
6.5 Medium XLTab – Accordions and Tabs for Elementor Page Builder Plugin xl-tab Cross-Site Scripting Accordions and Tabs for Elementor Page Builder plugin <= 1.3 - Cross Site Scripting (XSS) ≤ 1.3 Fixed in 1.4 CVE-2024-47375 Patchstack
5.9 Medium Slideshow Gallery Plugin slideshow-gallery Cross-Site Scripting ≤ 1.8.3 Fixed in 1.8.4 CVE-2024-47376 Patchstack
5.9 Medium BuddyForms Plugin buddyforms Cross-Site Scripting ≤ 2.8.12 Fixed in 2.8.13 CVE-2024-47377 Patchstack
7.1 High WPCOM Member Plugin wpcom-member Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 Fixed in 1.5.4.1 CVE-2024-47378 Patchstack
7.1 High Web Directory Free Plugin web-directory-free Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-47379 Patchstack
7.1 High WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6.3 Fixed in 3.6.5 CVE-2024-47380 Patchstack
5.9 Medium Depicter Slider Plugin depicter Cross-Site Scripting ≤ 3.2.2 Fixed in 3.5.0 CVE-2024-47381 Patchstack
6.5 Medium Page-list Plugin page-list Cross-Site Scripting ≤ 5.6 Fixed in 5.7 CVE-2024-47382 Patchstack
5.9 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.0.8.8 Fixed in 2.0.9 CVE-2024-47383 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.20.13 Fixed in 6.21.01 CVE-2024-47384 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.8.4 Fixed in 4.9.0 CVE-2024-47385 Patchstack
7.1 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-47386 Patchstack
5.9 Medium Search Atlas SEO Plugin metasync Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-47387 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only