WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 1,351–1,400 of 1,407 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 28 of 29
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Brizy – Page Builder Plugin brizy Path Traversal Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.40 CVE-2024-1165 Wordfence
4.3 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Request Forgery Cross-Site Request Fogery via cp_shortcode_refresh No login needed ≤ 1.0.253 CVE-2024-1362 Wordfence
4.3 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Request Forgery Cross-Site Request Fogery via extend_builder No login needed ≤ 1.0.253 CVE-2024-1361 Wordfence
4.6 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button ≤ 1.8.2 CVE-2024-1590 Wordfence
4.3 Medium Themify Builder Plugin themify-builder Cross-Site Request Forgery WordPress Themify Builder Plugin <= 7.0.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2024-24872 Patchstack
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery ≤ 5.9.8 CVE-2024-1171 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion ≤ 5.9.8 CVE-2024-1172 Wordfence
4.3 Medium Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization ≤ 2.3.41 CVE-2024-1218 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1276 Wordfence
7.6 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation ≤ 2.3.41 CVE-2024-1217 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.18.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via get_image_alt ≤ 3.18.3 CVE-2024-0506 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.8 CVE-2024-1236 Wordfence
4.3 Medium SKT Page Builder Plugin skt-builder Broken Access Control Missing Authorization to Authenticated(Subscriber+) Content Injection ≤ 4.1 CVE-2024-1337 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Raw Content ≤ 4.8.0 CVE-2024-1159 Wordfence
5.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Link ≤ 4.8.0 CVE-2024-1160 Wordfence
5.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL ≤ 4.8.0 CVE-2024-1157 Wordfence
7.5 High popup-builder Plugin Server-Side Request Forgery Admin+ SSRF & File Read No login needed < 4.2.6 Fixed in 4.2.6 CVE-2023-6294 WPScan
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
5.9 Medium Chartify – WordPress Chart Plugin chart-builder Cross-Site Scripting WordPress Chartify Plugin <= 2.0.6 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-47526 Patchstack
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping ≤ 5.9.4 CVE-2024-0586 Wordfence
7.2 High Unlimited Addons for WPBakery Page Builder Plugin unlimited-addons-for-wpbakery-page-builder Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload ≤ 1.0.42 CVE-2023-6925 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.7 CVE-2024-0954 Wordfence
8.2 High Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Broken Access Control Missing Authorization via seedprod_lite_new_lpage No login needed ≤ 6.15.21 CVE-2024-1072 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insuf… 1.12.11 CVE-2024-0834 Wordfence
5.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image URl ≤ 5.9.4 CVE-2024-0585 Wordfence
8.2 High User Profile Builder Plugin profile-builder Broken Access Control Missing Authorization to Plugin Settings Change via wppb_two_factor_authentication_settings_update No login needed ≤ 3.10.8 CVE-2024-0324 Wordfence
7.1 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting WordPress RegistrationMagic Plugin <= 5.2.4.1 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 5.2.4.1 Fixed in 5.2.4.2 CVE-2023-51509 Patchstack
5.9 Medium Everest Forms – Build Contact Forms, Surveys, Polls, Application Forms, and more with Ease! Plugin everest-forms Cross-Site Scripting WordPress Everest Forms Plugin <= 2.0.4.1 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.4.1 Fixed in 2.0.5 CVE-2023-51695 Patchstack
6.5 Medium Icegram Engage – WordPress Lead Generation, Popup Builder, CTA, Optins and Email List Building Plugin icegram Cross-Site Scripting WordPress Icegram Plugin <= 3.1.19 is vulnerable to Cross Site Scripting (XSS) ≤ 3.1.19 Fixed in 3.1.20 CVE-2023-51532 Patchstack
5.9 Medium Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content Plugin brave-popup-builder Cross-Site Scripting WordPress Brave Popup Builder Plugin <= 0.6.2 is vulnerable to Cross Site Scripting (XSS) ≤ 0.6.2 Fixed in 0.6.3 CVE-2023-51534 Patchstack
5.9 Medium CRM Perks Forms – WordPress Form Builder Plugin crm-perks-forms Cross-Site Scripting WordPress CRM Perks Forms Plugin <= 1.1.2 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.2 Fixed in 1.1.3 CVE-2023-51536 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting WordPress Page Builder: Live Composer Plugin <= 1.5.23 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.23 Fixed in 1.5.24 CVE-2023-52193 Patchstack
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read() No login needed ≤ 8.5.6 CVE-2024-1130 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred() No login needed ≤ 8.5.6 CVE-2024-1129 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via restore_records() No login needed ≤ 8.5.6 CVE-2024-0907 Wordfence
4.3 Medium Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder Plugin droit-elementor-addons Cross-Site Request Forgery WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.5 CVE-2024-22136 Patchstack
8.8 High Profile Builder Pro Plugin Cross-Site Request Forgery WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22140 Patchstack
7.5 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms Plugin <= 2.3.36 is vulnerable to Insecure Direct Object References (IDOR) No login needed ≤ 2.3.36 Fixed in 2.3.37 CVE-2024-22305 Patchstack
6.5 Medium Profile Builder Pro Plugin Information Disclosure WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Sensitive Data Exposure ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22141 Patchstack
4.3 Medium Ultimate Addons for Beaver Builder – Lite Plugin ultimate-addons-for-beaver-builder-lite Broken Access Control Lite Plugin <= 1.5.5 is vulnerable to Broken Access Control No login needed ≤ 1.5.5 Fixed in 1.5.6 CVE-2023-23882 Patchstack
4.3 Medium Contact Form & Lead Form Elementor Builder Plugin Broken Access Control Multiple Subscriber+ Settings Update < 1.7.4 Fixed in 1.7.4 CVE-2022-23180 WPScan
4.8 Medium Contact Form & Lead Form Elementor Builder Plugin Cross-Site Scripting Multiple Admin+ Stored Cross-Site Scripting < 1.7.0 Fixed in 1.7.0 CVE-2022-23179 WPScan
7.1 High Profile Builder Pro Plugin Cross-Site Scripting WordPress Profile Builder Pro Plugin <= 3.10.0 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.1 CVE-2024-22142 Patchstack
6.4 Medium Oxygen Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 4.8 CVE-2023-6938 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.6 CVE-2023-7071 Wordfence
4.3 Medium Profile Builder Plugin profile-builder Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure via user_meta Shortcode ≤ 3.10.6 CVE-2023-6504 Wordfence
4.3 Medium LightStart – Maintenance Mode, Coming Soon and Landing Page Builder Plugin wp-maintenance-mode Broken Access Control Maintenance Mode, Coming Soon and Landing Page Builder <= 2.6.8 - Missing Authorization ≤ 2.6.8 CVE-2023-7019 Wordfence
7.2 High Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload animation and page builder blocks <= 7.6.2 - Authenticated (Administrator+) Arbitrary File Upload ≤ 7.6.2 CVE-2023-6636 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.239 CVE-2023-6988 Wordfence
6.4 Medium Ibtana – WordPress Website Builder Plugin ibtana-visual-editor Cross-Site Scripting WordPress Website Builder <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.2 CVE-2023-6684 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only