WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 13,951–14,000 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 280 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control Missing Authorization to Plugin Deactivation and Data Deletion No login needed ≤ 1.5.6 CVE-2024-7032 Wordfence
4.3 Medium Smart Online Order for Clover Plugin clover-online-orders Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Data Update ≤ 1.5.6 CVE-2024-7030 Wordfence
4.3 Medium Event Espresso 4 Decaf – Event Registration Event Ticketing Plugin event-espresso-decaf Broken Access Control Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification ≤ 4.10.46.decaf CVE-2024-6883 Wordfence
5.3 Medium WP Testimonial Widget Plugin wp-testimonial-widget Broken Access Control Missing Authorization No login needed ≤ 3.1 CVE-2024-7390 Wordfence
5.5 Medium WordSurvey Plugin wordsurvey Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via sounding_title Parameter ≤ 3.2 CVE-2024-6767 Wordfence
4.3 Medium Hide My Site Plugin hide-my-site Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.2 CVE-2024-5880 Wordfence
6.4 Medium Popup Maker Plugin popup-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.19.0 CVE-2024-7054 Wordfence
6.4 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel Widget ≤ 2.1.4 CVE-2024-5576 Wordfence
6.4 Medium WP Last Modified Info Plugin wp-last-modified-info Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via lmt-post-modified-info Shortcode ≤ 1.9.0 CVE-2024-6864 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via TP Page Scroll Widget ≤ 5.6.2 CVE-2024-6575 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Widget ≤ 5.6.2 CVE-2024-5763 Wordfence
5.5 Medium Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Arbitrary File Upload Authenticated (Administrator+) Arbitrary JavaScript File Uploads 2.0 – 2.13.9 CVE-2024-7775 Wordfence
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed ≤ 3.13.0 CVE-2024-5940 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Limited Information Exposure No login needed ≤ 3.13.0 CVE-2024-5939 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.14.1 - Missing Authorization to Authenticated (Subscriber+) Limited File Deletion ≤ 3.14.1 CVE-2024-5941 Wordfence
6.1 Medium BP Profile Search Plugin bp-profile-search Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 5.7.5 CVE-2024-7850 Wordfence
5.4 Medium Plugin Notes Plus Plugin plugin-notes-plus Broken Access Control Arbitrary Content Deletion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-43326 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.1.0 Fixed in 6.0.1.1 CVE-2024-43317 Patchstack
5.3 Medium Void Elementor Post Grid Addon for Elementor Page builder Plugin void-elementor-post-grid-addon-for-elementor-page-builder Local File Inclusion ≤ 2.3 Fixed in 2.4 CVE-2024-43281 Patchstack
4.7 Medium Salon booking system Plugin salon-booking-system Open Redirect No login needed ≤ 10.8.1 Fixed in 10.9 CVE-2024-43280 Patchstack
5.3 Medium Icegram Plugin icegram Authentication Bypass Unauthenticated Unpublished Campaign Viewer No login needed ≤ 3.1.24 Fixed in 3.1.25 CVE-2024-43272 Patchstack
4.7 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Open Redirect No login needed ≤ 1.9 Fixed in 1.9.1 CVE-2024-43236 Patchstack
6.1 Medium SmartSearch WP Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.4.5 Fixed in 2.4.5 CVE-2024-6843 WPScan
5.3 Medium Sensei LMS Plugin sensei-lms Broken Access Control No login needed ≤ 4.23.1, ≤ 4.23.1.1.23.1 Fixed in 4.24.0 CVE-2024-35686 Patchstack
4.3 Medium Masteriyo - LMS Plugin learning-management-system Broken Access Control Insecure Direct Object Reference (IDOR) ≤ 1.11.4 Fixed in 1.11.5 CVE-2024-43239 Patchstack
5.4 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-43266 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-43288 Patchstack
5.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.3.100 Fixed in 3.3.101 CVE-2024-43322 Patchstack
5.3 Medium Propovoice CRM Plugin propovoice Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.7.6.4 CVE-2024-43350 Patchstack
6.5 Medium Busiprof Theme busiprof Cross-Site Scripting ≤ 2.4.8 CVE-2024-43262 Patchstack
6.5 Medium Visual Composer Starter Theme visual-composer-starter Cross-Site Scripting ≤ 3.3 CVE-2024-43263 Patchstack
6.5 Medium Mega Addons For Elementor Plugin ultimate-addons-for-elementor Cross-Site Scripting ≤ 1.9 CVE-2024-43267 Patchstack
6.5 Medium Meta Field Block Plugin display-a-meta-field-as-block Cross-Site Scripting ≤ 1.2.13 Fixed in 1.2.14 CVE-2024-43278 Patchstack
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.5.1 Fixed in 3.6.0 CVE-2024-43284 Patchstack
5.9 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Cross-Site Scripting ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-43291 Patchstack
5.9 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.16 Fixed in 1.4.17 CVE-2024-43292 Patchstack
6.5 Medium Bold Timeline Lite Plugin bold-timeline-lite Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-43294 Patchstack
6.5 Medium Custom Layouts – Post + Product grids made easy Plugin custom-layouts Cross-Site Scripting Post + Product grids made easy plugin <= 1.4.11 - Cross Site Scripting (XSS) ≤ 1.4.11 Fixed in 1.4.12 CVE-2024-43305 Patchstack
6.5 Medium Structured Content Plugin structured-content Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-43307 Patchstack
6.5 Medium Gutentor - Gutenberg Blocks - Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor plugin <= 3.3.5 - Cross Site Scripting (XSS) ≤ 3.3.5 Fixed in 3.3.6 CVE-2024-43308 Patchstack
6.5 Medium WP Telegram Widget and Join Link Plugin wptelegram-widget Cross-Site Scripting ≤ 2.1.27 Fixed in 2.1.28 CVE-2024-43309 Patchstack
6.5 Medium e2pdf Plugin e2pdf Cross-Site Scripting Export To Pdf Tool for WordPress plugin <= 1.25.05 - Cross Site Scripting (XSS) ≤ 1.25.05 Fixed in 1.25.11 CVE-2024-43318 Patchstack
6.5 Medium Livemesh Addons for WPBakery Page Builder Plugin addons-for-visual-composer Cross-Site Scripting ≤ 3.9 Fixed in 3.9.1 CVE-2024-43320 Patchstack
6.5 Medium Team Showcase Plugin team Cross-Site Scripting ≤ 1.22.23 Fixed in 1.22.24 CVE-2024-43321 Patchstack
5.9 Medium Clever Addons for Elementor Plugin cafe-lite Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-43324 Patchstack
6.5 Medium Allegiant Theme allegiant Cross-Site Scripting ≤ 1.2.7 CVE-2024-43329 Patchstack
6.5 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks plugin <= 1.8.8 - Cross Site Scripting (XSS) ≤ 1.8.8 Fixed in 1.8.9 CVE-2024-43335 Patchstack
5.9 Medium WooCommerce Plugin woocommerce Cross-Site Scripting ≤ 9.1.2 Fixed in 9.1.3 CVE-2024-39666 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.6.4 Fixed in 2.0.0 CVE-2024-43342 Patchstack
6.5 Medium Icegram Plugin icegram Cross-Site Scripting Ultimate WP Popup Builder, Lead Generation, Optins, and CTA plugin <= 3.1.25 - Cross Site Scripting (XSS) ≤ 3.1.25 Fixed in 3.1.26 CVE-2024-43344 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only