WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 14,001–14,050 of 17,733 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 281 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Modal Window Plugin modal-window Cross-Site Scripting create popup modal window plugin <= 6.0.3 - Cross Site Scripting (XSS) ≤ 6.0.3 Fixed in 6.0.4 CVE-2024-43346 Patchstack
5.9 Medium Button contact VR Plugin button-contact-vr Cross-Site Scripting ≤ 4.7.3 CVE-2024-43347 Patchstack
6.5 Medium All Bootstrap Blocks Plugin all-bootstrap-blocks Cross-Site Scripting ≤ 1.3.19 Fixed in 1.3.20 CVE-2024-43349 Patchstack
6.5 Medium Bravada Theme bravada Cross-Site Scripting ≤ 1.1.2 CVE-2024-43351 Patchstack
6.5 Medium GivingPress Lite Theme givingpress-lite Cross-Site Scripting ≤ 1.8.6 CVE-2024-43352 Patchstack
6.5 Medium myCred Plugin mycred Cross-Site Scripting ≤ 2.7.2 Fixed in 2.7.3 CVE-2024-43353 Patchstack
6.4 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0.37 CVE-2024-7703 Wordfence
6.8 Medium BackWPup Plugin backwpup Path Traversal Authenticated (Administrator+) Directory Traversal ≤ 4.0.1 CVE-2023-5505 Wordfence
4.3 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed ≤ 1.8.1 CVE-2023-3408 Wordfence
5.4 Medium Bricks Theme Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed ≤ 1.8.1 CVE-2023-3409 Wordfence
6.1 Medium Slideshow, Image Slider by 2J Plugin 2j-slideshow Cross-Site Scripting Reflected Cross-Site Scripting via 'post' No login needed ≤ 1.3.54 CVE-2023-4604 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Player Update No login needed ≤ 2.0.73 CVE-2023-4025 Wordfence
4.7 Medium Short URL Plugin shorten-url Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed ≤ 1.6.8 CVE-2023-1604 Wordfence
5.3 Medium LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… Plugin ladipage Broken Access Control Missing Authorization via init_endpoint No login needed ≤ 4.3 CVE-2023-4730 Wordfence
6.1 Medium Admission AppManager Plugin admission-appmanager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2023-4507 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Player Deletion No login needed ≤ 2.0.73 CVE-2023-4024 Wordfence
6.5 Medium LOGIN AND REGISTRATION ATTEMPTS LIMIT<= Plugin login-attempts-limit-wp Other IP Address Spoofing to Protection Mechanism Bypass No login needed ≤ 2.1 CVE-2022-4532 Wordfence
5.3 Medium Radio Player Plugin radio-player Broken Access Control Missing Authorization to Settings Update No login needed ≤ 2.0.73 CVE-2023-4027 Wordfence
6.4 Medium JetElements Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.20 CVE-2024-7144 Wordfence
6.4 Medium JetSearch Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.5.2 CVE-2024-7136 Wordfence
6.4 Medium JetBlocks Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.12 CVE-2024-7147 Wordfence
4.2 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery No login needed ≤ 1.8.7 CVE-2024-7501 Wordfence
4.3 Medium Theme My Login Plugin theme-my-login Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 7.1.7 CVE-2024-7422 Wordfence
4.4 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.4.17.1 CVE-2022-3399 Wordfence
4.3 Medium Custom Field For WP Job Manager Plugin custom-field-for-wp-job-manager Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure via Shortcode ≤ 1.2 CVE-2023-7049 Wordfence
5.3 Medium Relevanssi Plugin relevanssi Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.25.1, ≤ 4.22.2 CVE-2024-7630 Wordfence
5.3 Medium Newsletters Plugin newsletters-lite Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 4.9.9 CVE-2024-7411 Wordfence
4.3 Medium ElementsKit Pro Plugin Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 3.6.6 CVE-2024-7063 Wordfence
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.6.5 CVE-2024-7064 Wordfence
5.8 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed ≤ 1.3.6 CVE-2024-7420 Wordfence
6.4 Medium Sheet to Table Live Sync for Google Sheet Plugin sheet-to-wp-table-for-google-sheet Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode ≤ 1.0.1 CVE-2024-6532 Wordfence
6.4 Medium Gutenberg Blocks, Page Builder – ComboBlocks Plugin post-grid Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block ≤ 2.2.84 CVE-2024-7588 Wordfence
6.5 Medium WPSection Plugin wpsection Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-43165 Patchstack
6.5 Medium Event Manager for WooCommerce Plugin mage-eventpress Local File Inclusion ≤ 4.2.1 Fixed in 4.2.2 CVE-2024-43138 Patchstack
6.5 Medium BetterDocs Plugin betterdocs Local File Inclusion ≤ 3.5.8 Fixed in 3.5.9 CVE-2024-43129 Patchstack
6.5 Medium WooCommerce Product Table Lite Plugin wc-product-table-lite Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.5.1 Fixed in 3.8.6 CVE-2024-43128 Patchstack
6.5 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object References (IDOR) ≤ 4.2.6.8.2 Fixed in 4.2.6.9 CVE-2024-39642 Patchstack
5.3 Medium Send Users Email Plugin send-users-email Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-38760 Patchstack
5.3 Medium Coming Soon Plugin responsive-coming-soon-page Information Disclosure Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure No login needed ≤ 1.6.3 CVE-2024-38756 Patchstack
6.5 Medium Zoho Campaigns Plugin zoho-campaigns Cross-Site Scripting ≤ 2.0.8 Fixed in 2.1.0 CVE-2024-38752 Patchstack
5.3 Medium Olive One Click Demo Import Plugin olive-one-click-demo-import Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1.2 CVE-2024-38749 Patchstack
5.3 Medium MBE eShip Plugin mail-boxes-etc Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.2 CVE-2024-38742 Patchstack
4.8 Medium Generate Images – Magic Post Thumbnail Plugin Cross-Site Scripting Magic Post Thumbnail < 5.2.8 - Admin+ Stored XSS < 5.2.8 Fixed in 5.2.8 CVE-2024-6724 WPScan
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets ≤ 5.7.2 CVE-2024-7247 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter ≤ 5.9.27 CVE-2024-7092 Wordfence
4.0 Medium WP Bannerize Pro Plugin wp-bannerize-pro Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 1.9.0 CVE-2024-7388 Wordfence
5.3 Medium SmartMag Theme smartmag-responsive-retina-wordpress-magazine Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 10.1.0 Fixed in 10.1.0 CVE-2024-37930 Patchstack
5.3 Medium WP2Speed Faster Plugin wp2speed Information Disclosure Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure No login needed ≤ 1.0.1 CVE-2024-37924 Patchstack
5.9 Medium Slider by Soliloquy Plugin soliloquy-lite Broken Access Control Broken Access Control to XSS ≤ 2.7.6 Fixed in 2.7.7 CVE-2024-35775 Patchstack
6.5 Medium Card Elements for Elementor Plugin card-elements-for-elementor Cross-Site Scripting ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-43123 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only