WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 14,001–14,050 of 17,733 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Modal Window | Cross-Site Scripting create popup modal window plugin <= 6.0.3 - Cross Site Scripting (XSS) |
≤ 6.0.3 Fixed in 6.0.4 |
CVE-2024-43346 |
Patchstack | |
| 5.9 Medium | Button contact VR | Cross-Site Scripting |
≤ 4.7.3 |
CVE-2024-43347 |
Patchstack | |
| 6.5 Medium | All Bootstrap Blocks | Cross-Site Scripting |
≤ 1.3.19 Fixed in 1.3.20 |
CVE-2024-43349 |
Patchstack | |
| 6.5 Medium | Bravada | Cross-Site Scripting |
≤ 1.1.2 |
CVE-2024-43351 |
Patchstack | |
| 6.5 Medium | GivingPress Lite | Cross-Site Scripting |
≤ 1.8.6 |
CVE-2024-43352 |
Patchstack | |
| 6.5 Medium | myCred | Cross-Site Scripting |
≤ 2.7.2 Fixed in 2.7.3 |
CVE-2024-43353 |
Patchstack | |
| 6.4 Medium | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | Cross-Site Scripting Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload |
≤ 4.0.37 |
CVE-2024-7703 |
Wordfence | |
| 6.8 Medium | BackWPup | Path Traversal Authenticated (Administrator+) Directory Traversal |
≤ 4.0.1 |
CVE-2023-5505 |
Wordfence | |
| 4.3 Medium | Bricks | Cross-Site Request Forgery Cross-Site Request Forgery via save_settings No login needed |
≤ 1.8.1 |
CVE-2023-3408 |
Wordfence | |
| 5.4 Medium | Bricks | Cross-Site Request Forgery Cross-Site Request Forgery via reset_settings No login needed |
≤ 1.8.1 |
CVE-2023-3409 |
Wordfence | |
| 6.1 Medium | Slideshow, Image Slider by 2J | Cross-Site Scripting Reflected Cross-Site Scripting via 'post' No login needed |
≤ 1.3.54 |
CVE-2023-4604 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Player Update No login needed |
≤ 2.0.73 |
CVE-2023-4025 |
Wordfence | |
| 4.7 Medium | Short URL | Cross-Site Request Forgery Cross-Site Request Forgery via configuration_page No login needed |
≤ 1.6.8 |
CVE-2023-1604 |
Wordfence | |
| 5.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Broken Access Control Missing Authorization via init_endpoint No login needed |
≤ 4.3 |
CVE-2023-4730 |
Wordfence | |
| 6.1 Medium | Admission AppManager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2023-4507 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Player Deletion No login needed |
≤ 2.0.73 |
CVE-2023-4024 |
Wordfence | |
| 6.5 Medium | LOGIN AND REGISTRATION ATTEMPTS LIMIT<= | Other IP Address Spoofing to Protection Mechanism Bypass No login needed |
≤ 2.1 |
CVE-2022-4532 |
Wordfence | |
| 5.3 Medium | Radio Player | Broken Access Control Missing Authorization to Settings Update No login needed |
≤ 2.0.73 |
CVE-2023-4027 |
Wordfence | |
| 6.4 Medium | JetElements | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.20 |
CVE-2024-7144 |
Wordfence | |
| 6.4 Medium | JetSearch | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.5.2 |
CVE-2024-7136 |
Wordfence | |
| 6.4 Medium | JetBlocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.12 |
CVE-2024-7147 |
Wordfence | |
| 4.2 Medium | Download Plugins and Themes from Dashboard | Cross-Site Request Forgery No login needed |
≤ 1.8.7 |
CVE-2024-7501 |
Wordfence | |
| 4.3 Medium | Theme My Login | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 7.1.7 |
CVE-2024-7422 |
Wordfence | |
| 4.4 Medium | Cookie Notice & Compliance for GDPR / CCPA | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.4.17.1 |
CVE-2022-3399 |
Wordfence | |
| 4.3 Medium | Custom Field For WP Job Manager | Broken Access Control Insecure Direct Object Reference to Sensitive Information Exposure via Shortcode |
≤ 1.2 |
CVE-2023-7049 |
Wordfence | |
| 5.3 Medium | Relevanssi | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 2.25.1, ≤ 4.22.2 |
CVE-2024-7630 |
Wordfence | |
| 5.3 Medium | Newsletters | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 4.9.9 |
CVE-2024-7411 |
Wordfence | |
| 4.3 Medium | ElementsKit Pro | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure |
≤ 3.6.6 |
CVE-2024-7063 |
Wordfence | |
| 6.4 Medium | ElementsKit Pro | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.6.5 |
CVE-2024-7064 |
Wordfence | |
| 5.8 Medium | Insert PHP Code Snippet | Cross-Site Request Forgery Cross-Site Request Forgery to Code Snippet Activate/Deactivate/Deletion No login needed |
≤ 1.3.6 |
CVE-2024-7420 |
Wordfence | |
| 6.4 Medium | Sheet to Table Live Sync for Google Sheet | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STWT_Sheet_Table Shortcode |
≤ 1.0.1 |
CVE-2024-6532 |
Wordfence | |
| 6.4 Medium | Gutenberg Blocks, Page Builder – ComboBlocks | Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block |
≤ 2.2.84 |
CVE-2024-7588 |
Wordfence | |
| 6.5 Medium | WPSection | Local File Inclusion Contributor+ Limited Local File Inclusion |
≤ 1.3.8 Fixed in 1.3.9 |
CVE-2024-43165 |
Patchstack | |
| 6.5 Medium | Event Manager for WooCommerce | Local File Inclusion |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2024-43138 |
Patchstack | |
| 6.5 Medium | BetterDocs | Local File Inclusion |
≤ 3.5.8 Fixed in 3.5.9 |
CVE-2024-43129 |
Patchstack | |
| 6.5 Medium | WooCommerce Product Table Lite | Remote Code Execution Arbitrary Code Execution No login needed |
≤ 3.5.1 Fixed in 3.8.6 |
CVE-2024-43128 |
Patchstack | |
| 6.5 Medium | LearnPress | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 4.2.6.8.2 Fixed in 4.2.6.9 |
CVE-2024-39642 |
Patchstack | |
| 5.3 Medium | Send Users Email | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2024-38760 |
Patchstack | |
| 5.3 Medium | Coming Soon | Information Disclosure Responsive Coming Soon & Maintenance Mode plugin <= 1.6.3 - Sensitive Data Exposure No login needed |
≤ 1.6.3 |
CVE-2024-38756 |
Patchstack | |
| 6.5 Medium | Zoho Campaigns | Cross-Site Scripting |
≤ 2.0.8 Fixed in 2.1.0 |
CVE-2024-38752 |
Patchstack | |
| 5.3 Medium | Olive One Click Demo Import | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.1.2 |
CVE-2024-38749 |
Patchstack | |
| 5.3 Medium | MBE eShip | Information Disclosure Sensitive Data Exposure No login needed |
≤ 2.1.2 |
CVE-2024-38742 |
Patchstack | |
| 4.8 Medium | Generate Images – Magic Post Thumbnail | Cross-Site Scripting Magic Post Thumbnail < 5.2.8 - Admin+ Stored XSS |
< 5.2.8 Fixed in 5.2.8 |
CVE-2024-6724 |
WPScan | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets |
≤ 5.7.2 |
CVE-2024-7247 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.27 - Authenticated (Contributor+) Stored Cross-Site Scripting via no_more_items_text Parameter |
≤ 5.9.27 |
CVE-2024-7092 |
Wordfence | |
| 4.0 Medium | WP Bannerize Pro | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 1.9.0 |
CVE-2024-7388 |
Wordfence | |
| 5.3 Medium | SmartMag | Information Disclosure Sensitive Data Exposure via Log File No login needed |
≤ 10.1.0 Fixed in 10.1.0 |
CVE-2024-37930 |
Patchstack | |
| 5.3 Medium | WP2Speed Faster | Information Disclosure Optimize PageSpeed Insights Score 90-100 plugin <= 1.0.1 - Sensitive Data Exposure No login needed |
≤ 1.0.1 |
CVE-2024-37924 |
Patchstack | |
| 5.9 Medium | Slider by Soliloquy | Broken Access Control Broken Access Control to XSS |
≤ 2.7.6 Fixed in 2.7.7 |
CVE-2024-35775 |
Patchstack | |
| 6.5 Medium | Card Elements for Elementor | Cross-Site Scripting |
≤ 1.2.2 Fixed in 1.2.3 |
CVE-2024-43123 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.