WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,051–14,100 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 282 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Mantra Theme mantra Cross-Site Scripting ≤ 3.3.2 CVE-2024-44056 Patchstack
6.5 Medium Nirvana Theme nirvana Cross-Site Scripting ≤ 1.6.3 CVE-2024-44057 Patchstack
6.5 Medium Parabola Theme parabola Cross-Site Scripting ≤ 2.4.1 CVE-2024-44058 Patchstack
6.5 Medium Custom Query Blocks Plugin post-type-archive-mapping Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4.0 CVE-2024-44059 Patchstack
7.1 High Filmix Theme filmix Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-44060 Patchstack
6.5 Medium Custom Field Template Plugin custom-field-template Cross-Site Scripting ≤ 2.6.5 CVE-2024-44062 Patchstack
6.5 Medium Happyforms Plugin happyforms Cross-Site Scripting ≤ 1.26.0 Fixed in 1.26.1 CVE-2024-44063 Patchstack
5.9 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45455 Patchstack
6.5 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45456 Patchstack
6.5 Medium Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45457 Patchstack
7.1 High Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45458 Patchstack
7.1 High Product Slider for WooCommerce Plugin woocommerce-products-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.50 Fixed in 1.13.51 CVE-2024-45459 Patchstack
5.9 Medium Flipping Cards Plugin flipping-cards Cross-Site Scripting ≤ 1.30 Fixed in 1.31 CVE-2024-45460 Patchstack
6.1 Medium WordPress Affiliates Plugin — SliceWP Affiliates Plugin slicewp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.20 CVE-2024-8714 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
6.4 Medium Avada | Website Builder For WordPress & eCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode ≤ 3.11.9 CVE-2024-5628 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed ≤ 4.2.7 CVE-2024-8529 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed ≤ 4.2.7 CVE-2024-8522 Wordfence
4.8 Medium CM Pop-Up Banners Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.7.3 Fixed in 1.7.3 CVE-2024-5799 WPScan
6.4 Medium Advanced WordPress Backgrounds Plugin advanced-backgrounds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter ≤ 1.12.3 CVE-2024-8045 Wordfence
8.8 High Bit File Manager – 100% Free & Open Source File Manager and Code Editor Plugin file-manager Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 6.5.5 CVE-2024-7770 Wordfence
6.4 Medium Preloader Plus – WordPress Loading Screen Plugin preloader-plus Cross-Site Scripting WordPress Loading Screen Plugin <= 2.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.2.1 CVE-2024-6849 Wordfence
4.3 Medium Frontend Post Submission Manager Lite – Frontend Posting Plugin frontend-post-submission-manager-lite Broken Access Control Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.2.2 CVE-2024-8427 Wordfence
5.3 Medium Ivory Search – WordPress Search Plugin add-search-to-menu Information Disclosure WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form No login needed ≤ 5.5.6 CVE-2024-6835 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change ≤ 3.0.8 CVE-2024-8121 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Insecure Direct Object Reference ≤ 3.0.8 CVE-2024-8123 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.0.8 CVE-2024-8102 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page No login needed ≤ 3.0.8 CVE-2024-8119 Wordfence
6.5 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Information Disclosure WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 3.0.8 CVE-2024-8106 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Path Traversal WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download ≤ 3.0.8 CVE-2024-8104 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option No login needed ≤ 3.0.8 CVE-2024-8117 Wordfence
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence
5.4 Medium WP Armour Extended Plugin Cross-Site Request Forgery No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43947 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.9.4 - Cross Site Scripting (XSS) ≤ 1.9.4 Fixed in 2.0.0 CVE-2024-43920 Patchstack
7.1 High Magic Post Thumbnail Plugin magic-post-thumbnail Cross-Site Scripting Magic Post Thumbnail plugin <= 5.2.9 - Cross Site Scripting (XSS) No login needed ≤ 5.2.9 Fixed in 5.2.10 CVE-2024-43921 Patchstack
7.1 High Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.3.2 Fixed in 2.8.3.4 CVE-2024-43926 Patchstack
6.5 Medium Collapsing Archives Plugin collapsing-archives Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-43934 Patchstack
6.5 Medium Delicious Recipes – WordPress Recipe Plugin delicious-recipes Cross-Site Scripting Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin <= 1.6.7 - Cross Site Scripting (XSS) ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-43935 Patchstack
6.5 Medium EmbedPress Plugin embedpress Cross-Site Scripting ≤ 4.0.8 Fixed in 4.0.9 CVE-2024-43936 Patchstack
6.5 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting ≤ 1.5 CVE-2024-43946 Patchstack
7.1 High WP Armour Extended Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.26 Fixed in 1.32 CVE-2024-43948 Patchstack
6.5 Medium GHActivity Plugin Cross-Site Scripting ≤ 2.0.0-alpha CVE-2024-43949 Patchstack
7.1 High Brickscore Plugin Cross-Site Scripting No login needed ≤ 1.4.2.5 CVE-2024-43950 Patchstack
6.5 Medium Tempera Theme tempera Cross-Site Scripting ≤ 1.8.2 CVE-2024-43951 Patchstack
6.5 Medium Esotera Theme esotera Cross-Site Scripting ≤ 1.2.5.1 CVE-2024-43952 Patchstack
6.5 Medium Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Cross-Site Scripting WPBakery Page Builder plugin <= 3.5 - Cross Site Scripting (XSS) ≤ 3.5 Fixed in 3.6 CVE-2024-43953 Patchstack
7.1 High IntoTheDark Theme intothedark Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5 CVE-2024-43958 Patchstack
5.9 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Cross-Site Scripting ≤ 1.4.6 CVE-2024-43960 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only