WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,351–14,400 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 288 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Lifetime free Drag & Drop Contact Form Builder for WordPress VForm Plugin v-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.1.5 CVE-2024-6770 Wordfence
5.3 Medium Campaign Monitor Plugin forms-for-campaign-monitor Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 2.8.15 CVE-2024-6569 Wordfence
5.8 Medium Ultimate WordPress Auction Plugin ultimate-auction Broken Access Control Missing Authorization to Unauthenticated Email Creation No login needed ≤ 4.2.7 CVE-2024-6591 Wordfence
4.3 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update ≤ 3.4.6 CVE-2024-6836 Wordfence
5.4 Medium Search & Replace Plugin search-and-replace PHP Object Injection Deserialization of untrusted data No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2024-38759 Patchstack
7.2 High BerqWP Plugin searchpro Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-37942 Patchstack
6.4 Medium JSON Content Importer Plugin json-content-importer Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) ≤ 1.5.6 Fixed in 1.6.0 CVE-2024-38723 Patchstack
7.1 High Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Server-Side Request Forgery No login needed ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38728 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38730 Patchstack
4.3 Medium Academy LMS Plugin academy Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-38701 Patchstack
7.6 High Spiffy Calendar Plugin spiffy-calendar SQL Injection ≤ 4.9.11 Fixed in 4.9.12 CVE-2024-38692 Patchstack
8.5 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-38708 Patchstack
8.5 High DirectoryPress Plugin directorypress SQL Injection ≤ 3.6.10 CVE-2024-38755 Patchstack
9.3 Critical FormLift for Infusionsoft Web Forms Plugin formlift SQL Injection Unauthenticated Blind SQL Injection No login needed ≤ 7.5.17 Fixed in 7.5.18 CVE-2024-38773 Patchstack
7.6 High UiPress lite Plugin uipress-lite SQL Injection ≤ 3.4.06 Fixed in 3.4.07 CVE-2024-38788 Patchstack
6.5 Medium Elementor – Header, Footer & Blocks Template Plugin header-footer-elementor Cross-Site Scripting Contributor+ DOM-Based Cross Site Scripting (XSS) ≤ 1.6.35 Fixed in 1.6.36 CVE-2024-33933 Patchstack
7.1 High Shortcodes by United Themes Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.0.5 Fixed in 5.0.5 CVE-2024-37097 Patchstack
6.5 Medium Elegant Themes Icons Plugin elegant-themes-icons Cross-Site Scripting ≤ 1.3 CVE-2024-37100 Patchstack
6.5 Medium WP Post Author Plugin wp-post-author Cross-Site Scripting ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-37101 Patchstack
6.5 Medium My Favorites Plugin my-favorites Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-37114 Patchstack
6.5 Medium Sinatra Theme sinatra Cross-Site Scripting ≤ 1.3 CVE-2024-37116 Patchstack
7.1 High Uncanny Automator Pro Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3 Fixed in 5.3.0.1 CVE-2024-37117 Patchstack
5.9 Medium Tabs Plugin vc-tabs Cross-Site Scripting ≤ 4.0.6 CVE-2024-37120 Patchstack
5.9 Medium Shortcode Addons Plugin shortcode-addons Cross-Site Scripting ≤ 3.2.5 CVE-2024-37121 Patchstack
5.9 Medium Accordions Plugin accordions-or-faqs Cross-Site Scripting ≤ 2.3.5 CVE-2024-37122 Patchstack
7.1 High Enfold Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.9 Fixed in 5.6.10 CVE-2024-37199 Patchstack
7.1 High Demo Awesome Plugin demo-awesome Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2024-37206 Patchstack
7.1 High Ali2Woo Lite Plugin ali2woo-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37211 Patchstack
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Sketchfab Embed Plugin sketchfab-oembed Cross-Site Scripting ≤ 1.5 CVE-2024-37216 Patchstack
6.5 Medium Empty Cart Button for WooCommerce Plugin empty-cart-button-for-woocommerce Cross-Site Scripting ≤ 1.3.8 CVE-2024-37217 Patchstack
6.5 Medium Page Builder Sandwich – Front-End Page Builder Plugin page-builder-sandwich Cross-Site Scripting ≤ 5.1.0 CVE-2024-37219 Patchstack
6.5 Medium Kimili Flash Embed Plugin kimili-flash-embed Cross-Site Scripting ≤ 2.5.3 CVE-2024-37221 Patchstack
6.5 Medium Restaurant Reservations Plugin nd-restaurant-reservations Cross-Site Scripting ≤ 2.0 CVE-2024-37223 Patchstack
6.5 Medium Blogmentor – Blog Layouts for Elementor Plugin blogmentor Cross-Site Scripting Blog Layouts for Elementor plugin <= 1.5 - Cross Site Scripting (XSS) ≤ 1.5 CVE-2024-37229 Patchstack
5.9 Medium Branda Plugin branda-white-labeling Cross-Site Scripting ≤ 3.4.17 Fixed in 3.4.18 CVE-2024-37239 Patchstack
6.5 Medium Ninja Beaver Add-ons for Beaver Builder Plugin ninja-beaver-lite-addons-for-beaver-builder Cross-Site Scripting ≤ 2.4.5 CVE-2024-37244 Patchstack
7.1 High All In One Redirection Plugin all-in-one-redirection Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-37245 Patchstack
6.5 Medium Gallery Slideshow Plugin gallery-slideshow Cross-Site Scripting ≤ 1.4.1 CVE-2024-37246 Patchstack
7.1 High Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.3.3 Fixed in 2.4.3.4 CVE-2024-37257 Patchstack
7.1 High Social Rocket Plugin social-rocket Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2024-37258 Patchstack
7.1 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting No login needed ≤ 2.4.7 Fixed in 3.0.0 CVE-2024-37259 Patchstack
7.1 High WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.16 Fixed in 2.6.17 CVE-2024-37261 Patchstack
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37262 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor plugin <= 2.1.6 - Cross Site Scripting (XSS) ≤ 2.1.6 Fixed in 2.1.7 CVE-2024-37263 Patchstack
7.1 High Groundhogg Plugin groundhogg Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2.3 Fixed in 3.4.3 CVE-2024-37264 Patchstack
6.5 Medium IdeaPush Plugin ideapush Cross-Site Scripting ≤ 8.60 Fixed in 8.61 CVE-2024-37265 Patchstack
7.1 High Striking Theme striking-r Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2024-37267 Patchstack
5.9 Medium Print My Blog Plugin print-my-blog Cross-Site Scripting ≤ 3.27.0 Fixed in 3.27.1 CVE-2024-37271 Patchstack
7.1 High NextScripts Plugin social-networks-auto-poster-facebook-twitter-g Cross-Site Scripting No login needed ≤ 4.4.7 CVE-2024-37275 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only