WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 14,351–14,400 of 16,921 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.2 High | Lifetime free Drag & Drop Contact Form Builder for WordPress VForm | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.1.5 |
CVE-2024-6770 |
Wordfence | |
| 5.3 Medium | Campaign Monitor | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 2.8.15 |
CVE-2024-6569 |
Wordfence | |
| 5.8 Medium | Ultimate WordPress Auction | Broken Access Control Missing Authorization to Unauthenticated Email Creation No login needed |
≤ 4.2.7 |
CVE-2024-6591 |
Wordfence | |
| 4.3 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update |
≤ 3.4.6 |
CVE-2024-6836 |
Wordfence | |
| 5.4 Medium | Search & Replace | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2024-38759 |
Patchstack | |
| 7.2 High | BerqWP | Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed |
≤ 1.7.5 Fixed in 1.7.6 |
CVE-2024-37942 |
Patchstack | |
| 6.4 Medium | JSON Content Importer | Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) |
≤ 1.5.6 Fixed in 1.6.0 |
CVE-2024-38723 |
Patchstack | |
| 7.1 High | Seraphinite Post .DOCX Source | Server-Side Request Forgery No login needed |
≤ 2.16.9 Fixed in 2.16.10 |
CVE-2024-38728 |
Patchstack | |
| 4.9 Medium | Magical Addons For Elementor | Server-Side Request Forgery |
≤ 1.1.41 Fixed in 1.1.42 |
CVE-2024-38730 |
Patchstack | |
| 4.3 Medium | Academy LMS | Broken Access Control |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2024-38701 |
Patchstack | |
| 7.6 High | Spiffy Calendar | SQL Injection |
≤ 4.9.11 Fixed in 4.9.12 |
CVE-2024-38692 |
Patchstack | |
| 8.5 High | Barcode Scanner with Inventory & Order Manager | SQL Injection |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-38708 |
Patchstack | |
| 8.5 High | DirectoryPress | SQL Injection |
≤ 3.6.10 |
CVE-2024-38755 |
Patchstack | |
| 9.3 Critical | FormLift for Infusionsoft Web Forms | SQL Injection Unauthenticated Blind SQL Injection No login needed |
≤ 7.5.17 Fixed in 7.5.18 |
CVE-2024-38773 |
Patchstack | |
| 7.6 High | UiPress lite | SQL Injection |
≤ 3.4.06 Fixed in 3.4.07 |
CVE-2024-38788 |
Patchstack | |
| 6.5 Medium | Elementor – Header, Footer & Blocks Template | Cross-Site Scripting Contributor+ DOM-Based Cross Site Scripting (XSS) |
≤ 1.6.35 Fixed in 1.6.36 |
CVE-2024-33933 |
Patchstack | |
| 7.1 High | Shortcodes by United Themes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 5.0.5 Fixed in 5.0.5 |
CVE-2024-37097 |
Patchstack | |
| 6.5 Medium | Elegant Themes Icons | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-37100 |
Patchstack | |
| 6.5 Medium | WP Post Author | Cross-Site Scripting |
≤ 3.6.7 Fixed in 3.6.8 |
CVE-2024-37101 |
Patchstack | |
| 6.5 Medium | My Favorites | Cross-Site Scripting |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2024-37114 |
Patchstack | |
| 6.5 Medium | Sinatra | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-37116 |
Patchstack | |
| 7.1 High | Uncanny Automator Pro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.3 Fixed in 5.3.0.1 |
CVE-2024-37117 |
Patchstack | |
| 5.9 Medium | Tabs | Cross-Site Scripting |
≤ 4.0.6 |
CVE-2024-37120 |
Patchstack | |
| 5.9 Medium | Shortcode Addons | Cross-Site Scripting |
≤ 3.2.5 |
CVE-2024-37121 |
Patchstack | |
| 5.9 Medium | Accordions | Cross-Site Scripting |
≤ 2.3.5 |
CVE-2024-37122 |
Patchstack | |
| 7.1 High | Enfold | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.6.9 Fixed in 5.6.10 |
CVE-2024-37199 |
Patchstack | |
| 7.1 High | Demo Awesome | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 Fixed in 1.0.2 |
CVE-2024-37206 |
Patchstack | |
| 7.1 High | Ali2Woo Lite | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.3.5 Fixed in 3.3.7 |
CVE-2024-37211 |
Patchstack | |
| 5.9 Medium | Transition Slider – Responsive Image Slider and Gallery | Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) |
≤ 2.20.3 |
CVE-2024-37215 |
Patchstack | |
| 6.5 Medium | Sketchfab Embed | Cross-Site Scripting |
≤ 1.5 |
CVE-2024-37216 |
Patchstack | |
| 6.5 Medium | Empty Cart Button for WooCommerce | Cross-Site Scripting |
≤ 1.3.8 |
CVE-2024-37217 |
Patchstack | |
| 6.5 Medium | Page Builder Sandwich – Front-End Page Builder | Cross-Site Scripting |
≤ 5.1.0 |
CVE-2024-37219 |
Patchstack | |
| 6.5 Medium | Kimili Flash Embed | Cross-Site Scripting |
≤ 2.5.3 |
CVE-2024-37221 |
Patchstack | |
| 6.5 Medium | Restaurant Reservations | Cross-Site Scripting |
≤ 2.0 |
CVE-2024-37223 |
Patchstack | |
| 6.5 Medium | Blogmentor – Blog Layouts for Elementor | Cross-Site Scripting Blog Layouts for Elementor plugin <= 1.5 - Cross Site Scripting (XSS) |
≤ 1.5 |
CVE-2024-37229 |
Patchstack | |
| 5.9 Medium | Branda | Cross-Site Scripting |
≤ 3.4.17 Fixed in 3.4.18 |
CVE-2024-37239 |
Patchstack | |
| 6.5 Medium | Ninja Beaver Add-ons for Beaver Builder | Cross-Site Scripting |
≤ 2.4.5 |
CVE-2024-37244 |
Patchstack | |
| 7.1 High | All In One Redirection | Cross-Site Scripting No login needed |
≤ 2.2.0 |
CVE-2024-37245 |
Patchstack | |
| 6.5 Medium | Gallery Slideshow | Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-37246 |
Patchstack | |
| 7.1 High | Permalink Manager Lite | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.4.3.3 Fixed in 2.4.3.4 |
CVE-2024-37257 |
Patchstack | |
| 7.1 High | Social Rocket | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3.3 Fixed in 1.3.4 |
CVE-2024-37258 |
Patchstack | |
| 7.1 High | The Ultimate WordPress Toolkit – WP Extended | Cross-Site Scripting No login needed |
≤ 2.4.7 Fixed in 3.0.0 |
CVE-2024-37259 |
Patchstack | |
| 7.1 High | WP-Lister Lite for Amazon | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.6.16 Fixed in 2.6.17 |
CVE-2024-37261 |
Patchstack | |
| 7.1 High | Online Booking & Scheduling Calendar for WordPress by vcita | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 4.4.2 Fixed in 4.4.3 |
CVE-2024-37262 |
Patchstack | |
| 6.5 Medium | Enter Addons | Cross-Site Scripting Ultimate Template Builder for Elementor plugin <= 2.1.6 - Cross Site Scripting (XSS) |
≤ 2.1.6 Fixed in 2.1.7 |
CVE-2024-37263 |
Patchstack | |
| 7.1 High | Groundhogg | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.4.2.3 Fixed in 3.4.3 |
CVE-2024-37264 |
Patchstack | |
| 6.5 Medium | IdeaPush | Cross-Site Scripting |
≤ 8.60 Fixed in 8.61 |
CVE-2024-37265 |
Patchstack | |
| 7.1 High | Striking | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.3.4 Fixed in 2.3.5 |
CVE-2024-37267 |
Patchstack | |
| 5.9 Medium | Print My Blog | Cross-Site Scripting |
≤ 3.27.0 Fixed in 3.27.1 |
CVE-2024-37271 |
Patchstack | |
| 7.1 High | NextScripts | Cross-Site Scripting No login needed |
≤ 4.4.7 |
CVE-2024-37275 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.