WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,401–14,450 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 289 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Cards for Beaver Builder Plugin bb-bootstrap-cards Cross-Site Scripting ≤ 1.1.4 Fixed in 1.1.5 CVE-2024-37278 Patchstack
5.9 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting ≤ 1.3.0.4 Fixed in 1.3.0.5 CVE-2024-37409 Patchstack
5.9 Medium Depicter Slider Plugin depicter Cross-Site Scripting ≤ 3.0.2 Fixed in 3.1.0 CVE-2024-37414 Patchstack
7.1 High WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.8.00.002 Fixed in 8.8.00.003 CVE-2024-37416 Patchstack
6.5 Medium Progress Planner Plugin progress-planner Cross-Site Scripting ≤ 0.9.2 Fixed in 0.9.3 CVE-2024-37422 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit plugin <= 2.5.0 - Cross Site Scripting (XSS) ≤ 2.5.0 Fixed in 2.5.1 CVE-2024-37428 Patchstack
5.9 Medium Login with phone number Plugin login-with-phone-number Cross-Site Scripting Admin+ Cross Site Scripting (XSS) ≤ 1.7.35 Fixed in 1.7.36 CVE-2024-37429 Patchstack
5.9 Medium Esteem Theme esteem Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-37432 Patchstack
7.1 High Mailster Plugin mailster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2024-37433 Patchstack
5.9 Medium Atarim Plugin atarim-visual-collaboration Cross-Site Scripting Authenticated Cross Site Scripting (XSS) ≤ 3.31 Fixed in 3.32 CVE-2024-37434 Patchstack
7.1 High Uncanny Toolkit Pro for LearnDash Plugin uncanny-toolkit-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.1.4.1 Fixed in 4.1.4.1 CVE-2024-37436 Patchstack
6.5 Medium Html5 Audio Player Plugin html5-audio-player Cross-Site Scripting ≤ 2.2.23 Fixed in 2.2.24 CVE-2024-37445 Patchstack
5.4 Medium CM Popup Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.6.6 Fixed in 1.6.6 CVE-2024-5004 WPScan
5.9 Medium Chained Quiz Plugin chained-quiz Cross-Site Scripting ≤ 1.3.2.8 Fixed in 1.3.2.9 CVE-2024-37446 Patchstack
5.9 Medium PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Scripting ≤ 9.6.1.1 Fixed in 9.6.2 CVE-2024-37447 Patchstack
5.9 Medium Slider Revolution Plugin Cross-Site Scripting ≤ 6.7.13 Fixed in 6.7.14 CVE-2024-37449 Patchstack
6.5 Medium Ultimate Blocks – Gutenberg Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin plugin <= 3.1.9 - Cross Site Scripting (XSS) ≤ 3.1.9 Fixed in 3.2.0 CVE-2024-37457 Patchstack
7.1 High PayPlus Payment Gateway Plugin payplus-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.8 Fixed in 6.6.9 CVE-2024-37459 Patchstack
6.5 Medium SuperSaaS – online appointment scheduling Plugin supersaas-appointment-scheduling Cross-Site Scripting online appointment scheduling plugin <= 2.1.9 - Cross Site Scripting (XSS) ≤ 2.1.9 Fixed in 2.1.10 CVE-2024-37460 Patchstack
7.1 High IdeaPush Plugin ideapush Cross-Site Scripting No login needed ≤ 8.65 Fixed in 8.66 CVE-2024-37461 Patchstack
6.5 Medium GPT3 AI Content Writer Plugin gpt3-ai-content-generator Cross-Site Scripting Powered by GPT-4 plugin <= 1.8.66 - Cross Site Scripting (XSS) ≤ 1.8.66 Fixed in 1.8.67 CVE-2024-37465 Patchstack
6.5 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Contributor+ Cross Site Scripting (XSS) ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-37466 Patchstack
6.5 Medium Apollo13 Framework Extensions Plugin apollo13-framework-extensions Cross-Site Scripting ≤ 1.9.3 Fixed in 1.9.4 CVE-2024-37480 Patchstack
7.1 High bbPress Notify Plugin bbpress-notify-nospam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.18.3 Fixed in 2.18.4 CVE-2024-37485 Patchstack
7.1 High CopySafe Web Protection Plugin wp-copysafe-web Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.15 Fixed in 4.0 CVE-2024-38781 Patchstack
6.5 Medium Leaflet Maps Marker Plugin leaflet-maps-marker Cross-Site Scripting ≤ 3.12.9 Fixed in 3.12.10 CVE-2024-38782 Patchstack
5.9 Medium Livemesh Addons for Beaver Builder Plugin addons-for-beaver-builder Cross-Site Scripting ≤ 3.6.1 Fixed in 3.7 CVE-2024-38784 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Cross-Site Scripting ≤ 1.9.2 Fixed in 1.9.3 CVE-2024-38785 Patchstack
6.5 Medium CoziPress Theme cozipress Cross-Site Scripting ≤ 1.0.30 CVE-2024-38786 Patchstack
7.1 High WP Directory Kit Plugin wpdirectorykit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-37487 Patchstack
6.5 Medium HelloAsso Plugin helloasso Cross-Site Scripting ≤ 1.1.9 Fixed in 1.1.10 CVE-2024-37488 Patchstack
6.5 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting Authenticated Cross Site Scripting (XSS) ≤ 2.2.9 Fixed in 2.3.0 CVE-2024-37489 Patchstack
6.5 Medium Gutenberg Plugin gutenberg Cross-Site Scripting ≤ 18.6.0 Fixed in 18.6.1 CVE-2024-37492 Patchstack
6.5 Medium Create by Mediavine Plugin mediavine-create Cross-Site Scripting ≤ 1.9.7 Fixed in 1.9.8 CVE-2024-37495 Patchstack
6.5 Medium Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting ≤ 2.8.2.2 Fixed in 2.8.3 CVE-2024-37500 Patchstack
6.5 Medium Eventin Plugin wp-event-solution Cross-Site Scripting ≤ 3.3.57 Fixed in 4.0.0 CVE-2024-37507 Patchstack
7.1 High MakeCommerce for WooCommerce Plugin makecommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.1 Fixed in 3.5.2 CVE-2024-37509 Patchstack
6.5 Medium NEX-Forms – Ultimate Form Builder Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Ultimate Form Builder plugin <= 8.5.10 - Cross Site Scripting (XSS) ≤ 8.5.10 Fixed in 8.6.1 CVE-2024-37512 Patchstack
6.5 Medium CopySafe Web Protection Plugin wp-copysafe-web Cross-Site Scripting ≤ 3.14 Fixed in 3.15 CVE-2024-37514 Patchstack
5.8 Medium XPlainer - WooCommerce Product FAQ Plugin faq-for-woocommerce Cross-Site Scripting WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] plugin <= 1.6.3 - Cross Site Scripting (XSS) No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2024-37515 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting Gutenberg Blocks for WordPress plugin <= 2.1.27 - Cross Site Scripting (XSS) ≤ 2.1.27 Fixed in 2.1.28 CVE-2024-37519 Patchstack
6.5 Medium zBench Theme zbench Cross-Site Scripting ≤ 1.4.2 CVE-2024-37521 Patchstack
5.9 Medium CC & BCC for Woocommerce Order Emails Plugin cc-bcc-for-woocommerce-order-emails Cross-Site Scripting ≤ 1.4.1 CVE-2024-37522 Patchstack
5.9 Medium Login Logo Editor Plugin login-logo-editor-by-oizuled Cross-Site Scripting ≤ 1.3.3 CVE-2024-37523 Patchstack
5.9 Medium Easy Custom Code (LESS/CSS/JS) – Live editing Plugin easy-custom-code Cross-Site Scripting ≤ 1.0.8 CVE-2024-37536 Patchstack
5.9 Medium WS Contact Form Plugin ws-contact-form Cross-Site Scripting ≤ 1.3.7 CVE-2024-37537 Patchstack
5.9 Medium Link To Bible Plugin link-to-bible Cross-Site Scripting ≤ 2.5.9 CVE-2024-37538 Patchstack
5.9 Medium Floating Social Media Links Plugin floating-social-media-links Cross-Site Scripting ≤ 1.5.2 CVE-2024-37545 Patchstack
5.9 Medium Meks Easy Ads Widget Plugin meks-easy-ads-widget Cross-Site Scripting ≤ 2.0.8 CVE-2024-37548 Patchstack
5.9 Medium Save as PDF plugin by Pdfcrowd Plugin save-as-pdf-by-pdfcrowd Cross-Site Scripting ≤ 4.0.0 Fixed in 4.0.1 CVE-2024-37549 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only