WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,401–14,450 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 289 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.8 Medium User Submitted Posts Plugin user-submitted-posts Cross-Site Scripting Admin+ Stored XSS < 20240516 Fixed in 20240516 CVE-2024-5002 WPScan
6.8 Medium Index WP MySQL For Speed Plugin index-wp-mysql-for-speed Cross-Site Scripting Admin+ Reflected XSS < 1.4.18 Fixed in 1.4.18 CVE-2024-4977 WPScan
5.9 Medium EventON Plugin eventon-lite Cross-Site Scripting Admin+ Stored Cross-Site Scripting via event subtitle < 2.2.15 Fixed in 2.2.15 CVE-2024-4752 WPScan
5.4 Medium Embed Peertube Playlist Plugin embed-peertube-playlist Cross-Site Scripting Editor+ Stored XSS < 1.10 Fixed in 1.10 CVE-2024-4602 WPScan
6.1 Medium Support SVG Plugin Cross-Site Scripting Stored XSS via SVG Upload No login needed < 1.1.0 Fixed in 1.1.0 CVE-2024-4272 WPScan
6.1 Medium SVG Block Plugin svg-block Cross-Site Scripting Author+ Stored XSS via SVG File Upload No login needed < 1.1.20 Fixed in 1.1.20 CVE-2024-4269 WPScan
4.7 Medium Shortcodes Ultimate Pro Plugin Cross-Site Scripting Contributor+ Stored Cross-Site Scripting XSS No login needed < 7.1.5 Fixed in 7.1.5 CVE-2024-4217 WPScan
5.9 Medium Product Enquiry for WooCommerce Plugin gm-woocommerce-quote-popup Cross-Site Scripting Admin+ Stored XSS < 3.1.8 Fixed in 3.1.8 CVE-2024-3964 WPScan
6.5 Medium RafflePress Lite Plugin Cross-Site Scripting Editor+ Stored XSS < 1.12.14 Fixed in 1.12.14 CVE-2024-3963 WPScan
4.6 Medium OpenPGP Form Encryption Plugin openpgp-form-encryption Cross-Site Scripting Contributor+ Stored XSS < 1.5.1 Fixed in 1.5.1 CVE-2024-3919 WPScan
5.9 Medium Hostel Plugin hostel Cross-Site Scripting Reflected XSS < 1.1.5.3 Fixed in 1.1.5.3 CVE-2024-3753 WPScan
4.8 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Scripting Admin+ Stored XSS < 3.3.0 Fixed in 3.3.0 CVE-2024-3751 WPScan
6.8 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Contributor+ Stored XSS < 3.6.0 Fixed in 3.6.0 CVE-2024-3710 WPScan
6.8 Medium Smart Image Gallery Plugin Cross-Site Request Forgery Update/Delete Google API Key via CSRF < 1.0.19 Fixed in 1.0.19 CVE-2024-3632 WPScan
5.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Editor+ Stored XSS < 9.7.8 Fixed in 9.7.8 CVE-2024-3026 WPScan
6.1 Medium Swift Framework Plugin Cross-Site Scripting Reflected XSS No login needed < 2024.04.30 Fixed in 2024.04.30 CVE-2024-2870 WPScan
5.3 Medium Laposta Plugin laposta Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.12 CVE-2024-6574 Wordfence
6.5 Medium Events Calendar for Google Plugin events-calendar-for-google Local File Inclusion ≤ 2.1.0 CVE-2024-38716 Patchstack
6.5 Medium ExS Widgets Plugin exs-widgets Local File Inclusion ≤ 0.3.1 CVE-2024-38715 Patchstack
5.3 Medium GD Rating System Plugin gd-rating-system Local File Inclusion ≤ 3.6 Fixed in 3.6.1 CVE-2024-38709 Patchstack
6.5 Medium HT Mega Plugin ht-mega-for-elementor Path Traversal JSON Path Traversal ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-38706 Patchstack
6.5 Medium WordPress Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-38704 Patchstack
6.5 Medium WPCS Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional plugin <= 1.2.0.3 - Arbitrary Shortcode Execution No login needed ≤ 1.2.0.3 CVE-2024-38700 Patchstack
4.3 Medium SociallyViral Theme sociallyviral Cross-Site Request Forgery No login needed ≤ 1.0.10 CVE-2024-37938 Patchstack
4.3 Medium Patricia Lite Theme patricia-lite Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2024-37939 Patchstack
4.3 Medium Internal Link Juicer: SEO Auto Linker Plugin internal-links Cross-Site Request Forgery No login needed ≤ 2.24.3 Fixed in 2.24.4 CVE-2024-37941 Patchstack
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack
4.3 Medium Get Better Reviews for WooCommerce Plugin more-better-reviews-for-woocommerce Broken Access Control ≤ 4.0.6 CVE-2024-37544 Patchstack
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
5.5 Medium WP Total Branding Plugin wp-total-branding Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via title Parameter ≤ 1.2 CVE-2024-6625 Wordfence
6.4 Medium PowerPress Podcasting plugin by Blubrry Plugin powerpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter ≤ 11.9.10 CVE-2024-6588 Wordfence
6.1 Medium Simple Video Directory Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed < 1.4.4 Fixed in 1.4.4 CVE-2024-5811 WPScan
5.9 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting Reflected XSS < 3.7.0 Fixed in 3.7.0 CVE-2024-5626 WPScan
5.9 Medium WP Secure Maintenance Plugin Cross-Site Scripting Admin+ Stored XSS < 1.7 Fixed in 1.7 CVE-2024-4753 WPScan
4.9 Medium Quotes and Tips Plugin quotes-and-tips Arbitrary File Upload Admin+ Arbitrary File Upload < 1.45 Fixed in 1.45 CVE-2024-3112 WPScan
4.8 Medium Swift Framework Plugin Cross-Site Scripting Admin+ Stored XSS via Settings < 2024.04.30 Fixed in 2024.04.30 CVE-2024-2696 WPScan
6.8 Medium Watu Quiz Plugin watu Cross-Site Scripting Author+ Stored XSS < 3.4.1.2 Fixed in 3.4.1.2 CVE-2024-2640 WPScan
6.5 Medium Website Content in Page or Post Plugin Cross-Site Scripting Contributor+ Stored Cross-Site Scripting < 2024.04.09 Fixed in 2024.04.09 CVE-2024-2430 WPScan
4.8 Medium Social Media Widget Plugin Cross-Site Scripting Admin+ Stored XSS < 4.0.9 Fixed in 4.0.9 CVE-2024-0974 WPScan
5.3 Medium WP Popups – WordPress Popup builder Plugin wp-popups-lite Information Disclosure WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure No login needed ≤ 2.2.0.1 CVE-2024-6555 Wordfence
4.3 Medium Event post Plugin event-post Cross-Site Request Forgery No login needed ≤ 5.9.10 CVE-2024-1375 Wordfence
5.4 Medium Image Optimizer, Resizer and CDN – Sirv Plugin sirv Broken Access Control Sirv <= 7.2.7 - Authenticated(Subscriber+) Missing Authorization to Plugin Settings Update ≤ 7.2.7 CVE-2024-6392 Wordfence
6.4 Medium Feeds for YouTube (YouTube video, channel, and gallery plugin) Plugin feeds-for-youtube Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-6256 Wordfence
6.5 Medium Secure Copy Content Protection Plugin Cross-Site Scripting Admin+ Stored XSS < 4.0.9 Fixed in 4.0.9 CVE-2024-6138 WPScan
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Editor+ Stored XSS No login needed < 1.2.56 Fixed in 1.2.56 CVE-2024-6026 WPScan
6.5 Medium Quiz and Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.5 Fixed in 9.0.5 CVE-2024-6025 WPScan
5.4 Medium Bible Text Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 0.2 CVE-2024-5444 WPScan
6.3 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Contributor+ Stored XSS No login needed < 3.1.9 Fixed in 3.1.9 CVE-2024-4655 WPScan
5.3 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Broken Access Control Missing Authorization to Order Status Update No login needed ≤ 2.5.0 CVE-2024-0619 Wordfence
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only