WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,501–14,550 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 291 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Cross-Site Scripting ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-38686 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.5 Fixed in 2.5.8 CVE-2024-38687 Patchstack
5.9 Medium Simple Popup Plugin simple-popup-plugin Cross-Site Scripting ≤ 4.4 Fixed in 4.5 CVE-2024-38689 Patchstack
7.1 High Moloni Plugin moloni Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.4 Fixed in 4.8.0 CVE-2024-38694 Patchstack
7.1 High Zoho CRM Lead Magnet Plugin zoho-crm-forms Cross-Site Scripting No login needed ≤ 1.7.8.8 Fixed in 1.7.8.9 CVE-2024-38696 Patchstack
6.5 Medium Goftino Plugin goftino Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-38697 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-38698 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-38705 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-38711 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.3 Fixed in 1.3.1 CVE-2024-38712 Patchstack
6.5 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 8.8.02.002 Fixed in 8.8.02.003 CVE-2024-38713 Patchstack
6.5 Medium Download Button for Elementor Plugin download-button-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2024-38718 Patchstack
6.5 Medium EazyDocs Plugin eazydocs Cross-Site Scripting ≤ 2.5.0 CVE-2024-38720 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.57 CVE-2024-38722 Patchstack
5.9 Medium Admin Dashboard RSS Feed Plugin admin-dashboard-rss-feed Cross-Site Scripting ≤ 3.1 CVE-2024-38725 Patchstack
5.9 Medium Change From Email Plugin wp-from-email Cross-Site Scripting ≤ 1.2.1 CVE-2024-38738 Patchstack
5.1 Medium OnePress Theme onepress Cross-Site Scripting ≤ 2.3.8 CVE-2024-38739 Patchstack
6.5 Medium Amazing Hover Effects Plugin amazing-hover-effects Cross-Site Scripting ≤ 2.4.9 CVE-2024-38741 Patchstack
6.5 Medium Advanced post slider Plugin advanced-post-slider Cross-Site Scripting ≤ 3.0.0 CVE-2024-38750 Patchstack
6.5 Medium Typebot Plugin typebot Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2024-38757 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.6 Fixed in 3.6.1 CVE-2024-38767 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack
8.8 High FV Player Plugin fv-wordpress-flowplayer SQL Injection Authenticated (Subscriber+) SQL Injection via exclude Parameter ≤ 7.5.46.7212 CVE-2024-6338 Wordfence
6.4 Medium Cooked Plugin cooked Content Injection Authenticated (Contributor+) HTML Injection via Recipe Excerpt < 1.8.0 CVE-2024-39682 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Apply Template to All Recipes No login needed < 1.8.0 CVE-2024-39681 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Default Recipe Template Save No login needed < 1.8.0 CVE-2024-39680 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Recipe Template Reset No login needed < 1.8.0 CVE-2024-39679 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Get Recipe IDs No login needed < 1.8.0 CVE-2024-39678 GitHub_M
5.5 Medium AI ChatBot for WordPress – WPBot Plugin chatbot Cross-Site Scripting WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.5.7 CVE-2024-6669 Wordfence
4.3 Medium WordPress File Upload Plugin Arbitrary File Upload Authenticated (Contributor+) Directory Traversal ≤ 4.24.7 CVE-2024-5852 Wordfence
8.8 High Insert or Embed Articulate Content into Plugin Arbitrary File Upload Author+ Arbitrary File Upload < 4.3000000024 Fixed in 4.3000000024 CVE-2024-5630 WPScan
5.4 Medium WordPress Plugin Tournamatch Plugin Cross-Site Scripting Admin+ Stored XSS via Ladders < 4.6.1 Fixed in 4.6.1 CVE-2024-5644 WPScan
5.4 Medium WordPress Plugin Tournamatch Plugin Cross-Site Scripting Subscriber+ Stored XSS < 4.6.1 Fixed in 4.6.1 CVE-2024-5627 WPScan
6.5 Medium CM WordPress Search And Replace Plugin Cross-Site Request Forgery Plugin Reset via CSRF < 1.3.9 Fixed in 1.3.9 CVE-2024-5028 WPScan
4.6 Medium OpenPGP Form Encryption Plugin openpgp-form-encryption Cross-Site Scripting Contributor+ Stored XSS < 1.5.1 Fixed in 1.5.1 CVE-2024-3919 WPScan
5.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Editor+ Stored XSS < 9.7.8 Fixed in 9.7.8 CVE-2024-3026 WPScan
9.1 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Arbitrary File Upload ≤ 4.14.13 CVE-2024-38736 Patchstack
7.5 High Event post Plugin event-post Local File Inclusion No login needed ≤ 5.9.5 Fixed in 5.9.6 CVE-2024-38735 Patchstack
9.1 Critical Import Spreadsheets from Microsoft Excel Plugin import-spreadsheets-from-microsoft-excel Arbitrary File Upload ≤ 10.1.4 CVE-2024-38734 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
6.5 Medium Events Calendar for Google Plugin events-calendar-for-google Local File Inclusion ≤ 2.1.0 CVE-2024-38716 Patchstack
6.5 Medium ExS Widgets Plugin exs-widgets Local File Inclusion ≤ 0.3.1 CVE-2024-38715 Patchstack
5.3 Medium GD Rating System Plugin gd-rating-system Local File Inclusion ≤ 3.6 Fixed in 3.6.1 CVE-2024-38709 Patchstack
6.5 Medium HT Mega Plugin ht-mega-for-elementor Path Traversal JSON Path Traversal ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-38706 Patchstack
6.5 Medium WordPress Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-38704 Patchstack
6.5 Medium WPCS Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional plugin <= 1.2.0.3 - Arbitrary Shortcode Execution No login needed ≤ 1.2.0.3 CVE-2024-38700 Patchstack
8.6 High Woocommerce OpenPos Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.4.4 CVE-2024-37932 Patchstack
8.6 High Jobmonster Theme Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 4.7.0 CVE-2024-37928 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only