WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,501–14,550 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 291 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'email' ≤ 1.5.112 CVE-2024-6170 Wordfence
6.4 Medium Blog, Posts and Category Filter for Elementor Plugin blog-posts-and-category-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post and Category Filter Widget ≤ 1.0.3 CVE-2024-4667 Wordfence
5.3 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Other IP Address Spoofing to Antispam Bypass No login needed ≤ 1.5.112 CVE-2024-6171 Wordfence
4.3 Medium Media Hygiene Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion ≤ 3.0.1 CVE-2024-5855 Wordfence
6.5 Medium UltraAddons Elementor Lite Plugin ultraaddons-elementor-lite Cross-Site Scripting ≤ 2.0.2 CVE-2024-37554 Patchstack
6.5 Medium Testimonials Widget Plugin testimonials-widget Cross-Site Scripting ≤ 4.0.4 CVE-2024-37553 Patchstack
6.5 Medium Livemesh Addons for Elementor Plugin addons-for-elementor Local File Inclusion ≤ 8.4.0 Fixed in 8.4.1 CVE-2024-37547 Patchstack
6.5 Medium Image Hover Effects - Caption Hover with Carousel Plugin image-hover-effects-with-carousel Cross-Site Scripting ≤ 3.0.2 CVE-2024-37546 Patchstack
5.4 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Broken Access Control Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Broken Access Control ≤ 2.0.3 CVE-2024-37542 Patchstack
6.5 Medium Elementor Addons, Widgets and Enhancements – Stax Plugin stax-addons-for-elementor Cross-Site Scripting Stax plugin <= 1.5.0 - Cross Site Scripting (XSS) ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-37541 Patchstack
6.5 Medium WP To Do Plugin wp-todo Cross-Site Scripting ≤ 1.3.0 CVE-2024-37539 Patchstack
4.9 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery ≤ 5.7 Fixed in 5.8 CVE-2024-37208 Patchstack
6.5 Medium Newspack Ads Plugin Cross-Site Scripting ≤ 1.47.1 Fixed in 1.47.2 CVE-2024-37474 Patchstack
6.5 Medium Newspack Campaigns Plugin Cross-Site Scripting ≤ 2.31.1 Fixed in 2.31.2 CVE-2024-37476 Patchstack
6.4 Medium One Click Order Re-Order Plugin one-click-order-reorder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.9 CVE-2024-5641 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid ≤ 8.3.7 CVE-2024-3639 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Various Widgets ≤ 8.3.7 CVE-2024-2926 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Marquee Text Widget, Testimonials Widget, and Testimonial Slider Widgets ≤ 8.4.1 CVE-2024-3638 Wordfence
5.4 Medium WP Tweet Walls Plugin wp-tweet-walls Cross-Site Request Forgery A cross-site request forgery vulnerability exists in WP Tweet Walls versions prior to 1.0.4. If this vulnerability is exploited, an attacker allows a user who logs in to the WordP… versions prior to 1.0.4 CVE-2024-38344 jpcert
6.4 Medium WP Lightbox 2 Plugin wp-lightbox-2 Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.0.6.6 CVE-2024-6263 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 4.10.36 CVE-2024-6340 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 5.6.1 CVE-2024-4482 Wordfence
5.9 Medium WPQA Plugin Cross-Site Scripting Contributor+ Stored XSS < 6.1.1 Fixed in 6.1.1 CVE-2024-2375 WPScan
6.3 Medium Himer - Social Questions and Answers Theme Cross-Site Request Forgery Social Questions and Answers < 2.1.1 - Bypass Poll Voting Restrictions via CSRF No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-2235 WPScan
6.3 Medium Himer - Social Questions and Answers Theme Cross-Site Scripting Social Questions and Answers < 2.1.1 - Contributor+ Stored XSS No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-2234 WPScan
6.3 Medium Himer - Social Questions and Answers Theme Cross-Site Request Forgery Social Questions and Answers < 2.1.1 - Multiple CSRF on the Group Section No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-2233 WPScan
6.3 Medium Himer - Social Questions and Answers Theme Cross-Site Request Forgery Social Questions and Answers < 2.1.1 - Arbitrary Group Joining via CSRF No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-2040 WPScan
4.3 Medium Snippet Shortcodes Plugin shortcode-variables Cross-Site Request Forgery No login needed ≤ 4.1.4 CVE-2024-4543 Wordfence
6.4 Medium Post Meta Data Manager Plugin post-meta-data-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-6264 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Other WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration No login needed ≤ 4.2.6.8.1 CVE-2024-6099 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass No login needed ≤ 4.2.6.8.1 CVE-2024-6088 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 3.1.9 CVE-2024-4268 Wordfence
4.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation ≤ 3.2.12 CVE-2024-6012 Wordfence
4.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.2.12 CVE-2024-6011 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via read_more_text Parameter ≤ 3.5.5 CVE-2024-5260 Wordfence
6.1 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.17 CVE-2024-5544 Wordfence
5.3 Medium Motors – Car Dealer, Classifieds & Listing Plugin Broken Access Control Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization No login needed ≤ 1.4.9 CVE-2024-5545 Wordfence
6.4 Medium Rife Elementor Extensions & Templates Plugin rife-elementor-extensions Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Widget ≤ 1.2.1 CVE-2024-5504 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via title tag attribute ≤ 3.1.9 CVE-2024-3513 Wordfence
6.4 Medium Easy Google Maps Plugin google-maps-easy Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.11.15 CVE-2024-5219 Wordfence
5.5 Medium Rank Math SEO Plugin seo-by-rank-math Cross-Site Scripting Authenticated Stored XSS < 1.0.219 Fixed in 1.0.219 CVE-2024-4627 WPScan
4.8 Medium EazyDocs Plugin eazydocs Cross-Site Scripting Admin+ Stored XSS < 2.5.0 Fixed in 2.5.0 CVE-2024-3999 WPScan
6.4 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag ≤ 7.7.1 CVE-2024-1427 Wordfence
6.4 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute ≤ 2.4 CVE-2024-5419 Wordfence
6.4 Medium Boot Store Theme boot-store Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.6.4 CVE-2024-5938 Wordfence
5.4 Medium Basil Theme Cross-Site Scripting WordPress Basil Theme Authenticated (Contributor+) Persistent Cross-Site Scripting < 2.0.5 CVE-2024-39310 GitHub_M
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.26 Fixed in 1.15.26 CVE-2024-6130 WPScan
5.5 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.2 Fixed in 9.0.2 CVE-2024-4934 WPScan
6.1 Medium Goya Theme Cross-Site Scripting Unauthenticated Reflected Cross-Site Scripting via Multiple Parameters No login needed ≤ 1.0.8.7 CVE-2023-4017 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes ≤ 3.2.45 CVE-2024-5819 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only