WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,601–14,650 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 293 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium WordPress Core Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML API 5.9 – 5.9.9, 6.0 – 6.0.8, 6.1 – 6.1.6, … CVE-2024-6307 Wordfence
4.3 Medium Zita Elementor Site Library Plugin zita-site-library Broken Access Control Missing Authorization to Page Creation and Options Modification ≤ 1.6.2 CVE-2024-3249 Wordfence
5.5 Medium Mime Types Extended Plugin Cross-Site Scripting Author+ Stored XSS via SVG Upload ≤ 0.11 CVE-2024-4759 WPScan
4.3 Medium Play.ht Plugin play-ht Broken Access Control ≤ 3.6.4 CVE-2024-37233 Patchstack
6.1 Medium SEOPress Plugin wp-seopress Open Redirect Contributor+ Open Redirect No login needed < 7.8 Fixed in 7.8 CVE-2024-4900 WPScan
5.0 Medium SEOPress Plugin wp-seopress Cross-Site Scripting Contributor+ Stored XSS No login needed < 7.8 Fixed in 7.8 CVE-2024-4899 WPScan
6.3 Medium ARMember Premium Plugin Cross-Site Request Forgery Cross-Site Request Forgery via multiple functions No login needed ≤ 6.7 CVE-2024-5596 Wordfence
4.3 Medium Bricks Builder Plugin Broken Access Control Insecure Direct Object Reference ≤ 1.9.8 CVE-2024-4874 Wordfence
6.4 Medium Mosaic Theme mosaic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.7.1 CVE-2024-5965 Wordfence
6.4 Medium Grey Opaque Theme grey-opaque Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Download-Button Shortcode ≤ 2.0.1 CVE-2024-5966 Wordfence
6.4 Medium Table Addons for Elementor Plugin table-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter ≤ 2.1.2 CVE-2024-4313 Wordfence
6.4 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets ≤ 2.10.34 CVE-2024-2484 Wordfence
6.4 Medium Flatsome | Multi-Purpose Responsive WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.18.7 CVE-2024-5346 Wordfence
6.5 Medium Sparkle Demo Importer Plugin sparkle-demo-importer Broken Access Control Missing Authorization to Authorized(Subscriber+) Post/Pages/Attachements Deletion and Demo Data Import ≤ 1.4.7 CVE-2024-6120 Wordfence
6.5 Medium Word Balloon Plugin word-balloon Local File Inclusion ≤ 4.21.1 Fixed in 4.22.0 CVE-2024-35781 Patchstack
6.5 Medium Slideshow SE Plugin slideshow-se Local File Inclusion Auth. Limited Local File Inclusion ≤ 2.5.17 Fixed in 2.5.18 CVE-2024-35778 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2022-44587 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Content Injection Auth. HTML Injection ≤ 2.0.9 Fixed in 2.1.0 CVE-2022-38055 Patchstack
5.4 Medium Uncanny Automator Pro Plugin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Leading to License Settings Reset No login needed ≤ 5.3 CVE-2024-37118 Patchstack
4.3 Medium Digital Newspaper Theme digital-newspaper Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-37198 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.9.7 Fixed in 4.9.8 CVE-2024-37227 Patchstack
4.3 Medium Book Landing Page Theme book-landing-page Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-37230 Patchstack
4.3 Medium EmbedPress Plugin embedpress Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2023-51375 Patchstack
6.5 Medium WordPress Form Builder Plugin – Gutenberg Forms Plugin forms-gutenberg Broken Access Control Auth. Broken Access Control ≤ 2.2.8.3 Fixed in 2.2.9 CVE-2022-45803 Patchstack
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
4.3 Medium Customizr Theme customizr Cross-Site Request Forgery No login needed ≤ 4.4.21 Fixed in 4.4.22 CVE-2024-35771 Patchstack
4.3 Medium Hueman Theme hueman Cross-Site Request Forgery No login needed ≤ 3.7.24 Fixed in 3.7.25 CVE-2024-35772 Patchstack
5.3 Medium phpinfo() WP Plugin phpinfo-wp Information Disclosure Unauthenticated Data Exposure No login needed ≤ 5.0 CVE-2024-35776 Patchstack
5.3 Medium Event Management Tickets Booking Plugin event-monster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.0 CVE-2024-5059 Patchstack
5.9 Medium Easy Age Verify Plugin easy-age-verify Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-35757 Patchstack
6.5 Medium Interface Theme interface Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-35758 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35759 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35760 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-35761 Patchstack
6.5 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-35762 Patchstack
6.5 Medium Excellent Theme excellent Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-35763 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.4.4 Fixed in 4.4.5 CVE-2024-35764 Patchstack
5.9 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting ≤ 2.1.22 CVE-2024-35768 Patchstack
5.9 Medium Slideshow SE Plugin slideshow-se Cross-Site Scripting ≤ 2.5.17 CVE-2024-35769 Patchstack
6.5 Medium DImage 360 Plugin dimage-360 Cross-Site Scripting ≤ 2.0 CVE-2024-35774 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting Contributor+ Shortcode Cross Site Scripting (XSS) ≤ 1.5.42 CVE-2024-35779 Patchstack
6.5 Medium Typing Text Plugin typing-text Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-5058 Patchstack
6.1 Medium Appointment Booking and Online Scheduling Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5859 Wordfence
6.4 Medium WP SVG Images Plugin wp-svg-images Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 4.3 CVE-2024-5945 Wordfence
4.4 Medium Amelia Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1.5, ≤ 7.5.1 CVE-2024-6225 Wordfence
6.4 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.4.17 CVE-2024-5191 Wordfence
4.3 Medium User Profile Picture Plugin metronet-profile-picture Broken Access Control Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update ≤ 2.6.1 CVE-2024-5639 Wordfence
6.1 Medium PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed ≤ 1.7 CVE-2024-5448 WPScan
5.4 Medium PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.7 CVE-2024-5447 WPScan
6.1 Medium Widget Bundle Plugin Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 2.0.0 CVE-2024-4970 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only