WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,651–14,700 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 294 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Widget Bundle Plugin Cross-Site Request Forgery Widget Disable/Enable via CSRF No login needed ≤ 2.0.0 CVE-2024-4969 WPScan
4.0 Medium Google CSE Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.7 CVE-2024-4755 WPScan
6.1 Medium Widget Bundle Plugin Cross-Site Scripting Unauthencated Reflected XSS No login needed ≤ 2.0.0 CVE-2024-4616 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Scripting Unauthenticated Stored XSS ≤ 1.0.1 CVE-2024-4477 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Request Forgery Log Clearing via CSRF ≤ 1.0.1 CVE-2024-4475 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Request Forgery Disable Logging via CSRF ≤ 1.0.1 CVE-2024-4474 WPScan
6.1 Medium CSSable Countdown Plugin Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 1.5 CVE-2024-4384 WPScan
4.3 Medium CB (legacy) Plugin Cross-Site Request Forgery Code/Timeframe/Booking Deletion via CSRF No login needed ≤ 0.9.4.18 CVE-2024-4382 WPScan
4.8 Medium CB (legacy) Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 0.9.4.18 CVE-2024-4381 WPScan
6.1 Medium DOP Shortcodes Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode No login needed ≤ 1.2 CVE-2024-4377 WPScan
5.3 Medium ConvertKit Plugin Broken Access Control Missing Authorization No login needed ≤ 2.4.9 CVE-2024-3961 Wordfence
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Broken Access Control Missing Authorization to Authenticated(Contributor+) Plugin Settings Modification ≤ 1.3 CVE-2024-1955 Wordfence
4.3 Medium Smush – Lazy Load Images, Optimize & Compress Images Plugin wp-smushit Broken Access Control Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion ≤ 3.16.4 CVE-2023-3352 Wordfence
5.3 Medium WP Child Theme Generator Plugin wp-child-theme-generator Broken Access Control Missing Authorization to Unauthenticated Child Theme Creation/Activation No login needed ≤ 1.1.1 CVE-2024-3610 Wordfence
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Information Disclosure Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure ≤ 3.0.6 CVE-2024-1639 Wordfence
6.1 Medium The Plus Addons for Elementor Page Builder Plugin Cross-Site Scripting Reflected Cross-Site Scripting via WP Login and Register Widget No login needed ≤ 5.5.6 CVE-2024-5344 Wordfence
6.4 Medium Flatsome Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.18.7 CVE-2024-5156 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.5.4 CVE-2024-5036 Wordfence
6.5 Medium HTML5 Video Player Plugin html5-video-player SQL Injection Unauthenticated SQLi No login needed < 2.5.27 Fixed in 2.5.27 CVE-2024-5522 WPScan
5.4 Medium Responsive video embed Plugin responsive-video-embed Cross-Site Scripting Contributor+ Stored XSS No login needed < 0.5.1 Fixed in 0.5.1 CVE-2024-5475 WPScan
6.4 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget ≤ 1.1.38 CVE-2024-5686 Wordfence
6.5 Medium Depicter Plugin depicter Broken Access Control Authenticated (Contributor+) Arbitrary Nonce Generation ≤ 3.0.2 CVE-2024-4390 Wordfence
6.4 Medium SEOPress – On-site SEO Plugin wp-seopress Cross-Site Scripting On-site SEO <= 7.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Social Image URL ≤ 7.9 CVE-2024-1168 Wordfence
6.5 Medium Materialis Theme materialis Broken Access Control Missing Authorization to Limited Arbitrary Options Update ≤ 1.1.24 CVE-2023-3204 Wordfence
6.4 Medium Custom Field Suite Plugin custom-field-suite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_title] ≤ 2.6.7 CVE-2024-3558 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters ≤ 1.0.17 CVE-2024-4626 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify SQL Injection BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection ≤ 1.2.5 CVE-2024-4742 Wordfence
5.4 Medium Wheel of Life: Coaching and Assessment Tool for Life Coach Plugin wheel-of-life Broken Access Control Missing Authorization on Several AJAX Endpoints ≤ 1.1.7 CVE-2024-3627 Wordfence
4.3 Medium Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer Plugin promolayer-popup-builder Broken Access Control Promolayer <= 1.1.0 - Missing Authorization ≤ 1.1.0 CVE-2024-3602 Wordfence
5.9 Medium Slider Revolution Plugin Cross-Site Scripting < 6.7.11 Fixed in 6.7.11 CVE-2024-34443 Patchstack
5.4 Medium GamiPress Plugin gamipress Cross-Site Request Forgery CSRF Leading to Settings Change No login needed ≤ 2.5.6 Fixed in 2.5.7 CVE-2023-25697 Patchstack
6.5 Medium Attorney Theme attorney Broken Access Control Unauth. Arbitrary Content Deletion No login needed ≤ 3 CVE-2022-45832 Patchstack
5.4 Medium JupiterX Core Plugin Broken Access Control Multiple Auth. Broken Access Control 3.0.0 – 3.3.0 Fixed in 3.3.5 CVE-2023-38394 Patchstack
5.4 Medium Fusion Builder Plugin Broken Access Control Authenticated Broken Access Control ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39310 Patchstack
5.4 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.6.6 Fixed in 2.6.7 CVE-2023-36676 Patchstack
6.5 Medium Schema Pro Plugin Broken Access Control No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2023-36683 Patchstack
6.5 Medium Premium Addons PRO Plugin Broken Access Control ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-37869 Patchstack
6.5 Medium WooCommerce Ship to Multiple Addresses Plugin Broken Access Control ≤ 3.8.5 Fixed in 3.8.6 CVE-2023-37872 Patchstack
6.5 Medium AutomateWoo Plugin Broken Access Control No login needed ≤ 5.7.5 Fixed in 5.7.6 CVE-2023-36512 Patchstack
5.4 Medium Elementor Pro Plugin Broken Access Control Auth. Broken Access Control ≤ 3.13.0 Fixed in 3.13.1 CVE-2023-35050 Patchstack
6.5 Medium Premium Starter Templates Plugin astra-sites Broken Access Control Broken Access Control vulnerability in multiple Brainstorm Force plugins ≤ 3.2.5 Fixed in 3.2.6 CVE-2023-41805 Patchstack
4.3 Medium Avada Theme Broken Access Control Authenticated Broken Access Control ≤ 7.11.1 Fixed in 7.11.2 CVE-2023-39922 Patchstack
5.4 Medium Paid Memberships Pro Plugin Broken Access Control ≤ 1.2.3 Fixed in 1.2.4 CVE-2023-39990 Patchstack
4.3 Medium Elements kit Elementor addons Plugin elementskit-lite Broken Access Control ≤ 2.9.0 Fixed in 2.9.1 CVE-2023-39993 Patchstack
5.4 Medium Astra Bulk Edit Plugin astra-bulk-edit Broken Access Control ≤ 1.2.7 Fixed in 1.2.8 CVE-2023-44148 Patchstack
5.4 Medium Pre-Publish Checklist Plugin pre-publish-checklist Broken Access Control ≤ 1.1.1 Fixed in 1.1.2 CVE-2023-44151 Patchstack
6.5 Medium WooCommerce Checkout Manager Plugin woocommerce-checkout-manager Broken Access Control No login needed ≤ 7.3.0 Fixed in 7.3.1 CVE-2023-47681 Patchstack
4.3 Medium Jetpack Plugin jetpack Broken Access Control Contributor+ Broken Access Control < 12.7 Fixed in 12.7 CVE-2023-47788 Patchstack
6.3 Medium JetElements For Elementor Plugin Broken Access Control ≤ 2.6.13 Fixed in 2.6.13.1 CVE-2023-48761 Patchstack
6.5 Medium Greenshift – animation and page builder blocks Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting animation and page builder blocks plugin <= 8.8.9.1 - Cross Site Scripting (XSS) ≤ 8.8.9.1 Fixed in 8.9.4 CVE-2024-35765 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only