WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,701–14,750 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 295 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Master Slider Plugin master-slider Cross-Site Request Forgery No login needed ≤ 3.9.10 CVE-2023-50900 Patchstack
6.4 Medium WooCommerce Checkout & Funnel Builder by CartFlows – Create High Converting Stores For WooCommerce Plugin cartflows Cross-Site Scripting Create High Converting Stores For WooCommerce <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.7 CVE-2024-4632 Wordfence
4.4 Medium YARPP – Yet Another Related Posts Plugin Cross-Site Scripting Yet Another Related Posts Plugin <= 5.30.9 - Authenticated(Administrator+) Cross-Site Scripting ≤ 5.30.9 CVE-2023-6495 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'group_tag' ≤ 9.1.0 CVE-2024-0383 Wordfence
5.3 Medium WP Maintenance Plugin wp-maintenance Other IP Spoofing to Maintenance Mode Bypass No login needed ≤ 6.1.9.2 CVE-2024-0789 Wordfence
5.4 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery Cross-Site Request Forgery to Membership Modification No login needed ≤ 2.12.10 CVE-2024-1407 Wordfence
6.4 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title ≤ 3.2.19 CVE-2024-3894 Wordfence
5.3 Medium SiteGuard WP Plugin siteguard Other SiteGuard WP Plugin provides a functionality to customize the path to the login page wp-login.php and implements a measure to avoid redirection from other URLs. However, SiteGuard… No login needed prior to 1.7.7 CVE-2024-37881 jpcert
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.0.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via metabox ≤ 3.1.0 CVE-2023-6692 Wordfence
6.4 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2024-5768 Wordfence
6.4 Medium Blogmentor – Blog Layouts for Elementor Plugin blogmentor Cross-Site Scripting Blog Layouts for Elementor <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagination_style Parameter ≤ 1.5 CVE-2024-4623 Wordfence
5.4 Medium Universal Slider Plugin fusion-slider PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.6.5 CVE-2024-5649 Wordfence
4.3 Medium Replace Image Plugin replace-image Broken Access Control Insecure Direct Object Reference ≤ 1.1.10 CVE-2024-4873 Wordfence
6.4 Medium EmbedSocial – Social Media Feeds, Reviews and Galleries Plugin embedalbum-pro Cross-Site Scripting Social Media Feeds, Reviews and Galleries <= 1.1.29 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.29 CVE-2024-3984 Wordfence
6.4 Medium OSM Map Widget for Elementor Plugin osm-map-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.2.2 CVE-2024-4663 Wordfence
4.3 Medium Custom Product List Table Plugin custom-product-list-table Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2024-4541 Wordfence
6.3 Medium AliExpress Dropshipping with AliNext Lite Plugin ali2woo-lite Broken Access Control Missing Authorization via Several Functions ≤ 3.3.6 CVE-2024-4450 Wordfence
6.4 Medium MaxGalleria Plugin maxgalleria Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thumb Shortcode ≤ 6.4.4 CVE-2024-5970 Wordfence
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.25.1 CVE-2024-5533 Wordfence
4.8 Medium Expert Invoice Plugin Cross-Site Scripting Expert Invoice <= 1.0.2 -Admin+ Stored XSS ≤ 1.0.2 CVE-2024-5172 WPScan
5.4 Medium Simple Share Buttons Adder Plugin simple-share-buttons-adder Cross-Site Scripting Admin+ Stored XSS < 8.5.1 Fixed in 8.5.1 CVE-2024-4094 WPScan
6.1 Medium FooBox (Free and Premium) Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.7.28 Fixed in 2.7.28 CVE-2024-3276 WPScan
4.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion ≤ 3.5.2.8 CVE-2024-5860 Wordfence
5.3 Medium Ibtana - WordPress Website Builder Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder <= 1.2.3.3 - Unauthenticated reCAPTCHA Settings Update No login needed ≤ 1.2.3.3 CVE-2024-5541 Wordfence
6.5 Medium Scheduling Plugin – Online Booking Plugin calendar-booking Broken Access Control Online Booking for WordPress <= 3.5.10 - Missing Authorization to Unauthenticated Service Disconnection No login needed ≤ 3.5.10 CVE-2024-1634 Wordfence
6.4 Medium PDF Viewer for Elementor Plugin pdf-viewer-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via render ≤ 2.9.3 CVE-2024-0845 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.9.10 CVE-2024-4375 Wordfence
6.8 Medium PostX Plugin Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-4305 WPScan
5.4 Medium Easy Notify Lite Plugin easy-notify-lite Cross-Site Scripting Contributor+ Stored XSS < 1.1.33 Fixed in 1.1.33 CVE-2024-3236 WPScan
6.4 Medium Stratum – Elementor Widgets Plugin stratum Cross-Site Scripting Elementor Widgets <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.4.1 CVE-2024-5611 Wordfence
6.4 Medium Collapse-O-Matic Plugin jquery-collapse-o-matic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.8.5.8 CVE-2024-4095 Wordfence
6.4 Medium Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Authenticated (Contributor+) Arbitrary File Inclusion via Shortcode ≤ 1.3.13 CVE-2024-4551 Wordfence
6.4 Medium Shariff Wrapper Plugin shariff Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.6.13 CVE-2024-2695 Wordfence
4.3 Medium Infographic Maker iList Plugin infographic-and-list-builder-ilist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Title Update ≤ 4.7.4 CVE-2024-5858 Wordfence
6.4 Medium Restaurant Menu and Food Ordering Plugin mp-restaurant-menu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.4.0 CVE-2024-1399 Wordfence
6.5 Medium WooCommerce - Social Login Plugin Other Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness No login needed ≤ 2.6.2 CVE-2024-5868 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets ≤ 2.6.5 CVE-2024-4479 Wordfence
5.5 Medium Newspaper Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta ≤ 12.6.5 CVE-2024-3815 Wordfence
6.4 Medium ElementsKit Elementor addons and Templates Library Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Motion Text and Table Widgets ≤ 3.6.2 CVE-2024-5263 Wordfence
5.5 Medium tagDiv Composer Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta ≤ 4.8 CVE-2024-3814 Wordfence
4.3 Medium Folders Plugin folders Path Traversal Directory Traversal via handle_folders_file_upload ≤ 3.0, ≤ 3.0.2 CVE-2024-2023 Wordfence
4.3 Medium ProjectHuddle Client Site Plugin projecthuddle-child-site Broken Access Control ≤ 1.0.34 Fixed in 1.0.35 CVE-2023-51376 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.38 - Authenticated (Contributor+) Stored Cross-Site Scripting via titleFont Parameter ≤ 3.2.38 CVE-2024-4863 Wordfence
6.4 Medium WP Go Maps (formerly WP Google Maps) Plugin wp-google-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.0.38 CVE-2024-5994 Wordfence
6.1 Medium Inquiry Cart Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 3.4.2 CVE-2024-5155 WPScan
4.3 Medium WP Prayer II Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 2.4.7 CVE-2024-4751 WPScan
6.1 Medium WP Prayer II Plugin Cross-Site Request Forgery Email Settings Update via CSRF ≤ 2.4.7 CVE-2024-4480 WPScan
4.6 Medium SVGator Plugin svgator Cross-Site Scripting Stored XSS via SVG Upload ≤ 1.2.6 CVE-2024-4271 WPScan
5.4 Medium SVGMagic Plugin Cross-Site Scripting Stored XSS via SVG Upload ≤ 1.1 CVE-2024-4270 WPScan
5.4 Medium Social Pixel Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 2.1 CVE-2024-4005 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only