WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–150 of 217 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Scripting ≤ 2.3 CVE-2025-23897 Patchstack
6.5 Medium Easy Shortcode Buttons Plugin easy-shortcode-buttons Cross-Site Scripting ≤ 1.2 CVE-2025-23825 Patchstack
4.3 Medium Button Block Plugin button-block Broken Access Control ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-22787 Patchstack
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link ≤ 3.4.2 CVE-2024-12304 Wordfence
6.5 Medium Button Block Plugin button-block Cross-Site Scripting ≤ 1.1.9 Fixed in 1.2.0 CVE-2025-22815 Patchstack
4.3 Medium Social Media Share Buttons | MashShare Plugin mashsharer Broken Access Control ≤ 4.0.47 CVE-2025-22319 Patchstack
6.5 Medium mcjh button shortcode Plugin mcjh-button-shortcode Cross-Site Scripting ≤ 1.6.4 CVE-2025-22558 Patchstack
6.5 Medium ICS Button Plugin ics-button Cross-Site Scripting ≤ 0.6 CVE-2025-22574 Patchstack
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
5.3 Medium Floating Action Buttons Plugin floating-action-buttons Broken Access Control No login needed ≤ 0.9.1 Fixed in 1.0.1 CVE-2024-56238 Patchstack
6.5 Medium SvegliaT Buttons Plugin svegliat-buttons Cross-Site Scripting ≤ 1.3.0 CVE-2024-56020 Patchstack
6.4 Medium Spoki – Chat Buttons and WooCommerce Notifications Plugin spoki Cross-Site Scripting Chat Buttons and WooCommerce Notifications <= 2.15.15 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.15.15 CVE-2024-11893 Wordfence
4.7 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting Admin+ Stored XSS via Text Color No login needed < 9.8.1 Fixed in 9.8.1 CVE-2024-8968 WPScan
4.8 Medium MaxButtons Plugin maxbuttons Cross-Site Scripting Admin+ Stored XSS via Button Width < 9.8.1 Fixed in 9.8.1 CVE-2024-10555 WPScan
4.3 Medium Button Block – Get fully customizable & multi-functional buttons Plugin button-block Information Disclosure Get fully customizable & multi-functional buttons <= 1.1.5 - Authenticated (Contributor+) Post Disclosure via Post Duplication ≤ 1.1.5 CVE-2024-12560 Wordfence
5.4 Medium Tithe.ly Giving Button Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1 CVE-2024-11841 WPScan
4.3 Medium Social Share Icons & Social Share Buttons Plugin ultimate-social-media-plus Broken Access Control ≤ 3.5.7 Fixed in 3.5.8 CVE-2023-38514 Patchstack
5.4 Medium Change WooCommerce Add To Cart Button Text Plugin change-woocommerce-add-to-cart-button-text Broken Access Control ≤ 1.3 CVE-2023-34376 Patchstack
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control Broken Access Control + CSRF ≤ 2.8.1 Fixed in 2.8.2 CVE-2023-34009 Patchstack
6.5 Medium Protected Posts Logout Button Plugin protected-posts-logout-button Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2023-25454 Patchstack
4.3 Medium WP Like Button Plugin wp-like-button Broken Access Control ≤ 1.7.0 CVE-2023-47820 Patchstack
5.3 Medium Button Generator – easily Button Builder Plugin button-generation Broken Access Control easily Button Builder plugin <= 2.3.8 - Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2023-49154 Patchstack
6.1 Medium Pulsating Chat Button Plugin amin-chat-button Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.4.1 CVE-2024-11813 Wordfence
5.9 Medium Add Chat App Button Plugin add-whatsapp-button Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.8 CVE-2024-52489 Patchstack
6.5 Medium 소셜 공유 버튼 By 코스모스팜 Plugin cosmosfarm-share-buttons Cross-Site Scripting ≤ 1.9 CVE-2024-53745 Patchstack
6.5 Medium Elementor Button Plus Plugin fd-elementor-button-plus Cross-Site Scripting ≤ 1.3.9 CVE-2024-53746 Patchstack
6.4 Medium Spotify Play Button Plugin spotify-play-button-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode ≤ 2.11 CVE-2024-11192 Wordfence
6.4 Medium Twitter Follow Button Plugin twitter-follow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter ≤ 0.2 CVE-2024-10116 Wordfence
4.3 Medium Button Block – Get fully customizable & multi-functional buttons Plugin button-block Information Disclosure Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.1.4 CVE-2024-10671 Wordfence
6.5 Medium Social button Plugin social-button Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2024-51866 Patchstack
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
6.1 Medium Razorpay Payment Button for Elementor Plugin razorpay-payment-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-10850 Wordfence
6.1 Medium Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-10851 Wordfence
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget ≤ 2.8.4.2 CVE-2024-9505 Wordfence
5.9 Medium Button contact VR Plugin button-contact-vr Cross-Site Scripting ≤ 4.7.9.1 Fixed in 4.7.10 CVE-2024-50414 Patchstack
6.4 Medium Bamazoo – Button Generator Plugin bamazoo-button-generator Cross-Site Scripting Button Generator <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via dgs Shortcode ≤ 1.0 CVE-2024-10150 Wordfence
6.4 Medium Awesome buttons Plugin wp-awesome-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via btn2 Shortcode ≤ 1.0 CVE-2024-10148 Wordfence
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
6.4 Medium Flat UI Button Plugin flat-ui-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via flatbtn Shortcode 1.0 CVE-2024-10014 Wordfence
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.4 Medium BigBlueButton Plugin bigbluebutton Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.0.0-beta.4 CVE-2023-7296 Wordfence
4.3 Medium Read more By Adam Plugin read-more Broken Access Control Missing Authorization to Authenticated (Subscriber+) Read More Button Deletion ≤ 1.1.8 CVE-2024-9187 Wordfence
6.1 Medium Easy Social Share Buttons Plugin easy-social-share-buttons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-8729 Wordfence
6.4 Medium WordPress Infinite Scroll - Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter ≤ 7.1.2 CVE-2024-8505 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module ≤ 2.8.3.6 CVE-2024-9049 Wordfence
6.1 Medium Beam me up Scotty – Back to Top Button Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting No login needed ≤ 1.0.21 CVE-2024-8741 Wordfence
6.4 Medium Tweaker5 Theme tweaker5 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.2 CVE-2024-5870 Wordfence
6.4 Medium Neighborly Theme neighborly Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.4 CVE-2024-5869 Wordfence
6.4 Medium Delicate Theme delicate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 3.5.5 CVE-2024-5867 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only