WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 101–150 of 164 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Image Carousel Shortcode | Cross-Site Scripting |
≤ 1.2 |
CVE-2024-51842 |
Patchstack | |
| 5.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Map Widget |
≤ 5.10.2 |
CVE-2024-9867 |
Wordfence | |
| 6.5 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 5.10.2 |
CVE-2024-9657 |
Wordfence | |
| 5.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate |
≤ 5.10.1 |
CVE-2024-9868 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget |
≤ 5.10.1 |
CVE-2024-10310 |
Wordfence | |
| 9.9 Critical | WP donimedia carousel | Arbitrary File Upload |
≤ 1.0.1 |
CVE-2024-50511 |
Patchstack | |
| 6.5 Medium | Meta slider and carousel with lightbox | Cross-Site Scripting |
≤ 2.0.1 Fixed in 2.0.2 |
CVE-2024-47307 |
Patchstack | |
| 6.5 Medium | Logo Carousel – Clients logo carousel for WP | Cross-Site Scripting Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) |
≤ 1.2 Fixed in 1.3.0 |
CVE-2024-47631 |
Patchstack | |
| 6.5 Medium | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated Local File Inclusion |
≤ 1.9.10 Fixed in 1.10.0 |
CVE-2024-44048 |
Patchstack | |
| 4.8 Medium | Carousel Slider | Cross-Site Scripting Editor+ Stored XSS |
< 2.2.4 Fixed in 2.2.4 |
CVE-2024-6850 |
WPScan | |
| 4.9 Medium | video carousel slider with lightbox | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.0.6 |
CVE-2019-25212 |
Wordfence | |
| 4.3 Medium | Carousel Slider | Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed |
prior to 2.2.4 |
CVE-2024-45270 |
jpcert | |
| 4.3 Medium | Carousel Slider | Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed |
prior to 2.0 |
CVE-2024-45269 |
jpcert | |
| 6.4 Medium | Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | Cross-Site Scripting Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.4.1 |
CVE-2024-8046 |
Wordfence | |
| 6.4 Medium | Tutor LMS Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Course Carousel Widget |
≤ 2.1.4 |
CVE-2024-5576 |
Wordfence | |
| 8.8 High | Depicter — Popup & Slider Builder | Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 3.1.1 |
CVE-2024-4389 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets |
≤ 5.7.2 |
CVE-2024-7247 |
Wordfence | |
| 6.5 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Path Traversal Authenticated (Contributor+) Arbitrary File Read |
≤ 5.7.2 |
CVE-2024-4359 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag |
≤ 5.7.6 |
CVE-2024-4360 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-4643 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget |
≤ 2.2.85 |
CVE-2024-6346 |
Wordfence | |
| 6.5 Medium | FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross-Site Scripting |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-38686 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.5 |
CVE-2024-5555 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-5554 |
Wordfence | |
| 6.5 Medium | Image Hover Effects - Caption Hover with Carousel | Cross-Site Scripting |
≤ 3.0.2 |
CVE-2024-37546 |
Patchstack | |
| 6.4 Medium | Ultimate Post Kit Addons for Elementor | Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget |
≤ 3.11.7 |
CVE-2024-5662 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events |
≤ 5.6.11 |
CVE-2024-3925 |
Wordfence | |
| 4.3 Medium | Advanced Testimonial Carousel for Elementor | Broken Access Control |
≤ 3.0.0 Fixed in 3.0.1 |
CVE-2024-32783 |
Patchstack | |
| 6.5 Medium | Testimonial Carousel For Elementor | Cross-Site Scripting |
≤ 10.1.1 Fixed in 10.2.0 |
CVE-2024-35713 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute |
≤ 2.2.80 |
CVE-2024-4042 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-1988 |
Wordfence | |
| 6.4 Medium | Image Hover Effects for Elementor with Lightbox and Flipbox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _id, oxi_addons_f_title_tag, and content_description_tag Parameters |
≤ 3.0.2 |
CVE-2024-5001 |
Wordfence | |
| 8.8 High | Responsive Owl Carousel for Elementor | Local File Inclusion |
≤ 1.2.0 |
CVE-2024-5345 |
Wordfence | |
| 6.4 Medium | Testimonial Carousel For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.2.2 |
CVE-2024-2253 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor PRO – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Carousel Widget |
≤ 5.8.14 |
CVE-2024-5086 |
Wordfence | |
| 5.3 Medium | Testimonial Carousel For Elementor | Broken Access Control Missing Authorization to Limited Setting Update No login needed |
≤ 10.2.0 |
CVE-2024-4858 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes |
≤ 5.6.1 |
CVE-2024-3926 |
Wordfence | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Other Form Submission Admin Email Bypass No login needed |
≤ 5.6.3 |
CVE-2024-3927 |
Wordfence | |
| 5.4 Medium | Carousel Slider | Cross-Site Scripting Editor+ Stored XSS |
< 2.2.11 Fixed in 2.2.11 |
CVE-2024-4372 |
WPScan | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-3155 |
Wordfence | |
| 6.4 Medium | Testimonial Carousel For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.1.1 |
CVE-2024-4698 |
Wordfence | |
| 5.3 Medium | Slider Carousel – Responsive Image Slider | Broken Access Control Responsive Image Slider plugin <=1.5.1 - Broken Access Control No login needed |
≤ 1.5.1 Fixed in 1.5.2 |
CVE-2023-25457 |
Patchstack | |
| 4.7 Medium | Carousel Slider | Cross-Site Scripting Editor+ Stored XSS No login needed |
< 2.2.10 Fixed in 2.2.10 |
CVE-2024-3703 |
WPScan | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes |
≤ 1.3.971 |
CVE-2024-3675 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget |
≤ 5.6.0 |
CVE-2024-1429 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget |
≤ 5.6.0 |
CVE-2024-1426 |
Wordfence | |
| 4.7 Medium | Carousel Slider | Cross-Site Scripting Editor+ Stored XSS No login needed |
< 2.2.7 Fixed in 2.2.7 |
CVE-2024-1712 |
WPScan | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Information Disclosure Sensitive Information Exposure via element_pack_ajax_search No login needed |
≤ 5.5.6 |
CVE-2024-2966 |
Wordfence | |
| 6.4 Medium | Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows | Cross-Site Scripting Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode |
≤ 3.70.0 |
CVE-2024-3285 |
Wordfence | |
| 7.2 High | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection |
≤ 2.6.3 |
CVE-2024-3020 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.