WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 179 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting Reflected XSS No login needed ≤ 1.40 CVE-2024-13574 WPScan
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.8.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Countdown Widget ≤ 2.8.2 CVE-2025-1261 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin responsive-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Featherlight.js JavaScript Library ≤ 1.3.4, ≤ 2.4.7 CVE-2024-5667 Wordfence
7.1 High Stray Random Quotes Plugin stray-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.9 CVE-2025-23883 Patchstack
4.4 Medium Counter Box: Add Engaging Countdowns, Timers & Counters to Your WordPress Site Plugin counter-box Cross-Site Scripting Authenticated (Administrator+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-13901 Wordfence
6.4 Medium Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty Plugin chaty Cross-Site Scripting Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.3.5 CVE-2025-1450 Wordfence
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.6.0 CVE-2024-6261 Wordfence
7.5 High LTL Freight Quotes – Old Dominion Edition Plugin SQL Injection Old Dominion Edition <= 4.2.10 - Unauthenticated SQL Injection No login needed ≤ 4.2.10 CVE-2024-13489 Wordfence
6.5 Medium OPSI Israel Domestic Shipments Plugin woo-ups-pickup Broken Access Control No login needed ≤ 2.8.2 CVE-2025-23766 Patchstack
6.4 Medium Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math Cross-Site Scripting AI SEO Tools to Dominate SEO Rankings <= 1.0.235 - Authenticated (Contributor+) Stored Cross-Site Scripting via Rank Math API ≤ 1.0.235 CVE-2024-13227 Wordfence
6.1 Medium Stray Random Quotes Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.9.9 CVE-2024-13570 WPScan
7.1 High WP24 Domain Check Plugin wp24-domain-check Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.10.14 Fixed in 1.10.15 CVE-2025-24602 Patchstack
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via url Parameter ≤ 3.7.8 CVE-2025-0321 Wordfence
6.1 Medium Quiz Maker Business, Developer, and Agency <= (Multiple Versions) Plugin Cross-Site Scripting Reflected DOM-Based Cross-Site Scripting via content No login needed ≤ 21.8.0, ≤ 31.8.0, ≤ 8.8.0 CVE-2024-10636 Wordfence
7.1 High Mind3doM RyeBread Widgets Plugin mind3dom-ryebread-widgets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23722 Patchstack
6.4 Medium HTML5 Video Player – mp4 Video Player Plugin and Block Plugin html5-video-player Cross-Site Scripting mp4 Video Player Plugin and Block <= 2.5.35 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via heading Parameter ≤ 2.5.35 CVE-2024-13156 Wordfence
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'booking' Shortcode ≤ 10.9.2 CVE-2024-13323 Wordfence
6.4 Medium Dominion – Domain Checker for WPBakery Plugin dominion-domain-checker-wpbakery-addon Cross-Site Scripting Domain Checker for WPBakery <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 CVE-2024-12520 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Sina Image Differ ≤ 3.5.91 CVE-2024-12624 Wordfence
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting Unauthenticated DOM-XSS No login needed 13.0 – < 14.1 Fixed in 14.1 CVE-2024-10858 WPScan
6.4 Medium Listdom – Business Directory and Classified Ads Listings Plugin listdom Cross-Site Scripting Business Directory and Classified Ads Listings WordPress Plugin <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode Parameter ≤ 3.7.0 CVE-2024-11854 Wordfence
6.4 Medium Multiple Plugins <= (Various Versions) Plugin woo-smart-quick-view Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via FancyBox JavaScript Library ≤ 1.0.286, ≤ 1.8.15, ≤ 1.9.12, … CVE-2024-5020 Wordfence
6.4 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Lightbox Widget ≤ 5.10.5 CVE-2024-9058 Wordfence
6.5 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-53787 Patchstack
7.1 High Domain Sharding Plugin domain-sharding Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-50533 Patchstack
7.1 High Random Featured Post Plugin random-featured-post-plugin Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2024-51650 Patchstack
6.5 Medium EndomondoWP Plugin endomondowp Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.1 CVE-2024-50551 Patchstack
9.8 Critical AJAX Random Posts Plugin ajax-random-posts PHP Object Injection No login needed ≤ 0.3.3 CVE-2024-52409 Patchstack
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Form Builder Widget ≤ 1.7.1001 CVE-2024-9682 Wordfence
6.4 Medium Royal Elementor Addons and Template Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Google Maps Widget ≤ 1.7.1001 CVE-2024-9059 Wordfence
6.5 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.10.2 CVE-2024-9657 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Custom Gallery Widget ≤ 5.10.1 CVE-2024-10310 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget ≤ 2.8.4.2 CVE-2024-9505 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Box Widget ≤ 4.10.60 CVE-2024-10266 Wordfence
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip' ≤ 9.6.1 CVE-2024-9650 Wordfence
5.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 7.2.2 CVE-2024-8500 Wordfence
7.5 High SB Random Posts Widget Plugin sb-random-posts-widget Local File Inclusion ≤ 1.0 Fixed in 1.1 CVE-2024-48029 Patchstack
7.2 High Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math PHP Object Injection AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection ≤ 1.0.228 CVE-2024-9314 Wordfence
6.5 Medium Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete No login needed ≤ 1.0.228 CVE-2024-9161 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module ≤ 2.8.3.6 CVE-2024-9049 Wordfence
6.4 Medium Absolute Reviews Plugin absolute-reviews Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Criteria Name ≤ 1.1.3 CVE-2024-8965 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
6.4 Medium Lightbox & Modal Popup WordPress Plugin – FooBox Plugin foobox-image-lightbox Cross-Site Scripting FooBox <= 2.7.28 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes ≤ 2.7.28 CVE-2024-5668 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget ≤ 1.3.980 CVE-2024-5818 Wordfence
6.5 Medium Elementor – Header, Footer & Blocks Template Plugin header-footer-elementor Cross-Site Scripting Contributor+ DOM-Based Cross Site Scripting (XSS) ≤ 1.6.35 Fixed in 1.6.36 CVE-2024-33933 Patchstack
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
6.4 Medium Feeds for YouTube (YouTube video, channel, and gallery plugin) Plugin feeds-for-youtube Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-6256 Wordfence
6.4 Medium WP Lightbox 2 Plugin wp-lightbox-2 Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.0.6.6 CVE-2024-6263 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes ≤ 3.2.45 CVE-2024-5819 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.13.1 CVE-2024-6296 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only