WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 286 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce 1.0.4 - 1.2.1 - Missing Authorization to Unauthenticated Limited Arbitrary Options Update No login needed 1.0.4 – 1.2.1 CVE-2025-2568 Wordfence
6.5 Medium Gutena Kit – Gutenberg Blocks and Templates Plugin gutena-kit Cross-Site Scripting ≤ 2.0.7 CVE-2025-31805 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
6.5 Medium Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Cross-Site Scripting Gutenberg Blocks plugin <= 1.4.7 - Cross Site Scripting (XSS) ≤ 1.4.7 CVE-2025-22644 Patchstack
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.19.0 CVE-2025-1784 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
4.3 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Information Disclosure Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_content ≤ 1.8.13 CVE-2024-13228 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 CVE-2025-1664 Wordfence
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.0 CVE-2024-13675 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon' ≤ 3.4.9 CVE-2025-1291 Wordfence
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin post-grid Information Disclosure ComboBlocks <= 2.3.6 - Unauthenticated User Information Exposure No login needed ≤ 2.3.6 CVE-2024-13796 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.3 CVE-2024-13803 Wordfence
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-26983 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.8.3 Fixed in 4.8.4 CVE-2025-26871 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks – ComboBlocks Plugin Broken Access Control ComboBlocks <= 2.3.5 - Unauthenticated Paid Order Creation No login needed ≤ 2.3.5 CVE-2024-13798 Wordfence
6.4 Medium UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included Plugin ultraembed-advanced-iframe Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11335 Wordfence
6.4 Medium aBlocks – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 1.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.1 CVE-2024-13465 Wordfence
6.5 Medium Qubely – Advanced Gutenberg Blocks Plugin qubely Cross-Site Scripting Advanced Gutenberg Blocks <= 1.8.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' and 'UniqueID' ≤ 1.8.12 CVE-2024-9601 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleTag Parameter ≤ 3.6 CVE-2025-0506 Wordfence
6.5 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.7 CVE-2025-25080 Patchstack
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13733 Wordfence
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
7.1 High Photo Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.24 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.7.24 Fixed in 2.7.7.25 CVE-2025-24707 Patchstack
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
5.4 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.6.2 CVE-2024-10867 Wordfence
6.4 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13400 Wordfence
7.2 High Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Remote Code Execution Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.0 - Authenticated (Administrator+) Remote Code Execution ≤ 1.6.0 CVE-2024-11600 Wordfence
4.3 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Broken Access Control Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing Authorization to Icon Font Deletion ≤ 1.5.9 CVE-2024-11583 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter ≤ 1.9.9 CVE-2024-13732 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-24753 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
5.4 Medium Radius Blocks Plugin radius-blocks Cross-Site Request Forgery WordPress Gutenberg Blocks Plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.1.2 Fixed in 2.2.0 CVE-2025-24712 Patchstack
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.10 CVE-2024-13408 Wordfence
7.5 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() ≤ 1.6.10 CVE-2024-13409 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
9.8 Critical Post Grid and Gutenberg Blocks Plugin post-grid Privilege Escalation Unauthenticated Privilege Escalation No login needed 2.2.85 – 2.3.3 CVE-2024-9636 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link ≤ 3.4.2 CVE-2024-12304 Wordfence
4.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 5.1.0 CVE-2024-12045 Wordfence
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control No login needed ≤ 2.7.8 Fixed in 3.0.0 CVE-2023-45271 Patchstack
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
5.3 Medium Gutenverse Plugin gutenverse Broken Access Control Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.8.5 - Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.6 CVE-2023-35875 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control No login needed ≤ 3.8.5 Fixed in 3.8.6 CVE-2022-47594 Patchstack
9.8 Critical Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.1.1 CVE-2024-10124 Wordfence
6.4 Medium Gutenberg Blocks and Page Layouts – Attire Blocks Plugin attire-blocks Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.5 CVE-2024-11914 Wordfence
3.1 Low Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Import_WPforms ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23825 Patchstack
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Activate_Plugin No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23834 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only