WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 101–150 of 246 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13733 Wordfence
4.3 Medium B Slider- Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Authenticated (Contributor+) Private Post Disclosure via bsb-slider Shortcode ≤ 1.1.23 CVE-2024-13514 Wordfence
5.3 Medium AnimateGL Animations for WordPress – Elementor & Gutenberg Blocks Animations Plugin animategl Broken Access Control Elementor & Gutenberg Blocks Animations <= 1.4.23 - Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.4.23 CVE-2024-12620 Wordfence
5.4 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 1.6.2 CVE-2024-10867 Wordfence
6.4 Medium Kona Gallery Block Plugin kona-instagram-feed-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13400 Wordfence
4.3 Medium Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Broken Access Control Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Missing Authorization to Icon Font Deletion ≤ 1.5.9 CVE-2024-11583 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via section_tag Parameter ≤ 1.9.9 CVE-2024-13732 Wordfence
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Local File Inclusion with Shortcode, Gutenberg Block & Elementor Widget plugin <= 1.6.10 - Local File Inclusion ≤ 1.6.10 Fixed in 1.7 CVE-2025-24782 Patchstack
4.3 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-24753 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack
5.4 Medium Radius Blocks Plugin radius-blocks Cross-Site Request Forgery WordPress Gutenberg Blocks Plugin <= 2.1.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.1.2 Fixed in 2.2.0 CVE-2025-24712 Patchstack
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.4.2 - Authenticated (contributor+) Stored Cross-Site Scripting via Button Link ≤ 3.4.2 CVE-2024-12304 Wordfence
4.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 5.1.0 CVE-2024-12045 Wordfence
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
6.4 Medium Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode Plugin chat-viber Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.3 CVE-2024-12457 Wordfence
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
4.3 Medium WowStore Plugin product-blocks Broken Access Control Gutenberg WooCommerce Blocks plugin <= 2.7.8 - Broken Access Control No login needed ≤ 2.7.8 Fixed in 3.0.0 CVE-2023-45271 Patchstack
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
5.3 Medium Gutenverse Plugin gutenverse Broken Access Control Gutenberg Blocks – Page Builder for Site Editor plugin <= 1.8.5 - Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.6 CVE-2023-35875 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control No login needed ≤ 3.8.5 Fixed in 3.8.6 CVE-2022-47594 Patchstack
6.4 Medium Gutenberg Blocks and Page Layouts – Attire Blocks Plugin attire-blocks Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.5 CVE-2024-11914 Wordfence
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Activate_Plugin No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23834 Patchstack
4.3 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-47760 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control Multiple Subscriber+ Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-51360 Patchstack
5.4 Medium Essential Blocks for Gutenberg Plugin essential-blocks Broken Access Control Multiple Contributor+ Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2023-51359 Patchstack
5.9 Medium Borderless Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin <= 1.5.8 - Cross Site Scripting (XSS) ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54211 Patchstack
6.4 Medium Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor Plugin gutentor Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.3.9 CVE-2024-10178 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.16.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team Widget ≤ 2.16.2 CVE-2024-10484 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' ≤ 4.1.3 CVE-2024-11203 Wordfence
5.3 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Path Traversal Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.6 - Unauthetnicated Path Traversal to Arbitrary Image View No login needed ≤ 3.0.6 CVE-2024-11219 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin Cross-Site Scripting Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.3.3 CVE-2024-10785 Wordfence
6.4 Medium Getwid – Gutenberg Blocks Plugin getwid Cross-Site Scripting Gutenberg Blocks <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.12 CVE-2024-10872 Wordfence
4.3 Medium Easy Accordion Gutenberg Block Plugin easy-accordion-block Broken Access Control ≤ 1.2.3 Fixed in 1.2.5 CVE-2024-51660 Patchstack
4.3 Medium Content Slider Block – Create fully functional slider with Gutenberg block Plugin content-slider-block Information Disclosure Create fully functional slider with Gutenberg block <= 3.1.5 - Authenticated (Contributor+) Post Disclosure ≤ 3.1.5 CVE-2024-10667 Wordfence
4.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control ≤ 2.13.7 Fixed in 2.13.8 CVE-2024-37517 Patchstack
4.3 Medium Recipe Card Blocks for Gutenberg & Elementor Plugin recipe-card-blocks-by-wpzoom Broken Access Control ≤ 3.3.1 Fixed in 3.3.2 CVE-2024-43293 Patchstack
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.0.4 CVE-2024-10367 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget ≤ 3.3.1 CVE-2024-9655 Wordfence
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.93 Fixed in 2.2.94 CVE-2024-50432 Patchstack
5.3 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Content Injection Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection No login needed ≤ 3.13.6 CVE-2024-8760 Wordfence
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Cross-Site Scripting ≤ 2.2.89 Fixed in 2.2.90 CVE-2024-47340 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.33 Fixed in 2.1.34 CVE-2024-47368 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.8.4 Fixed in 4.9.0 CVE-2024-47385 Patchstack
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.6.0 Fixed in 3.7.0 CVE-2024-47627 Patchstack
6.4 Medium Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg Plugin guten-post-layout Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.2.4 CVE-2024-8288 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.9.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.9.7 CVE-2024-8668 Wordfence
6.4 Medium GutenGeek Free Gutenberg Blocks Plugin gtg-advanced-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.3 CVE-2024-9073 Wordfence
6.4 Medium Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) Plugin graphicsly Cross-Site Scripting The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9069 Wordfence
6.5 Medium Gutenberg Blocks Plugin unlimited-blocks Cross-Site Scripting Unlimited blocks For Gutenberg plugin <= 1.2.8 - Authenticated Cross Site Scripting (XSS) ≤ 1.2.8 CVE-2024-44049 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only