WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 101–144 of 144 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 3 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages Plugin clickwhale Cross-Site Scripting Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2025-0804 Wordfence
6.1 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 2.7.2 CVE-2024-12385 Wordfence
6.5 Medium Progress Tracker Plugin progress-tracker Cross-Site Scripting ≤ 0.9.3 CVE-2025-23892 Patchstack
5.9 Medium WordPress HelpDesk & Support Ticket System Plugin – Octrace Support Plugin octrace-support Cross-Site Scripting ≤ 1.2.7 CVE-2025-22762 Patchstack
6.4 Medium Trackserver Plugin trackserver Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.2 CVE-2024-12505 Wordfence
6.1 Medium ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages Plugin clickwhale Cross-Site Scripting Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages <= 2.4.1 - Reflected Cross-Site Scripting No login needed ≤ 2.4.1 CVE-2024-11327 Wordfence
4.3 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Limited Settings Update ≤ 1.0.2 CVE-2024-5769 Wordfence
6.4 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 CVE-2024-8721 Wordfence
6.4 Medium Outdooractive Embed Plugin outdooractive-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5 CVE-2024-11774 Wordfence
6.1 Medium isee-products-extractor Plugin isee-products-extractor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.3 CVE-2024-11331 Wordfence
5.4 Medium WPCargo Track & Trace Plugin wpcargo Broken Access Control Settings Change ≤ 8.0.2 CVE-2024-54271 Patchstack
5.3 Medium Conversios.io Plugin enhanced-e-commerce-for-woocommerce-store Broken Access Control No login needed ≤ 6.5.0 Fixed in 6.5.1 CVE-2023-51357 Patchstack
6.5 Medium Znajdź Pracę z Praca.pl Plugin znajdz-prace-z-pracapl Cross-Site Scripting ≤ 2.2.3 CVE-2024-53773 Patchstack
4.3 Medium Order Tracking Plugin order-tracking Broken Access Control WordPress Status Tracking Plugin plugin < 3.3.13 - Broken Access Control ≤ 3.3.12 Fixed in 3.3.13 CVE-2024-43343 Patchstack
5.9 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-50411 Patchstack
6.5 Medium Interactive World Map Plugin interactive-world-map Cross-Site Scripting ≤ 3.4.4 Fixed in 3.4.8 CVE-2024-50462 Patchstack
5.9 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Scripting ≤ 2.6.5 Fixed in 2.7.0 CVE-2024-44045 Patchstack
6.4 Medium RD Station Plugin integracao-rd-station Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.2 CVE-2024-6894 Wordfence
5.3 Medium Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free Plugin funnelforms-free Broken Access Control Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Deletion No login needed ≤ 3.7.3.2 CVE-2024-5857 Wordfence
5.3 Medium Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free Plugin funnelforms-free Broken Access Control Funnelforms Free <= 3.7.3.2 - Missing Authorization to Unauthenticated Arbitrary Media Upload No login needed ≤ 3.7.3.2 CVE-2024-7447 Wordfence
5.9 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting ≤ 1.15.6 Fixed in 1.15.7 CVE-2024-43152 Patchstack
6.4 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2024-5768 Wordfence
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2023-52217 Patchstack
4.3 Medium Tracking Code Manager Plugin tracking-code-manager Broken Access Control ≤ 2.1.0 Fixed in 2.2.0 CVE-2024-31347 Patchstack
5.3 Medium Vision Interactive Plugin vision Broken Access Control Image Map Builder plugin <= 1.7.1 - Broken Access Control No login needed ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-32779 Patchstack
5.9 Medium Brave Plugin brave-popup-builder Cross-Site Scripting Interactive Content plugin <= 0.6.9 - Cross Site Scripting (XSS) ≤ 0.6.9 Fixed in 0.7.0 CVE-2024-35655 Patchstack
6.5 Medium Orders Tracking for WooCommerce Plugin woo-orders-tracking Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.10 CVE-2024-4039 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' ≤ 5.9.19 CVE-2024-4275 Wordfence
5.3 Medium Democracy Poll Plugin democracy-poll Broken Access Control No login needed ≤ 6.0.3 CVE-2024-33920 Patchstack
6.1 Medium Interactive World Maps Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.14 CVE-2024-3681 Wordfence
5.3 Medium Analytify Plugin wp-analytify Broken Access Control Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification No login needed ≤ 5.2.3 CVE-2024-1584 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle ≤ 5.9.15 CVE-2024-3728 Wordfence
6.4 Medium 3D FlipBook Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scritping via Bookmark URL ≤ 1.15.4 CVE-2024-3883 Wordfence
5.3 Medium TrackShip for WooCommerce Plugin trackship-for-woocommerce Broken Access Control No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-32678 Patchstack
6.5 Medium Lordicon Animated Icons Plugin lordicon-interactive-icons Cross-Site Scripting ≤ 2.0.1 CVE-2024-30519 Patchstack
6.5 Medium Dracula Dark Mode - The Revolutionary Dark Mode Plugin dracula-dark-mode Cross-Site Scripting ≤ 1.0.8 Fixed in 1.0.9 CVE-2024-29771 Patchstack
4.3 Medium WooCommerce Conversion Tracking Plugin woocommerce-conversion-tracking Broken Access Control ≤ 2.0.11 Fixed in 2.0.12 CVE-2024-24711 Patchstack
4.3 Medium Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Cross-Site Request Forgery Affiliate Links, Link Branding, Link Tracking & Marketing Plugin <= 3.6.3 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.6.3 CVE-2024-2326 Wordfence
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting ≤ 2.0.16 Fixed in 2.1.0 CVE-2024-2579 Patchstack
5.4 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin Cross-Site Scripting Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.0.13 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.0.13 CVE-2024-0903 Wordfence
5.9 Medium Brave – Create Popup, Optins, Lead Generation, Survey, Sticky Elements & Interactive Content Plugin brave-popup-builder Cross-Site Scripting WordPress Brave Popup Builder Plugin <= 0.6.2 is vulnerable to Cross Site Scripting (XSS) ≤ 0.6.2 Fixed in 0.6.3 CVE-2023-51534 Patchstack
6.5 Medium Ideal Interactive Map Plugin ideal-interactive-map Cross-Site Scripting WordPress Ideal Interactive Map Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.4 CVE-2023-52189 Patchstack
4.8 Medium Restrict Usernames Emails Characters Plugin restrict-usernames-emails-characters Cross-Site Scripting Admin+ Stored XSS < 3.1.4 Fixed in 3.1.4 CVE-2023-6165 WPScan
6.4 Medium 3D Flipbook Plugin interactive-3d-flipbook-powered-physics-engine Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting via Ready Function ≤ 1.15.2 CVE-2023-6776 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only