WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 14,951–15,000 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 300 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Icegram Plugin icegram Broken Access Control ≤ 3.1.21 Fixed in 3.1.22 CVE-2024-21748 Patchstack
5.4 Medium WP-Recall Plugin wp-recall Cross-Site Request Forgery No login needed ≤ 16.26.6 CVE-2024-35657 Patchstack
5.3 Medium KiviCare Plugin kivicare-clinic-management-system Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.6.6 Fixed in 3.6.7 CVE-2024-35659 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 1.93 Fixed in 1.94 CVE-2024-35675 Patchstack
6.5 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.7 Fixed in 1.8 CVE-2024-35676 Patchstack
8.5 High Contact Form to DB by BestWebSoft Plugin contact-form-to-db SQL Injection ≤ 1.7.2 Fixed in 1.7.3 CVE-2024-35678 Patchstack
7.1 High GiveWP Plugin give Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.12.0 Fixed in 3.12.1 CVE-2024-35679 Patchstack
6.5 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting ≤ 7.6.18 Fixed in 7.6.19 CVE-2024-35681 Patchstack
4.3 Medium Otter Blocks PRO Plugin Information Disclosure Authenticated Sensitive Data Exposure ≤ 2.6.11 Fixed in 2.6.12 CVE-2024-35682 Patchstack
4.3 Medium ElasticPress Plugin elasticpress Cross-Site Request Forgery No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2024-35684 Patchstack
6.5 Medium Sensei Pro (WC Paid Courses) Plugin Cross-Site Scripting ≤ 4.23.1.1.23.1 Fixed in 4.24.0.1.24.0 CVE-2024-34765 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross-Site Scripting (XSS) No login needed ≤ 7.6.3 Fixed in 7.6.4 CVE-2024-35687 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.9 Fixed in 2.0.6.0 CVE-2024-35688 Patchstack
5.4 Medium Analytify Plugin wp-analytify Cross-Site Request Forgery No login needed ≤ 5.2.3 Fixed in 5.2.4 CVE-2024-35689 Patchstack
6.5 Medium Widget Options - Extended Plugin Information Disclosure Extended plugin <= 5.1.0 - Multiple Data Exposure ≤ 5.1.0 Fixed in 5.1.3 CVE-2024-35691 Patchstack
7.1 High 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting No login needed ≤ 3.14.33 Fixed in 3.14.34 CVE-2024-35693 Patchstack
7.1 High WPMobile.App Plugin wpappninja Cross-Site Scripting No login needed ≤ 11.41 Fixed in 11.42 CVE-2024-35694 Patchstack
6.5 Medium WP Docs Plugin wp-docs Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35695 Patchstack
7.1 High WP Docs Plugin wp-docs Cross-Site Scripting No login needed ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35696 Patchstack
7.1 High Eduma Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.4.7 Fixed in 5.4.8 CVE-2024-35697 Patchstack
5.9 Medium YITH WooCommerce Tab Manager Plugin yith-woocommerce-tab-manager Cross-Site Scripting ≤ 1.35.0 Fixed in 1.35.1 CVE-2024-35698 Patchstack
6.5 Medium HT Feed Plugin ht-instagram Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-35699 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.0.13 Fixed in 2.0.14 CVE-2024-35701 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.6.0 Fixed in 2.0.6.1 CVE-2024-35702 Patchstack
6.5 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting ≤ 3.5.3 Fixed in 3.5.4 CVE-2024-35703 Patchstack
6.5 Medium BlockArt Blocks Plugin blockart-blocks Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-35704 Patchstack
6.5 Medium Block for Font Awesome Plugin block-for-font-awesome Cross-Site Scripting ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-35705 Patchstack
7.1 High Heateor Social Login Plugin heateor-social-login Cross-Site Scripting No login needed ≤ 1.1.32 Fixed in 1.1.33 CVE-2024-35706 Patchstack
6.5 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Scripting ≤ 1.1.32 Fixed in 1.1.33 CVE-2024-35707 Patchstack
6.5 Medium Rife Free Theme rife-free Cross-Site Scripting ≤ 2.4.19 Fixed in 2.4.20 CVE-2024-35708 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.5.4 Fixed in 5.5.5 CVE-2024-35709 Patchstack
5.3 Medium Podlove Web Player Plugin podlove-web-player Information Disclosure Sensitive Data Exposure No login needed ≤ 5.7.3 Fixed in 5.7.4 CVE-2024-35710 Patchstack
6.5 Medium Event Theme event Cross-Site Scripting ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-35711 Patchstack
6.5 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting ≤ 10.1.1 Fixed in 10.2.0 CVE-2024-35713 Patchstack
6.5 Medium Idyllic Theme idyllic Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-35714 Patchstack
6.5 Medium Bloglo Theme bloglo Cross-Site Scripting WordPress Bloglo and Blogvi themes affected by Cross Site Scripting (XSS) ≤ 1.1.3, ≤ 1.0.5 Fixed in 1.1.4 CVE-2024-35715 Patchstack
7.1 High Newsletters Plugin newsletters-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2024-35718 Patchstack
6.5 Medium RestroPress Plugin restropress Cross-Site Scripting ≤ 3.1.2.1 Fixed in 3.1.2.2 CVE-2024-35719 Patchstack
7.1 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6.3 Fixed in 1.0.6.4 CVE-2024-35730 Patchstack
6.5 Medium Kenta Gutenberg Blocks Responsive Blocks and block templates library for Gutenberg Editor Plugin kenta-blocks Cross-Site Scripting ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-35731 Patchstack
5.9 Medium YITH Custom Login Plugin yith-custom-login Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2024-35732 Patchstack
7.1 High Auto Coupons for WooCommerce Plugin woo-auto-coupons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.14 Fixed in 3.0.15 CVE-2024-35733 Patchstack
7.1 High WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Scripting No login needed ≤ 1.2.10 Fixed in 1.2.11 CVE-2024-35734 Patchstack
8.5 High Visualizer Plugin visualizer SQL Injection ≤ 3.11.1 Fixed in 3.11.2 CVE-2024-35736 Patchstack
7.1 High WP Visitors Tracker Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 Fixed in 2.4 CVE-2024-35737 Patchstack
6.5 Medium Kognetiks Chatbot Plugin chatbot-chatgpt Cross-Site Scripting ≤ 1.9.8 Fixed in 1.9.9 CVE-2024-35738 Patchstack
6.5 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-35739 Patchstack
6.5 Medium Pixgraphy Theme pixgraphy Cross-Site Scripting ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-35740 Patchstack
8.5 High Responsive Image Gallery, Gallery Album Plugin gallery-album SQL Injection Image and Video Gallery with Thumbnails plugin <= 2.0.3 - SQL Injection ≤ 2.0.3 CVE-2024-35750 Patchstack
6.5 Medium Woody ad snippets Plugin insert-php Cross-Site Scripting ≤ 2.4.10 CVE-2024-35751 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only