WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,101–15,150 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 303 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Elegant Blocks Plugin elegant-blocks Cross-Site Scripting Amazing Gutenberg Blocks plugin <= 1.7 - Cross Site Scripting (XSS) ≤ 1.7 CVE-2024-34769 Patchstack
6.5 Medium Popup Maker WP Plugin popup-maker-wp Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-34770 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.16 Fixed in 2.0.17 CVE-2024-34789 Patchstack
5.9 Medium ImageMagick Sharpen Resized Images Theme imagemagick-sharpen-resized-images Cross-Site Scripting ≤ 1.1.7 CVE-2024-34790 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.0.9 Fixed in 1.2 CVE-2024-34791 Patchstack
5.9 Medium WP Next Post Navi Plugin wp-next-post-navi Cross-Site Scripting ≤ 1.8.3 CVE-2024-34793 Patchstack
7.1 High Tainacan Plugin tainacan Cross-Site Scripting No login needed ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34794 Patchstack
6.5 Medium Tainacan Plugin tainacan Cross-Site Scripting ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34795 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-34796 Patchstack
5.9 Medium Simple Popup Manager Plugin simple-popup-manager Cross-Site Scripting ≤ 1.3.5 CVE-2024-34797 Patchstack
6.5 Medium Praison SEO Plugin seo-wordpress Cross-Site Scripting ≤ 4.0.15 Fixed in 4.0.16 CVE-2024-34801 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting No login needed ≤ 7.5.45.7212 Fixed in 7.5.46.7212 CVE-2024-35631 Patchstack
7.6 High WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection ≤ 12.6 Fixed in 12.7 CVE-2024-35630 Patchstack
5.3 Medium Contact Form Widget Plugin new-contact-form-widget Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34754 Patchstack
5.3 Medium Debug Log – Manger Tool Plugin debug-log-config-tool Information Disclosure Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2024-34798 Patchstack
4.3 Medium Fastly Plugin fastly Broken Access Control ≤ 1.2.25 Fixed in 1.2.26 CVE-2024-34803 Patchstack
4.4 Medium Blocksy Companion Plugin blocksy-companion Server-Side Request Forgery ≤ 2.0.42 Fixed in 2.0.43 CVE-2024-35633 Patchstack
4.4 Medium Ninja Tables Plugin ninja-tables Server-Side Request Forgery ≤ 5.0.9 Fixed in 5.0.10 CVE-2024-35635 Patchstack
4.4 Medium Church Admin Plugin church-admin Server-Side Request Forgery ≤ 4.3.6 Fixed in 4.4.0 CVE-2024-35637 Patchstack
4.3 Medium ActiveDEMAND Plugin activedemand Cross-Site Request Forgery No login needed ≤ 0.2.43 CVE-2024-35638 Patchstack
5.9 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2024-35639 Patchstack
5.9 Medium Safety Exit Plugin safety-exit Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2024-35640 Patchstack
5.9 Medium Just Writing Statistics Plugin just-writing-statistics Cross-Site Scripting ≤ 4.5 Fixed in 4.6 CVE-2024-35641 Patchstack
5.9 Medium Site Favicon Plugin site-favicon Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2024-35642 Patchstack
5.9 Medium WP Back Button Plugin wp-back-button Cross-Site Scripting ≤ 1.1.3 CVE-2024-35643 Patchstack
5.9 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-35645 Patchstack
5.9 Medium Smartarget Message Bar Plugin smartarget-message-bar Cross-Site Scripting ≤ 1.5 CVE-2024-35646 Patchstack
5.9 Medium Global Notification Bar Plugin global-notification-bar Cross-Site Scripting ≤ 1.0.1 CVE-2024-35647 Patchstack
4.3 Medium Uploadcare File Uploader and Adaptive Delivery (beta) Plugin uploadcare Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed ≤ 3.0.11 CVE-2024-35636 Patchstack
7.1 High User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation ≤ 3.2.0.1 CVE-2024-4958 Wordfence
6.4 Medium WordPress Infinite Scroll – Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting ≤ 7.1.1 CVE-2024-4711 Wordfence
8.8 High Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX Plugin ultimate-post Broken Access Control PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update ≤ 4.1.2 CVE-2024-5326 Wordfence
7.2 High POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP Plugin post-smtp SQL Injection Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection ≤ 2.9.3 CVE-2024-5207 Wordfence
6.4 Medium Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX Plugin ultimate-post Cross-Site Scripting PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 4.1.1 CVE-2024-5223 Wordfence
9.1 Critical WP STAGING WordPress Backup Plugin – Migration Backup Restore Plugin wp-staging Arbitrary File Upload Migration Backup Restore <= 3.4.3 - Authenticated (Admin+) Arbitrary File Upload ≤ 3.4.3 CVE-2024-3412 Wordfence
5.3 Medium WordPress Tour & Travel Booking Plugin for WooCommerce – WpTravelly Plugin tour-booking-manager Broken Access Control WpTravelly <= 1.7.1 - Missing Authorization via ttbm_new_place_save No login needed ≤ 1.7.1 CVE-2024-0434 Wordfence
6.4 Medium Popup Builder by OptinMonster – WordPress Popups for Optins, Email Newsletters and Lead Generation Plugin optinmonster Cross-Site Scripting WordPress Popups for Optins, Email Newsletters and Lead Generation <= 2.16.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.16.1 CVE-2024-4045 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 2.13.0 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.13.0 CVE-2024-4366 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Block ≤ 2.12.8 CVE-2024-1814 Wordfence
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Cross-Site Scripting WordPress Gutenberg Blocks <= 2.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Gallery Block ≤ 2.12.8 CVE-2024-1815 Wordfence
6.4 Medium WordPress + Microsoft Office 365 / Azure AD | LOGIN Plugin wpo365-login Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode ≤ 27.2 CVE-2024-4706 Wordfence
4.3 Medium Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers Broken Access Control Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.17 - Missing Authorization ≤ 5.7.17 CVE-2024-3626 Wordfence
4.7 Medium wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin wpdatatables Cross-Site Scripting WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import No login needed ≤ 3.4.2.12 CVE-2024-4895 Wordfence
9.8 Critical Business Directory Plugin – Easy Listing Directories Plugin business-directory-plugin SQL Injection Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter No login needed ≤ 6.4.2 CVE-2024-4443 Wordfence
6.4 Medium Toolbar Extras for Elementor & More – WordPress Admin Bar Enhanced Plugin toolbar-extras Cross-Site Scripting WordPress Admin Bar Enhanced <= 1.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.9 CVE-2024-3611 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin learnpress Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 4.2.6.6 CVE-2024-4971 Wordfence
5.3 Medium YouTube Video Gallery by YouTube Showcase – Video Gallery Plugin youtube-showcase Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed ≤ 3.3.6 CVE-2024-3268 Wordfence
6.4 Medium WP Table Builder – WordPress Table Plugin wp-table-builder Cross-Site Scripting WordPress Table Plugin <= 1.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.14 CVE-2024-4700 Wordfence
7.1 High ShopLentor Plugin woolentor-addons Broken Access Control Missing Authorization to WordPress Option Modification ≤ 2.8.8 CVE-2024-4566 Wordfence
6.4 Medium WordPress Automatic Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter ≤ 3.94.0 CVE-2024-4849 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only