WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,351–15,400 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 308 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Favorite Posts Plugin wp-favorite-posts Cross-Site Request Forgery No login needed ≤ 1.6.8 CVE-2024-34427 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34557 Patchstack
8.0 High Timber Plugin timber-library PHP Object Injection Deserialization of untrusted data ≤ 1.23.0 Fixed in 1.23.1 CVE-2024-29800 Patchstack
6.5 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-34415 Patchstack
5.9 Medium Viet Nam Affiliate Plugin viet-nam-affiliate Cross-Site Scripting ≤ 1.0.0 CVE-2024-34417 Patchstack
5.9 Medium WPCS ( WordPress Custom Search ) Plugin wpcs-wp-custom-search Cross-Site Scripting ≤ 1.1 CVE-2024-34418 Patchstack
5.9 Medium Configure Login Timeout Plugin configure-login-timeout Cross-Site Scripting ≤ 1.0 CVE-2024-34419 Patchstack
5.9 Medium Comments Evolved Plugin gplus-comments Cross-Site Scripting ≤ 1.6.3 CVE-2024-34420 Patchstack
6.5 Medium BlogLentor Plugin bloglentor-for-elementor Cross-Site Scripting Blog Designer Pack for Elementor plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 CVE-2024-34421 Patchstack
5.9 Medium Viet Affiliate Link Plugin viet-affiliate-link Cross-Site Scripting ≤ 1.2 CVE-2024-34422 Patchstack
5.9 Medium Forty Four – 404 Plugin forty-four Cross-Site Scripting ≤ 1.4 CVE-2024-34423 Patchstack
5.9 Medium Featured Content Gallery Plugin featured-content-gallery Cross-Site Scripting ≤ 3.2.0 CVE-2024-34424 Patchstack
5.9 Medium QuickieBar Plugin quickiebar Cross-Site Scripting ≤ 1.8.4 CVE-2024-34425 Patchstack
5.9 Medium Brozzme Scroll Top Plugin brozzme-scroll-top Cross-Site Scripting ≤ 1.8.5 CVE-2024-34426 Patchstack
5.9 Medium AWSOM News Announcement Plugin awsom-news-announcement Cross-Site Scripting ≤ 1.6.0 CVE-2024-34428 Patchstack
5.9 Medium Corona Virus (COVID-19) Banner & Live Data Plugin corona-virus-covid-19-banner Cross-Site Scripting ≤ 1.8.0.2 CVE-2024-34429 Patchstack
5.9 Medium TT Custom Post Type Creator Plugin tt-custom-post-type-creator Cross-Site Scripting ≤ 1.0 CVE-2024-34430 Patchstack
7.1 High WP etracker Plugin wp-etracker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-34431 Patchstack
6.5 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-34432 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34436 Patchstack
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.24 Fixed in 1.15.25 CVE-2024-34437 Patchstack
6.5 Medium Easy Affiliate Links Plugin easy-affiliate-links Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-34441 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34445 Patchstack
4.3 Medium EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-33573 Patchstack
4.3 Medium Vitepos Plugin vitepos-lite Broken Access Control ≤ 3.0.1 Fixed in 3.0.2 CVE-2024-33574 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Broken Access Control on Post Clone ≤ 3.10.1 Fixed in 3.10.2 CVE-2024-24833 Patchstack
7.6 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31270 Patchstack
5.3 Medium AI WP Writer Plugin ai-wp-writer Broken Access Control No login needed ≤ 3.6.5 Fixed in 3.6.5.6 CVE-2024-30459 Patchstack
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares ≤ 4.8.1, ≤ 2.1.10, ≤ 1.9.3 Fixed in 4.9.0 CVE-2024-4233 Patchstack
7.7 High Rolo Slider Plugin rolo-slider Broken Access Control ≤ 1.0.9 CVE-2024-1438 Patchstack
6.5 Medium Advance WordPress Search Plugin th-advance-product-search Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2022-40218 Patchstack
6.5 Medium raindrops Theme raindrops Cross-Site Scripting ≤ 1.600 Fixed in 1.700 CVE-2024-34414 Patchstack
5.9 Medium Sticky Social Link Plugin sticky-social-link Cross-Site Scripting ≤ 2.0.1 CVE-2024-34546 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.1.34 Fixed in 1.1.35 CVE-2024-34547 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit plugin <= 2.4.8 - Cross Site Scripting (XSS) ≤ 2.4.8 Fixed in 2.5.0 CVE-2024-34548 Patchstack
7.1 High Stockholm Core Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-34553 Patchstack
5.9 Medium WOLF Plugin bulk-editor Cross-Site Scripting ≤ 1.0.8.2 Fixed in 1.0.8.3 CVE-2024-34558 Patchstack
5.9 Medium gee Search Plus Plugin gsearch-plus Cross-Site Scripting ≤ 1.4.4 CVE-2024-34560 Patchstack
5.9 Medium 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 3.71 Fixed in 3.72 CVE-2024-34561 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34562 Patchstack
6.5 Medium Gold Addons for Elementor Plugin gold-addons-for-elementor Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-34563 Patchstack
6.5 Medium Counter Up Plugin wp-counter-up Cross-Site Scripting ≤ 2.2.1 Fixed in 2.3.0 CVE-2024-34564 Patchstack
5.9 Medium Debug Info Plugin debug-info Cross-Site Scripting ≤ 1.3.10 CVE-2024-34565 Patchstack
6.5 Medium Content Blocks (Custom Post Widget) Plugin custom-post-widget Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2024-34566 Patchstack
5.9 Medium LetterPress Plugin letterpress Cross-Site Scripting ≤ 1.2.1 CVE-2024-34568 Patchstack
6.5 Medium Zotpress Plugin zotpress Cross-Site Scripting ≤ 7.3.9 Fixed in 7.3.10 CVE-2024-34569 Patchstack
5.9 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.3 CVE-2024-34570 Patchstack
6.5 Medium Himalayas Theme himalayas Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34571 Patchstack
6.5 Medium Fancy Elementor Flipbox Plugin fancy-elementor-flipbox Cross-Site Scripting ≤ 2.4.2 CVE-2024-34572 Patchstack
6.5 Medium Pootle Pagebuilder – WordPress Page builder Plugin pootle-page-builder Cross-Site Scripting ≤ 5.7.1 CVE-2024-34573 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only