WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,351–15,400 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 308 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Carousel Slider Plugin carousel-slider Cross-Site Scripting Editor+ Stored XSS < 2.2.11 Fixed in 2.2.11 CVE-2024-4372 WPScan
6.1 Medium Sailthru Triggermail Plugin sailthru-triggermail Cross-Site Scripting Reflected XSS No login needed ≤ 1.1 CVE-2024-4289 WPScan
4.8 Medium Survey Maker Plugin survey-maker Cross-Site Scripting Admin+ Stored XSS via Plugin Settings < 4.2.9 Fixed in 4.2.9 CVE-2024-4061 WPScan
6.1 Medium Social Icons Widget & Block Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 4.2.18 Fixed in 4.2.18 CVE-2024-2189 WPScan
6.4 Medium Blocksy Theme blocksy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.46 CVE-2024-4943 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-3155 Wordfence
6.1 Medium All in One SEO Plugin all-in-one-seo-pack Cross-Site Scripting Contributor+ Stored XSS No login needed < 4.6.1.1 Fixed in 4.6.1.1 CVE-2024-3368 WPScan
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.8 CVE-2024-5088 Wordfence
6.4 Medium Piotnet Addons For Elementor Plugin piotnet-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.4.26 CVE-2024-4432 Wordfence
6.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.16 CVE-2024-4709 Wordfence
6.4 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.1.1 CVE-2024-4698 Wordfence
6.4 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 5.1.13 CVE-2024-2772 Wordfence
6.4 Medium Salient Shortcodes Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.3 CVE-2024-3811 Wordfence
6.4 Medium WordPress Automatic Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via autoplay Parameter ≤ 3.94.0 CVE-2024-4849 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.12 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.12 CVE-2024-4891 Wordfence
6.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.10.0 CVE-2024-3714 Wordfence
6.4 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.1.3 CVE-2024-4374 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter ≤ 3.10.8 CVE-2024-4865 Wordfence
5.3 Medium Flo Forms Plugin flo-forms Broken Access Control No login needed ≤ 1.0.42 CVE-2024-35174 Patchstack
4.3 Medium Integration for Contact Form 7 and Salesforce Plugin cf7-salesforce Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34755 Patchstack
4.3 Medium Integration for Contact Form 7 HubSpot Plugin cf7-hubspot Cross-Site Request Forgery No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-34756 Patchstack
4.3 Medium Clearfy Cache Plugin clearfy Cross-Site Request Forgery ≤ 2.2.1 CVE-2024-34806 Patchstack
4.3 Medium Fast Custom Social Share by CodeBard Plugin fast-custom-social-share-by-codebard Cross-Site Request Forgery No login needed ≤ 1.1.2 CVE-2024-34807 Patchstack
4.3 Medium EmpowerWP Theme empowerwp Cross-Site Request Forgery No login needed ≤ 1.0.21 Fixed in 1.0.22 CVE-2024-34809 Patchstack
5.3 Medium Giveaways and Contests Plugin rafflepress Authentication Bypass IP Restriction Bypass No login needed ≤ 1.12.7 Fixed in 1.12.11 CVE-2024-32827 Patchstack
5.3 Medium BP Better Messages Plugin bp-better-messages Authentication Bypass Broken Authentication No login needed ≤ 2.4.32 Fixed in 2.4.33 CVE-2024-32802 Patchstack
5.3 Medium Royal Elementor Addons Plugin royal-elementor-addons Authentication Bypass IP Bypass No login needed ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-32786 Patchstack
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Other Group Members Limit Bypass ≤ 5.8.2 Fixed in 5.8.3 CVE-2024-32774 Patchstack
5.3 Medium Appointment Hour Booking Plugin appointment-hour-booking Authentication Bypass Captcha Bypass No login needed ≤ 1.4.56 Fixed in 1.4.57 CVE-2024-32720 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Other Review Score Manipulation No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32685 Patchstack
5.3 Medium Zero Spam Plugin zero-spam Other Bypass Spam Protection No login needed ≤ 5.5.6 Fixed in 5.5.7 CVE-2024-32521 Patchstack
5.3 Medium weForms Plugin weforms Other Form Submission Restriction Bypass No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-32512 Patchstack
6.3 Medium Church Admin Plugin church-admin Broken Access Control ≤ 4.1.6 Fixed in 4.1.7 CVE-2024-31281 Patchstack
6.5 Medium SellKit Plugin sellkit Path Traversal Arbitrary File Download ≤ 1.8.1 Fixed in 1.8.3 CVE-2024-30509 Patchstack
6.5 Medium BookIt Plugin bookit Other Price Bypass Vulnerability No login needed ≤ 2.4.0 Fixed in 2.4.2 CVE-2024-24715 Patchstack
5.3 Medium Formidable Forms Plugin formidable Content Injection No login needed ≤ 6.7 Fixed in 6.7.1 CVE-2024-23522 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Authentication Bypass IP limit Bypass No login needed ≤ 2.3.6 Fixed in 2.3.7 CVE-2024-21746 Patchstack
6.3 Medium Ultimate Addons for Beaver Builder Plugin ultimate-addons-for-beaver-builder-lite Path Traversal Limited Arbitrary File Download ≤ 1.35.13 Fixed in 1.35.14 CVE-2023-51401 Patchstack
6.8 Medium Salon booking system Plugin salon-booking-system Privilege Escalation Editor+ Privilege Escalation ≤ 8.6 Fixed in 8.7 CVE-2023-48319 Patchstack
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion ≤ 1.6.3 Fixed in 1.6.4 CVE-2023-47679 Patchstack
5.3 Medium Popup by Supsystic Plugin popup-by-supsystic Information Disclosure Unauthenticated Subscriber Email Addresses Disclosure No login needed ≤ 1.10.19 Fixed in 1.10.20 CVE-2023-46197 Patchstack
6.5 Medium Remote Content Shortcode Plugin remote-content-shortcode Local File Inclusion ≤ 1.5 CVE-2023-45652 Patchstack
6.4 Medium Cost Calculator Builder Pro Plugin Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 3.1.72 CVE-2024-4789 Wordfence
5.3 Medium CP Polls Plugin cp-polls Other Polls Limitation Bypass No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24873 Patchstack
5.3 Medium CP Polls Plugin cp-polls Content Injection No login needed ≤ 1.0.71 Fixed in 1.0.72 CVE-2024-24874 Patchstack
5.3 Medium Defender Security Plugin defender-security Authentication Bypass IP Restriction Bypass No login needed ≤ 4.4.1 Fixed in 4.4.2 CVE-2024-25595 Patchstack
4.3 Medium Comments Like Dislike Plugin comments-like-dislike Authentication Bypass IP Restriction Bypass Vulnerability ≤ 1.2.2 Fixed in 1.2.3 CVE-2024-25906 Patchstack
5.3 Medium IP Blocker Lite Plugin ip-address-blocker Authentication Bypass No login needed ≤ 11.1.1 CVE-2024-30479 Patchstack
5.3 Medium Newsletter Plugin newsletter Authentication Bypass IP Blacklist Bypass No login needed ≤ 8.2.0 Fixed in 8.2.1 CVE-2024-30522 Patchstack
5.3 Medium VS Contact Form Plugin very-simple-contact-form Authentication Bypass Sum Captcha Bypass No login needed ≤ 14.7 Fixed in 14.8 CVE-2024-30540 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only