WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,401–15,450 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 309 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Table Maker Plugin table-maker Cross-Site Scripting ≤ 1.9.1 CVE-2024-34574 Patchstack
6.5 Medium Multi-column Tag Map Plugin multi-column-tag-map Broken Access Control No login needed ≤ 17.0.26 Fixed in 17.0.27 CVE-2023-41651 Patchstack
5.4 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Scripting Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web br… prior to 1.1.32 CVE-2024-32674 jpcert
6.3 Medium Tilda Publishing Plugin tilda-publishing Broken Access Control ≤ 0.3.23 Fixed in 0.3.24 CVE-2023-31234 Patchstack
5.9 Medium SliceWP Plugin slicewp Cross-Site Scripting ≤ 1.1.10 Fixed in 1.1.11 CVE-2024-34413 Patchstack
4.3 Medium Metform Plugin metform Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2024-33570 Patchstack
6.5 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.18.10 Fixed in 3.18.11 CVE-2024-33576 Patchstack
5.3 Medium Print My Blog Plugin print-my-blog Broken Access Control No login needed ≤ 3.26.2 Fixed in 3.26.3 CVE-2024-33907 Patchstack
5.3 Medium WidgetKit Plugin widgetkit-for-elementor Broken Access Control No login needed ≤ 2.5.0 CVE-2024-33908 Patchstack
5.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Broken Access Control No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-33910 Patchstack
7.1 High Academy LMS Plugin academy Broken Access Control Broken Access Control on Paid Courses ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-33912 Patchstack
4.3 Medium Login with phone number Plugin login-with-phone-number Broken Access Control No login needed ≤ 1.7.18 Fixed in 1.7.20 CVE-2024-34371 Patchstack
5.3 Medium Post Grid Master Plugin ajax-filter-posts Broken Access Control No login needed ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-34372 Patchstack
4.3 Medium Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery Plugin new-video-gallery Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-34377 Patchstack
8.6 High LeadConnector Plugin leadconnector Broken Access Control No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-34378 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control Rating Value Manipulation ≤ 3.6.4 CVE-2024-34387 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control ≤ 3.6.4 CVE-2024-34389 Patchstack
5.9 Medium Download Alt Text AI Plugin alttext-ai Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-34366 Patchstack
7.1 High Webpushr Plugin webpushr-web-push-notifications Cross-Site Scripting Webpushr plugin <= 4.35.0 - Cross Site Scripting (XSS) No login needed ≤ 4.35.0 Fixed in 4.36.0 CVE-2024-34369 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.4.2 Fixed in 5.5.0 CVE-2024-34373 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 5.8.0 Fixed in 5.9.0 CVE-2024-34374 Patchstack
5.9 Medium Sheets To WP Table Live Sync Plugin sheets-to-wp-table-live-sync Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1 CVE-2024-34375 Patchstack
6.5 Medium Edge Theme edge Cross-Site Scripting ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-34376 Patchstack
5.9 Medium Conversational Forms for ChatBot Plugin conversational-forms Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-34380 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2024-34381 Patchstack
6.5 Medium Post Grid Master Plugin ajax-filter-posts Cross-Site Scripting Auth. Cross Site Scripting (XSS) ≤ 3.4.8 CVE-2024-34390 Patchstack
4.3 Medium Restaurant and Cafe Theme restaurant-and-cafe Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-34379 Patchstack
7.1 High Popup box Plugin ays-popup-box Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-34367 Patchstack
7.6 High Auto Affiliate Links Plugin wp-auto-affiliate-links SQL Injection ≤ 6.4.3.1 Fixed in 6.4.4 CVE-2024-34386 Patchstack
8.5 High ParcelPanel Plugin parcelpanel SQL Injection Auth. SQL Injection ≤ 3.8.1 Fixed in 3.9.0 CVE-2024-34412 Patchstack
5.3 Medium Mooberry Book Manager Plugin mooberry-book-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 4.15.12 Fixed in 4.15.13 CVE-2024-34368 Patchstack
5.3 Medium Robo Gallery Plugin robo-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.18 Fixed in 3.2.19 CVE-2024-34382 Patchstack
5.3 Medium SEOPress Plugin wp-seopress Information Disclosure Sensitive Data Exposure No login needed ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-34383 Patchstack
7.5 High GDPR Compliance Plugin gdpr-compliance Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.5 CVE-2024-34388 Patchstack
8.5 High Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Path Traversal Arbitrary File Download and Deletion ≤ 4.0.17 Fixed in 4.0.18 CVE-2024-32807 Patchstack
4.3 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Broken Access Control Broken Access Control on Post Duplication ≤ 2.6.9.1 Fixed in 2.6.9.2 CVE-2024-33914 Patchstack
4.3 Medium Debug Log Manager Plugin debug-log-manager Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2024-33915 Patchstack
6.5 Medium RomethemeKit For Elementor Plugin rometheme-for-elementor Broken Access Control No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-33919 Patchstack
5.3 Medium Democracy Poll Plugin democracy-poll Broken Access Control No login needed ≤ 6.0.3 CVE-2024-33920 Patchstack
4.3 Medium ReviewX Plugin reviewx Broken Access Control ≤ 1.6.21 Fixed in 1.6.22 CVE-2024-33921 Patchstack
6.3 Medium SP Project & Document Manager Plugin sp-client-document-manager Broken Access Control ≤ 4.69 CVE-2024-33923 Patchstack
4.3 Medium Embed Google Fonts Plugin embed-google-fonts Broken Access Control ≤ 3.1.0 CVE-2024-33925 Patchstack
5.3 Medium Directorist Plugin directorist Broken Access Control No login needed ≤ 7.8.6 Fixed in 7.9.0 CVE-2024-33929 Patchstack
6.5 Medium JW Player Plugin jw-player-7-for-wp Broken Access Control No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2024-33931 Patchstack
4.3 Medium Progressive WordPress (PWA) Plugin progressive-wp Broken Access Control ≤ 2.1.13 CVE-2024-33937 Patchstack
4.3 Medium Feed Them Social Plugin feed-them-social Broken Access Control ≤ 4.2.0 Fixed in 4.2.1 CVE-2024-24710 Patchstack
7.6 High ShortPixel Critical CSS Plugin shortpixel-critical-css Broken Access Control ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-32810 Patchstack
5.3 Medium Slider Carousel – Responsive Image Slider Plugin slider-images Broken Access Control Responsive Image Slider plugin <=1.5.1 - Broken Access Control No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2023-25457 Patchstack
4.3 Medium Unyson Plugin unyson Broken Access Control ≤ 2.7.28 CVE-2023-44472 Patchstack
5.3 Medium iPanorama 360 WordPress Virtual Tour Builder Plugin ipanorama-360-virtual-tour-builder-lite Broken Access Control No login needed ≤ 1.8.1 Fixed in 1.8.2 CVE-2024-33941 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only