WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,401–15,450 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 309 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Captcha by BestWebSoft Plugin captcha-bws Authentication Bypass Captcha Bypass No login needed ≤ 5.2.0 Fixed in 5.2.1 CVE-2024-31295 Patchstack
5.3 Medium Profile Builder Plugin profile-builder Other Bypass Vulnerability No login needed ≤ 3.11.2 Fixed in 3.11.3 CVE-2024-31341 Patchstack
5.3 Medium Download Manager Plugin download-manager Information Disclosure File Password Lock Bypass No login needed ≤ 3.2.82 Fixed in 3.2.83 CVE-2024-32131 Patchstack
4.3 Medium Pricing Table by Supsystic Plugin pricing-table-by-supsystic Content Injection ≤ 1.9.12 Fixed in 1.9.13 CVE-2024-32790 Patchstack
5.3 Medium WTI Like Post Plugin wti-like-post Authentication Bypass IP Restriction Bypass Vulnerability No login needed ≤ 1.4.6 CVE-2024-33917 Patchstack
6.5 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Arbitrary Shortcode Execution Meta Data and Taxonomies Filter plugin <= 1.3.3.2 - Arbitrary Shortcode Execution No login needed ≤ 1.3.3.2 Fixed in 1.3.3.3 CVE-2024-34434 Patchstack
5.3 Medium Headless CMS Plugin headless-cms Authentication Bypass Broken Authentication No login needed ≤ 2.0.3 CVE-2023-34186 Patchstack
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Information Disclosure Sensitive Data Exposure No login needed ≤ 2.8.6 Fixed in 3.0.0 CVE-2023-33321 Patchstack
6.0 Medium Unite Gallery Lite Plugin unite-gallery-lite Local File Inclusion ≤ 1.7.59 Fixed in 1.7.60 CVE-2023-33310 Patchstack
4.3 Medium Editorialmag Theme editorialmag Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 1.1.9 CVE-2023-32129 Patchstack
6.8 Medium Landing Page Builder – Free Landing Page Templates Plugin ultimate-landing-page Local File Inclusion Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusion ≤ 3.1.9.9 Fixed in 3.2 CVE-2023-24379 Patchstack
4.9 Medium GMAce Plugin gmace Path Traversal Arbitrary File Download ≤ 1.5.2 CVE-2023-23872 Patchstack
5.3 Medium Conditional Checkout Fields for WooCommerce Plugin Authentication Bypass Broken Authentication No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2022-45070 Patchstack
5.0 Medium Defender Security Plugin defender-security Authentication Bypass Broken Authentication ≤ 3.3.2 Fixed in 3.3.3 CVE-2022-44581 Patchstack
6.5 Medium Popup More Popups Plugin popup-more Cross-Site Scripting Popup More Popups plugin <= 2.3.1 - Cross Site Scripting (XSS) ≤ 2.3.1 Fixed in 2.3.3 CVE-2024-32800 Patchstack
6.5 Medium Popup Builder Plugin easy-notify-lite Cross-Site Scripting ≤ 1.1.29 Fixed in 1.1.30 CVE-2024-34567 Patchstack
6.5 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting ≤ 2.1.2 Fixed in 2.1.3 CVE-2024-34575 Patchstack
6.1 Medium Popup4Phone Plugin Cross-Site Scripting Editor+ Stored XSS No login needed ≤ 1.3.2 CVE-2024-3580 WPScan
6.1 Medium Popup4Phone Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.3.2 CVE-2024-3231 WPScan
4.3 Medium Nextgen Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.1 Fixed in 3.59.1 CVE-2024-2744 WPScan
6.5 Medium Swift Framework Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 2024.0.0 Fixed in 2024.0.0 CVE-2024-2697 WPScan
6.5 Medium Borderless Plugin borderless Cross-Site Scripting ≤ 1.7.3 CVE-2024-34757 Patchstack
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-3134 Wordfence
4.3 Medium ReviewX – Multi-criteria Rating & Reviews for WooCommerce Plugin Broken Access Control Multi-criteria Rating & Reviews for WooCommerce <= 1.6.27 - Missing Authorization ≤ 1.6.27 CVE-2024-3609 Wordfence
5.0 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Content Injection Authenticated (Author+) HTML Injection ≤ 1.6.26 CVE-2024-2619 Wordfence
4.3 Medium Bulk Posts Editing Plugin Cross-Site Request Forgery No login needed ≤ 4.2.3 CVE-2024-4204 Wordfence
5.9 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-34760 Patchstack
6.5 Medium iFrame Plugin iframe Cross-Site Scripting ≤ 5.0 CVE-2024-34805 Patchstack
4.4 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection ≤ 2.4.9 Fixed in 2.5.0 CVE-2024-34751 Patchstack
4.3 Medium JCH Optimize Plugin jch-optimize Path Traversal ≤ 4.2.0 Fixed in 4.2.1 CVE-2024-34808 Patchstack
6.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6.0 CVE-2024-4580 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.28 CVE-2024-4634 Wordfence
6.4 Medium Envo Extra Plugin envo-extra Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 1.8.16 CVE-2024-4385 Wordfence
6.4 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7.14 CVE-2024-4288 Wordfence
6.4 Medium Rank Math SEO with AI Best SEO Tools Plugin seo-by-rank-math Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.218 CVE-2024-4617 Wordfence
6.4 Medium Happy Addons for Elementor Authenticated (Contributor+) Stored-XSS Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar Widget ≤ 3.10.7 CVE-2024-4391 Wordfence
5.4 Medium Royal Elementor Addons and Templates Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Builder Widget ≤ 1.3.974 CVE-2024-3887 Wordfence
6.4 Medium Custom Post Type Attachment Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via pdf_attachment Shortcode ≤ 3.4.5 CVE-2024-4546 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group Widget ≤ 3.10.7 CVE-2024-4478 Wordfence
4.8 Medium Newsletter Popup Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.2 CVE-2024-3644 WPScan
6.9 Medium Newsletter Popup Plugin Cross-Site Request Forgery Subscriber Deletion via CSRF ≤ 1.2 CVE-2024-3642 WPScan
6.1 Medium Newsletter Popup Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.2 CVE-2024-3641 WPScan
6.4 Medium Menu Icons by ThemeIsle Plugin menu-icons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 0.13.13 CVE-2024-4635 Wordfence
6.5 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 2.7.0 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Course Deletion ≤ 2.7.0 CVE-2024-4279 Wordfence
6.4 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 22.6 CVE-2024-4984 Wordfence
6.4 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 1.2.1 CVE-2024-4702 Wordfence
6.4 Medium Image Optimization by Optimole – Lazy Load, CDN, Convert WebP & AVIF Plugin optimole-wp Cross-Site Scripting Lazy Load, CDN, Convert WebP & AVIF <= 3.12.10 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.12.10 CVE-2024-4636 Wordfence
5.5 Medium Base64 Encoder/Decoder Plugin Cross-Site Request Forgery Settings Reset via CSRF ≤ 0.9.2 CVE-2024-3824 WPScan
4.8 Medium Base64 Encoder/Decoder Plugin Cross-Site Scripting Reflected XSS ≤ 0.9.2 CVE-2024-3822 WPScan
6.5 Medium SP Project & Document Manager Plugin Broken Access Control Subscriber+ File Download via IDOR ≤ 4.71 CVE-2024-3749 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only