WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,451–15,500 of 16,921 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 310 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Accessibility Widget Plugin accessibility-widget Cross-Site Scripting ≤ 2.2 Fixed in 2.2.1 CVE-2024-32831 Patchstack
6.5 Medium CPO Companion Plugin cpo-companion Cross-Site Scripting ≤ 1.1.0 CVE-2024-33916 Patchstack
5.9 Medium AJAX Login and Registration modal popup + inline form Plugin ajax-login-and-registration-modal-popup Cross-Site Scripting ≤ 2.23 CVE-2024-33918 Patchstack
7.1 High Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Cross-Site Scripting No login needed ≤ 4.14.4 CVE-2024-33924 Patchstack
6.5 Medium GWP-Histats Plugin gwp-histats Cross-Site Scripting ≤ 1.0 CVE-2024-33926 Patchstack
6.5 Medium Giphypress Plugin giphypress Cross-Site Scripting ≤ 1.6.2 CVE-2024-33927 Patchstack
7.1 High CodeBard's Patron Button and Widgets for Patreon Plugin patron-button-and-widgets-by-codebard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-33928 Patchstack
6.5 Medium Login Logout Register Menu Plugin login-logout-register-menu Cross-Site Scripting ≤ 2.0 CVE-2024-33932 Patchstack
6.5 Medium Mini Loops Plugin mini-loops Cross-Site Scripting ≤ 1.4.1 CVE-2024-33934 Patchstack
6.5 Medium PB MailCrypt Plugin pb-mailcrypt-antispam-email-encryption Cross-Site Scripting ≤ 3.1.0 CVE-2024-33935 Patchstack
6.5 Medium Print-O-Matic Plugin print-o-matic Cross-Site Scripting Auth. Cross Site Scripting (XSS) ≤ 2.1.10 CVE-2024-33936 Patchstack
5.9 Medium EventON Plugin eventon-lite Cross-Site Scripting ≤ 2.2.14 CVE-2024-33940 Patchstack
5.9 Medium Ultimate Under Construction Plugin ultimate-under-construction Cross-Site Scripting ≤ 1.9.3 Fixed in 1.9.4 CVE-2024-33943 Patchstack
6.5 Medium Eleblog – Elementor Blog And Magazine Addons Plugin ele-blog Cross-Site Scripting Elementor Blog And Magazine Addons plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 CVE-2024-33945 Patchstack
7.1 High WPify Woo Czech Plugin wpify-woo Cross-Site Scripting No login needed ≤ 4.0.10 Fixed in 4.0.11 CVE-2024-33946 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 5.3.2.0 Fixed in 5.3.2.1 CVE-2024-33947 Patchstack
7.2 High WordPress Core Cross-Site Scripting WordPress Core is vulnerable to Stored Cross-Site Scripting via user display names in the Avatar block in various versions up to 6.5.2 due to insufficient output escaping on the d… No login needed 6.0 – 6.0.7, 6.1 – 6.1.5, 6.2 – 6.2.4, … CVE-2024-4439 Wordfence
5.3 Medium Poll Maker – Best WordPress Poll Plugin Broken Access Control Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Email Enumeration No login needed ≤ 5.1.8 CVE-2024-3601 Wordfence
5.3 Medium Popup Box – Best WordPress Popup Plugin ays-popup-box Broken Access Control Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure No login needed ≤ 4.3.6 CVE-2024-3897 Wordfence
8.8 High WP ULike – Most Advanced WordPress Marketing Toolkit Plugin SQL Injection Most Advanced WordPress Marketing Toolkit <= 4.6.9 - Authenticated (Contributor+) SQL Injection via Shortcodes ≤ 4.6.9 CVE-2024-1797 Wordfence
8.8 High User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation ≤ 3.1.5 CVE-2024-2417 Wordfence
4.3 Medium Ivory Search – WordPress Search Plugin add-search-to-menu Broken Access Control WordPress Search Plugin <= 5.5.5 - Missing Authorization to Authenticated (Subscriber+) Index Creation ≤ 5.5.5 CVE-2024-3233 Wordfence
6.4 Medium WordPress Header Builder Plugin – Pearl Plugin Cross-Site Scripting Pearl <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3.6 CVE-2024-4000 Wordfence
5.3 Medium SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer Plugin smartcrawl-seo Broken Access Control Missing Authorization No login needed ≤ 3.10.2 CVE-2024-3287 Wordfence
6.4 Medium ElementsKit Elementor addons and Templates Library Plugin elementskit-lite Cross-Site Scripting The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insuff… 3.0.7 – 3.1.2 CVE-2024-3650 Wordfence
6.5 Medium User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion No login needed ≤ 3.1.5 CVE-2024-3295 Wordfence
4.4 Medium Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor Plugin front-editor Cross-Site Scripting WP Front User Submit / Front Editor <= 4.4.7 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.4.7 CVE-2024-2967 Wordfence
5.4 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Broken Access Control WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference ≤ 5.6.3 CVE-2024-2346 Wordfence
6.4 Medium MailerLite – Signup forms (official) Plugin official-mailerlite-sign-up-forms Cross-Site Scripting Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insuffic… 1.5.0 – 1.7.6 CVE-2024-1386 Wordfence
5.4 Medium Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) Plugin Broken Access Control Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization ≤ 5.2.3 CVE-2024-1809 Wordfence
5.3 Medium Contact Form by WPForms – Drag & Drop Form Builder Plugin wpforms-lite Price Manipulation Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation No login needed ≤ 1.8.7.2 CVE-2024-3649 Wordfence
6.3 Medium MasterStudy LMS WordPress Plugin – for Online Courses and Education Plugin masterstudy-lms-learning-management-system Broken Access Control for Online Courses and Education <= 3.3.8 - Missing Authorization ≤ 3.3.8 CVE-2024-3942 Wordfence
4.3 Medium WordPress Backup & Migration Plugin Broken Access Control Missing Authorization to Directory Traversal ≤ 1.4.8 CVE-2024-3546 Wordfence
6.4 Medium All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic Plugin Cross-Site Scripting Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.6.0 CVE-2024-3554 Wordfence
4.3 Medium Spectra – WordPress Gutenberg Blocks Plugin ultimate-addons-for-gutenberg Path Traversal WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal ≤ 2.12.6 CVE-2024-3107 Wordfence
6.4 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Cross-Site Scripting WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 5.6.3 CVE-2024-2345 Wordfence
5.5 Medium TweetScroll Widget Plugin tweetscroll-widget Cross-Site Scripting ≤ 1.3.7 CVE-2024-33948 Patchstack
6.5 Medium Min and Max Purchase for WooCommerce Plugin min-and-max-purchase-for-woocommerce Cross-Site Scripting ≤ 2.0.0 CVE-2024-33949 Patchstack
5.9 Medium Simple Image Popup Plugin simple-image-popup Cross-Site Scripting ≤ 2.4.0 CVE-2024-4433 Patchstack
5.9 Medium Archives Calendar Widget Plugin archives-calendar-widget Cross-Site Scripting ≤ 1.0.15 CVE-2024-33950 Patchstack
6.5 Medium Perfect Pullquotes Plugin perfect-pullquotes Cross-Site Scripting ≤ 1.7.5 CVE-2024-33951 Patchstack
4.3 Medium Google Typography Plugin google-typography Broken Access Control ≤ 1.1.2 CVE-2024-33942 Patchstack
6.5 Medium WooCommerce AWeber Newsletter Subscription Plugin Broken Access Control Unauthenticated Access Token Change/Reset No login needed ≤ 4.0.2 Fixed in 4.0.3 CVE-2024-33944 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Broken Access Control ≤ 1.3.0 Fixed in 1.3.2 CVE-2024-33956 Patchstack
6.5 Medium Unique Theme unique Cross-Site Scripting ≤ 0.3.0 CVE-2024-33952 Patchstack
6.5 Medium Adventure Journal Theme adventure-journal Cross-Site Scripting ≤ 1.7.2 CVE-2024-33953 Patchstack
6.5 Medium Pliska Theme pliska Cross-Site Scripting ≤ 0.3.5 Fixed in 0.3.6 CVE-2024-33954 Patchstack
6.5 Medium Freesia Empire Theme freesia-empire Cross-Site Scripting ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-33955 Patchstack
6.5 Medium Sliding Widgets Plugin sliding-widgets Broken Access Control Broken Access Control to XSS ≤ 1.5.0 CVE-2024-33938 Patchstack
7.6 High School Management Pro Plugin SQL Injection ≤ 10.3.4 CVE-2024-33911 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only