WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,501–15,550 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 311 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium AppPresser Plugin apppresser Broken Access Control No login needed ≤ 4.3.0 Fixed in 4.3.1 CVE-2024-32776 Patchstack
5.4 Medium Unyson Plugin unyson Cross-Site Request Forgery No login needed ≤ 2.7.29 Fixed in 2.7.31 CVE-2024-34814 Patchstack
5.4 Medium WPCal.io – Easy Meeting Scheduler Plugin wpcal Cross-Site Request Forgery No login needed ≤ 0.9.5.8 Fixed in 0.9.5.9 CVE-2024-34816 Patchstack
4.3 Medium Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-pipedrive Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-34817 Patchstack
4.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Cross-Site Request Forgery No login needed ≤ 3.2.11 Fixed in 3.2.12 CVE-2024-31113 Patchstack
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Other WordPress LMS Plugin <= 4.2.6.5 - Unauthenticated Bypass to User Registration No login needed ≤ 4.2.6.5 CVE-2024-4444 Wordfence
5.4 Medium Pods – Custom Content Types and Fields Plugin pods Cross-Site Scripting Custom Content Types and Fields <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pod Form Redirect URL ≤ 3.2.1 CVE-2024-3956 Wordfence
4.3 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Cross-Site Request Forgery No login needed ≤ 3.8.3 Fixed in 3.8.4 CVE-2024-4689 Patchstack
4.3 Medium Arigato Autoresponder and Newsletter Plugin bft-autoresponder Cross-Site Request Forgery No login needed ≤ 2.7.2.3 Fixed in 2.7.2.4 CVE-2024-34823 Patchstack
4.3 Medium Social Warfare Plugin social-warfare Cross-Site Request Forgery No login needed ≤ 4.4.5.1 Fixed in 4.4.6 CVE-2024-34825 Patchstack
4.3 Medium TranslatePress Plugin translatepress-multilingual Cross-Site Request Forgery TranslatePress plugin <= 2.7.5 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.7.5 Fixed in 2.7.6 CVE-2024-34827 Patchstack
4.3 Medium Church Admin Plugin church-admin Cross-Site Request Forgery No login needed ≤ 4.1.32 Fixed in 4.2.0 CVE-2024-34828 Patchstack
6.4 Medium HTML5 Audio Player- Best WordPress Audio Player Plugin html5-audio-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 2.2.19 CVE-2024-4398 Wordfence
6.1 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.5.102 CVE-2024-3547 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Interactive Circles' ≤ 5.9.19 CVE-2024-4275 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Several Widgets ≤ 5.9.19 CVE-2024-4449 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' ≤ 5.9.19 CVE-2024-4448 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP Plugin kadence-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Link ≤ 3.2.36 CVE-2024-4481 Wordfence
4.7 Medium reCAPTCHA Jetpack Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 0.2.2 CVE-2024-3941 WPScan
5.9 Medium VikBooking Plugin Broken Access Control No login needed < 1.6.8 Fixed in 1.6.8 CVE-2024-2749 WPScan
5.3 Medium White Label CMS Plugin white-label-cms Broken Access Control Missing Authorization to Plugin Settings Reset No login needed ≤ 2.7.3 CVE-2024-4280 Wordfence
6.1 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Scripting Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting No login needed ≤ 1.9.0 CVE-2024-4104 Wordfence
6.5 Medium Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro Plugin back-in-stock-notifier-for-woocommerce Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.3.1 CVE-2024-4038 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Age Gate ≤ 5.4.2 CVE-2024-2785 Wordfence
4.3 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Request Forgery No login needed ≤ 0.4.7 CVE-2024-4463 Wordfence
4.3 Medium Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 4.1.6 CVE-2024-1467 Wordfence
6.4 Medium Themify Shortcodes Plugin themify-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via themify_button Shortcode ≤ 2.0.9 CVE-2024-4567 Wordfence
6.4 Medium Testimonial Slider Plugin testimonial-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.2 CVE-2024-4193 Wordfence
4.3 Medium Joli FAQ SEO – WordPress FAQ Plugin Cross-Site Request Forgery WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery No login needed ≤ 1.3.2 CVE-2024-4082 Wordfence
4.4 Medium Visual Footer Credit Remover Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.2 CVE-2024-2846 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.4.2 CVE-2024-0445 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget ≤ 2.5.0 CVE-2024-3990 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1.1 CVE-2024-3923 Wordfence
4.3 Medium SimpleShop Plugin simpleshop-cz Cross-Site Request Forgery No login needed ≤ 2.10.0 CVE-2024-1230 Wordfence
6.4 Medium Rank Math SEO with AI Best SEO Tools Plugin seo-by-rank-math Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.217 CVE-2024-4335 Wordfence
4.3 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Request Forgery Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery No login needed ≤ 1.9.0 CVE-2024-4103 Wordfence
5.3 Medium Swift Framework Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Update No login needed ≤ 2.7.31 CVE-2024-3915 Wordfence
6.4 Medium Mihdan: Yandex Turbo Feed Plugin mihdan-yandex-turbo-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.6.5.1 CVE-2024-4411 Wordfence
6.4 Medium Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Text Effect Widget ≤ 1.1.37 CVE-2024-2923 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.3 CVE-2024-4339 Wordfence
4.3 Medium hostel Plugin hostel Cross-Site Request Forgery No login needed ≤ 1.1.5.3 CVE-2024-4314 Wordfence
6.4 Medium Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) Plugin content-views-query-and-display-post-page Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter ≤ 3.7.1 CVE-2024-4446 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading widget ≤ 2.1.5 CVE-2024-3831 Wordfence
5.4 Medium Swift Performance Lite Plugin swift-performance-lite Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Settings Modification ≤ 2.3.6.18 CVE-2024-3722 Wordfence
6.4 Medium Pure Chat – Live Chat Plugin & More! Plugin pure-chat Cross-Site Scripting Live Chat Plugin & More! <= 2.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.22 CVE-2024-3595 Wordfence
4.3 Medium Soccer Engine – Soccer Plugin Cross-Site Request Forgery Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery No login needed ≤ 1.12 CVE-2024-4312 Wordfence
6.4 Medium Swift Framework Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes ≤ 2.7.31 CVE-2024-3916 Wordfence
6.4 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.5 CVE-2024-4383 Wordfence
6.4 Medium Advanced Ads – Ad Manager & AdSense Plugin advanced-ads Cross-Site Scripting Ad Manager & AdSense <= 1.52.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Ad Widget ≤ 1.52.1 CVE-2024-3952 Wordfence
6.1 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 22.5 CVE-2024-4041 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only