WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,551–15,600 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 312 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium SimpleShop Plugin simpleshop-cz Broken Access Control Missing Authorization No login needed ≤ 2.10.2 CVE-2024-1229 Wordfence
6.4 Medium Image Hover Effects - Elementor Addon Plugin Cross-Site Scripting Elementor Addon <= 1.4.1 - Authenticated(Contributor+) DOM-based Stored Cross-Site Scripting via Image Hover Effects Widget ≤ 1.4.1 CVE-2024-1166 Wordfence
6.4 Medium Gallery Block (Meow Gallery) Plugin meow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.3 CVE-2024-4386 Wordfence
6.4 Medium BuddyPress Plugin buddypress Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 12.4.0 CVE-2024-3974 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 3.9.16 CVE-2024-4316 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animation Title widget img tag ≤ 2.1.5 CVE-2024-3680 Wordfence
6.4 Medium Blocksy Theme blocksy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.42 CVE-2024-4158 Wordfence
5.3 Medium ShopLentor (formerly WooLentor) Plugin woolentor-addons Broken Access Control Missing Authorization via purchased_new_products No login needed ≤ 2.8.7 CVE-2023-6327 Wordfence
6.1 Medium Simple Basic Contact Form Plugin simple-basic-contact-form Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 20221201 CVE-2024-4150 Wordfence
4.3 Medium SP Project & Document Manager Plugin sp-client-document-manager Broken Access Control Authenticated (Subscriber+) Arbitrary Folder Name Update ≤ 4.70 CVE-2024-1693 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.21.0 CVE-2024-4107 Wordfence
4.4 Medium Custom Field Suite Plugin custom-field-suite Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.6.5 CVE-2024-3068 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify ≤ 2.5.0 CVE-2024-3989 Wordfence
6.5 Medium SchedulePress Plugin wp-scheduled-posts Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2024-32717 Patchstack
5.3 Medium WP Club Manager Plugin wp-club-manager Broken Access Control No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-32719 Patchstack
5.3 Medium WP Job Manager Plugin wp-job-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.2 Fixed in 2.3.0 CVE-2024-34549 Patchstack
5.3 Medium Dynamics 365 Integration Plugin integration-dynamics Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.17 Fixed in 1.3.18 CVE-2024-34550 Patchstack
5.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Information Disclosure Sensitive Data Exposure via Exported File No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34556 Patchstack
4.4 Medium One Click Demo Import Plugin one-click-demo-import PHP Object Injection ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-34433 Patchstack
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
4.3 Medium DS Site Message Plugin ds-site-message Cross-Site Request Forgery No login needed ≤ 1.14.4 CVE-2024-34439 Patchstack
4.3 Medium WP Favorite Posts Plugin wp-favorite-posts Cross-Site Request Forgery No login needed ≤ 1.6.8 CVE-2024-34427 Patchstack
4.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Request Forgery No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34557 Patchstack
6.5 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2024-34415 Patchstack
5.9 Medium Viet Nam Affiliate Plugin viet-nam-affiliate Cross-Site Scripting ≤ 1.0.0 CVE-2024-34417 Patchstack
5.9 Medium WPCS ( WordPress Custom Search ) Plugin wpcs-wp-custom-search Cross-Site Scripting ≤ 1.1 CVE-2024-34418 Patchstack
5.9 Medium Configure Login Timeout Plugin configure-login-timeout Cross-Site Scripting ≤ 1.0 CVE-2024-34419 Patchstack
5.9 Medium Comments Evolved Plugin gplus-comments Cross-Site Scripting ≤ 1.6.3 CVE-2024-34420 Patchstack
6.5 Medium BlogLentor Plugin bloglentor-for-elementor Cross-Site Scripting Blog Designer Pack for Elementor plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 CVE-2024-34421 Patchstack
5.9 Medium Viet Affiliate Link Plugin viet-affiliate-link Cross-Site Scripting ≤ 1.2 CVE-2024-34422 Patchstack
5.9 Medium Forty Four – 404 Plugin forty-four Cross-Site Scripting ≤ 1.4 CVE-2024-34423 Patchstack
5.9 Medium Featured Content Gallery Plugin featured-content-gallery Cross-Site Scripting ≤ 3.2.0 CVE-2024-34424 Patchstack
5.9 Medium QuickieBar Plugin quickiebar Cross-Site Scripting ≤ 1.8.4 CVE-2024-34425 Patchstack
5.9 Medium Brozzme Scroll Top Plugin brozzme-scroll-top Cross-Site Scripting ≤ 1.8.5 CVE-2024-34426 Patchstack
5.9 Medium AWSOM News Announcement Plugin awsom-news-announcement Cross-Site Scripting ≤ 1.6.0 CVE-2024-34428 Patchstack
5.9 Medium Corona Virus (COVID-19) Banner & Live Data Plugin corona-virus-covid-19-banner Cross-Site Scripting ≤ 1.8.0.2 CVE-2024-34429 Patchstack
5.9 Medium TT Custom Post Type Creator Plugin tt-custom-post-type-creator Cross-Site Scripting ≤ 1.0 CVE-2024-34430 Patchstack
6.5 Medium Better Elementor Addons Plugin better-elementor-addons Cross-Site Scripting ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-34432 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34436 Patchstack
5.9 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting ≤ 1.15.24 Fixed in 1.15.25 CVE-2024-34437 Patchstack
6.5 Medium Easy Affiliate Links Plugin easy-affiliate-links Cross-Site Scripting ≤ 3.7.2 Fixed in 3.7.3 CVE-2024-34441 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2024-34445 Patchstack
6.1 Medium LetterPress Plugin Cross-Site Request Forgery Subscriber Deletion via CSRF No login needed ≤ 1.2.2 CVE-2024-3590 WPScan
4.8 Medium Ungallery Plugin ungallery Cross-Site Scripting Stored XSS via CSRF ≤ 2.2.4 CVE-2024-3582 WPScan
4.8 Medium Save as PDF Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.0 Fixed in 3.2.0 CVE-2023-5971 WPScan
4.3 Medium EPROLO Dropshipping Plugin eprolo-dropshipping Broken Access Control ≤ 1.7.1 Fixed in 1.7.2 CVE-2024-33573 Patchstack
4.3 Medium Vitepos Plugin vitepos-lite Broken Access Control ≤ 3.0.1 Fixed in 3.0.2 CVE-2024-33574 Patchstack
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Broken Access Control on Post Clone ≤ 3.10.1 Fixed in 3.10.2 CVE-2024-24833 Patchstack
5.3 Medium AI WP Writer Plugin ai-wp-writer Broken Access Control No login needed ≤ 3.6.5 Fixed in 3.6.5.6 CVE-2024-30459 Patchstack
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Broken Access Control vulnerability in multiple WordPress plugins by Tyche Softwares ≤ 4.8.1, ≤ 2.1.10, ≤ 1.9.3 Fixed in 4.9.0 CVE-2024-4233 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only