WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,601–15,650 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 313 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Advance WordPress Search Plugin th-advance-product-search Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.1.4 Fixed in 1.1.5 CVE-2022-40218 Patchstack
6.5 Medium raindrops Theme raindrops Cross-Site Scripting ≤ 1.600 Fixed in 1.700 CVE-2024-34414 Patchstack
5.9 Medium Sticky Social Link Plugin sticky-social-link Cross-Site Scripting ≤ 2.0.1 CVE-2024-34546 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.1.34 Fixed in 1.1.35 CVE-2024-34547 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit plugin <= 2.4.8 - Cross Site Scripting (XSS) ≤ 2.4.8 Fixed in 2.5.0 CVE-2024-34548 Patchstack
5.9 Medium WOLF Plugin bulk-editor Cross-Site Scripting ≤ 1.0.8.2 Fixed in 1.0.8.3 CVE-2024-34558 Patchstack
5.9 Medium gee Search Plus Plugin gsearch-plus Cross-Site Scripting ≤ 1.4.4 CVE-2024-34560 Patchstack
5.9 Medium 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 3.71 Fixed in 3.72 CVE-2024-34561 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34562 Patchstack
6.5 Medium Gold Addons for Elementor Plugin gold-addons-for-elementor Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-34563 Patchstack
6.5 Medium Counter Up Plugin wp-counter-up Cross-Site Scripting ≤ 2.2.1 Fixed in 2.3.0 CVE-2024-34564 Patchstack
5.9 Medium Debug Info Plugin debug-info Cross-Site Scripting ≤ 1.3.10 CVE-2024-34565 Patchstack
6.5 Medium Content Blocks (Custom Post Widget) Plugin custom-post-widget Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2024-34566 Patchstack
5.9 Medium LetterPress Plugin letterpress Cross-Site Scripting ≤ 1.2.1 CVE-2024-34568 Patchstack
6.5 Medium Zotpress Plugin zotpress Cross-Site Scripting ≤ 7.3.9 Fixed in 7.3.10 CVE-2024-34569 Patchstack
5.9 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.3 CVE-2024-34570 Patchstack
6.5 Medium Himalayas Theme himalayas Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34571 Patchstack
5.4 Medium WP Latest Posts Plugin wp-latest-posts Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 5.0.7 CVE-2024-4135 Wordfence
6.4 Medium Link Library Plugin link-library Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcode ≤ 7.6.11 CVE-2024-4281 Wordfence
6.5 Medium Fancy Elementor Flipbox Plugin fancy-elementor-flipbox Cross-Site Scripting ≤ 2.4.2 CVE-2024-34572 Patchstack
6.5 Medium Pootle Pagebuilder – WordPress Page builder Plugin pootle-page-builder Cross-Site Scripting ≤ 5.7.1 CVE-2024-34573 Patchstack
5.9 Medium Table Maker Plugin table-maker Cross-Site Scripting ≤ 1.9.1 CVE-2024-34574 Patchstack
6.5 Medium Multi-column Tag Map Plugin multi-column-tag-map Broken Access Control No login needed ≤ 17.0.26 Fixed in 17.0.27 CVE-2023-41651 Patchstack
6.5 Medium SSL Zen Plugin Other Unauthenticated Private Keys Access No login needed < 4.6.0 Fixed in 4.6.0 CVE-2024-1076 WPScan
6.4 Medium Mesmerize Companion Plugin mesmerize-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mesmerize_contact_form Shortcode ≤ 1.6.148 CVE-2024-3494 Wordfence
5.4 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Scripting Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web br… prior to 1.1.32 CVE-2024-32674 jpcert
6.3 Medium Tilda Publishing Plugin tilda-publishing Broken Access Control ≤ 0.3.23 Fixed in 0.3.24 CVE-2023-31234 Patchstack
4.3 Medium ClickCease Click Fraud Protection Plugin clickcease-click-fraud-protection Information Disclosure Improper Authorization to sensitive information exposure via get_settings ≤ 3.2.4 CVE-2023-6810 Wordfence
5.9 Medium SliceWP Plugin slicewp Cross-Site Scripting ≤ 1.1.10 Fixed in 1.1.11 CVE-2024-34413 Patchstack
4.3 Medium Metform Plugin metform Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2024-33570 Patchstack
6.5 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.18.10 Fixed in 3.18.11 CVE-2024-33576 Patchstack
5.3 Medium Print My Blog Plugin print-my-blog Broken Access Control No login needed ≤ 3.26.2 Fixed in 3.26.3 CVE-2024-33907 Patchstack
5.3 Medium WidgetKit Plugin widgetkit-for-elementor Broken Access Control No login needed ≤ 2.5.0 CVE-2024-33908 Patchstack
5.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Broken Access Control No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-33910 Patchstack
4.3 Medium Login with phone number Plugin login-with-phone-number Broken Access Control No login needed ≤ 1.7.18 Fixed in 1.7.20 CVE-2024-34371 Patchstack
5.3 Medium Post Grid Master Plugin ajax-filter-posts Broken Access Control No login needed ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-34372 Patchstack
4.3 Medium Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery Plugin new-video-gallery Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-34377 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control Rating Value Manipulation ≤ 3.6.4 CVE-2024-34387 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control ≤ 3.6.4 CVE-2024-34389 Patchstack
5.9 Medium Download Alt Text AI Plugin alttext-ai Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-34366 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.4.2 Fixed in 5.5.0 CVE-2024-34373 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 5.8.0 Fixed in 5.9.0 CVE-2024-34374 Patchstack
5.9 Medium Sheets To WP Table Live Sync Plugin sheets-to-wp-table-live-sync Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1 CVE-2024-34375 Patchstack
6.5 Medium Edge Theme edge Cross-Site Scripting ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-34376 Patchstack
5.9 Medium Conversational Forms for ChatBot Plugin conversational-forms Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-34380 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2024-34381 Patchstack
6.5 Medium Post Grid Master Plugin ajax-filter-posts Cross-Site Scripting Auth. Cross Site Scripting (XSS) ≤ 3.4.8 CVE-2024-34390 Patchstack
4.3 Medium Restaurant and Cafe Theme restaurant-and-cafe Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-34379 Patchstack
5.3 Medium Mooberry Book Manager Plugin mooberry-book-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 4.15.12 Fixed in 4.15.13 CVE-2024-34368 Patchstack
5.3 Medium Robo Gallery Plugin robo-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.18 Fixed in 3.2.19 CVE-2024-34382 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only