WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 15,751–15,800 of 17,704 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Slider Revolution | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via htmltag Parameter |
≤ 6.7.7 |
CVE-2024-4092 |
Wordfence | |
| 4.3 Medium | ShopLentor | Broken Access Control Improper Authorization via woolentor_template_store |
≤ 2.8.1 |
CVE-2023-7067 |
Wordfence | |
| 4.4 Medium | Guest posting / Frontend Posting wordpress plugin – WP Front User Submit / Front Editor | Cross-Site Scripting WP Front User Submit / Front Editor <= 4.4.7 - Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 4.4.7 |
CVE-2024-2967 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Stack Group, Photo Stack, & Horizontal Timeline |
≤ 3.10.4 |
CVE-2024-3724 |
Wordfence | |
| 5.4 Medium | FileBird – WordPress Media Library Folders & File Manager | Broken Access Control WordPress Media Library Folders & File Manager <= 5.6.3 - Authenticated (Author+) Insecure Direct Object Reference |
≤ 5.6.3 |
CVE-2024-2346 |
Wordfence | |
| 6.1 Medium | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | Open Redirect Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.30 - Open Redirect No login needed |
≤ 4.0.30 |
CVE-2024-4133 |
Wordfence | |
| 6.4 Medium | MailerLite – Signup forms (official) | Cross-Site Scripting Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions 1.5.0 to 1.7.6 due to insuffic… |
1.5.0 – 1.7.6 |
CVE-2024-1386 |
Wordfence | |
| 6.4 Medium | Ultimate 410 Gone Status Code | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.4 |
CVE-2024-3677 |
Wordfence | |
| 5.4 Medium | Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) | Broken Access Control Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization |
≤ 5.2.3 |
CVE-2024-1809 |
Wordfence | |
| 6.4 Medium | WPBakery Visual Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button onclick attribute |
≤ 7.5 |
CVE-2024-1805 |
Wordfence | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Expired Title |
≤ 2.6.9.4 |
CVE-2024-3489 |
Wordfence | |
| 4.3 Medium | SVS Pricing Tables | Cross-Site Request Forgery Cross-Site Request Forgery to Pricing Table Edit/Creation No login needed |
≤ 1.0.4 |
CVE-2024-2959 |
Wordfence | |
| 6.4 Medium | Icon Widget | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode |
≤ 1.3.0 |
CVE-2024-1993 |
Wordfence | |
| 5.3 Medium | EleForms – All In One Form Integration including DB for Elementor | Broken Access Control All In One Form Integration including DB for Elementor <= 2.9.9.7 - Missing Authorization to Sensitive Information Exposure No login needed |
≤ 2.9.9.7 |
CVE-2024-2043 |
Wordfence | |
| 6.3 Medium | Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce | Broken Access Control Improper Authorization |
≤ 3.4.6 |
CVE-2024-1677 |
Wordfence | |
| 5.3 Medium | Contact Form by WPForms – Drag & Drop Form Builder | Price Manipulation Drag & Drop Form Builder for WordPress <= 1.8.7.2 - Unauthenticated Price Manipulation No login needed |
≤ 1.8.7.2 |
CVE-2024-3649 |
Wordfence | |
| 6.4 Medium | WPBakery Visual Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Heading tag attribute |
≤ 7.5 |
CVE-2024-1842 |
Wordfence | |
| 6.3 Medium | MasterStudy LMS WordPress Plugin – for Online Courses and Education | Broken Access Control for Online Courses and Education <= 3.3.8 - Missing Authorization |
≤ 3.3.8 |
CVE-2024-3942 |
Wordfence | |
| 4.4 Medium | SVS Pricing Tables | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0.4 |
CVE-2024-2958 |
Wordfence | |
| 6.4 Medium | Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.12.8 |
CVE-2024-3670 |
Wordfence | |
| 5.3 Medium | Woo Total Sales | Broken Access Control Missing Authorization to Unauthenticated Sales Report Retrieval No login needed |
≤ 3.1.4 |
CVE-2024-1688 |
Wordfence | |
| 4.3 Medium | eRoom – Zoom Meetings & Webinar | Broken Access Control Zoom Meetings & Webinar <= 1.4.18 - Missing Authorization to Information Exposure |
≤ 1.4.18 |
CVE-2024-3275 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.7 - Authenticated (contributor+) Stored Cross-Site Scripting via _id |
≤ 2.8.7 |
CVE-2024-3991 |
Wordfence | |
| 5.3 Medium | Subway – Private Site Option | Broken Access Control Private Site Option <= 2.1.4 - Improper Access Control to Sensitive Information Exposure via REST API No login needed |
≤ 2.1.4 |
CVE-2024-1678 |
Wordfence | |
| 6.4 Medium | Shortcodes and extra features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' |
≤ 2.15.7 |
CVE-2024-1396 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion/FAQ |
≤ 2.4.8 |
CVE-2024-2790 |
Wordfence | |
| 5.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.10.30 |
CVE-2024-4203 |
Wordfence | |
| 6.4 Medium | Inline Google Spreadsheet Viewer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 0.13.2 |
CVE-2024-3674 |
Wordfence | |
| 6.4 Medium | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | Cross-Site Scripting ProfilePress <= 4.15.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.15.4 |
CVE-2024-2867 |
Wordfence | |
| 6.4 Medium | WP ULike | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.6.9 |
CVE-2024-1572 |
Wordfence | |
| 6.5 Medium | FOX – Currency Switcher Professional for WooCommerce | Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.4.1.8 |
CVE-2024-3734 |
Wordfence | |
| 5.3 Medium | WP Cookie Consent ( for GDPR, CCPA & ePrivacy ) | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 3.0.2 |
CVE-2024-3599 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'arrow_style' |
≤ 4.10.28 |
CVE-2024-3647 |
Wordfence | |
| 6.4 Medium | Jeg Elementor Kit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget |
≤ 2.6.4 |
CVE-2024-3161 |
Wordfence | |
| 4.3 Medium | ACF On-The-Go | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Update |
≤ 1.0.1 |
CVE-2024-3071 |
Wordfence | |
| 6.4 Medium | Jeg Elementor Kit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Banner |
≤ 2.6.4 |
CVE-2024-3819 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.10.28 |
CVE-2024-3885 |
Wordfence | |
| 4.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 1.0.262 |
CVE-2024-3338 |
Wordfence | |
| 6.4 Medium | Shortcodes and extra features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aux_gmaps' Shortcode |
≤ 2.15.7 |
CVE-2024-3341 |
Wordfence | |
| 6.4 Medium | WPBakery Visual Composer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title tag attribute |
≤ 7.5 |
CVE-2024-1841 |
Wordfence | |
| 4.3 Medium | WordPress Backup & Migration | Broken Access Control Missing Authorization to Directory Traversal |
≤ 1.4.8 |
CVE-2024-3546 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget |
≤ 2.4.9 |
CVE-2024-3308 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes |
≤ 1.3.971 |
CVE-2024-3675 |
Wordfence | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget |
≤ 2.6.9.3 |
CVE-2024-2750 |
Wordfence | |
| 4.4 Medium | Mhr Post Ticker | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2024-3021 |
Wordfence | |
| 5.3 Medium | Analytify | Broken Access Control Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification No login needed |
≤ 5.2.3 |
CVE-2024-1584 |
Wordfence | |
| 6.4 Medium | All in One SEO – Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic | Cross-Site Scripting Best WordPress SEO Plugin – Easily Improve SEO Rankings & Increase Traffic <= 4.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.6.0 |
CVE-2024-3554 |
Wordfence | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid |
≤ 2.6.9.2 |
CVE-2024-2503 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery & Interactive Circle |
≤ 5.9.15 |
CVE-2024-3728 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.17 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.9.17 |
CVE-2024-4156 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.