WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 15,901–15,950 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 319 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload < 8.6.03.005 Fixed in 8.6.03.005 CVE-2024-31286 Patchstack
7.2 High Import XML and RSS Feeds Plugin import-xml-feed Arbitrary File Upload ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-31292 Patchstack
9.1 Critical Auto Poster Plugin auto-poster Arbitrary File Upload ≤ 1.2 CVE-2024-31345 Patchstack
8.7 High Product Designer Plugin product-designer PHP Object Injection No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2024-31277 Patchstack
4.4 Medium WP Import Export Lite Plugin wp-import-export-lite PHP Object Injection ≤ 3.9.26 Fixed in 3.9.27 CVE-2024-31308 Patchstack
7.2 High RapidLoad Power-Up for Autoptimize Plugin unusedcss Server-Side Request Forgery No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-31288 Patchstack
6.4 Medium Powerkit – Supercharge your WordPress Site Plugin powerkit Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.9.1 CVE-2024-2458 Wordfence
5.3 Medium WordPress Core Information Disclosure Sensitive Information Exposure via redirect_guess_404_permalink No login needed ≤ 6.4.3 CVE-2023-5692 Wordfence
8.8 High LearnPress – WordPress LMS Plugin learnpress Cross-Site Request Forgery WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.0.0 CVE-2024-2115 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
9.0 Critical VideoWhisper Live Streaming Integration Plugin videowhisper-live-streaming-integration Remote Code Execution No login needed ≤ 5.5.15 Fixed in 5.5.16 CVE-2023-25699 Patchstack
9.9 Critical Cwicly Plugin Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 1.4.0.2 Fixed in 1.4.0.3 CVE-2024-24707 Patchstack
10.0 Critical Canto Plugin canto Remote Code Execution Unauth. Remote Code Execution (RCE) No login needed ≤ 3.0.7 CVE-2024-25096 Patchstack
9.9 Critical InstaWP Connect Plugin instawp-connect Remote Code Execution ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-25918 Patchstack
8.5 High Slivery Extender Plugin slivery-extender Remote Code Execution ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-27191 Patchstack
9.1 Critical Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-27951 Patchstack
9.9 Critical WP Fusion Lite Plugin wp-fusion-lite Remote Code Execution ≤ 3.41.24 Fixed in 3.42.10 CVE-2024-27972 Patchstack
9.9 Critical Oxygen Builder Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 4.9 CVE-2024-31380 Patchstack
9.9 Critical Breakdance Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 1.7.2 CVE-2024-31390 Patchstack
9.8 Critical LayerSlider Plugin SQL Injection The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user suppl… No login needed 7.9.11 – 7.10.0 CVE-2024-2879 Wordfence
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-30531 Patchstack
4.9 Medium Builderall Builder Plugin builderall-cheetah-for-wp Server-Side Request Forgery ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-30532 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.25 Fixed in 3.2.26 CVE-2024-24888 Patchstack
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2024-31105 Patchstack
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button ≤ 2.8.0.5 CVE-2024-2925 Wordfence
4.3 Medium SecuPress Free — WordPress Security Plugin secupress Cross-Site Request Forgery Cross-Site Request Forgery to Banned IP Address No login needed ≤ 2.2.5.1 CVE-2024-1504 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.15.7 Fixed in 2.15.8 CVE-2024-31099 Patchstack
6.5 Medium PDF Viewer for Elementor Plugin pdf-viewer-for-elementor Cross-Site Scripting ≤ 2.9.3 CVE-2024-30524 Patchstack
6.5 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting ≤ 5.1 Fixed in 5.1.1 CVE-2024-30530 Patchstack
5.9 Medium underConstruction Plugin underconstruction Cross-Site Scripting ≤ 1.21 Fixed in 1.22 CVE-2024-30548 Patchstack
5.9 Medium Contact Forms by Cimatti Plugin contact-forms Cross-Site Scripting ≤ 1.8.0 Fixed in 1.9.1 CVE-2024-30549 Patchstack
7.1 High Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.3 CVE-2024-30550 Patchstack
7.1 High Sticky Anything Plugin toast-stick-anything Cross-Site Scripting No login needed ≤ 2.1.5 CVE-2024-30551 Patchstack
6.5 Medium Responsive flipbook Plugin wppdf Cross-Site Scripting ≤ 1.0.0 CVE-2024-30552 Patchstack
5.9 Medium WP Twitter Mega Fan Box Widget Plugin wp-twitter-mega-fan-box Cross-Site Scripting ≤ 1.0 CVE-2024-30553 Patchstack
5.9 Medium DD Rating Plugin dd-rating Cross-Site Scripting ≤ 1.7.1 CVE-2024-30554 Patchstack
6.5 Medium Ultimate Social Comments – Email Notification & Lazy Load Plugin ultimate-facebook-comments Cross-Site Scripting ≤ 1.4.8 CVE-2024-30555 Patchstack
6.5 Medium Mighty Classic Pros And Cons Plugin joomdev-wp-pros-cons Cross-Site Scripting ≤ 2.0.9 CVE-2024-30556 Patchstack
6.5 Medium Aesop Story Engine Plugin aesop-story-engine Cross-Site Scripting ≤ 2.3.2 CVE-2024-30557 Patchstack
7.1 High Add Shortcodes Actions And Filters Plugin add-actions-and-filters Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.10 CVE-2024-30558 Patchstack
6.5 Medium Spin 360 deg and 3D Model Viewer Plugin spin360 Cross-Site Scripting ≤ 1.2.7 CVE-2024-30559 Patchstack
7.1 High Appointment Calendar Plugin appointment-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.9.6 CVE-2024-30561 Patchstack
7.1 High Weekly Class Schedule Plugin weekly-class-schedule Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.19 CVE-2024-31084 Patchstack
7.1 High Post-Plugin Library Plugin post-plugin-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2.1 CVE-2024-31085 Patchstack
7.1 High pageMash > Page Management Plugin pagemash Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2024-31087 Patchstack
5.9 Medium Platinum SEO Plugin platinum-seo-pack Cross-Site Scripting ≤ 2.4.0 CVE-2024-31089 Patchstack
7.1 High Hacklog Down As PDF Plugin down-as-pdf Cross-Site Scripting No login needed ≤ 2.3.6 CVE-2024-31090 Patchstack
7.1 High Custom Field Bulk Editor Plugin custom-field-bulk-editor Cross-Site Scripting No login needed ≤ 1.9.1 CVE-2024-31091 Patchstack
7.1 High Comic Easel Plugin comic-easel Cross-Site Scripting No login needed ≤ 1.15 CVE-2024-31092 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only