WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 15,901–15,950 of 17,704 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 319 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.31 Fixed in 1.10.32 CVE-2024-32829 Patchstack
4.7 Medium Page Builder: Live Composer Plugin live-composer-page-builder Broken Access Control ≤ 1.5.38 Fixed in 1.5.39 CVE-2024-32957 Patchstack
4.3 Medium Contact Form 7 Extension For Mailchimp Plugin contact-form-7-mailchimp-extension Cross-Site Request Forgery No login needed ≤ 0.5.70 CVE-2024-33677 Patchstack
4.3 Medium ClickCease Click Fraud Protection Plugin clickcease-click-fraud-protection Cross-Site Request Forgery No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-33678 Patchstack
4.3 Medium FameTheme Demo Importer Plugin famethemes-demo-importer Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-33679 Patchstack
5.4 Medium MainWP Child Reports Plugin mainwp-child-reports Cross-Site Request Forgery No login needed ≤ 2.1.1 Fixed in 2.2 CVE-2024-33680 Patchstack
5.4 Medium WP GDPR Compliance Plugin wp-gdpr-compliance Cross-Site Request Forgery No login needed ≤ 2.0.23 CVE-2024-33682 Patchstack
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.3 CVE-2024-33683 Patchstack
5.3 Medium WP STAGING Plugin wp-staging Information Disclosure Sensitive Information Exposure via Log File No login needed ≤ 3.4.3, ≤ 5.4.3 CVE-2024-3682 Wordfence
5.3 Medium WP-Members Membership Plugin Information Disclosure Unprotected Storage of Potentially Sensitive Files No login needed ≤ 3.4.9.3 CVE-2024-2920 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Calendly Widget ≤ 3.10.6 CVE-2024-3890 Wordfence
5.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Information Disclosure Information Exposure No login needed ≤ 7.4.2 CVE-2024-3678 Wordfence
5.9 Medium Advanced Post List Plugin advanced-post-list Cross-Site Scripting ≤ 0.5.6.1 CVE-2024-33642 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 CVE-2024-33639 Patchstack
5.9 Medium Annual Archive Plugin anual-archive Cross-Site Scripting ≤ 1.6.0 CVE-2024-33598 Patchstack
5.4 Medium Smart Maintenance Mode Plugin smart-maintenance-mode Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-33638 Patchstack
4.3 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Request Forgery No login needed ≤ 1.2.4 CVE-2024-33650 Patchstack
5.4 Medium MF Gig Calendar Plugin mf-gig-calendar Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2024-33651 Patchstack
6.3 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Contributor+ Stored XSS No login needed < 7.1.0 Fixed in 7.1.0 CVE-2024-3188 WPScan
4.5 Medium ENL Newsletter Plugin enl-newsletter SQL Injection Admin+ SQL Injection ≤ 1.0.1 CVE-2024-3060 WPScan
5.7 Medium ENL Newsletter Plugin enl-newsletter Cross-Site Request Forgery Campaign Deletion via CSRF ≤ 1.0.1 CVE-2024-3059 WPScan
5.4 Medium ENL Newsletter Plugin enl-newsletter Cross-Site Scripting Stored XSS via CSRF ≤ 1.0.1 CVE-2024-3058 WPScan
5.5 Medium Bannerlid Plugin bannerlid Cross-Site Scripting Reflected XSS ≤ 1.1.0 CVE-2024-3048 WPScan
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Scripting Admin+ Stored XSS < 1.4.7 Fixed in 1.4.7 CVE-2024-2908 WPScan
5.4 Medium WP Chat App Plugin wp-whatsapp Cross-Site Scripting Admin+ Stored XSS No login needed < 3.6.4 Fixed in 3.6.4 CVE-2024-2837 WPScan
6.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Scripting Editor+ Stored XSS via Email Settings No login needed ≤ 9.6.5 CVE-2024-2603 WPScan
4.8 Medium Salon booking system Plugin salon-booking-system Cross-Site Scripting Editor+ Stored XSS ≤ 9.6.5 CVE-2024-2439 WPScan
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 9.6.5 CVE-2024-2429 WPScan
5.9 Medium WP Google Review Slider Plugin wp-google-places-review-slider Cross-Site Scripting Admin+ Stored XSS No login needed < 13.6 Fixed in 13.6 CVE-2024-2310 WPScan
4.7 Medium Sassy Social Share Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed < 3.3.61 Fixed in 3.3.61 CVE-2024-2159 WPScan
6.3 Medium Fancy Product Designer Plugin Cross-Site Scripting Reflected Cross Site Scripting No login needed < 6.1.8 Fixed in 6.1.8 CVE-2024-0905 WPScan
4.7 Medium WP Advanced Search Plugin SQL Injection Admin+ SQL Injection ≤ 1.1.6 CVE-2024-3265 WPScan
5.4 Medium Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-33592 Patchstack
5.4 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.3 CVE-2024-3730 Wordfence
5.3 Medium LoginPress Pro Plugin Authentication Bypass Captcha Bypass No login needed < 3.0.0 Fixed in 3.0.0 CVE-2024-32676 Patchstack
4.3 Medium Google Analytics by Monster Insights Plugin google-analytics-for-wordpress Broken Access Control ≤ 8.21.0 Fixed in 8.22.0 CVE-2023-52220 Patchstack
5.4 Medium Tutor LMS – eLearning and online course solution Plugin tutor Cross-Site Scripting eLearning and online course solution <= 2.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tutor_instructor_list' Shortcode ≤ 2.6.2 CVE-2024-3994 Wordfence
6.4 Medium Photo Gallery - GT3 Image Gallery & Gutenberg Block Gallery Plugin gt3-photo-video-gallery Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery <= 2.7.7.21 - Authenticated (Author+) Cross-Site Scripting ≤ 2.7.7.21 CVE-2024-4035 Wordfence
6.5 Medium Blocksy Plugin blocksy Cross-Site Scripting ≤ 2.0.33 Fixed in 2.0.34 CVE-2024-32961 Patchstack
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.15 - Information Exposure No login needed ≤ 5.9.15 CVE-2024-3733 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Sina Fancy Text Widget ≤ 3.5.2 CVE-2024-3988 Wordfence
4.3 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Broken Access Control Classified ads & Business Directory Plugin <= 3.0.10.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Attachment Deletion ≤ 3.0.10.3 CVE-2024-3893 Wordfence
6.4 Medium Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) Plugin Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Post Overlay ≤ 3.7.0 CVE-2024-3929 Wordfence
6.8 Medium AGCA – Custom Dashboard & Login Page Plugin ag-custom-admin Cross-Site Scripting Custom Dashboard & Login Page < 7.2.2 - Admin+ Stored XSS via Image URL < 7.2.2 Fixed in 7.2.2 CVE-2024-2907 WPScan
5.3 Medium JetFormBuilder Plugin jetformbuilder Content Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2023-48763 Patchstack
5.4 Medium Jetpack Plugin jetpack Other Auth. Iframe Injection < 12.7 Fixed in 12.7 CVE-2023-47774 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Authentication Bypass Auth. Arbitrary Attachment Read ≤ 3.16.4 Fixed in 3.16.5 CVE-2023-47504 Patchstack
5.3 Medium Multi Rating Plugin multi-rating Broken Access Control Unauth Arbitrary rating value change No login needed ≤ 5.0.6 CVE-2023-32127 Patchstack
5.3 Medium WoodMart Theme Authentication Bypass Unauth Arbitrary Shortcodes Injection No login needed ≤ 7.0.4 Fixed in 7.1.1 CVE-2023-25790 Patchstack
4.1 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Open Redirect Unvalidated Redirects and Forwards ≤ 7.5.44.7212 Fixed in 7.5.45.7212 CVE-2024-32078 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only