WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,001–16,050 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 321 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id' ≤ 3.6.0 CVE-2024-3598 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2.6.4 CVE-2024-3560 Wordfence
6.4 Medium EAN for WooCommerce Plugin ean-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode ≤ 4.9.2 CVE-2023-6892 Wordfence
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control Insecure Direct Object Reference to Sensitve Information Exposure via Shortcode ≤ 4.9.2 CVE-2023-6897 Wordfence
6.8 Medium Store Locator Plugin agile-store-locator Arbitrary File Deletion WordPress Store Locator WordPress Plugin <= 1.4.14 is vulnerable to Arbitrary File Deletion ≤ 1.4.14 CVE-2023-50885 Patchstack
4.3 Medium WP Social Comments Plugin gs-facebook-comments Broken Access Control ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-32689 Patchstack
5.3 Medium Backup Migration Plugin backup-backup Information Disclosure Sensitive Data Exposure via Log No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-32686 Patchstack
5.5 Medium Really Simple SSL Plugin really-simple-ssl Server-Side Request Forgery ≤ 7.2.3 Fixed in 8.0.0 CVE-2024-31229 Patchstack
6.5 Medium WP-FormAssembly Plugin formassembly-web-forms Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2023-49768 Patchstack
5.9 Medium Navigation menu as Dropdown Widget Plugin navigation-menu-as-dropdown-widget Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-32126 Patchstack
6.5 Medium Taggbox Plugin taggbox-widget Cross-Site Scripting UGC Galleries, Social Media Widgets, User Reviews & Analytics plugin <= 3.2 - Cross Site Scripting (XSS) ≤ 3.2 Fixed in 3.3 CVE-2024-32552 Patchstack
6.5 Medium Knight Lab Timeline Plugin knight-lab-timelinejs Cross-Site Scripting ≤ 3.9.3.4 CVE-2024-32554 Patchstack
6.5 Medium HurryTimer Plugin hurrytimer Cross-Site Scripting ≤ 2.9.2 Fixed in 2.10.0 CVE-2024-32556 Patchstack
6.5 Medium QR Code Composer Plugin qr-code-composer Cross-Site Scripting ≤ 2.0.3 CVE-2024-32560 Patchstack
6.5 Medium Tagembed Plugin tagembed-widget Cross-Site Scripting ≤ 4.7 Fixed in 4.9 CVE-2024-32561 Patchstack
6.5 Medium PostX Plugin ultimate-post Cross-Site Scripting ≤ 4.0.1 Fixed in 4.0.2 CVE-2024-32564 Patchstack
6.5 Medium App Builder Plugin app-builder Cross-Site Scripting ≤ 3.8.8 Fixed in 3.8.9 CVE-2024-32565 Patchstack
6.5 Medium WP Club Manager Plugin wp-club-manager Cross-Site Scripting ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-32566 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.31 Fixed in 3.1.32 CVE-2024-32569 Patchstack
6.5 Medium WP Stripe Checkout Plugin wp-stripe-checkout Cross-Site Scripting ≤ 1.2.2.41 Fixed in 1.2.2.42 CVE-2024-32571 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.6.0 Fixed in 5.6.1 CVE-2024-32572 Patchstack
5.9 Medium WP-Lister Lite for eBay Plugin wp-lister-for-ebay Cross-Site Scripting ≤ 3.5.11 Fixed in 3.6.0 CVE-2024-32573 Patchstack
6.5 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting ≤ 1.1.9 Fixed in 1.2.0 CVE-2024-32575 Patchstack
6.5 Medium BA Book Everything Plugin ba-book-everything Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2024-32576 Patchstack
6.5 Medium CBX Bookmark & Favorite Plugin cbxwpbookmark Cross-Site Scripting ≤ 1.7.20 Fixed in 1.7.22 CVE-2024-32577 Patchstack
6.1 Medium Jobs Plugin job-postings Cross-Site Scripting Reflected Cross-Site Scripting via job-search No login needed ≤ 2.7.5 CVE-2024-2833 Wordfence
6.5 Medium Restaurant Menu – Food Ordering System – Table Reservation Plugin menu-ordering-reservations Cross-Site Scripting Food Ordering System – Table Reservation plugin <= 2.4.1 - Cross Site Scripting (XSS) ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-32579 Patchstack
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.9.8 Fixed in 3.9.9 CVE-2024-32580 Patchstack
6.5 Medium Mortgage Calculators WP Plugin mortgage-calculators-wp Cross-Site Scripting ≤ 1.56 Fixed in 1.60 CVE-2024-32581 Patchstack
5.9 Medium TeraWallet – For WooCommerce Plugin woo-wallet Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-32584 Patchstack
5.9 Medium Import Content in WordPress & WooCommerce with Excel Plugin content-excel-importer Cross-Site Scripting ≤ 4.2 Fixed in 4.3 CVE-2024-32585 Patchstack
6.5 Medium Gutenberg Block Editor Toolkit Plugin block-options Cross-Site Scripting ≤ 1.40.4 Fixed in 1.40.5 CVE-2024-32586 Patchstack
5.8 Medium EnvíaloSimple Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 Fixed in 2.3 CVE-2024-32587 Patchstack
6.5 Medium Kattene Plugin kattene Cross-Site Scripting ≤ 1.7 Fixed in 1.8 CVE-2024-32590 Patchstack
5.9 Medium Backend Designer Plugin backend-designer Cross-Site Scripting ≤ 1.3 Fixed in 1.4 CVE-2024-32591 Patchstack
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0 Fixed in 2.0.1 CVE-2024-32592 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.3.4.2 Fixed in 1.4 CVE-2024-32593 Patchstack
6.5 Medium Attesa Extra Plugin attesa-extra Cross-Site Scripting ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-32594 Patchstack
6.5 Medium DSGVO Youtube Plugin dsgvo-youtube Cross-Site Scripting ≤ 1.4.5 Fixed in 1.4.6 CVE-2024-32596 Patchstack
5.9 Medium WordPress Importer Plugin wp-smart-import Cross-Site Scripting ≤ 1.0.7 Fixed in 1.1.0 CVE-2024-32597 Patchstack
5.9 Medium BA Book Everything Plugin ba-book-everything Cross-Site Scripting ≤ 1.6.8 Fixed in 1.6.9 CVE-2024-32598 Patchstack
5.3 Medium Popup Anything Plugin popup-anything-on-click Broken Access Control No login needed ≤ 2.8 Fixed in 2.8.1 CVE-2024-32601 Patchstack
4.3 Medium WP-Recall Plugin wp-recall Broken Access Control Insecure Direct Object References (IDOR) ≤ 16.26.5 Fixed in 16.26.6 CVE-2024-32604 Patchstack
4.3 Medium PeproDev CF7 Database Plugin pepro-cf7-database Cross-Site Request Forgery No login needed ≤ 1.8.0 Fixed in 1.9.0 CVE-2023-41864 Patchstack
5.4 Medium Ovic Responsive WPBakery Plugin ovic-vc-addon Broken Access Control ≤ 1.3.0 CVE-2024-32142 Patchstack
6.1 Medium Otter Blocks Plugin otter-blocks Cross-Site Scripting Contributor+ Stored XSS No login needed < 2.6.6 Fixed in 2.6.6 CVE-2024-2729 WPScan
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget ≤ 5.6.0 CVE-2024-1429 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget ≤ 5.6.0 CVE-2024-1426 Wordfence
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) ≤ 4.4.7 CVE-2023-6805 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute ≤ 5.9.14 CVE-2024-3333 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only