WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,301–16,350 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 327 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Automatic Plugin SQL Injection Unauthenticated Arbitrary SQL Execution No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2024-27956 Patchstack
7.1 High Super Page Cache for Cloudflare Plugin wp-cloudflare-page-cache Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to XSS No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-27968 Patchstack
5.9 Medium WP Coder Plugin wp-coder Cross-Site Scripting ≤ 3.5 Fixed in 3.5.1 CVE-2024-2578 Patchstack
5.9 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting ≤ 2.0.16 Fixed in 2.1.0 CVE-2024-2579 Patchstack
6.5 Medium Automation By Autonami Plugin wp-marketing-automations Cross-Site Scripting ≤ 2.8.2 Fixed in 2.8.3 CVE-2024-2580 Patchstack
7.1 High wp-mpdf Plugin wp-mpdf Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.1 Fixed in 3.8 CVE-2024-27962 Patchstack
6.5 Medium Crisp Plugin crisp Cross-Site Scripting Live Chat and Chatbot plugin <= 0.44 - Cross Site Scripting (XSS) ≤ 0.44 Fixed in 0.45 CVE-2024-27963 Patchstack
8.8 High Zippy Plugin zippy Arbitrary File Upload ≤ 1.6.9 Fixed in 1.6.10 CVE-2024-27964 Patchstack
5.9 Medium WPFunnels Plugin wpfunnels Cross-Site Scripting ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-27965 Patchstack
5.9 Medium Quiz And Survey Master Plugin quiz-master-next Cross-Site Scripting ≤ 8.2.2 Fixed in 8.2.3 CVE-2024-27966 Patchstack
4.3 Medium DSGVO All in one for WP Plugin dsgvo-all-in-one-for-wp Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2024-27967 Patchstack
6.5 Medium Free Downloads WooCommerce Plugin download-now-for-woocommerce Cross-Site Scripting ≤ 3.5.8.2 Fixed in 3.5.8.3 CVE-2024-27969 Patchstack
5.4 Medium WP SendFox Plugin wp-sendfox Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-27970 Patchstack
5.4 Medium PropertyHive Plugin propertyhive PHP Object Injection No login needed ≤ 2.0.9 Fixed in 2.0.10 CVE-2024-27985 Patchstack
6.5 Medium WEN Responsive Columns Plugin wen-responsive-columns Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-27988 Patchstack
6.5 Medium WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs Cross-Site Scripting ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-27989 Patchstack
6.5 Medium The Moneytizer Plugin the-moneytizer Cross-Site Scripting ≤ 9.5.20 Fixed in 9.6.1 CVE-2024-27990 Patchstack
6.5 Medium SupportCandy Plugin supportcandy Cross-Site Scripting ≤ 3.2.3 Fixed in 3.2.4 CVE-2024-27991 Patchstack
7.1 High Link Whisper Free Plugin link-whisper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.8 Fixed in 0.6.9 CVE-2024-27992 Patchstack
7.1 High Calendarista Basic Edition Plugin calendarista-basic-edition Cross-Site Scripting No login needed ≤ 3.0.2 Fixed in 3.0.3 CVE-2024-27993 Patchstack
7.1 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons Cross-Site Scripting No login needed ≤ 4.5.0 Fixed in 4.6.0 CVE-2024-27994 Patchstack
5.9 Medium ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup Plugin armember-membership Cross-Site Scripting ≤ 4.0.23 Fixed in 4.0.24 CVE-2024-27995 Patchstack
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
6.5 Medium Word Replacer Pro Plugin word-replacer-ultra Broken Access Control No login needed ≤ 1.0 CVE-2023-52229 Patchstack
8.2 High Olive One Click Demo Import Plugin olive-one-click-demo-import Broken Access Control No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-2702 Patchstack
6.4 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Cross-Site Scripting Weglot <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 4.2.5 CVE-2024-2124 Wordfence
8.8 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin SQL Injection The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 6.8.6 CVE-2024-1799 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-27996 Patchstack
5.9 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.6.0 Fixed in 45.7.0 CVE-2024-27997 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-27998 Patchstack
6.5 Medium Five Star Restaurant Menu Plugin food-and-drink-menu Cross-Site Scripting ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-29089 Patchstack
7.1 High WP Armour – Honeypot Anti Spam Plugin honeypot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2024-29091 Patchstack
7.1 High Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.3 Fixed in 2.4.3.1 CVE-2024-29092 Patchstack
4.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.01.3 Fixed in 1.01.4 CVE-2024-29093 Patchstack
7.1 High HT Easy GA4 ( Google Analytics 4 ) Plugin ht-easy-google-analytics Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-29094 Patchstack
5.9 Medium Site Reviews Plugin site-reviews Cross-Site Scripting ≤ 6.11.6 Fixed in 6.11.7 CVE-2024-29095 Patchstack
6.5 Medium MJM Clinic Plugin mjm-clinic Cross-Site Scripting ≤ 1.1.22 Fixed in 1.1.23 CVE-2024-29096 Patchstack
6.3 Medium User profile Plugin user-profile Cross-Site Scripting Subscriber+ Stored Cross Site Scripting (XSS) ≤ 2.0.20 Fixed in 2.0.21 CVE-2024-29097 Patchstack
6.5 Medium WP Calameo Plugin wp-calameo Cross-Site Scripting ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-29098 Patchstack
7.1 High Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-29099 Patchstack
6.5 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-29101 Patchstack
7.1 High Extensions For CF7 Plugin extensions-for-cf7 Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29102 Patchstack
7.1 High Database for Contact Form 7 Plugin cf7-database Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29103 Patchstack
6.5 Medium Ticket Tailor Plugin ticket-tailor Cross-Site Scripting ≤ 1.10 Fixed in 1.12 CVE-2024-29104 Patchstack
5.9 Medium WP Popups Plugin wp-popups-lite Cross-Site Scripting WordPress Popup builder plugin <= 2.1.5.5 - Cross Site Scripting (XSS) ≤ 2.1.5.5 Fixed in 2.1.5.6 CVE-2024-29105 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.10.16 Fixed in 4.10.17 CVE-2024-29106 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting ≤ 1.12.10 Fixed in 1.12.11 CVE-2024-29107 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.10.1 Fixed in 3.10.2 CVE-2024-29108 Patchstack
6.5 Medium Shariff Wrapper Plugin shariff Cross-Site Scripting Contributor+ Cross Site Scripting (XSS) ≤ 4.6.10 Fixed in 4.6.11 CVE-2024-29109 Patchstack
7.1 High Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Scripting No login needed ≤ 1.0.27 Fixed in 1.0.28 CVE-2024-29110 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only