WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,351–16,400 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 328 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-29111 Patchstack
5.9 Medium WooCommerce Google Feed Manager Plugin wp-product-feed-manager Cross-Site Scripting ≤ 2.2.0 Fixed in 2.3.0 CVE-2024-29112 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-29113 Patchstack
6.5 Medium Download Manager Plugin download-manager Cross-Site Scripting ≤ 3.2.84 Fixed in 3.2.85 CVE-2024-29114 Patchstack
6.5 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-29115 Patchstack
7.1 High WooThumbs for WooCommerce by Iconic Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-29116 Patchstack
7.1 High Contact Forms by Cimatti Plugin contact-forms Cross-Site Scripting Unauthenticated Stored Cross Site Scripting (XSS) No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-29117 Patchstack
6.5 Medium Scrollsequence Plugin scrollsequence Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-29118 Patchstack
7.1 High WooCommerce License Manager Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-29121 Patchstack
6.5 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting ≤ 7.5.41.7212 Fixed in 7.5.44.7212 CVE-2024-29122 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6 Fixed in 7.6.1 CVE-2024-29123 Patchstack
5.9 Medium Advanced Access Manager Plugin advanced-access-manager Cross-Site Scripting ≤ 6.9.20 Fixed in 6.9.21 CVE-2024-29124 Patchstack
7.1 High Coupon Affiliates Plugin woo-coupon-usage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.12.7 Fixed in 5.12.8 CVE-2024-29125 Patchstack
7.1 High Specific Content For Mobile – Customize the mobile version without redirections Plugin specific-content-for-mobile Cross-Site Scripting No login needed ≤ 0.1.9.5 Fixed in 0.1.9.6 CVE-2024-29126 Patchstack
7.1 High Advanced Access Manager Plugin advanced-access-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.9.20 Fixed in 6.9.21 CVE-2024-29127 Patchstack
7.1 High POST SMTP Plugin post-smtp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.6 Fixed in 2.8.7 CVE-2024-29128 Patchstack
7.1 High OxyExtras Plugin Cross-Site Scripting No login needed ≤ 1.4.4 Fixed in 1.4.5 CVE-2024-29129 Patchstack
7.1 High Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 Fixed in 2.1 CVE-2024-29130 Patchstack
6.5 Medium Tourfic Plugin tourfic Cross-Site Scripting ≤ 2.11.8 Fixed in 2.11.9 CVE-2024-29134 Patchstack
9.9 Critical Tourfic Plugin tourfic Arbitrary File Upload ≤ 2.11.15 Fixed in 2.11.16 CVE-2024-29135 Patchstack
8.5 High Tourfic Plugin tourfic PHP Object Injection ≤ 2.11.17 Fixed in 2.11.19 CVE-2024-29136 Patchstack
7.1 High Tourfic Plugin tourfic Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.11.7 Fixed in 2.11.8 CVE-2024-29137 Patchstack
7.1 High Restrict User Access – Membership Plugin with Force Plugin restrict-user-access Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.6 CVE-2024-29138 Patchstack
7.1 High MyCurator Content Curation Plugin mycurator Cross-Site Scripting No login needed ≤ 3.76 Fixed in 3.77 CVE-2024-29139 Patchstack
5.9 Medium MJM Clinic Plugin mjm-clinic Cross-Site Scripting ≤ 1.1.22 Fixed in 1.1.23 CVE-2024-29140 Patchstack
5.5 Medium PDF Embedder Plugin pdf-embedder Cross-Site Scripting ≤ 4.6.4 Fixed in 4.7.1 CVE-2024-29141 Patchstack
7.1 High Better Search – Relevant search results Plugin better-search Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 3.3.0 Fixed in 3.3.1 CVE-2024-29142 Patchstack
6.5 Medium Passwordless Login Plugin passwordless-login Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-29143 Patchstack
5.4 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.4 Fixed in 2.7.4 CVE-2024-0820 WPScan
7.1 High AntiSpam for Contact Form 7 Plugin cf7-antispam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.0 Fixed in 0.6.1 CVE-2024-27961 Patchstack
7.1 High Email Subscription Popup Plugin email-subscribe Cross-Site Scripting No login needed ≤ 1.2.20 Fixed in 1.2.21 CVE-2024-27960 Patchstack
7.1 High WC Shop Sync – Integrate Square and WooCommerce for Seamless Shop Management Plugin woosquare Cross-Site Scripting No login needed ≤ 4.2.9 Fixed in 4.3 CVE-2024-27959 Patchstack
7.1 High Visualizer Plugin visualizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.10.5 Fixed in 3.10.6 CVE-2024-27958 Patchstack
10.0 Critical Pie Register Plugin pie-register Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.8.3.1 CVE-2024-27957 Patchstack
5.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Information Disclosure Sensitive Data Exposure No login needed ≤ 22.7 Fixed in 22.8 CVE-2024-25903 Patchstack
5.3 Medium WP Editor Plugin wp-editor Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-25591 Patchstack
5.3 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 6.9.4 Fixed in 6.9.5 CVE-2024-24867 Patchstack
5.3 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.7 CVE-2024-25933 Patchstack
5.3 Medium Post Thumbnail Editor Plugin post-thumbnail-editor Information Disclosure Unauthenticated Sensitive Data Exposure No login needed ≤ 2.4.8 CVE-2024-24845 Patchstack
6.5 Medium Elementor Pro Plugin Information Disclosure Contributor+ Arbitrary User Meta Data Retrieval ≤ 3.19.2 Fixed in 3.19.3 CVE-2024-23523 Patchstack
7.1 High Fontific | Google Fonts Plugin fontific Cross-Site Request Forgery CSRF to XSS No login needed ≤ 0.1.6 CVE-2024-27194 Patchstack
7.1 High Watermark RELOADED Plugin watermark-reloaded Cross-Site Request Forgery CSRF to XSS No login needed ≤ 1.3.5 Fixed in 1.4.0 CVE-2024-27195 Patchstack
7.1 High BeePress Plugin beepress Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 6.9.8 CVE-2024-27197 Patchstack
8.8 High TerraClassifieds Plugin terraclassifieds Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.0.3 CVE-2023-51474 Patchstack
5.4 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.101 Fixed in 1.2.102 CVE-2023-51486 Patchstack
5.4 Medium ARI Stream Quiz Plugin ari-stream-quiz Cross-Site Request Forgery WordPress Quizzes Builder plugin <= 1.2.32 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.32 Fixed in 1.3.0 CVE-2023-51487 Patchstack
5.4 Medium Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Request Forgery No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51489 Patchstack
5.4 Medium Depicter Slider Plugin depicter Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2023-51491 Patchstack
4.3 Medium Export Media URLs Plugin export-media-urls Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 2.0 CVE-2023-51510 Patchstack
4.3 Medium Product Table by WBW Plugin woo-product-tables Cross-Site Request Forgery No login needed ≤ 1.8.6 Fixed in 1.8.7 CVE-2023-51512 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only