WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,401–16,450 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 329 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) Plugin easy-digital-downloads Information Disclosure Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure No login needed ≤ 3.2.9 CVE-2024-2302 Wordfence
4.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Information Disclosure Sensitive Information Exposure ≤ 4.4.5 CVE-2024-2033 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget ≤ 1.3.4 CVE-2024-2185 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget ≤ 1.3.4 CVE-2024-2187 Wordfence
5.4 Medium Soledad Theme Cross-Site Request Forgery No login needed ≤ 8.4.2 CVE-2024-31369 Patchstack
6.5 Medium Soledad Theme Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 8.4.2 CVE-2024-31368 Patchstack
6.1 Medium Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS No login needed < 2.3.11 Fixed in 2.3.11 CVE-2024-1664 WPScan
5.4 Medium WP2LEADS Plugin wp2leads Broken Access Control ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-31375 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.5.2 Fixed in 1.6.0 CVE-2024-31357 Patchstack
4.8 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS < 2.7 Fixed in 2.7 CVE-2024-1958 WPScan
6.1 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS No login needed < 2.7 Fixed in 2.7 CVE-2024-1956 WPScan
6.1 Medium Font Farsi Plugin Cross-Site Scripting Admin+ Stored XSS in Settings No login needed ≤ 1.6.6 CVE-2024-1752 WPScan
6.1 Medium SendPress Newsletters Plugin Cross-Site Scripting Admin+ Stored XSS via Form Settings No login needed ≤ 1.23.11.6 CVE-2024-1589 WPScan
6.8 Medium SendPress Newsletters Plugin Cross-Site Scripting Admin+ Stored XSS via Settings ≤ 1.23.11.6 CVE-2024-1588 WPScan
4.7 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS No login needed < 2.7 Fixed in 2.7 CVE-2024-1292 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control IDOR on Friend Request ≤ 5.7.6 Fixed in 5.7.7 CVE-2024-31291 Patchstack
4.3 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0.81 Fixed in 1.0.82 CVE-2024-31296 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery No login needed ≤ 8.5.2 Fixed in 8.6.0 CVE-2024-22155 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-31236 Patchstack
6.5 Medium Formsite | Embed online forms to collect orders, registrations, leads, and surveys Plugin formsite Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-31257 Patchstack
6.5 Medium Form to Chat App Plugin form-to-chat Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-31258 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-31306 Patchstack
5.9 Medium Easy Login Styler – White Label Admin Login Page Plugin easy-login-styler Cross-Site Scripting ≤ 1.0.6 CVE-2024-31344 Patchstack
6.5 Medium Gradient Text Widget for Elementor Plugin gradient-text-widget-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-31346 Patchstack
6.5 Medium Testimonials Plugin super-testimonial Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-31348 Patchstack
6.5 Medium MailMunch – Grow your Email List Plugin mailmunch Cross-Site Scripting Grow your Email List plugin <= 3.1.6 - Cross Site Scripting (XSS) ≤ 3.1.6 Fixed in 3.1.7 CVE-2024-31349 Patchstack
4.4 Medium WP Import Export Lite Plugin wp-import-export-lite PHP Object Injection ≤ 3.9.26 Fixed in 3.9.27 CVE-2024-31308 Patchstack
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message ≤ 4.3.3 CVE-2023-6877 Wordfence
5.5 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG ≤ 1.8.21 CVE-2024-2296 Wordfence
6.4 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Widget ≤ 1.4.0 CVE-2024-2132 Wordfence
6.4 Medium Powerkit – Supercharge your WordPress Site Plugin powerkit Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.9.1 CVE-2024-2458 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
6.4 Medium Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' ≤ 2.6.3 CVE-2024-2949 Wordfence
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields ≤ 2.4.14 CVE-2024-2471 Wordfence
4.8 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting Admin+ Stored XSS < 3.5.0 Fixed in 3.5.0 CVE-2024-2444 WPScan
5.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 4.4.2 CVE-2024-3216 Wordfence
5.3 Medium BoldGrid Easy SEO – Simple and Effective SEO Plugin boldgrid-easy-seo Information Disclosure Simple and Effective SEO <= 1.6.14 - Information Exposure No login needed ≤ 1.6.14 CVE-2024-2950 Wordfence
4.4 Medium Icegram Express Plugin email-subscribers Cross-Site Scripting Authenticated (Administrator+) Cross-Site Scripting via CSV import ≤ 5.7.15 CVE-2024-2656 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block ≤ 3.9.14 CVE-2024-3245 Wordfence
4.3 Medium Image Watermark Plugin image-watermark Broken Access Control Missing Authorization to Authenticated (Subscriber+) Watermark Modification ≤ 1.7.3 CVE-2024-1994 Wordfence
6.4 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via accordions Shortcode ≤ 0.4.3 CVE-2024-2499 Wordfence
5.3 Medium WordPress Core Information Disclosure Sensitive Information Exposure via redirect_guess_404_permalink No login needed ≤ 6.4.3 CVE-2023-5692 Wordfence
6.5 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.26 Fixed in 3.2.26 CVE-2024-2509 WPScan
5.3 Medium CGC Maintenance Mode Plugin cgc-maintenance-mode Information Disclosure Sensitive Information Exposure No login needed ≤ 1.2 CVE-2024-1418 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget ≤ 3.2.31 CVE-2024-2919 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
4.4 Medium Announce from the Dashboard Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.5.2 CVE-2024-3030 Wordfence
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.0.7 CVE-2024-2803 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout ≤ 2.8.3 CVE-2024-2868 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only