WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,551–16,600 of 16,788 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 332 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium My Agile Privacy – The only GDPR solution for WordPress that you can truly trust Plugin myagileprivacy Cross-Site Scripting WordPress My Agile Privacy Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 2.1.7 Fixed in 2.1.8 CVE-2023-51404 Patchstack
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting WordPress GiveWP Plugin <= 3.2.2 is vulnerable to Cross Site Scripting (XSS) ≤ 3.2.2 Fixed in 3.3.0 CVE-2023-51415 Patchstack
6.5 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Scripting WordPress Active Products Tables for WooCommerce Plugin <= 1.0.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0.6 Fixed in 1.0.6.1 CVE-2023-51480 Patchstack
6.5 Medium Pay with Vipps and MobilePay for WooCommerce Plugin woo-vipps Cross-Site Scripting WordPress Pay with Vipps for WooCommerce Plugin <= 1.14.13 is vulnerable to Cross Site Scripting (XSS) ≤ 1.14.13 Fixed in 1.14.14 CVE-2023-51485 Patchstack
7.1 High Crowdsignal Dashboard – Polls, Surveys & more Plugin polldaddy Cross-Site Scripting Polls, Surveys & more Plugin <= 3.0.11 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 3.0.11 Fixed in 3.1.0 CVE-2023-51488 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting WordPress If-So Dynamic Content Personalization Plugin <= 1.6.3.1 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.3.1 Fixed in 1.7 CVE-2023-51492 Patchstack
6.5 Medium Custom Post Carousels with Owl Plugin dd-post-carousel Cross-Site Scripting WordPress Custom Post Carousels with Owl Plugin <= 1.4.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.6 Fixed in 1.4.7 CVE-2023-51493 Patchstack
6.5 Medium Click To Tweet Plugin click-to-tweet Cross-Site Scripting WordPress Click To Tweet Plugin <= 2.0.14 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.14 CVE-2024-23514 Patchstack
6.5 Medium CC BMI Calculator Plugin cc-bmi-calculator Cross-Site Scripting WordPress CC BMI Calculator Plugin <= 2.0.1 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.1 CVE-2024-23516 Patchstack
6.5 Medium Scheduling Plugin – Online Booking Plugin calendar-booking Cross-Site Scripting Online Booking for WordPress Plugin <= 3.5.10 is vulnerable to Cross Site Scripting (XSS) ≤ 3.5.10 CVE-2024-23517 Patchstack
6.5 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Scripting WordPress Heateor Social Login Plugin <= 1.1.30 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.30 Fixed in 1.1.31 CVE-2024-24712 Patchstack
6.5 Medium Auto Listings – Car Listings & Car Dealership Plugin auto-listings Cross-Site Scripting WordPress Auto Listings Plugin <= 2.6.5 is vulnerable to Cross Site Scripting (XSS) ≤ 2.6.5 Fixed in 2.6.6 CVE-2024-24713 Patchstack
5.9 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting WordPress Beds24 Online Booking Plugin <= 2.0.23 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.23 Fixed in 2.0.24 CVE-2024-24717 Patchstack
6.5 Medium OWL Carousel – WordPress Owl Carousel Slider Plugin lgx-owl-carousel Cross-Site Scripting WordPress OWL Carousel Plugin <= 1.4.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.4.0 CVE-2024-24801 Patchstack
6.5 Medium Ultra Companion – Companion plugin for WPoperation Themes Plugin ultra-companion Cross-Site Scripting WordPress Ultra Companion Plugin <= 1.1.9 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.9 CVE-2024-24803 Patchstack
6.5 Medium MW WP Form Plugin mw-wp-form Cross-Site Scripting WordPress MW WP Form Plugin <= 5.0.6 is vulnerable to Cross Site Scripting (XSS) ≤ 5.0.6 CVE-2024-24804 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.10.16 Fixed in 4.10.17 CVE-2024-24831 Patchstack
5.3 Medium Awesome Support – WordPress HelpDesk & Support Plugin Broken Access Control WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html() No login needed ≤ 6.1.7 CVE-2024-0596 Wordfence
4.3 Medium Awesome Support – WordPress HelpDesk & Support Plugin awesome-support Broken Access Control WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via wpas_get_users() ≤ 6.1.7 CVE-2024-0595 Wordfence
8.8 High Awesome Support – WordPress HelpDesk & Support Plugin awesome-support SQL Injection WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection ≤ 6.1.7 CVE-2024-0594 Wordfence
5.9 Medium BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net Plugin woo-bulk-editor Cross-Site Scripting WordPress BEAR Plugin <= 1.1.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.4.1 CVE-2024-24834 Patchstack
6.5 Medium GDPR Data Request Form Plugin gdpr-data-request-form Cross-Site Scripting WordPress GDPR Data Request Form Plugin <= 1.6 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6 Fixed in 1.7 CVE-2024-24836 Patchstack
6.5 Medium Blocksy Plugin blocksy Cross-Site Scripting ≤ 2.0.19 Fixed in 2.0.20 CVE-2024-24871 Patchstack
7.1 High Wonder Slider Lite Plugin wonderplugin-slider-lite Cross-Site Scripting WordPress Wonder Slider Lite Plugin <= 13.9 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 13.9 Fixed in 14.0 CVE-2024-24877 Patchstack
7.1 High Portugal CTT Tracking for WooCommerce Plugin portugal-ctt-tracking-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 Fixed in 2.2 CVE-2024-24878 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting WordPress Link Library Plugin <= 7.5.13 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 7.5.13 Fixed in 7.6 CVE-2024-24879 Patchstack
6.5 Medium Apollo13 Framework Extensions Plugin apollo13-framework-extensions Cross-Site Scripting WordPress Apollo13 Framework Extensions Plugin <= 1.9.2 is vulnerable to Cross Site Scripting (XSS) ≤ 1.9.2 Fixed in 1.9.3 CVE-2024-24880 Patchstack
7.1 High WP SMS – Messaging & SMS Notification for WordPress, WooCommerce, GravityForms, etc Plugin wp-sms Cross-Site Scripting WordPress WP SMS Plugin <= 6.5.2 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 6.5.2 Fixed in 6.5.3 CVE-2024-24881 Patchstack
5.9 Medium Woocommerce Vietnam Checkout Plugin woo-vietnam-checkout Cross-Site Scripting WordPress Woocommerce Vietnam Checkout Plugin <= 2.0.7 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.7 Fixed in 2.0.8 CVE-2024-24885 Patchstack
5.9 Medium Product Labels For Woocommerce (Sale Badges) Plugin aco-product-labels-for-woocommerce Cross-Site Scripting WordPress Product Labels For Woocommerce Plugin <= 1.5.3 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-24886 Patchstack
5.4 Medium WP-CFM Plugin wp-cfm Cross-Site Request Forgery WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2024-24706 Patchstack
5.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 4.0.11 CVE-2024-1109 Wordfence
5.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control Missing Authorization to Settings Import No login needed ≤ 4.0.11 CVE-2024-1110 Wordfence
3.8 Low WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Server-Side Request Forgery The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. Thi… 4.23.5 CVE-2024-0628 Wordfence
6.4 Medium WordPress Button Plugin MaxButtons Plugin maxbuttons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 9.7.6 CVE-2023-7029 Wordfence
9.8 Critical Cryptocurrency Widgets – Price Ticker & Coins List Plugin cryptocurrency-price-ticker-widget SQL Injection Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficie… No login needed 2.0 – 2.6.5 CVE-2024-0709 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insuf… 1.12.11 CVE-2024-0834 Wordfence
5.3 Medium WP Club Manager – WordPress Sports Club Plugin Broken Access Control WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update No login needed ≤ 2.2.10 CVE-2024-1177 Wordfence
5.4 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Cross-Site Request Forgery WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery No login needed ≤ 1.0.8.1 CVE-2024-0790 Wordfence
6.4 Medium Meta Box – WordPress Custom Fields Framework Plugin Cross-Site Scripting WordPress Custom Fields Framework <= 5.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.2 CVE-2023-6526 Wordfence
4.3 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Broken Access Control WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Missing Authorization ≤ 1.0.8.1 CVE-2024-0791 Wordfence
6.5 Medium Five Star Restaurant Reviews Plugin good-reviews-wp Cross-Site Scripting WordPress Five Star Restaurant Reviews Plugin <= 2.3.5 is vulnerable to Cross Site Scripting (XSS) ≤ 2.3.5 Fixed in 2.3.6 CVE-2024-24838 Patchstack
6.5 Medium Structured Content (JSON-LD) #wpsc Plugin structured-content Cross-Site Scripting WordPress Structured Content Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-24839 Patchstack
5.9 Medium Add Customer for WooCommerce Plugin add-customer-for-woocommerce Cross-Site Scripting WordPress Add Customer for WooCommerce Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7 Fixed in 1.7.1 CVE-2024-24841 Patchstack
7.1 High Mighty Addons for Elementor Plugin mighty-addons Cross-Site Scripting WordPress Mighty Addons for Elementor Plugin <= 1.9.3 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.9.3 CVE-2024-24846 Patchstack
7.1 High CalculatorPro Calculators Plugin calculatorpro-calculators Cross-Site Scripting WordPress CalculatorPro Calculators Plugin <= 1.1.7 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.1.7 CVE-2024-24847 Patchstack
7.1 High PT Sign Ups – Beautiful volunteer sign ups and management made easy Plugin ptoffice-sign-ups Cross-Site Scripting WordPress PT Sign Ups Plugin <= 1.0.4 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-24848 Patchstack
6.5 Medium Scroll Triggered Box Plugin dreamgrow-scroll-triggered-box Cross-Site Scripting WordPress Scroll Triggered Box Plugin <= 2.3 is vulnerable to Cross Site Scripting (XSS) ≤ 2.3 CVE-2024-24865 Patchstack
7.1 High Biteship: Plugin Ongkos Kirim Kurir Instant, Reguler, Kargo Plugin biteship Cross-Site Scripting WordPress Biteship Plugin <= 2.2.24 is vulnerable to Cross Site Scripting (XSS) No login needed ≤ 2.2.24 Fixed in 2.2.25 CVE-2024-24866 Patchstack
6.5 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting WordPress Advanced iFrame Plugin <= 2023.10 is vulnerable to Cross Site Scripting (XSS) ≤ 2023.10 Fixed in 2024.0 CVE-2024-24870 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only