WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 16,651–16,700 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 334 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Crypto Converter Widget Plugin crypto-converter-widget Cross-Site Scripting ≤ 1.8.4 Fixed in 1.9.0 CVE-2024-29930 Patchstack
5.9 Medium WCFM – Frontend Manager for WooCommerce Plugin wc-frontend-manager Cross-Site Scripting ≤ 6.7.8 Fixed in 6.7.9 CVE-2024-29929 Patchstack
5.3 Medium Networker - Tech News WordPress Theme with Dark Mode Theme Broken Access Control Tech News WordPress Theme with Dark Mode <= 1.1.9 - Missing Authorization No login needed ≤ 1.1.9 CVE-2024-2962 Wordfence
4.4 Medium Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 20231101 CVE-2024-2956 Wordfence
6.5 Medium WishSuite Plugin wishsuite Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-29927 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-29926 Patchstack
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Cross-Site Scripting ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-29925 Patchstack
5.9 Medium Slider Hero Plugin slider-hero Cross-Site Scripting ≤ 8.6.1 Fixed in 8.7.0 CVE-2024-29922 Patchstack
5.9 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Scripting ≤ 1.15.16 Fixed in 1.15.17 CVE-2024-29921 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-29920 Patchstack
6.5 Medium Compact WP Audio Player Plugin compact-wp-audio-player Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2024-29917 Patchstack
6.5 Medium Stratum Plugin stratum Cross-Site Scripting Elementor Widgets plugin <= 1.3.15 - Cross Site Scripting (XSS) ≤ 1.3.15 Fixed in 1.3.16 CVE-2024-29914 Patchstack
6.5 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-29913 Patchstack
6.5 Medium iCalendrier Plugin icalendrier Cross-Site Scripting ≤ 1.80 Fixed in 1.81 CVE-2024-29912 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-29911 Patchstack
6.5 Medium Dropdown Multisite selector Plugin dropdown-multisite-selector Cross-Site Scripting ≤ 0.9.2 Fixed in 0.9.2.1 CVE-2024-29910 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-29909 Patchstack
6.5 Medium Co-marquage service-public.fr Plugin co-marquage-service-public Cross-Site Scripting ≤ 0.5.71 Fixed in 0.5.72 CVE-2024-29908 Patchstack
6.5 Medium PDF Builder for WPForms Plugin pdf-builder-for-wpforms Cross-Site Scripting ≤ 1.2.88 Fixed in 1.2.89 CVE-2024-29820 Patchstack
5.9 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting Meta Data and Taxonomies Filter plugin <= 1.3.2 - Cross Site Scripting (XSS) ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-29906 Patchstack
6.5 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-30192 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.1.17 Fixed in 4.1.18 CVE-2024-30193 Patchstack
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation ≤ 3.20.1 CVE-2024-2120 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload ≤ 3.20.1 CVE-2024-1521 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag ≤ 3.20.1 CVE-2024-2781 Wordfence
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.1 CVE-2024-2121 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authententicated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.1 CVE-2024-1364 Wordfence
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-27188 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30197 Patchstack
5.8 Medium BuddyForms Plugin buddyforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2024-30198 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.24 Fixed in 2.0.25 CVE-2023-52228 Patchstack
6.5 Medium WP SMS Plugin wp-sms Cross-Site Scripting ≤ 6.3.4 Fixed in 6.4 CVE-2024-25920 Patchstack
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Clients Widget ≤ 5.4.1 CVE-2024-2203 Wordfence
6.4 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget ≤ 2.0.5.6 CVE-2024-2139 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Team Member Listing ≤ 5.4.1 CVE-2024-2210 Wordfence
5.3 Medium Community by PeepSo Plugin peepso-core Information Disclosure Server Information Disclosure No login needed ≤ 6.0.9.0 Fixed in 6.1.0.0 CVE-2023-27630 Patchstack
5.9 Medium Upload Resume Plugin resume-upload-form Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.0 CVE-2023-25965 Patchstack
4.3 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Request Forgery No login needed ≤ 5.3.0.0 Fixed in 5.3.1.0 CVE-2024-2951 Patchstack
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Stored Cross Site Scripting in UploadHandler 1.0.1 – 1.8.21 CVE-2024-29833 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg thumb_url 1.0.1 – 1.8.21 CVE-2024-29810 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_url 1.0.1 – 1.8.21 CVE-2024-29809 AppCheck
5.4 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Reflected Cross Site Scripting in editimage_bwg image_id 1.0.1 – 1.8.21 CVE-2024-29808 AppCheck
6.1 Medium PhotoGallery Plugin photo-gallery Cross-Site Scripting WordPress Photo Gallery Plugin <= 1.8.21 Unauthenticated Reflected Cross Site Scripting in GalleryBox current_url No login needed 1.0.1 – 1.8.21 CVE-2024-29832 AppCheck
4.3 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Broken Access Control ≤ 2.3 Fixed in 2.4 CVE-2023-52214 Patchstack
6.5 Medium SalesKing Plugin Broken Access Control Unauthenticated Plugin Settings Change No login needed ≤ 1.6.15 Fixed in 1.6.30 CVE-2024-22156 Patchstack
6.5 Medium Radio Player Plugin radio-player Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 2.0.73 Fixed in 2.0.74 CVE-2024-2906 Patchstack
4.3 Medium Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Broken Access Control MPG plugin <= 3.4.0 - Broken Access Control ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-30235 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Broken Access Control ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30234 Patchstack
6.5 Medium WholesaleX Plugin wholesalex Information Disclosure Sensitive Data Exposure on User Export ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-30233 Patchstack
6.5 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.6.9 Fixed in 2.6.9.1 CVE-2024-30232 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only