WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 17,001–17,050 of 17,674 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Broken Access Control Missing Authorization on publish_lp() |
≤ 4.4 |
CVE-2023-4728 |
Wordfence | |
| 4.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Broken Access Control The LadiApp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ladiflow_save_hook() function in versions up to, and i… |
4.3 |
CVE-2023-4626 |
Wordfence | |
| 4.3 Medium | LadiApp: Landing Page, PopupX, Marketing Automation, Affiliate Marketing… | Cross-Site Request Forgery Cross-Site Request Forgery via init_endpoint No login needed |
≤ 4.4 |
CVE-2023-4731 |
Wordfence | |
| 4.3 Medium | LadiApp | Cross-Site Request Forgery Cross-Site Request Forgery via ladiflow_save_hook() No login needed |
≤ 4.4 |
CVE-2023-4628 |
Wordfence | |
| 5.3 Medium | f(x) Private Site | Information Disclosure Sensitive Information Exposure No login needed |
≤ 1.2.1 |
CVE-2024-0906 |
Wordfence | |
| 6.4 Medium | Newsletter2Go | Cross-Site Scripting Authenticated(Subscriber+) Stored Cross-Site Scripting via style |
≤ 4.0.14 |
CVE-2024-1328 |
Wordfence | |
| 4.3 Medium | Mollie Forms | Broken Access Control Missing Authorization |
≤ 2.6.3 |
CVE-2024-1645 |
Wordfence | |
| 4.3 Medium | Mollie Forms | Broken Access Control Missing Authorization to Arbitrary Post Duplication |
≤ 2.6.3 |
CVE-2024-1400 |
Wordfence | |
| 5.4 Medium | Photos and Files Contest Gallery | Cross-Site Scripting Author+ Stored Cross Site Scripting |
< 21.3.1 Fixed in 21.3.1 |
CVE-2024-1487 |
WPScan | |
| 5.4 Medium | Ultimate Posts Widget | Cross-Site Scripting Admin+ Stored XSS |
< 2.3.1 Fixed in 2.3.1 |
CVE-2024-0561 |
WPScan | |
| 6.5 Medium | Formidable Registration | Privilege Escalation Contributor+ Arbitrary User Password Reset To Account Takeover |
< 2.12 Fixed in 2.12 |
CVE-2024-1290 |
WPScan | |
| 4.3 Medium | Paid Memberships Pro | Information Disclosure Contributor+ Arbitrary User Custom Field Disclosure |
< 2.12.9 Fixed in 2.12.9 |
CVE-2024-1279 |
WPScan | |
| 4.9 Medium | Login as User or Customer | Privilege Escalation Admin Account Takeover |
≤ 3.8 |
CVE-2023-7247 |
WPScan | |
| 6.1 Medium | Starbox | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 3.5.0 Fixed in 3.5.0 |
CVE-2024-1273 |
WPScan | |
| 6.5 Medium | Enhanced Text Widget | Cross-Site Scripting Admin+ Stored XSS No login needed |
< 1.6.6 Fixed in 1.6.6 |
CVE-2024-0559 |
WPScan | |
| 5.3 Medium | Seriously Simple Podcasting | Information Disclosure Unauthenticated Administrator Email Disclosure No login needed |
< 3.0.0 Fixed in 3.0.0 |
CVE-2023-6444 |
WPScan | |
| 4.3 Medium | Colibri Page Builder | Broken Access Control Missing Authorization |
≤ 1.0.260 |
CVE-2024-1870 |
Wordfence | |
| 6.4 Medium | Blocksy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.26 |
CVE-2024-1767 |
Wordfence | |
| 5.4 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 3.4.3 |
CVE-2024-1125 |
Wordfence | |
| 6.5 Medium | EventPrime – Events Calendar, Bookings and Tickets | Cross-Site Scripting Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 3.4.3 |
CVE-2024-1320 |
Wordfence | |
| 6.5 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite |
≤ 3.4.2 |
CVE-2024-1123 |
Wordfence | |
| 4.3 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
≤ 3.4.3 |
CVE-2024-1124 |
Wordfence | |
| 4.3 Medium | affiliate-toolkit – WordPress Affiliate | Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_import_product |
≤ 3.5.4 |
CVE-2024-2298 |
Wordfence | |
| 6.3 Medium | affiliate-toolkit – WordPress Affiliate | Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list |
≤ 3.5.4 |
CVE-2024-1851 |
Wordfence | |
| 6.4 Medium | WP-Members Membership | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.4.9.1 |
CVE-2024-1987 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block |
≤ 3.9.10 |
CVE-2024-1802 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes |
≤ 1.8.3 |
CVE-2024-2127 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget |
≤ 3.9.10 |
CVE-2024-2128 |
Wordfence | |
| 6.4 Medium | Booster for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde |
≤ 7.1.7 |
CVE-2024-1534 |
Wordfence | |
| 6.4 Medium | WPKoi Templates for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget |
≤ 2.5.6 |
CVE-2024-2136 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget |
≤ 5.4.0 |
CVE-2024-1419 |
Wordfence | |
| 6.4 Medium | Prime Slider – Addons For Elementor | Cross-Site Scripting Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget |
≤ 3.13.1 |
CVE-2024-1506 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget |
≤ 3.10.3 |
CVE-2024-1377 |
Wordfence | |
| 4.7 Medium | User Registration – Custom Registration Form, Login Form, and User Profile | Cross-Site Scripting Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting No login needed |
≤ 3.1.4 |
CVE-2024-1720 |
Wordfence | |
| 5.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget |
≤ 1.3.91 |
CVE-2024-1500 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget |
≤ 3.10.3 |
CVE-2024-1366 |
Wordfence | |
| 6.4 Medium | WP Chat App | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes |
≤ 3.6.1 |
CVE-2024-1761 |
Wordfence | |
| 6.4 Medium | Social Sharing Plugin – Sassy Social Share | Cross-Site Scripting Sassy Social Share <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.3.58 |
CVE-2024-1989 |
Wordfence | |
| 4.3 Medium | Total | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sections Update |
≤ 2.1.59 |
CVE-2024-1771 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Reset No login needed |
≤ 1.6.6.20 |
CVE-2024-1760 |
Wordfence | |
| 5.3 Medium | JM Twitter Cards | Information Disclosure Information Exposure via Meta Description No login needed |
≤ 14 |
CVE-2024-1769 |
Wordfence | |
| 5.3 Medium | Change Memory Limit | Broken Access Control Missing Authorization via admin_logic() No login needed |
≤ 1.0 |
CVE-2024-1093 |
Wordfence | |
| 6.5 Medium | Page Builder Sandwich – Front End WordPress Page Builder | Information Disclosure Front End WordPress Page Builder Plugin <= 5.1.0 - Sensitive Information Exposure |
≤ 5.1.0 |
CVE-2024-1381 |
Wordfence | |
| 5.3 Medium | Password Protected Store for WooCommerce | Information Disclosure Information Exposure via REST API No login needed |
≤ 2.2 |
CVE-2024-1088 |
Wordfence | |
| 6.5 Medium | Page Builder Sandwich | Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Post Editing |
≤ 5.1.0 |
CVE-2024-1285 |
Wordfence | |
| 5.3 Medium | Build & Control Block Patterns – Boost up Gutenberg Editor | Broken Access Control Boost up Gutenberg Editor <= 1.3.5.4 - Missing Authorization No login needed |
≤ 1.3.5.4 |
CVE-2024-1095 |
Wordfence | |
| 6.4 Medium | Easy!Appointments | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-0698 |
Wordfence | |
| 6.1 Medium | Blue Triad EZAnalytics | Cross-Site Scripting Reflected Cross-Site Scripting via 'bt_webid' No login needed |
≤ 1.0 |
CVE-2024-1782 |
Wordfence | |
| 5.3 Medium | Maintenance Mode | Information Disclosure Information Exposure No login needed |
≤ 3.0.1 |
CVE-2024-1478 |
Wordfence | |
| 5.3 Medium | SportsPress – Sports Club & League Manager | Broken Access Control Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update No login needed |
≤ 2.7.17 |
CVE-2024-1178 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.