WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 17,301–17,350 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 347 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium WP-CFM Plugin wp-cfm Cross-Site Request Forgery WordPress WP-CFM Plugin <= 1.7.8 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2024-24706 Patchstack
5.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control Missing Authorization to Unauthenticated Data Export No login needed ≤ 4.0.11 CVE-2024-1109 Wordfence
5.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control Missing Authorization to Settings Import No login needed ≤ 4.0.11 CVE-2024-1110 Wordfence
5.3 Medium Quiz Maker Plugin quiz-maker Broken Access Control Missing Authorization to Unauthenticated Quiz Data Retrieval No login needed ≤ 6.5.2.4 CVE-2024-1079 Wordfence
4.3 Medium Quiz Maker Plugin quiz-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification ≤ 6.5.2.4 CVE-2024-1078 Wordfence
4.4 Medium Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) Plugin timeline-widget-addon-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.3 CVE-2024-0977 Wordfence
6.1 Medium All-In-One Security (AIOS) – Security and Firewall Plugin all-in-one-wp-security-and-firewall Cross-Site Scripting Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2024-1037 Wordfence
5.4 Medium PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.14 CVE-2024-1055 Wordfence
6.4 Medium Starbox Plugin starbox Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Display Name and Social Settings ≤ 3.4.8 CVE-2024-0256 Wordfence
6.4 Medium GeneratePress Premium Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Meta ≤ 2.3.2 CVE-2023-6807 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 6.2.8.2 CVE-2023-6557 Wordfence
5.3 Medium ARMember Plugin armember-membership Broken Access Control Improper Access Control to Sensitive Information Exposure via REST API No login needed ≤ 4.0.24 CVE-2024-0969 Wordfence
6.4 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget ≤ 2.10.27 CVE-2024-0508 Wordfence
5.3 Medium UserPro Plugin Other Disabled Membership Registration Bypass No login needed ≤ 5.1.6 CVE-2024-0701 Wordfence
6.4 Medium Advanced Custom Fields Plugin advanced-custom-fields Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 6.2.4 CVE-2023-6701 Wordfence
6.6 Medium Advanced Database Cleaner Plugin advanced-database-cleaner PHP Object Injection Authenticated(Administrator+) PHP Object Injection via process_bulk_action ≤ 3.1.3 CVE-2024-0668 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Cross-Site Request Forgery Cross-Site Request Forgery via save_view No login needed ≤ 3.2.2 CVE-2024-0373 Wordfence
5.3 Medium Getwid – Gutenberg Blocks Plugin getwid Authentication Bypass Gutenberg Blocks <= 2.0.4 - Captcha Bypass No login needed ≤ 2.0.4 CVE-2023-6963 Wordfence
4.3 Medium Starbox – the Author Box for Humans Plugin starbox Broken Access Control the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference ≤ 3.4.7 CVE-2024-0366 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping ≤ 5.9.4 CVE-2024-0586 Wordfence
6.4 Medium WordPress Button Plugin MaxButtons Plugin maxbuttons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 9.7.6 CVE-2023-7029 Wordfence
6.1 Medium Formidable Forms Plugin formidable Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.7.2 CVE-2024-0660 Wordfence
4.3 Medium WPvivid Plugin wpvivid-backuprestore Broken Access Control Missing Authorization ≤ 0.9.94 CVE-2023-4637 Wordfence
4.9 Medium PDF Generator For Fluent Forms Plugin Cross-Site Scripting ≤ 1.1.7 CVE-2023-6953 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via API No login needed ≤ 4.10.2 CVE-2024-1208 Wordfence
4.4 Medium Content Views Plugin content-views-query-and-display-post-page Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via settings ≤ 3.6.2 CVE-2024-0612 Wordfence
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 1.0.93 CVE-2023-6808 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via create_view ≤ 3.2.2 CVE-2024-0371 Wordfence
6.4 Medium Plugin for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 3.1 CVE-2023-6884 Wordfence
4.4 Medium SEO Plugin by Squirrly SEO Plugin Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings ≤ 12.3.15 CVE-2024-0597 Wordfence
4.3 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization ≤ 4.4.1 CVE-2024-1092 Wordfence
4.4 Medium WP RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source ≤ 4.23.4 CVE-2024-0630 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.7 CVE-2024-0954 Wordfence
5.3 Medium Advanced Forms for ACF Plugin advanced-forms Broken Access Control Missing Authorization to Unauthenticated Form Settings Export No login needed ≤ 1.9.3.2 CVE-2024-1121 Wordfence
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.14.3 CVE-2024-1046 Wordfence
6.5 Medium Order Delivery Date for WP e-Commerce Plugin order-delivery-date Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2024-0678 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes ≤ 9.1.0 CVE-2024-0384 Wordfence
4.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification ≤ 2.0.4 CVE-2023-6959 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via assignments No login needed ≤ 4.10.1 CVE-2024-1209 Wordfence
6.4 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.58.1 CVE-2024-0961 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insuf… 1.12.11 CVE-2024-0834 Wordfence
6.1 Medium WP 404 Auto Redirect to Similar Post Plugin wp-404-auto-redirect-to-similar-post Cross-Site Scripting Reflected Cross-Site Scripting via request No login needed ≤ 1.0.3 CVE-2024-0509 Wordfence
5.3 Medium WP Club Manager – WordPress Sports Club Plugin Broken Access Control WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update No login needed ≤ 2.2.10 CVE-2024-1177 Wordfence
5.4 Medium WOLF – WordPress Posts Bulk Editor and Manager Professional Plugin bulk-editor Cross-Site Request Forgery WordPress Posts Bulk Editor and Manager Professional <= 1.0.8.1 - Cross-Site Request Forgery No login needed ≤ 1.0.8.1 CVE-2024-0790 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via API No login needed ≤ 4.10.1 CVE-2024-1210 Wordfence
4.3 Medium Royal Elementor Kit Theme royal-elementor-kit Broken Access Control Missing Authorization to Arbitrary Transient Update ≤ 1.0.116 CVE-2024-0835 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via icon_color ≤ 9.1.0 CVE-2024-0255 Wordfence
5.3 Medium Author Box, Guest Author and Co-Authors for Your Posts – Molongui Plugin Information Disclosure Molongui <= 4.7.4 - Information Exposure via ma_debug No login needed ≤ 4.7.4 CVE-2023-7014 Wordfence
4.3 Medium Active Products Tables for WooCommerce. Professional products tables for WooCommerce store Plugin profit-products-tables-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.6.1 CVE-2024-0796 Wordfence
5.5 Medium FileBird Plugin filebird Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via Folder Import ≤ 5.6.0 CVE-2024-0691 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only