WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 17,401–17,450 of 17,674 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 349 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium SlickNav Mobile Menu Plugin slicknav-mobile-menu Cross-Site Scripting WordPress SlickNav Mobile Menu Plugin <= 1.9.2 is vulnerable to Cross Site Scripting (XSS) ≤ 1.9.2 Fixed in 1.9.3 CVE-2023-51548 Patchstack
6.5 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Cross-Site Scripting WordPress WP User Profile Avatar Plugin <= 1.0 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0 Fixed in 1.0.1 CVE-2023-52118 Patchstack
6.5 Medium Auto Amazon Links – Amazon Associates Affiliate Plugin amazon-auto-links Cross-Site Scripting WordPress Auto Amazon Links Plugin <= 5.1.1 is vulnerable to Cross Site Scripting (XSS) ≤ 5.1.1 Fixed in 5.1.2 CVE-2023-52175 Patchstack
6.5 Medium Footer Putter Plugin footer-putter Cross-Site Scripting WordPress Footer Putter Plugin <= 1.17 is vulnerable to Cross Site Scripting (XSS) ≤ 1.17 CVE-2023-52188 Patchstack
6.5 Medium Ideal Interactive Map Plugin ideal-interactive-map Cross-Site Scripting WordPress Ideal Interactive Map Plugin <= 1.2.4 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.4 CVE-2023-52189 Patchstack
6.5 Medium Infogram – Add charts, maps and infographics Plugin infogram Cross-Site Scripting WordPress Infogram Plugin <= 1.6.1 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.1 CVE-2023-52191 Patchstack
6.5 Medium Keap Official Opt-in Forms Plugin infusionsoft-official-opt-in-forms Cross-Site Scripting WordPress Keap Official Opt-in Forms Plugin <= 1.0.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2023-52192 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting WordPress Page Builder: Live Composer Plugin <= 1.5.23 is vulnerable to Cross Site Scripting (XSS) ≤ 1.5.23 Fixed in 1.5.24 CVE-2023-52193 Patchstack
6.5 Medium oEmbed Gist Plugin oembed-gist Cross-Site Scripting WordPress oEmbed Gist Plugin <= 4.9.1 is vulnerable to Cross Site Scripting (XSS) ≤ 4.9.1 CVE-2023-52194 Patchstack
6.5 Medium Kerry James Plugin posts-to-page Cross-Site Scripting WordPress Posts to Page Plugin <= 1.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7 CVE-2023-52195 Patchstack
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_read() No login needed ≤ 8.5.6 CVE-2024-1130 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via set_starred() No login needed ≤ 8.5.6 CVE-2024-1129 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Broken Access Control Ultimate Form Builder – Contact forms and much more <= 8.5.6 - Missing Authorization via restore_records() No login needed ≤ 8.5.6 CVE-2024-0907 Wordfence
6.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2023.10 CVE-2023-7069 Wordfence
6.5 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting WordPress Schema & Structured Data for WP & AMP Plugin <= 1.25 is vulnerable to Cross Site Scripting (XSS) ≤ 1.25 Fixed in 1.26 CVE-2024-22146 Patchstack
5.9 Medium Stock Locations for WooCommerce Plugin stock-locations-for-woocommerce Cross-Site Scripting WordPress Stock Locations for WooCommerce Plugin <= 2.5.9 is vulnerable to Cross Site Scripting (XSS) ≤ 2.5.9 Fixed in 2.6.0 CVE-2024-22153 Patchstack
6.5 Medium Portfolio & Image Gallery for WordPress | PowerFolio Plugin portfolio-elementor Cross-Site Scripting WordPress Post Grid, Image Gallery & Portfolio for Elementor | PowerFolio Plugin <= 3.1 is vulnerable to Cross Site Scripting (XSS) ≤ 3.1 Fixed in 3.1.1 CVE-2024-22150 Patchstack
6.5 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Cross-Site Scripting WordPress PeepSo Core: Photos Plugin < 6.3.1.0 is vulnerable to Cross Site Scripting (XSS) < 6.3.1.0 Fixed in 6.3.1.0 CVE-2024-22158 Patchstack
5.9 Medium HD Quiz Plugin hd-quiz Cross-Site Scripting WordPress HD Quiz Plugin <= 1.8.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.8.11 Fixed in 1.8.12 CVE-2024-22161 Patchstack
6.5 Medium WP To Do Plugin wp-todo Cross-Site Scripting WordPress WP To Do Plugin <= 1.2.8 is vulnerable to Cross Site Scripting (XSS) ≤ 1.2.8 CVE-2024-22292 Patchstack
5.9 Medium Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Scripting WordPress Robo Gallery Plugin <= 3.2.17 is vulnerable to Cross Site Scripting (XSS) ≤ 3.2.17 Fixed in 3.2.18 CVE-2024-22295 Patchstack
6.5 Medium CBX Map for Google Map & OpenStreetMap Plugin cbxgooglemap Cross-Site Scripting WordPress CBX Map for Google Map & OpenStreetMap Plugin <= 1.1.11 is vulnerable to Cross Site Scripting (XSS) ≤ 1.1.11 CVE-2024-22297 Patchstack
6.5 Medium Albo Pretorio On line Plugin albo-pretorio-on-line Cross-Site Scripting WordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Cross Site Scripting (XSS) ≤ 4.6.6 CVE-2024-22302 Patchstack
5.9 Medium Mang Board WP Plugin mangboard Cross-Site Scripting WordPress Mang Board WP Plugin <= 1.7.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.7.7 CVE-2024-22306 Patchstack
6.5 Medium Formzu WP Plugin formzu-wp Cross-Site Scripting WordPress Formzu WP Plugin <= 1.6.7 is vulnerable to Cross Site Scripting (XSS) ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-22310 Patchstack
6.5 Medium Posts List Designer by Category – List Category Posts Or Recent Posts Plugin post-list-designer Cross-Site Scripting List Category Posts Or Recent Posts Plugin <= 3.3.2 is vulnerable to Cross Site Scripting (XSS) ≤ 3.3.2 CVE-2024-23502 Patchstack
6.5 Medium PDF Viewer & 3D PDF Flipbook – DearPDF Plugin dearpdf-lite Cross-Site Scripting DearPDF Plugin <= 2.0.38 is vulnerable to Cross Site Scripting (XSS) ≤ 2.0.38 CVE-2024-23505 Patchstack
4.3 Medium Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder Plugin droit-elementor-addons Cross-Site Request Forgery WordPress Droit Elementor Addons Plugin <= 3.1.5 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.5 CVE-2024-22136 Patchstack
5.4 Medium WP Spell Check Plugin wp-spell-check Cross-Site Request Forgery WordPress WP Spell Check Plugin <= 9.17 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 9.17 Fixed in 9.18 CVE-2024-22143 Patchstack
5.4 Medium Frontpage Manager Plugin frontpage-manager Cross-Site Request Forgery WordPress Frontpage Manager Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2024-22285 Patchstack
4.3 Medium Browser Theme Color Plugin browser-theme-color Cross-Site Request Forgery WordPress Browser Theme Color Plugin <= 1.3 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 1.3 CVE-2024-22291 Patchstack
5.4 Medium FreshMail Plugin freshmail-integration Cross-Site Request Forgery WordPress FreshMail For WordPress Plugin <= 2.3.2 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 2.3.2 CVE-2024-22304 Patchstack
4.3 Medium WordPress Review & Structure Data Schema Plugin – Review Schema Plugin review-schema Broken Access Control Review Schema <= 2.1.14 - Missing Authorization to Arbitrary Review Update ≤ 2.1.14 CVE-2024-0836 Wordfence
6.4 Medium UserPro - Community and User Profile Plugin Cross-Site Scripting The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up to, and including, 5.1.5 due to insufficient input sanitiz… 5.1.5 CVE-2023-2439 Wordfence
6.4 Medium MapPress Plugin mappress-google-maps-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Map Settings ≤ 2.88.16 CVE-2023-7225 Wordfence
4.8 Medium Restrict Usernames Emails Characters Plugin restrict-usernames-emails-characters Cross-Site Scripting Admin+ Stored XSS < 3.1.4 Fixed in 3.1.4 CVE-2023-6165 WPScan
6.1 Medium EventON Plugin eventon-lite Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 4.4.1 Fixed in 4.4.1 CVE-2023-7200 WPScan
5.4 Medium WP Plugin Lister Plugin Cross-Site Scripting Settings Update to Stored XSS via CSRF No login needed ≤ 2.1.0 CVE-2023-6503 WPScan
4.8 Medium Wp-Adv-Quiz Plugin advanced-quiz Cross-Site Scripting Admin+ Stored XSS < 1.0.3 Fixed in 1.0.3 CVE-2023-5943 WPScan
5.4 Medium Easy SVG Allow Plugin Cross-Site Scripting Author+ Stored XSS via SVG ≤ 1.0 CVE-2023-7089 WPScan
5.4 Medium TJ Shortcodes Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcodes ≤ 0.1.3 CVE-2023-6530 WPScan
4.8 Medium PageLayer Plugin Cross-Site Scripting Author+ Stored XSS 1.3.2 – < 1.8.0 Fixed in 1.8.0 CVE-2023-5124 WPScan
4.8 Medium Wp-Adv-Quiz Plugin advanced-quiz Cross-Site Scripting Admin+ Stored XSS in Quiz Overview ≤ 1.0.2 CVE-2023-5956 WPScan
5.3 Medium Relevanssi (Free Plugin Information Disclosure Unauthenticated Private/Draft Post Disclosure No login needed < 4.22.0, < 2.25.0 Fixed in 4.22.0 CVE-2023-7199 WPScan
4.3 Medium Site Notes Plugin Cross-Site Request Forgery Admin Note Deletion via CSRF No login needed ≤ 2.0.0 CVE-2023-6633 WPScan
6.1 Medium WordPress Toolbar Plugin Open Redirect No login needed ≤ 2.2.6 CVE-2023-6389 WPScan
6.1 Medium Biteship for WooCommerce Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed < 2.2.25 Fixed in 2.2.25 CVE-2023-6278 WPScan
4.4 Medium Fluent Forms Plugin fluentform Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via imported form title ≤ 5.1.5 CVE-2024-0618 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Link Anything ≤ 2.6.8 CVE-2024-0824 Wordfence
6.5 Medium Backuply – Backup, Restore, Migrate and Clone Plugin backuply Path Traversal Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal ≤ 1.2.3 CVE-2024-0697 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only