WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 18,701–18,750 of 29,694 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Modal Window | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via iframeBox Shortcode |
≤ 6.1.5 |
CVE-2025-0897 |
Wordfence | |
| 6.4 Medium | Login/Signup Popup ( Inline Form + Woocommerce ) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode |
≤ 2.8.5 |
CVE-2025-1064 |
Wordfence | |
| 7.2 High | WPMobile.App | Open Redirect Open Redirect via 'redirect' Parameter No login needed |
≤ 11.56 |
CVE-2024-13888 |
Wordfence | |
| 6.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget |
≤ 1.5.140 |
CVE-2024-13155 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder – More Than Just a Page Builder | Cross-Site Scripting More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.27.4 |
CVE-2024-13445 |
Wordfence | |
| 7.5 High | Small Package Quotes – Worldwide Express Edition | SQL Injection Worldwide Express Edition <= 5.2.18 - Unauthenticated SQL Injection No login needed |
≤ 5.2.18 |
CVE-2024-13534 |
Wordfence | |
| 7.5 High | Small Package Quotes – USPS Edition | SQL Injection USPS Edition <= 1.3.5 - Unauthenticated SQL Injection No login needed |
≤ 1.3.5 |
CVE-2024-13533 |
Wordfence | |
| 7.5 High | Small Package Quotes – For Customers of FedEx | SQL Injection For Customers of FedEx <= 4.3.1 - Unauthenticated SQL Injection No login needed |
≤ 4.3.1 |
CVE-2024-13491 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – SAIA Edition | SQL Injection SAIA Edition <= 2.2.10 - Unauthenticated SQL Injection No login needed |
≤ 2.2.10 |
CVE-2024-13483 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – ABF Freight Edition | SQL Injection ABF Freight Edition <= 3.3.7 - Unauthenticated SQL Injection No login needed |
≤ 3.3.7 |
CVE-2024-13485 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – R+L Carriers Edition | SQL Injection R+L Carriers Edition <= 3.3.4 - Unauthenticated SQL Injection No login needed |
≤ 3.3.4 |
CVE-2024-13481 |
Wordfence | |
| 5.3 Medium | ElementsKit Elementor addons | Information Disclosure Unauthenticated Information Exposure via get_megamenu_content Function No login needed |
≤ 3.4.0 |
CVE-2025-0968 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – SEFL Edition | SQL Injection SEFL Edition <= 3.2.4 - Unauthenticated SQL Injection No login needed |
≤ 3.2.4 |
CVE-2024-13479 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – TForce Edition | SQL Injection TForce Edition <= 3.6.4 - Unauthenticated SQL Injection No login needed |
≤ 3.6.4 |
CVE-2024-13478 |
Wordfence | |
| 7.2 High | YaySMTP | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
2.4.9 – 2.6.2 |
CVE-2025-0916 |
Wordfence | |
| 7.5 High | LTL Freight Quotes – Old Dominion Edition | SQL Injection Old Dominion Edition <= 4.2.10 - Unauthenticated SQL Injection No login needed |
≤ 4.2.10 |
CVE-2024-13489 |
Wordfence | |
| 6.1 Medium | Raptive Ads | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.6.3 |
CVE-2024-13363 |
Wordfence | |
| 5.3 Medium | Raptive Ads | Broken Access Control Missing Authorization to Unauthenticated Data/Settings Reset No login needed |
≤ 3.6.3 |
CVE-2024-13364 |
Wordfence | |
| 6.1 Medium | DeBounce Email Validator | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 5.8.0 |
CVE-2024-13339 |
Wordfence | |
| 4.3 Medium | Disable Auto Updates | Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed |
≤ 1.4 |
CVE-2024-13336 |
Wordfence | |
| 5.3 Medium | WordPress Portfolio Builder – Portfolio Gallery | Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed |
≤ 1.1.7 |
CVE-2024-13231 |
Wordfence | |
| 6.4 Medium | Widget BUY.BOX | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.1.5 |
CVE-2024-13679 |
Wordfence | |
| 4.3 Medium | Apptivo Business Site CRM | Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed |
≤ 5.3 |
CVE-2024-13405 |
Wordfence | |
| 7.5 High | Team Builder For WPBakery Page Builder(Formerly Visual Composer) | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.0 |
CVE-2024-13592 |
Wordfence | |
| 7.5 High | Trash Duplicate and 301 Redirect | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 1.9 |
CVE-2024-13468 |
Wordfence | |
| 6.1 Medium | Pure Chat – Live Chat & More! | Cross-Site Scripting Live Chat & More! <= 2.4 - Reflected Cross-Site Scripting via purechatWidgetName Parameter No login needed |
≤ 2.4 |
CVE-2024-13736 |
Wordfence | |
| 6.4 Medium | Store Locator Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2025r1 |
CVE-2024-13657 |
Wordfence | |
| 6.4 Medium | Team Builder For WPBakery Page Builder(Formerly Visual Composer) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2024-13591 |
Wordfence | |
| 6.5 Medium | Categorized Gallery | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 2.0 |
CVE-2024-13676 |
Wordfence | |
| 6.4 Medium | UMich OIDC Login | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.0 |
CVE-2024-11753 |
Wordfence | |
| 6.4 Medium | WP Wiki Tooltip | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.2 |
CVE-2024-13462 |
Wordfence | |
| 6.4 Medium | CanadaHelps Embedded Donation | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.1 |
CVE-2024-11778 |
Wordfence | |
| 6.4 Medium | UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included | Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.3 |
CVE-2024-11335 |
Wordfence | |
| 6.4 Medium | Responsive Flickr Slideshow | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13660 |
Wordfence | |
| 6.1 Medium | Digihood HTML Sitemap | Cross-Site Scripting Reflected Cross-Site Scripting via 'channel' No login needed |
≤ 3.1.1 |
CVE-2024-12339 |
Wordfence | |
| 6.4 Medium | Cosmic Blocks (40+) Content Editor Blocks Collection | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-13674 |
Wordfence | |
| 6.1 Medium | Lexicata | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.16 |
CVE-2024-12069 |
Wordfence | |
| 4.3 Medium | Education Addon for Elementor | Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode |
≤ 1.3.1 |
CVE-2024-13854 |
Wordfence | |
| 6.1 Medium | Pollin | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.01.1 |
CVE-2024-13711 |
Wordfence | |
| 6.4 Medium | Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.1 |
CVE-2024-12522 |
Wordfence | |
| 5.3 Medium | PeproDev Ultimate Invoice | Broken Access Control Insecure Direct Object Reference to Unauthenticated Order Information Exposure No login needed |
≤ 2.0.9 |
CVE-2024-13719 |
Wordfence | |
| 6.4 Medium | ADFO – Custom data in admin dashboard | Cross-Site Scripting Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.1 |
CVE-2024-13390 |
Wordfence | |
| 4.9 Medium | Pollin | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.01.1 |
CVE-2024-13712 |
Wordfence | |
| 6.4 Medium | YouTube Playlists with Schema | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2024-13589 |
Wordfence | |
| 6.5 Medium | WP Media Category Management | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
2.0 – 2.3.3 |
CVE-2025-0865 |
Wordfence | |
| 6.4 Medium | Coaching Staffs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.1 |
CVE-2024-13663 |
Wordfence | |
| 3.5 Low | Master Slider | Cross-Site Scripting Editor+ Stored XSS |
< 3.10.5 Fixed in 3.10.5 |
CVE-2024-12173 |
WPScan | |
| 6.4 Medium | User Private Files – File Upload & Download Manager with Secure File Sharing | Arbitrary File Upload File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.1.3 |
CVE-2024-13799 |
Wordfence | |
| 6.4 Medium | Visualizer: Tables and Charts Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File |
≤ 3.11.8 |
CVE-2025-1065 |
Wordfence | |
| 6.1 Medium | Royal Elementor Addons and Templates | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.7.1007 |
CVE-2025-1441 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.