WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 18,701–18,750 of 29,694 vulnerabilities

Known WordPress vulnerabilities, page 375 of 594
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Modal Window Plugin modal-window Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via iframeBox Shortcode ≤ 6.1.5 CVE-2025-0897 Wordfence
6.4 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via xoo_el_action Shortcode ≤ 2.8.5 CVE-2025-1064 Wordfence
7.2 High WPMobile.App Plugin wpappninja Open Redirect Open Redirect via 'redirect' Parameter No login needed ≤ 11.56 CVE-2024-13888 Wordfence
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Transparent Split Hero Widget ≤ 1.5.140 CVE-2024-13155 Wordfence
6.4 Medium Elementor Website Builder – More Than Just a Page Builder Plugin elementor Cross-Site Scripting More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.27.4 CVE-2024-13445 Wordfence
7.5 High Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection Worldwide Express Edition <= 5.2.18 - Unauthenticated SQL Injection No login needed ≤ 5.2.18 CVE-2024-13534 Wordfence
7.5 High Small Package Quotes – USPS Edition Plugin small-package-quotes-usps-edition SQL Injection USPS Edition <= 1.3.5 - Unauthenticated SQL Injection No login needed ≤ 1.3.5 CVE-2024-13533 Wordfence
7.5 High Small Package Quotes – For Customers of FedEx Plugin small-package-quotes-fedex-edition SQL Injection For Customers of FedEx <= 4.3.1 - Unauthenticated SQL Injection No login needed ≤ 4.3.1 CVE-2024-13491 Wordfence
7.5 High LTL Freight Quotes – SAIA Edition Plugin ltl-freight-quotes-saia-edition SQL Injection SAIA Edition <= 2.2.10 - Unauthenticated SQL Injection No login needed ≤ 2.2.10 CVE-2024-13483 Wordfence
7.5 High LTL Freight Quotes – ABF Freight Edition Plugin ltl-freight-quotes-abf-freight-edition SQL Injection ABF Freight Edition <= 3.3.7 - Unauthenticated SQL Injection No login needed ≤ 3.3.7 CVE-2024-13485 Wordfence
7.5 High LTL Freight Quotes – R+L Carriers Edition Plugin ltl-freight-quotes-rl-edition SQL Injection R+L Carriers Edition <= 3.3.4 - Unauthenticated SQL Injection No login needed ≤ 3.3.4 CVE-2024-13481 Wordfence
5.3 Medium ElementsKit Elementor addons Plugin elementskit-lite Information Disclosure Unauthenticated Information Exposure via get_megamenu_content Function No login needed ≤ 3.4.0 CVE-2025-0968 Wordfence
7.5 High LTL Freight Quotes – SEFL Edition Plugin ltl-freight-quotes-sefl-edition SQL Injection SEFL Edition <= 3.2.4 - Unauthenticated SQL Injection No login needed ≤ 3.2.4 CVE-2024-13479 Wordfence
7.5 High LTL Freight Quotes – TForce Edition Plugin ltl-freight-quotes-ups-edition SQL Injection TForce Edition <= 3.6.4 - Unauthenticated SQL Injection No login needed ≤ 3.6.4 CVE-2024-13478 Wordfence
7.2 High YaySMTP Plugin yaysmtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed 2.4.9 – 2.6.2 CVE-2025-0916 Wordfence
7.5 High LTL Freight Quotes – Old Dominion Edition Plugin SQL Injection Old Dominion Edition <= 4.2.10 - Unauthenticated SQL Injection No login needed ≤ 4.2.10 CVE-2024-13489 Wordfence
6.1 Medium Raptive Ads Plugin adthrive-ads Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.6.3 CVE-2024-13363 Wordfence
5.3 Medium Raptive Ads Plugin adthrive-ads Broken Access Control Missing Authorization to Unauthenticated Data/Settings Reset No login needed ≤ 3.6.3 CVE-2024-13364 Wordfence
6.1 Medium DeBounce Email Validator Plugin debounce-io-email-validator Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 5.8.0 CVE-2024-13339 Wordfence
4.3 Medium Disable Auto Updates Plugin disable-auto-updates Cross-Site Request Forgery Cross-Site Request Forgery to Auto-update Disable No login needed ≤ 1.4 CVE-2024-13336 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.4 Medium Widget BUY.BOX Plugin buybox-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.5 CVE-2024-13679 Wordfence
4.3 Medium Apptivo Business Site CRM Plugin apptivo-business-site Cross-Site Request Forgery Cross-Site Request Forgery to IP Address Block No login needed ≤ 5.3 CVE-2024-13405 Wordfence
7.5 High Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2024-13592 Wordfence
7.5 High Trash Duplicate and 301 Redirect Plugin trash-duplicate-and-301-redirect Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 1.9 CVE-2024-13468 Wordfence
6.1 Medium Pure Chat – Live Chat & More! Plugin pure-chat Cross-Site Scripting Live Chat & More! <= 2.4 - Reflected Cross-Site Scripting via purechatWidgetName Parameter No login needed ≤ 2.4 CVE-2024-13736 Wordfence
6.4 Medium Store Locator Widget Plugin store-locator-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2025r1 CVE-2024-13657 Wordfence
6.4 Medium Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-13591 Wordfence
6.5 Medium Categorized Gallery Plugin categorized-gallery SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.0 CVE-2024-13676 Wordfence
6.4 Medium UMich OIDC Login Plugin umich-oidc-login Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.0 CVE-2024-11753 Wordfence
6.4 Medium WP Wiki Tooltip Plugin wp-wiki-tooltip Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 CVE-2024-13462 Wordfence
6.4 Medium CanadaHelps Embedded Donation Plugin embedded-cdn Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2024-11778 Wordfence
6.4 Medium UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included Plugin ultraembed-advanced-iframe Cross-Site Scripting Advanced Iframe Plugin For WordPress with Gutenberg Block Included <= 1.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11335 Wordfence
6.4 Medium Responsive Flickr Slideshow Plugin mobile-friendly-flickr-slideshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13660 Wordfence
6.1 Medium Digihood HTML Sitemap Plugin wedesin-html-sitemap Cross-Site Scripting Reflected Cross-Site Scripting via 'channel' No login needed ≤ 3.1.1 CVE-2024-12339 Wordfence
6.4 Medium Cosmic Blocks (40+) Content Editor Blocks Collection Plugin cosmic-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.0 CVE-2024-13674 Wordfence
6.1 Medium Lexicata Plugin lexicata Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.16 CVE-2024-12069 Wordfence
4.3 Medium Education Addon for Elementor Plugin education-addon Broken Access Control Authenticated (Contributor+) Insecure Direct Object Reference via naedu_elementor_template Shortcode ≤ 1.3.1 CVE-2024-13854 Wordfence
6.1 Medium Pollin Plugin pollin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.01.1 CVE-2024-13711 Wordfence
6.4 Medium Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily Plugin yayforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-12522 Wordfence
5.3 Medium PeproDev Ultimate Invoice Plugin pepro-ultimate-invoice Broken Access Control Insecure Direct Object Reference to Unauthenticated Order Information Exposure No login needed ≤ 2.0.9 CVE-2024-13719 Wordfence
6.4 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Scripting Custom data in admin dashboard <= 1.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.1 CVE-2024-13390 Wordfence
4.9 Medium Pollin Plugin pollin SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.01.1 CVE-2024-13712 Wordfence
6.4 Medium YouTube Playlists with Schema Plugin jma-youtube-playlists-with-schema Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2024-13589 Wordfence
6.5 Medium WP Media Category Management Plugin wp-media-category-management Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed 2.0 – 2.3.3 CVE-2025-0865 Wordfence
6.4 Medium Coaching Staffs Plugin coaching-staffs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.1 CVE-2024-13663 Wordfence
3.5 Low Master Slider Plugin master-slider Cross-Site Scripting Editor+ Stored XSS < 3.10.5 Fixed in 3.10.5 CVE-2024-12173 WPScan
6.4 Medium User Private Files – File Upload & Download Manager with Secure File Sharing Plugin user-private-files Arbitrary File Upload File Upload & Download Manager with Secure File Sharing <= 2.1.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.1.3 CVE-2024-13799 Wordfence
6.4 Medium Visualizer: Tables and Charts Manager Plugin visualizer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Import Data From File ≤ 3.11.8 CVE-2025-1065 Wordfence
6.1 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed ≤ 1.7.1007 CVE-2025-1441 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only