WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 275 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection No login needed ≤ 1.0.2 CVE-2024-55982 Patchstack
7.1 High CRUDLab Google Plus Button Plugin crudlab-google-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2024-54399 Patchstack
5.4 Medium Tithe.ly Giving Button Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1 CVE-2024-11841 WPScan
4.3 Medium Social Share Icons & Social Share Buttons Plugin ultimate-social-media-plus Broken Access Control ≤ 3.5.7 Fixed in 3.5.8 CVE-2023-38514 Patchstack
5.4 Medium Change WooCommerce Add To Cart Button Text Plugin change-woocommerce-add-to-cart-button-text Broken Access Control ≤ 1.3 CVE-2023-34376 Patchstack
4.3 Medium Social Media & Share Icons Plugin ultimate-social-media-icons Broken Access Control Broken Access Control + CSRF ≤ 2.8.1 Fixed in 2.8.2 CVE-2023-34009 Patchstack
6.5 Medium Protected Posts Logout Button Plugin protected-posts-logout-button Broken Access Control No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2023-25454 Patchstack
4.3 Medium WP Like Button Plugin wp-like-button Broken Access Control ≤ 1.7.0 CVE-2023-47820 Patchstack
5.3 Medium Button Generator – easily Button Builder Plugin button-generation Broken Access Control easily Button Builder plugin <= 2.3.8 - Broken Access Control No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2023-49154 Patchstack
6.1 Medium Pulsating Chat Button Plugin amin-chat-button Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.4.1 CVE-2024-11813 Wordfence
5.9 Medium Add Chat App Button Plugin add-whatsapp-button Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.8 CVE-2024-52489 Patchstack
7.1 High Google Plus Share and +1 Button Plugin google-plus-share-and-plusone-button Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-53723 Patchstack
6.5 Medium 소셜 공유 버튼 By 코스모스팜 Plugin cosmosfarm-share-buttons Cross-Site Scripting ≤ 1.9 CVE-2024-53745 Patchstack
6.5 Medium Elementor Button Plus Plugin fd-elementor-button-plus Cross-Site Scripting ≤ 1.3.9 CVE-2024-53746 Patchstack
6.4 Medium Spotify Play Button Plugin spotify-play-button-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spotifyplaybutton Shortcode ≤ 2.11 CVE-2024-11192 Wordfence
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
6.4 Medium Twitter Follow Button Plugin twitter-follow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter ≤ 0.2 CVE-2024-10116 Wordfence
4.3 Medium Button Block – Get fully customizable & multi-functional buttons Plugin button-block Information Disclosure Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.1.4 CVE-2024-10671 Wordfence
6.5 Medium Social button Plugin social-button Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2024-51866 Patchstack
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
6.1 Medium Razorpay Payment Button for Elementor Plugin razorpay-payment-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-10850 Wordfence
6.1 Medium Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-10851 Wordfence
8.5 High Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection ≤ 1.0.2 CVE-2024-51845 Patchstack
6.4 Medium Active Products Tables for WooCommerce. Use constructor to create tables Plugin profit-products-tables-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woot_button Shortcode ≤ 1.0.6.4 CVE-2024-10168 Wordfence
9.8 Critical Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery SQL Injection Upload, Vote, Sell via PayPal, Social Share Buttons <= 24.0.3 - Unauthenticated SQL Injection No login needed ≤ 24.0.3 CVE-2024-10687 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget ≤ 2.8.4.2 CVE-2024-9505 Wordfence
5.9 Medium Button contact VR Plugin button-contact-vr Cross-Site Scripting ≤ 4.7.9.1 Fixed in 4.7.10 CVE-2024-50414 Patchstack
6.4 Medium Bamazoo – Button Generator Plugin bamazoo-button-generator Cross-Site Scripting Button Generator <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via dgs Shortcode ≤ 1.0 CVE-2024-10150 Wordfence
6.4 Medium Awesome buttons Plugin wp-awesome-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via btn2 Shortcode ≤ 1.0 CVE-2024-10148 Wordfence
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
6.4 Medium Flat UI Button Plugin flat-ui-button Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via flatbtn Shortcode 1.0 CVE-2024-10014 Wordfence
6.5 Medium Custom Add to Cart Button Label and Link Plugin woo-custom-cart-button Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-49296 Patchstack
6.4 Medium BigBlueButton Plugin bigbluebutton Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.0.0-beta.4 CVE-2023-7296 Wordfence
4.3 Medium Read more By Adam Plugin read-more Broken Access Control Missing Authorization to Authenticated (Subscriber+) Read More Button Deletion ≤ 1.1.8 CVE-2024-9187 Wordfence
6.1 Medium Easy Social Share Buttons Plugin easy-social-share-buttons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-8729 Wordfence
7.5 High Instant Chat Floating Button for WordPress Websites Plugin instant-chat-wp Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44018 Patchstack
6.4 Medium WordPress Infinite Scroll - Ajax Load More Plugin ajax-load-more Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter ≤ 7.1.2 CVE-2024-8505 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.3.6 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Group Module ≤ 2.8.3.6 CVE-2024-9049 Wordfence
6.1 Medium Beam me up Scotty – Back to Top Button Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting No login needed ≤ 1.0.21 CVE-2024-8741 Wordfence
7.1 High Like Button Rating Plugin likebtn-like-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.53 Fixed in 2.6.54 CVE-2024-44064 Patchstack
6.4 Medium Tweaker5 Theme tweaker5 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.2 CVE-2024-5870 Wordfence
6.4 Medium Neighborly Theme neighborly Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.4 CVE-2024-5869 Wordfence
6.4 Medium Delicate Theme delicate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 3.5.5 CVE-2024-5867 Wordfence
6.4 Medium Triton Lite Theme triton-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.3 CVE-2024-5789 Wordfence
6.4 Medium Avada | Website Builder For WordPress & eCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode ≤ 3.11.9 CVE-2024-5628 Wordfence
4.8 Medium Floating Contact Button Plugin floating-contact Cross-Site Scripting Admin+ Stored XSS < 2.8 Fixed in 2.8 CVE-2024-7891 WPScan
6.4 Medium Share This Image Plugin share-this-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STI Buttons Shortcode ≤ 2.02 CVE-2024-8363 Wordfence
5.3 Medium WordPress Button Plugin MaxButtons Plugin maxbuttons Information Disclosure Full Path Disclosure No login needed ≤ 9.7.8 CVE-2024-6499 Wordfence
4.7 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Open Redirect No login needed ≤ 1.9 Fixed in 1.9.1 CVE-2024-43236 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only