WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 151–200 of 217 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Cross-Site Scripting |
≤ 1.6.4 Fixed in 2.0.0 |
CVE-2024-43342 |
Patchstack | |
| 6.4 Medium | Gutenberg Blocks, Page Builder – ComboBlocks | Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block |
≤ 2.2.84 |
CVE-2024-7588 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets |
≤ 5.7.2 |
CVE-2024-7247 |
Wordfence | |
| 6.5 Medium | ComboBlocks | Cross-Site Scripting |
≤ 2.2.86 Fixed in 2.2.87 |
CVE-2024-43155 |
Patchstack | |
| 6.5 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Path Traversal Authenticated (Contributor+) Arbitrary File Read |
≤ 5.7.2 |
CVE-2024-4359 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag |
≤ 5.7.6 |
CVE-2024-4360 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-4643 |
Wordfence | |
| 6.5 Medium | Filter & Grids | Cross-Site Scripting |
≤ 2.9.2 Fixed in 2.9.3 |
CVE-2024-39665 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget |
≤ 2.2.85 |
CVE-2024-6346 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid widget |
≤ 1.62.2 |
CVE-2024-5901 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget |
≤ 1.3.980 |
CVE-2024-5818 |
Wordfence | |
| 6.4 Medium | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | Cross-Site Scripting Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload |
≤ 1.26.6 |
CVE-2024-6848 |
Wordfence | |
| 6.5 Medium | FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross-Site Scripting |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-38686 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.5 |
CVE-2024-5555 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-5554 |
Wordfence | |
| 6.4 Medium | Premium Portfolio Features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios' |
≤ 2.3.2 |
CVE-2024-3587 |
Wordfence | |
| 6.8 Medium | Image Photo Gallery Final Tiles Grid | Cross-Site Scripting Contributor+ Stored XSS |
< 3.6.0 Fixed in 3.6.0 |
CVE-2024-3710 |
WPScan | |
| 4.3 Medium | ProfileGrid | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference |
≤ 5.8.9 |
CVE-2024-6410 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid |
≤ 8.3.7 |
CVE-2024-3639 |
Wordfence | |
| 6.4 Medium | The Post Grid | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag |
≤ 7.7.1 |
CVE-2024-1427 |
Wordfence | |
| 6.4 Medium | Ultimate Post Kit Addons for Elementor | Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget |
≤ 3.11.7 |
CVE-2024-5662 |
Wordfence | |
| 6.4 Medium | Orbit Fox by ThemeIsle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets |
≤ 2.10.34 |
CVE-2024-2484 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control |
≤ 5.6.6 Fixed in 5.6.7 |
CVE-2023-52117 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events |
≤ 5.6.11 |
CVE-2024-3925 |
Wordfence | |
| 6.5 Medium | The Post Grid | Cross-Site Scripting |
≤ 7.7.1 Fixed in 7.7.2 |
CVE-2024-35739 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute |
≤ 2.2.80 |
CVE-2024-4042 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-1988 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control Missing Authorization |
≤ 5.8.6 |
CVE-2024-5453 |
Wordfence | |
| 6.5 Medium | Post Grid Elementor Addon | Cross-Site Scripting |
≤ 2.0.16 Fixed in 2.0.17 |
CVE-2024-34789 |
Patchstack | |
| 6.4 Medium | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | Cross-Site Scripting PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 4.1.1 |
CVE-2024-5223 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode |
≤ 3.9.1 |
CVE-2024-4043 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes |
≤ 5.6.1 |
CVE-2024-3926 |
Wordfence | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Other Form Submission Admin Email Bypass No login needed |
≤ 5.6.3 |
CVE-2024-3927 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-3155 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Other Group Members Limit Bypass |
≤ 5.8.2 Fixed in 5.8.3 |
CVE-2024-32774 |
Patchstack | |
| 6.4 Medium | Visual Portfolio, Photo Gallery & Post Grid | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter |
≤ 3.3.2 |
CVE-2024-4363 |
Wordfence | |
| 6.4 Medium | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter |
≤ 3.7.1 |
CVE-2024-4446 |
Wordfence | |
| 5.3 Medium | Post Grid Master | Broken Access Control No login needed |
≤ 3.4.7 Fixed in 3.4.8 |
CVE-2024-34372 |
Patchstack | |
| 6.5 Medium | Post Grid Master | Cross-Site Scripting Auth. Cross Site Scripting (XSS) |
≤ 3.4.8 |
CVE-2024-34390 |
Patchstack | |
| 4.3 Medium | The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | Broken Access Control Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization |
≤ 7.6.1 |
CVE-2024-3936 |
Wordfence | |
| 4.3 Medium | ProfileGrid – User Profiles, Memberships, Groups and Communities | Broken Access Control User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization |
≤ 5.8.3 |
CVE-2024-3606 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget |
≤ 2.4.9 |
CVE-2024-3308 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes |
≤ 1.3.971 |
CVE-2024-3675 |
Wordfence | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid |
≤ 2.6.9.2 |
CVE-2024-2503 |
Wordfence | |
| 6.4 Medium | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Post Overlay |
≤ 3.7.0 |
CVE-2024-3929 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-32772 |
Patchstack | |
| 5.4 Medium | ProfileGrid | Broken Access Control Insecure Direct Object Reference (IDOR) |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-32808 |
Patchstack | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget |
≤ 5.6.0 |
CVE-2024-1429 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget |
≤ 5.6.0 |
CVE-2024-1426 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Cross-Site Request Forgery User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - Cross Site Request Forgery (CSRF) No login needed |
≤ 5.7.8 Fixed in 5.7.9 |
CVE-2024-31362 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.