WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–168 of 168 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Responsive Contact Form Builder & Lead Generation Plugin lead-form-builder Broken Access Control Missing Authorization No login needed ≤ 1.8.9 CVE-2024-1416 Wordfence
5.4 Medium Ovic Responsive WPBakery Plugin ovic-vc-addon Broken Access Control ≤ 1.3.0 CVE-2024-32142 Patchstack
5.4 Medium Responsive Tabs Plugin responsive-tabs Cross-Site Scripting Contributor+ Stored XSS < 4.0.7 Fixed in 4.0.7 CVE-2024-1846 WPScan
6.4 Medium Slider, Gallery, and Carousel by MetaSlider – Responsive WordPress Slideshows Plugin ml-slider Cross-Site Scripting Responsive WordPress Slideshows <= 3.70.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via metaslider Shortcode ≤ 3.70.0 CVE-2024-3285 Wordfence
6.1 Medium Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS No login needed < 2.3.11 Fixed in 2.3.11 CVE-2024-1664 WPScan
6.5 Medium Responsive flipbook Plugin wppdf Cross-Site Scripting ≤ 1.0.0 CVE-2024-30552 Patchstack
6.5 Medium Responsive Image Gallery, Gallery Album Plugin gallery-album Cross-Site Scripting Image and Video Gallery with Thumbnails plugin <= 2.0.3 - Cross Site Scripting (XSS) ≤ 2.0.3 CVE-2024-31120 Patchstack
5.4 Medium Lightbox slider – Responsive Lightbox Gallery Plugin simple-lightbox-gallery PHP Object Injection Responsive Lightbox Gallery <= 1.9.9 - Authenticated (Contributor+) PHP Object Injection ≤ 1.9.9 CVE-2024-1858 Wordfence
6.5 Medium WEN Responsive Columns Plugin wen-responsive-columns Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-27988 Patchstack
6.5 Medium WP Responsive Tabs horizontal vertical and accordion Tabs Plugin responsive-horizontal-vertical-and-accordion-tabs Cross-Site Scripting ≤ 1.1.17 Fixed in 1.1.18 CVE-2024-27989 Patchstack
5.4 Medium Responsive Pricing Table Plugin dk-pricr-responsive-pricing-table Cross-Site Scripting Author+ Stored XSS < 5.1.11 Fixed in 5.1.11 CVE-2024-1333 WPScan
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.9.10 CVE-2024-1449 Wordfence
4.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback ≤ 3.9.9 CVE-2024-0611 Wordfence
5.4 Medium Master Slider - Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed ≤ 3.9.10 CVE-2023-6326 Wordfence
5.3 Medium Coming Soon Page & Maintenance Mode Plugin responsive-coming-soon Broken Access Control Maintenance Mode Bypass No login needed ≤ 2.2.1 CVE-2024-1136 Wordfence
4.3 Medium JTRT Responsive Tables Plugin jtrt-responsive-tables Cross-Site Request Forgery WordPress JTRT Responsive Tables Plugin <= 4.1.9 is vulnerable to Cross Site Request Forgery (CSRF) No login needed ≤ 4.1.9 CVE-2024-24802 Patchstack
6.5 Medium WP Tabs – Responsive Tabs Plugin wp-expand-tabs-free Cross-Site Scripting WordPress WP Tabs Plugin <= 2.2.0 is vulnerable to Cross Site Scripting (XSS) ≤ 2.2.0 Fixed in 2.2.1 CVE-2023-52124 Patchstack
4.3 Medium Depicter Slider – Responsive Image Slider, Video Slider & Post Slider Plugin depicter Cross-Site Request Forgery Responsive Image Slider, Video Slider & Post Slider <= 2.0.6 - Cross-Site Request Forgery via save No login needed ≤ 2.0.6 CVE-2023-6493 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only