WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,001–20,050 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 401 of 589
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Header Builder Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Header Deletion No login needed ≤ 1.3.8 CVE-2024-12206 Wordfence
6.5 Medium WP Travel – Ultimate Travel Booking System, Tour Management Engine Plugin wp-travel SQL Injection Ultimate Travel Booking System, Tour Management Engine <= 10.0.0 - Authenticated (Subscriber+) SQL Injection ≤ 10.0.0 CVE-2024-12067 Wordfence
7.5 High WP Database Backup – Unlimited Database & Files Backup by Backup for WP Plugin wp-database-backup Information Disclosure Unlimited Database & Files Backup by Backup for WP <= 7.3 - Unauthenticated Database Back-Up Exposure No login needed ≤ 7.3 CVE-2024-12330 Wordfence
6.1 Medium SEMA API Plugin sema-api Cross-Site Scripting Reflected Cross-Site Scripting via catid Parameter No login needed ≤ 5.27 CVE-2024-12285 Wordfence
4.3 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Limited Settings Update ≤ 1.0.2 CVE-2024-5769 Wordfence
4.3 Medium GS Insever Portfolio Plugin gs-instagram-portfolio Broken Access Control Missing Authorization to Authenticated (Subscriber+) CSS Injection ≤ 1.4.5 CVE-2024-12249 Wordfence
6.1 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross-Site Scripting via dvsfw_bulk_label_url Parameter No login needed ≤ 2.1.7 CVE-2024-12222 Wordfence
6.4 Medium Linear Plugin linear Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.12 CVE-2024-12496 Wordfence
6.4 Medium Files Download Delay Plugin files-download-delay Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.9 CVE-2024-12493 Wordfence
4.3 Medium Newsletter2Go Plugin newsletter2go Broken Access Control Missing Authorization to Authenticated (Subscriber+) Style Reset ≤ 4.0.14 CVE-2024-12618 Wordfence
6.1 Medium ResAds Plugin resads Cross-Site Scripting Reflected Cross-Site Scripting via Multiple Parameters No login needed ≤ 2.0.6 CVE-2024-12122 Wordfence
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.135 CVE-2024-13153 Wordfence
6.1 Medium BU Section Editing Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.9.9 CVE-2024-12736 WPScan
6.1 Medium aklamator-infeed Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.0 CVE-2024-12731 WPScan
4.8 Medium aklamator-infeed Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 2.0.0 CVE-2024-12717 WPScan
6.1 Medium Asgard Security Scanner Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.7 CVE-2024-12715 WPScan
6.1 Medium Backlink Monitoring Manager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.1.3 CVE-2024-12714 WPScan
4.2 Medium PostLists Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.2 CVE-2024-10815 WPScan
6.1 Medium Shipping via Planzer for WooCommerce Plugin wc-planzer-shipping Cross-Site Scripting Reflected Cross-Site Scripting via processed-ids No login needed ≤ 1.0.25 CVE-2024-12337 Wordfence
6.4 Medium Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer Plugin Cross-Site Scripting PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer <= 2.3.52 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.52 CVE-2024-11830 Wordfence
7.5 High Ultimate Gift Cards for WooCommerce Plugin woo-gift-cards-lite Broken Access Control Missing Authorization to Infinite Money Glitch No login needed ≤ 2.9.1, ≤ 3.0.6 CVE-2024-11423 Wordfence
8.8 High Garden Gnome Package Plugin garden-gnome-package Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.3.0 CVE-2024-12854 Wordfence
8.8 High Modula Image Gallery Plugin modula-best-grid-gallery Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 2.11.10 CVE-2024-12853 Wordfence
5.3 Medium Shopping Cart & eCommerce Store Plugin wp-easycart Broken Access Control Missing Authorization to Order Updates No login needed ≤ 5.7.8 CVE-2024-12712 Wordfence
4.3 Medium AdForest - Classified Ads Theme Broken Access Control Classified Ads WordPress Theme <= 5.1.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post/Attachment Deletion ≤ 5.1.7 CVE-2024-12855 Wordfence
7.5 High Cost Calculator Builder PRO Plugin SQL Injection Unauthenticated SQL Injection via data No login needed ≤ 3.2.15 CVE-2024-11939 Wordfence
7.5 High WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php No login needed ≤ 4.24.13 CVE-2024-9939 Wordfence
6.4 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.1.7 CVE-2024-12328 Wordfence
9.8 Critical AdForest Theme Privilege Escalation Privilege Escalation via Password Reset/Account Takeover No login needed ≤ 5.1.6 CVE-2024-11350 Wordfence
4.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 5.1.0 CVE-2024-12045 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unuathenticated Remote Code Execution No login needed ≤ 4.24.12 CVE-2024-11635 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.15.1 CVE-2024-12852 Wordfence
4.3 Medium 140+ Widgets | Xpro Addons For Elementor – FREE Plugin xpro-elementor-addons Information Disclosure FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication ≤ 1.4.6.2 CVE-2024-12584 Wordfence
6.4 Medium Element Pack Lite - Addons for Elementor Plugin Cross-Site Scripting Addons for Elementor <= 5.10.14 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.10.14 CVE-2024-12851 Wordfence
9.8 Critical WordPress File Upload Plugin wp-file-upload Arbitrary File Upload Unauthenticated Remote Code Execution, Arbitrary File Read, and Arbitrary File Deletion No login needed ≤ 4.24.15 CVE-2024-11613 Wordfence
6.1 Medium PropertyHive Plugin Cross-Site Scripting Reflected XSS No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-12585 WPScan
5.4 Medium Auto iFrame Plugin auto-iframe Cross-Site Scripting Contributor+ XSS via Shortcode < 2.0 Fixed in 2.0 CVE-2024-10151 WPScan
5.3 Medium InfiniteWP Client Plugin iwp-client Path Traversal Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading No login needed ≤ 1.13.0 CVE-2024-10585 Wordfence
6.5 Medium MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter SQL Injection Meta Data and Taxonomies Filter <= 1.3.3.5 - Authenticated (Contributor+) SQL Injection ≤ 1.3.3.5 CVE-2024-12030 Wordfence
8.8 High WordPress Webinar Plugin – WebinarPress Plugin wp-webinarsystem Broken Access Control WebinarPress <= 1.33.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation ≤ 1.33.24 CVE-2024-11270 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.4 CVE-2024-12205 Wordfence
8.8 High WordPress Webinar Plugin – WebinarPress Plugin wp-webinarsystem Broken Access Control WebinarPress <= 1.33.24 - Missing Authorization to Authenticated (Subscriber+) Webinar Updates ≤ 1.33.24 CVE-2024-11271 Wordfence
6.4 Medium Easy Form Builder Plugin easy-form-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.8.8 CVE-2024-12112 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution ≤ 3.0.11 CVE-2024-11816 Wordfence
5.3 Medium SureForms – Drag and Drop Form Builder Plugin sureforms Broken Access Control Drag and Drop Form Builder for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Protected Post Disclosure No login needed ≤ 1.2.2 CVE-2024-12713 Wordfence
7.4 High The Ultimate WordPress Toolkit – WP Extended Plugin Broken Access Control WP Extended <= 3.0.11 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.0.11 CVE-2024-11916 Wordfence
6.4 Medium Slotti Ajanvaraus Plugin slotti-ajanvaraus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-12521 Wordfence
5.3 Medium Link Whisper Free Plugin link-whisper Information Disclosure Sensitive Data Exposure No login needed ≤ 0.7.7 Fixed in 0.7.9 CVE-2025-22306 Patchstack
5.3 Medium Allada T-shirt Designer for Woocommerce Plugin allada-tshirt-designer-for-woocommerce Broken Access Control No login needed ≤ 1.1 CVE-2025-22363 Patchstack
6.5 Medium Hash Elements Plugin hash-elements Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-22296 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only