WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 20,251–20,300 of 29,413 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Social Rocket – Social Sharing | Broken Access Control Social Sharing Plugin <= 1.3.4 - Missing Authorization to Settings Update No login needed |
≤ 1.3.4 |
CVE-2024-9697 |
Wordfence | |
| 6.1 Medium | Compare Products for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2.1 |
CVE-2024-12435 |
Wordfence | |
| 6.1 Medium | Unilevel MLM Plan | Cross-Site Scripting Reflected Cross-Site Scripting via 'page' No login needed |
≤ 1.1.0 |
CVE-2024-12324 |
Wordfence | |
| 6.4 Medium | Common Ninja: Fully Customizable & Perfectly Responsive Free Widgets for WordPress Websites | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11382 |
Wordfence | |
| 6.4 Medium | RightMessage WP | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.9.7 |
CVE-2024-12445 |
Wordfence | |
| 8.8 High | ThePerfectWedding.nl Widget | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.8 |
CVE-2024-12322 |
Wordfence | |
| 6.1 Medium | PayGreen Payment Gateway | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.26 |
CVE-2024-11810 |
Wordfence | |
| 9.8 Critical | School Management System – SakolaWP | Privilege Escalation SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation No login needed |
≤ 1.0.8 |
CVE-2024-12470 |
Wordfence | |
| 4.3 Medium | LazyLoad Background Images | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update |
≤ 1.0.7 |
CVE-2024-12327 |
Wordfence | |
| 6.5 Medium | Infility Global | Broken Access Control Authenticated (Subscriber+) Missing Authorization to Plugin Options Update |
≤ 2.9.8 |
CVE-2024-11496 |
Wordfence | |
| 6.1 Medium | Enable Accessibility | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.4.1 |
CVE-2024-9208 |
Wordfence | |
| 6.1 Medium | Simple Video Management System | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.4 |
CVE-2024-12256 |
Wordfence | |
| 5.3 Medium | WordLift – AI powered SEO – Schema | Broken Access Control AI powered SEO – Schema <= 3.54.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update No login needed |
≤ 3.54.2 |
CVE-2024-12176 |
Wordfence | |
| 5.3 Medium | Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords | Information Disclosure Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure No login needed |
≤ 3.1 |
CVE-2024-12159 |
Wordfence | |
| 6.5 Medium | School Management System – WPSchoolPress | SQL Injection WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection |
≤ 2.2.14 |
CVE-2024-12332 |
Wordfence | |
| 4.3 Medium | Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements | Information Disclosure Authenticated (Contributor+) Private Templates Content Disclosure |
≤ 2.2.1 |
CVE-2024-12140 |
Wordfence | |
| 9.8 Critical | PayU CommercePro | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 3.8.3 |
CVE-2024-12264 |
Wordfence | |
| 6.1 Medium | Automate Hub Free by Sperse.IO | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.7.0 |
CVE-2024-11377 |
Wordfence | |
| 5.3 Medium | Member Access | Information Disclosure Unauthenticated Content Restriction Bypass to Sensitive Information Exposure No login needed |
≤ 1.1.6 |
CVE-2024-11290 |
Wordfence | |
| 5.3 Medium | Popup – MailChimp, GetResponse and ActiveCampaign Intergrations | Broken Access Control MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Missing Authorization to Unauthenticated DB Table Truncation No login needed |
≤ 3.2.6 |
CVE-2024-12158 |
Wordfence | |
| 6.1 Medium | GDY Modular Content | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.9.92 |
CVE-2024-12153 |
Wordfence | |
| 6.4 Medium | Uptodown APK Download Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1.10 |
CVE-2024-12453 |
Wordfence | |
| 6.1 Medium | Same but Different – Related Posts by Taxonomy | Cross-Site Scripting Related Posts by Taxonomy <= 1.0.16 - Reflected Cross-Site Scripting No login needed |
≤ 1.0.16 |
CVE-2024-11363 |
Wordfence | |
| 6.4 Medium | Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode | Cross-Site Scripting Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode <= 1.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.3 |
CVE-2024-12457 |
Wordfence | |
| 4.4 Medium | Toggles Shortcode and Widget | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.14 |
CVE-2024-12207 |
Wordfence | |
| 9.8 Critical | SEO LAT Auto Post | Broken Access Control Missing Authorization to File Overwrite/Upload (Remote Code Execution) No login needed |
≤ 2.2.1 |
CVE-2024-12252 |
Wordfence | |
| 6.4 Medium | Horoscope And Tarot | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-11337 |
Wordfence | |
| 8.1 High | Compare Products for WooCommerce | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 3.2.1 |
CVE-2024-12313 |
Wordfence | |
| 6.1 Medium | ViewMedica 9 | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 1.4.17 |
CVE-2024-12291 |
Wordfence | |
| 6.1 Medium | Infility Global | Cross-Site Scripting Reflected Cross-Site Scripting via set_type Parameter No login needed |
≤ 2.9.8 |
CVE-2024-12290 |
Wordfence | |
| 5.4 Medium | ViewMedica Embed | Cross-Site Request Forgery Cross-Site Request Forgery to SQL Injection No login needed |
≤ 1.4.17 |
CVE-2024-12170 |
Wordfence | |
| 6.1 Medium | Simple add pages or posts | Cross-Site Request Forgery Cross-Site Request Forgery to Reflected Cross-Site Scripting No login needed |
≤ 2.0.0 |
CVE-2024-12288 |
Wordfence | |
| 6.4 Medium | Image Magnify | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2024-11445 |
Wordfence | |
| 6.1 Medium | WC1C | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.23.0 |
CVE-2024-11375 |
Wordfence | |
| 7.5 High | Popup – MailChimp, GetResponse and ActiveCampaign Intergrations | SQL Injection MailChimp, GetResponse and ActiveCampaign Intergrations <= 3.2.6 - Unauthenticated SQL Injection No login needed |
≤ 3.2.6 |
CVE-2024-12157 |
Wordfence | |
| 6.1 Medium | Bizapp for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.8 |
CVE-2024-11378 |
Wordfence | |
| 6.1 Medium | WooCommerce HSS Extension for Streaming Video | Cross-Site Scripting Reflected Cross-Site Scripting via videolink Parameter No login needed |
≤ 3.31 |
CVE-2024-12214 |
Wordfence | |
| 6.1 Medium | SEO Keywords | Cross-Site Scripting Reflected Cross-Site Scripting via google_error Parameter No login needed |
≤ 1.1.3 |
CVE-2024-12126 |
Wordfence | |
| 6.1 Medium | Financial Stocks & Crypto Market Data | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.10.3 |
CVE-2024-11690 |
Wordfence | |
| 7.2 High | Custom Product Tabs for WooCommerce | PHP Object Injection Authenticated (Shop Manager+) PHP Object Injection |
≤ 1.8.5 |
CVE-2024-11465 |
Wordfence | |
| 6.1 Medium | WP – Bulk SMS – by SMS.to | Cross-Site Scripting Bulk SMS – by SMS.to <= 1.0.12 - Reflected Cross-Site Scripting No login needed |
≤ 1.0.12 |
CVE-2024-11434 |
Wordfence | |
| 6.4 Medium | PIXNET | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.9.10 |
CVE-2024-11338 |
Wordfence | |
| 6.4 Medium | YOGO Booking | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.2 |
CVE-2024-12462 |
Wordfence | |
| 3.1 Low | Spacer | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Information Disclosure |
≤ 3.0.7 |
CVE-2024-10527 |
Wordfence | |
| 6.1 Medium | Woo Ukrposhta | Cross-Site Scripting Reflected Cross-Site Scripting via order, post, and idd Parameters No login needed |
≤ 1.17.11 |
CVE-2024-12049 |
Wordfence | |
| 6.4 Medium | CC Canadian Mortgage Calculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.0 |
CVE-2024-11383 |
Wordfence | |
| 4.3 Medium | Duplicate Post, Page and Any Custom Post | Information Disclosure Authenticated (Contributor+) Post Disclosure via Post Duplication |
≤ 3.5.5 |
CVE-2024-12538 |
Wordfence | |
| 5.3 Medium | ClickDesigns | Broken Access Control Missing Authorization to API Key Modification or Removal No login needed |
≤ 1.8.0 |
CVE-2024-12559 |
Wordfence | |
| 6.4 Medium | Slider Pro Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-11899 |
Wordfence | |
| 6.4 Medium | Sellsy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.3 |
CVE-2024-12592 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.