WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,351–20,400 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 408 of 589
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Point Theme point Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2024-37931 Patchstack
4.3 Medium i-amaze Theme i-amaze Cross-Site Request Forgery No login needed ≤ 1.3.7 CVE-2024-38731 Patchstack
4.3 Medium Patricia Blog Theme patricia-blog Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2024-38732 Patchstack
4.3 Medium i-transform Theme i-transform Cross-Site Request Forgery No login needed ≤ 3.0.9 CVE-2024-38764 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.69.234 Fixed in 1.70.236 CVE-2024-38778 Patchstack
8.8 High ListingPro Theme listingpro Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Account Takeover No login needed ≤ 2.9.4 Fixed in 2.9.5 CVE-2024-39623 Patchstack
7.1 High Olivia Theme olivia Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.5 CVE-2024-56014 Patchstack
6.5 Medium Coins MarketCap Plugin coins-marketcap Cross-Site Scripting ≤ 5.5.8 Fixed in 5.5.9 CVE-2024-56257 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-56268 Patchstack
6.5 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56302 Patchstack
7.1 High Interactive UK Map Plugin interactive-uk-map Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 3.4.8 Fixed in 3.4.9 CVE-2024-56267 Patchstack
6.3 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Broken Access Control ≤ 5.8 Fixed in 5.9 CVE-2024-56266 Patchstack
6.6 Medium ACF City Selector Plugin acf-city-selector Arbitrary File Upload ≤ 1.14.0 Fixed in 1.15.0 CVE-2024-56264 Patchstack
6.5 Medium GS Shots for Dribbble Plugin gs-dribbble-portfolio Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2024-56263 Patchstack
6.5 Medium GS Coaches Plugin gs-coach Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-56262 Patchstack
6.5 Medium Project Showcase Plugin gs-projects Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-56261 Patchstack
6.5 Medium ShopElement Plugin shopelement Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-56260 Patchstack
6.5 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting ≤ 2.3.84 Fixed in 2.3.85 CVE-2024-56259 Patchstack
6.5 Medium Magazine Blocks Plugin magazine-blocks Cross-Site Scripting ≤ 1.3.20 Fixed in 1.3.21 CVE-2024-56258 Patchstack
4.3 Medium AyeCode Connect Plugin ayecode-connect Broken Access Control ≤ 1.3.8 Fixed in 1.3.9 CVE-2024-56255 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-56254 Patchstack
5.4 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Broken Access Control ≤ 1.10.36 Fixed in 1.10.37 CVE-2024-56253 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting ≤ 2.1.9 Fixed in 2.2.1 CVE-2024-56252 Patchstack
4.3 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Cross-Site Request Forgery No login needed ≤ 5.0.28.decaf Fixed in 5.0.31.decaf CVE-2024-56251 Patchstack
7.6 High Just Writing Statistics Plugin just-writing-statistics SQL Injection ≤ 4.7 Fixed in 4.8 CVE-2024-56250 Patchstack
9.1 Critical WPMasterToolKit Plugin wpmastertoolkit Arbitrary File Upload ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56249 Patchstack
4.9 Medium WPMasterToolKit Plugin wpmastertoolkit Path Traversal Arbitrary File Download ≤ 1.13.1 Fixed in 1.14.0 CVE-2024-56248 Patchstack
7.6 High WP Post Author Plugin wp-post-author SQL Injection ≤ 3.8.2 Fixed in 3.8.3 CVE-2024-56247 Patchstack
6.5 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting ≤ 4.0.4 Fixed in 4.0.5 CVE-2024-56246 Patchstack
6.5 Medium Premium Blocks – Gutenberg Blocks Plugin premium-blocks-for-gutenberg Cross-Site Scripting ≤ 2.1.42 Fixed in 2.1.43 CVE-2024-56245 Patchstack
5.4 Medium Ashe Extra Plugin ashe-extra Broken Access Control ≤ 1.2.92 Fixed in 1.3 CVE-2024-56244 Patchstack
4.3 Medium WPSSO Core Plugin wpsso Broken Access Control ≤ 18.18.1 Fixed in 18.18.2 CVE-2024-56243 Patchstack
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.14 Fixed in 2.1.15 CVE-2024-56242 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2024-56241 Patchstack
6.5 Medium Pronamic Google Maps Plugin pronamic-google-maps Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2024-56240 Patchstack
6.5 Medium Themify Audio Dock Plugin themify-audio-dock Cross-Site Scripting ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-56239 Patchstack
5.3 Medium Floating Action Buttons Plugin floating-action-buttons Broken Access Control No login needed ≤ 0.9.1 Fixed in 1.0.1 CVE-2024-56238 Patchstack
5.9 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting ≤ 24.0.3 Fixed in 24.0.4 CVE-2024-56237 Patchstack
4.3 Medium Hestia Nginx Cache Plugin hestia-nginx-cache Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2024-56236 Patchstack
7.1 High Simple Proxy Plugin simple-proxy Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-56026 Patchstack
7.1 High AdWork Media EZ Content Locker Plugin adwork-media-ez-content-locker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0 CVE-2024-56025 Patchstack
7.1 High Custom Dashboard Widget Plugin create-custom-dashboard-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-56024 Patchstack
7.1 High WP eCommerce Quickpay Plugin wp-ecommerce-quickpay Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2024-56023 Patchstack
7.1 High Preloader by WordPress Monsters Plugin preloader-sws Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2024-56022 Patchstack
7.1 High BU Section Editing Plugin bu-section-editing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.9 CVE-2024-56018 Patchstack
4.3 Medium Email Address Encoder Plugin email-address-encoder Cross-Site Request Forgery No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2024-43927 Patchstack
6.5 Medium Smartsupp – live chat, chatbots, AI and lead generation Plugin smartsupp-live-chat Cross-Site Request Forgery No login needed ≤ 3.6 Fixed in 3.7 CVE-2024-38790 Patchstack
5.3 Medium Telegram Bot & Channel Plugin telegram-bot Cross-Site Request Forgery No login needed ≤ 3.8.2 Fixed in 4.0.1 CVE-2024-38789 Patchstack
4.3 Medium Matomo Analytics Plugin matomo Cross-Site Request Forgery Cross Site Request Forgery (CSRF) leading to Notice Dismissal No login needed ≤ 5.1.1 Fixed in 5.1.2 CVE-2024-38766 Patchstack
4.3 Medium Oceanic Plugin oceanic Cross-Site Request Forgery No login needed ≤ 1.0.48 CVE-2024-38765 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only