WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,601–20,650 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 413 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Jetpack Plugin jetpack Cross-Site Scripting Unauthenticated DOM-XSS No login needed 13.0 – < 14.1 Fixed in 14.1 CVE-2024-10858 WPScan
7.5 High WP Data Access – App, Table, Form and Chart Builder Plugin wp-data-access SQL Injection App, Table, Form and Chart Builder plugin <= 5.5.22 - Unauthenticated SQL Injection No login needed ≤ 5.5.22 CVE-2024-12428 Wordfence
4.3 Medium Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages Plugin Cross-Site Request Forgery No login needed ≤ 3.2.7 CVE-2024-12636 Wordfence
8.8 High WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor Plugin wte-elementor-widgets Local File Inclusion Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor <= 1.3.7 - Authenticated (Contributor+) Local File Inclusion ≤ 1.3.7 CVE-2024-12272 Wordfence
4.3 Medium Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Broken Access Control Missing Authorization to Authenticated (Subscriber+) Form Submission Disclosure ≤ 2.17.3 CVE-2024-12190 Wordfence
5.3 Medium MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution Plugin marketking-multivendor-marketplace-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.0.00 CVE-2024-12413 Wordfence
6.5 Medium Tourfic – Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking Plugin tourfic SQL Injection Ultimate Hotel Booking, Travel Booking & Apartment Booking WordPress Plugin | WooCommerce Booking <= 2.15.3 - Authenticated (Subscriber+) SQL Injection ≤ 2.15.3 CVE-2024-12032 Wordfence
6.5 Medium Appointment Booking Calendar Plugin and Scheduling Plugin – BookingPress Plugin bookingpress-appointment-booking SQL Injection BookingPress <= 1.1.21 - Authenticated (Contributor+) SQL Injection ≤ 1.1.21 CVE-2024-11726 Wordfence
6.5 Medium Booking Calendar WpDevArt Plugin booking-calendar SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.2.19 CVE-2024-10856 Wordfence
6.4 Medium Responsive Blocks – WordPress Gutenberg Blocks Plugin responsive-block-editor-addons Cross-Site Scripting WordPress Gutenberg Blocks <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.7 CVE-2024-12268 Wordfence
5.4 Medium DirectoryPress Plugin directorypress Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 3.6.16 CVE-2024-10584 Wordfence
8.8 High PlugVersions – Easily rollback to previous versions of your plugins Plugin Broken Access Control Easily rollback to previous versions of your plugins <= 0.0.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation ≤ 0.0.7 CVE-2024-12881 Wordfence
4.9 Medium Database Backup and check Tables Automated With Scheduler 2024 Plugin database-backup Path Traversal Authenticated (Admin+) Arbitrary File Read ≤ 2.32 CVE-2024-12850 Wordfence
5.3 Medium Content No Cache: prevent specific content from being cached Plugin content-no-cache Information Disclosure Unauthenticated Private Content Disclosure No login needed ≤ 0.1.2 CVE-2024-12103 Wordfence
6.5 Medium Advanced Floating Content Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 3.8.2 CVE-2024-12031 Wordfence
6.4 Medium Tracking Code Manager Plugin tracking-code-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.0 CVE-2024-8721 Wordfence
6.1 Medium WP Datepicker Plugin wp-datepicker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.4 CVE-2024-12468 Wordfence
6.4 Medium Text Prompter – Unlimited chatgpt text prompts for openai tasks Plugin ai-content Cross-Site Scripting Unlimited chatgpt text prompts for openai tasks <= 1.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.7 CVE-2024-11896 Wordfence
6.4 Medium Loan Comparison Plugin loan-comparison Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-12814 Wordfence
6.1 Medium Exhibit to WP Gallery Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.0.2 CVE-2024-12096 WPScan
6.1 Medium Export Customers Data Plugin export-customers-data Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.3 CVE-2024-12405 Wordfence
6.4 Medium WordPress Simple Shopping Cart Plugin wordpress-simple-paypal-shopping-cart Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.7 CVE-2024-12622 Wordfence
8.8 High ALL In One Custom Login Page Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+)Privilege Escalation ≤ 7.1.1 CVE-2024-12594 Wordfence
6.1 Medium Bitcoin Lightning Publisher Plugin bitcoin-lightning-publisher Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.1 CVE-2024-12100 Wordfence
4.3 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Logo Deletion ≤ 5.4.0 CVE-2024-12210 Wordfence
6.4 Medium NinjaTeam Chat for Telegram Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-11885 Wordfence
5.3 Medium Advanced Google reCAPTCHA Plugin advanced-google-recaptcha Other Brute Force Protection IP Unblock No login needed ≤ 1.25 CVE-2024-12034 Wordfence
5.4 Medium WC Price History for Omnibus Plugin Broken Access Control Missing Authorization ≤ 2.1.3 CVE-2024-12617 Wordfence
6.4 Medium Optio Dentistry Plugin optio-dentistry Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-12507 Wordfence
6.1 Medium WP-Appbox Plugin wp-appbox Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.5.3 CVE-2024-12710 Wordfence
6.4 Medium shMapper by Teplitsa Plugin shmapper-by-teplitsa Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.18 CVE-2024-12518 Wordfence
6.5 Medium ELEX WooCommerce Dynamic Pricing and Discounts Plugin elex-woocommerce-dynamic-pricing-and-discounts Broken Access Control Missing Authorization No login needed ≤ 2.1.7 CVE-2024-12266 Wordfence
6.4 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title Widget ≤ 1.6.46 CVE-2024-11230 Wordfence
4.3 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Broken Access Control Missing Authorization ≤ 5.10.12 CVE-2024-11852 Wordfence
4.9 Medium Easy Digital Downloads Plugin easy-digital-downloads Path Traversal Authenticated (Admin+) Arbitrary File Download ≤ 3.3.2 CVE-2024-12875 Wordfence
6.4 Medium MagicPost Plugin magicpost Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wb_share_social Shortcode ≤ 1.2.1 CVE-2024-12591 Wordfence
6.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.25.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typography Settings ≤ 3.25.9 CVE-2024-10453 Wordfence
5.9 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.25.1 CVE-2024-11722 Wordfence
6.1 Medium LaTeX2HTML Plugin latex2html Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.5.5 CVE-2024-11688 Wordfence
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.1 Medium WP on AWS Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.2.1 CVE-2024-12408 Wordfence
4.3 Medium Full Screen Menu for Elementor Plugin full-screen-menu-for-elementor Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.7 CVE-2024-10797 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Staff Widget ≤ 2.17.2 CVE-2024-12588 Wordfence
6.1 Medium Pingmeter Uptime Monitoring Plugin pingmeter-uptime-monitoring Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2024-11808 Wordfence
6.4 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aux_contact_box and aux_gmaps Shortcodes ≤ 2.17.0 CVE-2024-9545 Wordfence
6.1 Medium Reactflow Visitor Recording and Heatmaps Plugin reactflow-session-replay-heatmap Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.10 CVE-2024-11975 Wordfence
6.1 Medium G Web Pro Store Locator Plugin gwebpro-store-locator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1 CVE-2024-11682 Wordfence
6.4 Medium Multi-column Tag Map Plugin multi-column-tag-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mctagmap Shortcode ≤ 17.0.33 CVE-2024-11196 Wordfence
6.4 Medium real.Kit Plugin real-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.1 CVE-2024-12697 Wordfence
6.1 Medium Ebook Store Plugin ebook-store Cross-Site Scripting Reflected Cross-Site Scripting via 'step' No login needed ≤ 5.8001 CVE-2024-12262 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only