WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,751–20,800 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 416 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Stop Registration Spam Plugin stop-registration-spam Cross-Site Request Forgery Cross-Site Request Forgery to Cross-Site Scripting No login needed ≤ 1.23 CVE-2024-12219 Wordfence
7.6 High WP All Import Pro Plugin Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via File Import ≤ 4.9.3 CVE-2024-9624 Wordfence
4.8 Medium My WP Customize Admin/Frontend Plugin my-wp Cross-Site Scripting Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page wit… prior to ver 1.24.1 CVE-2024-55864 jpcert
6.1 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting Reflected Cross-Site Scripting via Navigate Parameter No login needed ≤ 1.3.0.5 CVE-2024-12239 Wordfence
6.4 Medium TPG Get Posts Plugin tpg-get-posts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.6.5 CVE-2024-11906 Wordfence
6.4 Medium Animated Counters Plugin animated-counters Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-11905 Wordfence
6.4 Medium Slope Widgets Plugin slope-widgets Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2.12 CVE-2024-11902 Wordfence
6.4 Medium Portfolio – Filterable Masonry Portfolio Gallery for Professionals Plugin portfolio-pro Cross-Site Scripting Filterable Masonry Portfolio Gallery for Professionals <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2024-11900 Wordfence
6.4 Medium CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout Plugin support-x Cross-Site Scripting WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.6 CVE-2024-12443 Wordfence
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.23 Fixed in 1.24 CVE-2024-56017 Patchstack
4.3 Medium Avada Theme avada Cross-Site Request Forgery No login needed ≤ 7.11.10 Fixed in 7.11.11 CVE-2024-54357 Patchstack
7.5 High EazyDocs Plugin eazydocs Local File Inclusion ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-54376 Patchstack
4.3 Medium Caldera SMTP Mailer Plugin caldera-smtp-mailer Broken Access Control ≤ 1.0.1 CVE-2024-56003 Patchstack
5.3 Medium XML Multilanguage Sitemap Generator Plugin xml-multilanguage-sitemap-generator Broken Access Control No login needed ≤ 2.0.6 CVE-2024-55999 Patchstack
6.5 Medium Brand Plugin brand Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-54348 Patchstack
9.1 Critical SeedProd Pro Plugin seedprod-coming-soon-pro-5 Remote Code Execution ≤ 6.18.10 CVE-2024-54285 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54284 Patchstack
7.6 High SeedProd Pro Plugin seedprod-coming-soon-pro-5 SQL Injection ≤ 6.18.10 CVE-2024-54283 Patchstack
9.3 Critical WPBookit Plugin wpbookit SQL Injection No login needed ≤ 1.6.0 CVE-2024-54280 Patchstack
7.5 High WP-NERD Toolkit Plugin wp-nerd-toolkit Information Disclosure Sensitive Data Exposure No login needed ≤ 1.1 CVE-2024-54279 Patchstack
7.1 High tydskrif Theme tydskrif Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2024-54257 Patchstack
7.1 High Advanced Options Editor Plugin advanced-options-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-54249 Patchstack
9.8 Critical Woffice Plugin woffice Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 5.4.14 Fixed in 5.4.15 CVE-2024-43234 Patchstack
9.8 Critical SV100 Companion Plugin sv100-companion Privilege Escalation No login needed ≤ 2.0.02 CVE-2024-54229 Patchstack
4.3 Medium Advanced Custom Fields PRO Plugin advanced-custom-fields-pro Cross-Site Request Forgery No login needed < 6.3.2 Fixed in 6.3.2 CVE-2024-37251 Patchstack
7.1 High Tidy Up Plugin tidy-up Cross-Site Request Forgery CSRF to Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2024-56015 Patchstack
7.1 High 3D Avatar User Profile Plugin 3d-avatar-user-profile Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-54358 Patchstack
6.5 Medium Termin-Kalender Plugin termin-kalender Broken Access Control ≤ 0.99.47 Fixed in 1.00.04 CVE-2024-54354 Patchstack
9.3 Critical Instant Appointment Plugin instant-appointment SQL Injection No login needed ≤ 1.2 CVE-2024-54361 Patchstack
8.2 High Banner System Plugin banner-system Broken Access Control No login needed ≤ 1.0.0 CVE-2024-54359 Patchstack
7.1 High Feedpress Generator Plugin feedpress-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-54364 Patchstack
9.8 Critical Wp NssUser Register Plugin wp-nssuser-register Privilege Escalation No login needed ≤ 1.0.0 CVE-2024-54363 Patchstack
8.8 High KH Easy User Settings Plugin kh-easy-user-settings Privilege Escalation ≤ 1.0.0 CVE-2024-54365 Patchstack
9.6 Critical GitSync Plugin git-sync Cross-Site Request Forgery CSRF to Remote Code Execution No login needed ≤ 1.1.0 CVE-2024-54368 Patchstack
9.8 Critical ForumWP Plugin forumwp PHP Object Injection No login needed ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-54367 Patchstack
9.9 Critical Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Arbitrary File Upload ≤ 1.1.0 Fixed in 1.1.1 CVE-2024-54370 Patchstack
9.1 Critical Zita Site Builder Plugin ai-site-builder Broken Access Control Arbitrary Plugin Installation and Activation No login needed ≤ 1.0.2 CVE-2024-54369 Patchstack
7.5 High Sogrid Plugin sogrid Local File Inclusion No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2024-54374 Patchstack
8.8 High Quietly Insights Plugin quietly-insights Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.2.2 CVE-2024-54378 Patchstack
7.5 High Woolook Plugin woolook Local File Inclusion No login needed ≤ 1.7.0 CVE-2024-54375 Patchstack
7.5 High WP Cookies Enabler Plugin wp-cookies-enabler Local File Inclusion No login needed ≤ 1.0.1 CVE-2024-54380 Patchstack
8.8 High Minterpress Plugin minterpress Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 1.0.5 CVE-2024-54379 Patchstack
7.2 High Radio Player Plugin radio-player Server-Side Request Forgery No login needed ≤ 2.0.83 Fixed in 2.0.85 CVE-2024-54385 Patchstack
4.9 Medium Bold Page Builder Plugin bold-page-builder Path Traversal ≤ 5.1.5 Fixed in 5.1.6 CVE-2024-54382 Patchstack
7.1 High Posts Date Ranges Plugin posts-date-ranges Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2024-54387 Patchstack
7.1 High Increase Sociability Plugin increase-sociability Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.3.0 CVE-2024-54395 Patchstack
7.1 High TagGator Plugin taggator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.54 CVE-2024-54390 Patchstack
7.1 High Comments On Feed Plugin comments-on-feed Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2024-54406 Patchstack
7.1 High Visual Recent Posts Plugin visual-recent-posts Cross-Site Request Forgery Reflected Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.3 CVE-2024-54403 Patchstack
7.1 High Evernote Sync Plugin evernote-sync Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.0 CVE-2024-54422 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only