WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,851–20,900 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 418 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Arabic Webfonts Plugin arabic-webfonts Broken Access Control ≤ 1.4.6 CVE-2024-54402 Patchstack
7.1 High Advanced Fancybox Plugin advanced-fancybox Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2024-54401 Patchstack
7.1 High MDC Comment Toolbar Plugin mdc-comment-toolbar Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54404 Patchstack
7.1 High CK and SyntaxHighlighter Plugin ck-and-syntaxhighlighter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.4.2 CVE-2024-54407 Patchstack
7.1 High ECT Social Share Plugin ect-social-share Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2024-54405 Patchstack
6.5 Medium Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.9 CVE-2024-54408 Patchstack
7.1 High SOPA Blackout Plugin sopa-blackout Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2024-54410 Patchstack
7.1 High XPD Reduce Image Filesize Plugin xpd-reduce-image-filesize Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54409 Patchstack
7.1 High WP Controller Plugin wp-management-controller Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 3.2.0 CVE-2024-54411 Patchstack
7.1 High Display Future Posts Plugin display-future-posts Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.2.3 CVE-2024-54413 Patchstack
7.1 High ECT Product Carousel Plugin ect-product-carousel Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.9 CVE-2024-54412 Patchstack
7.1 High WP-HideThat Plugin wp-hide-that Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2024-54415 Patchstack
7.1 High Geoportail Shortcode Plugin geoportail-shortcode Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.4.4 CVE-2024-54414 Patchstack
7.1 High Wp Login with Ajax Plugin wp-login-with-ajax Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.6 CVE-2024-54416 Patchstack
7.1 High Floating Video Player Plugin floating-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54421 Patchstack
7.1 High Metrika Plugin metrika Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2024-54420 Patchstack
7.1 High Like in Vk.com Plugin like-on-vkontakte Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 0.5.2 CVE-2024-54424 Patchstack
7.1 High Social Media Sharing Plugin social-media-sharing Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54423 Patchstack
7.1 High LionScripts: Site Maintenance & Noindex Nofollow Plugin maintenance-and-noindex-nofollow Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 2.1 CVE-2024-54425 Patchstack
7.1 High Category of Posts Plugin list-one-category-of-posts Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54427 Patchstack
7.1 High LeaderBoard Plugin leaderboard-lite Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.2.4 CVE-2024-54426 Patchstack
7.1 High Aphorismus Plugin aphorismus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.0 CVE-2024-54429 Patchstack
7.1 High Add image to Post Plugin add-image-to-post Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6 CVE-2024-54428 Patchstack
5.4 Medium EELV Newsletter Plugin eelv-newsletter Cross-Site Request Forgery No login needed ≤ 4.8.2 CVE-2024-54430 Patchstack
7.1 High WP Flipkart Importer Plugin wp-flipkart-importer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2024-54432 Patchstack
7.1 High Admin Customization Plugin wpp-customization Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2 CVE-2024-54431 Patchstack
7.1 High phZoom Plugin phzoom Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.92 CVE-2024-54434 Patchstack
7.1 High Simple Booking Widget Plugin simple-booking-widget Cross-Site Request Forgery Widget plugin <= 1.1 - CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54433 Patchstack
7.1 High Onlywire Multi Autosubmitter Plugin onlywire-multi-autosubmitter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2.4 CVE-2024-54435 Patchstack
7.1 High jCarousel Plugin jcarousel-for-wordpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54437 Patchstack
7.1 High Jet Footer Code Plugin jet-footer-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2024-54436 Patchstack
7.1 High Amazon Product Price Plugin amazon-product-price Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-54439 Patchstack
7.1 High Gaxx Keywords Plugin gaxx-keywords Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2 CVE-2024-54438 Patchstack
7.1 High WP-Ban-User Plugin wp-ban-user Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-54440 Patchstack
9.8 Critical Flash News / Post (Responsive) Plugin flashnews-fading-effect-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.1 CVE-2024-56012 Patchstack
7.6 High WP Simple Pay Lite Manager Plugin stripe-manager SQL Injection ≤ 1.4 CVE-2024-55989 Patchstack
7.6 High Mollie for Contact Form 7 Plugin cf7-mollie SQL Injection ≤ 5.0.0 CVE-2024-55990 Patchstack
5.4 Medium Popup Surveys & Polls for WordPress (Mare.io) Plugin popup-surveys Broken Access Control Settings Change ≤ 1.36 CVE-2024-55998 Patchstack
7.5 High EduAdmin Booking Plugin eduadmin-booking Local File Inclusion ≤ 5.2.0 Fixed in 5.3.0 CVE-2024-54373 Patchstack
5.4 Medium Easy Site Importer Plugin easy-site-importer Broken Access Control Settings Change ≤ 1.0.1 CVE-2024-56004 Patchstack
5.3 Medium Vimeography Plugin vimeography Information Disclosure Full Path Disclosure (FPD) No login needed ≤ 2.4.4 Fixed in 2.4.5 CVE-2024-54366 Patchstack
5.4 Medium Tithe.ly Giving Button Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode ≤ 1.1 CVE-2024-11841 WPScan
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Unauthenticated Password Protected Event Disclosure No login needed < 6.8.2.1 Fixed in 6.8.2.1 CVE-2024-5333 WPScan
8.1 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.24.5 CVE-2024-11721 Wordfence
7.2 High Frontend Admin by DynamiApps Plugin acf-frontend-form-element Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.24.5 CVE-2024-11720 Wordfence
5.3 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Arbitrary Resume Download No login needed ≤ 2.2.2 CVE-2024-11712 Wordfence
7.5 High WP Job Portal Plugin wp-job-portal SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.2.1 CVE-2024-11711 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection ≤ 2.2.2 CVE-2024-11710 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection via getFieldsForVisibleCombobox() ≤ 2.2.2 CVE-2024-11714 Wordfence
4.9 Medium WP Job Portal Plugin wp-job-portal SQL Injection Authenticated (Admin+) SQL Injection via wpjobportal_deactivate() ≤ 2.2.2 CVE-2024-11713 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only