WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,901–20,950 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 419 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Post to Pdf Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-12446 Wordfence
4.8 Medium WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Limited Privilege Escalation No login needed ≤ 2.2.2 CVE-2024-11715 Wordfence
4.4 Medium bodi0’s Easy Cache Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 0.8 CVE-2024-12628 Wordfence
6.4 Medium Ganohrs Toggle Shortcode Plugin ganohrs-toggle-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2.4 CVE-2024-12459 Wordfence
6.1 Medium Import Eventbrite Events Plugin import-eventbrite-events Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2024-12422 Wordfence
6.4 Medium GeoDataSource Country Region DropDown Plugin geodatasource-country-region-dropdown Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2024-12474 Wordfence
6.4 Medium Eveeno Plugin eveeno Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-11752 Wordfence
4.3 Medium Shortcodes for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.0.4 CVE-2024-10690 Wordfence
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
6.4 Medium Simple Locator Plugin simple-locator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.3 CVE-2024-12501 Wordfence
6.4 Medium Wp photo text slider 50 Plugin wp-photo-text-slider-50 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.1 CVE-2024-11884 Wordfence
7.2 High Crafthemes Demo Import Plugin crafthemes-demo-import Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload in process_uploaded_files ≤ 3.3 CVE-2024-9698 Wordfence
6.4 Medium IDer Login Plugin ider-login Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-11888 Wordfence
6.4 Medium Cricket Live Score Plugin cricket-score Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 CVE-2024-11877 Wordfence
6.4 Medium Buk Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.7 CVE-2024-11869 Wordfence
6.4 Medium My IDX Home Search Plugin my-idx-home-search Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.1 CVE-2024-12502 Wordfence
6.4 Medium The Permalinker Plugin the-permalinker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.1 CVE-2024-11894 Wordfence
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
6.4 Medium States Map US Plugin ymc-states-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.2 CVE-2024-12523 Wordfence
4.3 Medium Get Post Content Shortcode Plugin get-post-content-shortcode Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via post_content Shortcode ≤ 0.4 CVE-2024-12447 Wordfence
6.4 Medium Smart PopUp Blaster Plugin smart-popup-blaster Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.3 CVE-2024-12458 Wordfence
6.4 Medium Posts and Products Views for WooCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-12448 Wordfence
6.1 Medium WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More Plugin wp-ad-guru Cross-Site Scripting Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross-Site Scripting No login needed ≤ 2.5.4 CVE-2024-12411 Wordfence
6.4 Medium WooCommerce Cart Count Shortcode Plugin woo-cart-count-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2024-12517 Wordfence
6.4 Medium Connatix Video Embed Plugin connatix-video-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.5 CVE-2024-11883 Wordfence
6.4 Medium Plezi Plugin plezi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.6 CVE-2024-11763 Wordfence
6.4 Medium Post Carousel & Slider Plugin post-types-carousel-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2024-11770 Wordfence
6.1 Medium Filestack Official Plugin filestack-upload Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.0 CVE-2024-11462 Wordfence
6.4 Medium Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Plugin kredeum-nfts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.9 CVE-2024-11876 Wordfence
6.4 Medium Bukza Plugin bukza Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.0 CVE-2024-11759 Wordfence
6.4 Medium Visualmodo Elements Plugin visualmodo-elements Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-11095 Wordfence
6.4 Medium IMS Countdown Plugin ims-countdown Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.5 CVE-2024-11755 Wordfence
6.4 Medium TCBD Popover Plugin tcbd-popover Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2024-11751 Wordfence
5.3 Medium Tickera – WordPress Event Ticketing Plugin Information Disclosure WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure No login needed ≤ 3.5.4.8 CVE-2024-12578 Wordfence
6.4 Medium Companion Portfolio – Responsive Portfolio Plugin companion-portfolio Cross-Site Scripting Responsive Portfolio Plugin <= 2.4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0.1 CVE-2024-11867 Wordfence
6.4 Medium Tabs Maker Plugin tabs-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-11865 Wordfence
6.4 Medium My IDX Home Search Plugin my-idx-home-search Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.1 CVE-2024-11889 Wordfence
6.4 Medium glomex oEmbed Plugin glomex-oembed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.9.1 CVE-2024-11873 Wordfence
6.1 Medium SIP Calculator Plugin sip-calculator Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2024-12555 Wordfence
7.1 High Fancy Roller Scroller Plugin fancy-roller-scroller Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-54351 Patchstack
6.5 Medium Plain Post Plugin plain-post Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2024-54349 Patchstack
7.1 High FloristPress Plugin bakkbone-florist-companion Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.2.0 Fixed in 7.3.0 CVE-2024-54347 Patchstack
6.5 Medium Barter Plugin barter Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-54346 Patchstack
6.5 Medium Bicycleshop Plugin bicycleshop Cross-Site Scripting ≤ 1.5 Fixed in 1.6 CVE-2024-54345 Patchstack
7.1 High WP Quick Shop Plugin wp-quick-shop Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-54344 Patchstack
7.1 High Connect Contact Form 7 to Constant Contact Plugin connect-contact-form-7-to-constant-contact-v3 Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 Fixed in 1.5 CVE-2024-54343 Patchstack
7.1 High STAGGS Plugin staggs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 Fixed in 2.1.0 CVE-2024-54342 Patchstack
7.1 High LabelGrid Tools Plugin label-grid-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.58 Fixed in 1.3.59 CVE-2024-54341 Patchstack
7.1 High Simple Presenter Plugin simple-presenter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2024-54340 Patchstack
7.1 High geoFlickr Plugin geoflickr Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 Fixed in 1.4 CVE-2024-54339 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only