WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 20,951–21,000 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 420 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Hello Event Widgets For Elementor Plugin hello-event-widgets-for-elementor Cross-Site Scripting ≤ 1.0.2 Fixed in 1.1.0 CVE-2024-54338 Patchstack
7.1 High DX Dark Site Plugin devrix-dark-site Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.1 Fixed in 1.1.1 CVE-2024-54337 Patchstack
8.8 High Projectopia Plugin projectopia-core Privilege Escalation Account Takeover ≤ 5.1.7 Fixed in 5.1.8 CVE-2024-54336 Patchstack
7.1 High ImmoToolBox Connect Plugin immotoolbox-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 Fixed in 1.4.0 CVE-2024-54335 Patchstack
6.5 Medium Quran Phrases About Most People Shortcodes Plugin quran-phrases-about-most-people-shortcodes Cross-Site Scripting ≤ 1.4 Fixed in 1.5 CVE-2024-54334 Patchstack
7.1 High Check Pincode For Woocommerce Plugin check-pincode-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 Fixed in 1.2 CVE-2024-54333 Patchstack
7.2 High Hurrakify Plugin hurrakify Server-Side Request Forgery No login needed ≤ 2.4 Fixed in 8.0.1 CVE-2024-54330 Patchstack
7.1 High CleverNode Related Content Plugin clevernode-related-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-54329 Patchstack
7.1 High Invoice Payment for WooCommerce Plugin invoice-payment-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.2 Fixed in 2.0.0 CVE-2024-54328 Patchstack
7.1 High UNIVERSAM Plugin universam-demo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.59 Fixed in 8.59 CVE-2024-54327 Patchstack
6.5 Medium GEO my Plugin geo-my-wp Broken Access Control ≤ 4.5.0.4 Fixed in 4.5.1 CVE-2024-54326 Patchstack
7.1 High CarDealerPress Plugin cardealerpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.6.2410.02 Fixed in 6.7.2411.00 CVE-2024-54325 Patchstack
7.1 High SMSify Plugin smsify Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.4 Fixed in 6.1.0 CVE-2024-54324 Patchstack
5.4 Medium New User Approve Plugin new-user-approve Broken Access Control ≤ 2.6.2 Fixed in 2.6.4 CVE-2024-54323 Patchstack
7.1 High Media Downloader Plugin media-downloader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.7.4 Fixed in 0.4.7.5 CVE-2024-54322 Patchstack
4.3 Medium Hive Support Plugin hive-support Cross-Site Request Forgery No login needed ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-54321 Patchstack
7.1 High ICDSoft Reseller Store Plugin icdsoft-reseller-store Cross-Site Scripting WordPress ICDSoft Reseller Store plugin<= 2.4.5 -Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 Fixed in 2.5.0 CVE-2024-54320 Patchstack
7.1 High Kundgenerator Plugin kundgenerator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2024-54319 Patchstack
6.5 Medium NiceJob Plugin nicejob Cross-Site Scripting ≤ 3.6.5 Fixed in 3.7.2 CVE-2024-54318 Patchstack
6.5 Medium Web Stories Plugin web-stories Cross-Site Scripting ≤ 1.37.0 Fixed in 1.38.0 CVE-2024-54317 Patchstack
6.5 Medium Restaurant & Cafe Addon for Elementor Plugin restaurant-cafe-addon-for-elementor Cross-Site Scripting ≤ 1.5.8 Fixed in 1.5.9 CVE-2024-54316 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-54315 Patchstack
6.5 Medium Primary Addon for Elementor Plugin primary-addon-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.2 CVE-2024-54314 Patchstack
6.5 Medium FULL Customer Plugin full-customer Local File Inclusion Cliente plugin <= 3.1.25 - Local File Inclusion ≤ 3.1.25 Fixed in 3.1.26 CVE-2024-54313 Patchstack
7.1 High Persian Woocommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.0.5 Fixed in 7.0.6 CVE-2024-54312 Patchstack
5.4 Medium Mark New Posts Plugin mark-new-posts Broken Access Control ≤ 7.5.1 Fixed in 7.6 CVE-2024-54311 Patchstack
5.3 Medium Gou Manage My Account Menu Plugin gou-wc-account-tabs Broken Access Control No login needed ≤ 1.0.1.8 Fixed in 1.0.1.9 CVE-2024-54310 Patchstack
6.5 Medium PostBox Plugin postbox-email-logs Information Disclosure Sensitive Data Exposure ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-54309 Patchstack
5.9 Medium Cryptocurrency Price Widget Plugin cryptocurrency-price-widget Cross-Site Scripting ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-54308 Patchstack
4.3 Medium AIcomments Plugin aicomments Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-54307 Patchstack
4.3 Medium AIKCT Engine Chatbot, ChatGPT, Gemini, GPT-4o Best AI Chatbot Plugin ai-seo-translator Cross-Site Request Forgery No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2024-54306 Patchstack
7.1 High J&T Express Malaysia Plugin jt-express Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 Fixed in 2.0.15 CVE-2024-54305 Patchstack
8.5 High Hive Support Plugin hive-support SQL Injection ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-54304 Patchstack
7.1 High Simple Payment Plugin simple-payment Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.8 Fixed in 2.3.9 CVE-2024-54303 Patchstack
7.1 High VPSUForm Plugin v-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.0 Fixed in 3.0.1 CVE-2024-54302 Patchstack
7.1 High FormFacade Plugin formfacade Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-54301 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Cross-Site Request Forgery No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-54300 Patchstack
7.1 High Revi.io Plugin revi-io-customer-and-product-reviews Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.3 Fixed in 5.8.0 CVE-2024-54299 Patchstack
4.3 Medium Car Dealer Plugin cardealer Broken Access Control ≤ 4.46 Fixed in 4.48 CVE-2024-54298 Patchstack
9.8 Critical vBSSO-lite Plugin vbsso-lite Privilege Escalation Account Takeover No login needed ≤ 1.4.3 CVE-2024-54297 Patchstack
9.8 Critical CoSchool LMS Plugin coschool Privilege Escalation Account Takeover No login needed ≤ 1.4.3 CVE-2024-54296 Patchstack
9.8 Critical ListApp Mobile Manager Plugin listapp-mobile-manager Privilege Escalation Account Takeover No login needed ≤ 1.7.7 CVE-2024-54295 Patchstack
9.8 Critical Firebase OTP Authentication Plugin authentication-via-otp-using-firebase Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2024-54294 Patchstack
9.8 Critical CE21 Suite Plugin ce21-suite Privilege Escalation No login needed ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-54293 Patchstack
9.3 Critical Appsplate Plugin appsplate SQL Injection No login needed ≤ 2.1.3 CVE-2024-54292 Patchstack
7.1 High Role Includer Plugin role-includer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2024-54290 Patchstack
6.5 Medium Awesome Support Plugin awesome-support Broken Access Control ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-54289 Patchstack
7.1 High LDD Directory Lite Plugin ldd-directory-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3 CVE-2024-54288 Patchstack
6.5 Medium Advanced Blog Post Block Plugin advanced-blog-post-block Cross-Site Scripting ≤ 1.0.4 CVE-2024-54287 Patchstack
6.5 Medium Smaily for WP Plugin smaily-for-wp Cross-Site Scripting ≤ 3.1.5 Fixed in 3.1.6 CVE-2024-54286 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only