WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 21,201–21,250 of 29,413 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5.126 |
CVE-2024-10784 |
Wordfence | |
| 4.8 Medium | LearnPress | Cross-Site Scripting Admin+ Stored XSS |
< 4.2.7.2 Fixed in 4.2.7.2 |
CVE-2024-9881 |
WPScan | |
| 4.8 Medium | LuckyWP Table of Contents | Cross-Site Scripting Admin+ Stored XSS |
< 2.1.7 Fixed in 2.1.7 |
CVE-2024-9641 |
WPScan | |
| 5.4 Medium | Kadence Blocks | Cross-Site Scripting Admin+ Stored XSS |
< 3.2.54 Fixed in 3.2.54 |
CVE-2024-10637 |
WPScan | |
| 4.7 Medium | Ajax Search Lite | Cross-Site Scripting Admin+ Stored XSS No login needed |
< 4.12.4 Fixed in 4.12.4 |
CVE-2024-10568 |
WPScan | |
| 4.8 Medium | Popup Builder | Cross-Site Scripting Admin+ Stored XSS |
< 4.3.5 Fixed in 4.3.5 |
CVE-2024-9428 |
WPScan | |
| 4.8 Medium | ProfilePress | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.15 Fixed in 4.15.15 |
CVE-2024-10518 |
WPScan | |
| 4.8 Medium | ProfilePress | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.15 Fixed in 4.15.15 |
CVE-2024-10517 |
WPScan | |
| 7.2 High | AI-Engine | SQL Injection Admin+ SQLi |
< 2.6.5 Fixed in 2.6.5 |
CVE-2024-10499 |
WPScan | |
| 4.8 Medium | LearnPress | Cross-Site Scripting Admin+ Stored XSS |
< 4.2.7.2 Fixed in 4.2.7.2 |
CVE-2024-10010 |
WPScan | |
| 4.3 Medium | Child Theme Creator by Orbisius | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete |
≤ 1.5.5 |
CVE-2024-12263 |
Wordfence | |
| 5.3 Medium | Web3 Cryptocurrency Payments by DePay for WooCommerce | Broken Access Control Missing Authorization to Information Exposure No login needed |
≤ 2.12.17 |
CVE-2024-12265 |
Wordfence | |
| 4.3 Medium | ElementInvader Addons for Elementor | Broken Access Control Missing Authorization to Arbitrary Options Read |
≤ 1.3.1 |
CVE-2024-12059 |
Wordfence | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed |
≤ 3.8.19 |
CVE-2024-11052 |
Wordfence | |
| 6.4 Medium | Integrate Firebase | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.9.3 |
CVE-2024-11785 |
Wordfence | |
| 6.4 Medium | WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-11766 |
Wordfence | |
| 5.3 Medium | Accept Stripe Payments Using Contact Form 7 | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 2.5 |
CVE-2024-12255 |
Wordfence | |
| 6.4 Medium | Social Media Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.0 |
CVE-2024-11871 |
Wordfence | |
| 6.4 Medium | WP GeoNames | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.0.1 |
CVE-2024-11757 |
Wordfence | |
| 7.5 High | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses | Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed |
≤ 3.2.21 |
CVE-2024-12172 |
Wordfence | |
| 6.4 Medium | WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more | Cross-Site Scripting A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.3 |
CVE-2024-11765 |
Wordfence | |
| 9.8 Critical | Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce | Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed |
≤ 1.1.1 |
CVE-2024-10124 |
Wordfence | |
| 6.1 Medium | Analytics Cat – Google Analytics Made Easy | Cross-Site Scripting Google Analytics Made Easy <= 1.1.2 - Reflected Cross-Site Scripting No login needed |
≤ 1.1.2 |
CVE-2024-12072 |
Wordfence | |
| 4.3 Medium | Snippet Shortcodes | Broken Access Control Authenticated (Subscriber+) Shortcode Deletion |
≤ 4.1.6 |
CVE-2024-12018 |
Wordfence | |
| 6.1 Medium | Library Bookshelves | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.8 |
CVE-2024-11359 |
Wordfence | |
| 8.8 High | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' |
≤ 1.9.10 |
CVE-2024-12040 |
Wordfence | |
| 6.4 Medium | Smart Agenda – Prise de rendez-vous en ligne | Cross-Site Scripting Prise de rendez-vous en ligne <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.6 |
CVE-2024-11781 |
Wordfence | |
| 6.4 Medium | FAQ And Answers – Create Frequently Asked Questions Area on WP Sites | Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1.0 |
CVE-2024-11882 |
Wordfence | |
| 4.3 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Request Forgery Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 0.4.1 |
CVE-2024-12526 |
Wordfence | |
| 6.1 Medium | BP Email Assign Templates | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5 |
CVE-2024-12441 |
Wordfence | |
| 4.3 Medium | AI Post Generator | AutoWriter | Broken Access Control Missing Authorization to Authenticated (Contributor+) Post/Page Deletion |
≤ 3.5 |
CVE-2024-11709 |
Wordfence | |
| 6.1 Medium | Video & Photo Gallery for Ultimate Member | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.1 |
CVE-2024-12162 |
Wordfence | |
| 6.1 Medium | AI Content Writer, RSS Feed to Post, Autoblogging SEO Help | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 6.1.3 |
CVE-2024-12156 |
Wordfence | |
| 6.1 Medium | Planaday API | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 11.4 |
CVE-2024-11804 |
Wordfence | |
| 6.1 Medium | Country Blocker | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.2 |
CVE-2024-11459 |
Wordfence | |
| 6.4 Medium | Cognito Forms | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 2.0.7 |
CVE-2024-10182 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode |
≤ 0.4.1 |
CVE-2024-12463 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.3.0 |
CVE-2024-11384 |
Wordfence | |
| 6.4 Medium | Top and footer bars for announcements, notifications, advertisements, promotions – YooBar | Cross-Site Scripting YooBar <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.6 |
CVE-2024-11410 |
Wordfence | |
| 8.8 High | Opt-In Downloads | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 4.07 |
CVE-2024-10590 |
Wordfence | |
| 6.4 Medium | Add infos to the events calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-11875 |
Wordfence | |
| 7.3 High | Grid Plus – Unlimited grid layout | Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed |
≤ 1.3.5 |
CVE-2024-10910 |
Wordfence | |
| 6.5 Medium | Library Management System | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 3.2.0 |
CVE-2024-12406 |
Wordfence | |
| 6.4 Medium | Perfect Font Awesome Integration | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3 |
CVE-2024-11891 |
Wordfence | |
| 6.4 Medium | ONLYOFFICE DocSpace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.1 |
CVE-2024-11750 |
Wordfence | |
| 6.1 Medium | kvCORE IDX | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3.35 |
CVE-2024-11723 |
Wordfence | |
| 6.1 Medium | WP Service Payment Form With Authorize.net | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.6.3 |
CVE-2024-12258 |
Wordfence | |
| 6.1 Medium | Newsletter Subscriptions | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1 |
CVE-2024-11683 |
Wordfence | |
| 6.1 Medium | Website Toolbox Community | Cross-Site Scripting Reflected Cross-Site Scripting via websitetoolbox_username No login needed |
≤ 2.0.1 |
CVE-2024-12338 |
Wordfence | |
| 6.1 Medium | Ultimate Endpoints With Rest Api | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.2.2 |
CVE-2024-12260 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.