WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 21,201–21,250 of 29,413 vulnerabilities

Known WordPress vulnerabilities, page 425 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.126 CVE-2024-10784 Wordfence
4.8 Medium LearnPress Plugin learnpress Cross-Site Scripting Admin+ Stored XSS < 4.2.7.2 Fixed in 4.2.7.2 CVE-2024-9881 WPScan
4.8 Medium LuckyWP Table of Contents Plugin luckywp-table-of-contents Cross-Site Scripting Admin+ Stored XSS < 2.1.7 Fixed in 2.1.7 CVE-2024-9641 WPScan
5.4 Medium Kadence Blocks Plugin Cross-Site Scripting Admin+ Stored XSS < 3.2.54 Fixed in 3.2.54 CVE-2024-10637 WPScan
4.7 Medium Ajax Search Lite Plugin ajax-search-lite Cross-Site Scripting Admin+ Stored XSS No login needed < 4.12.4 Fixed in 4.12.4 CVE-2024-10568 WPScan
4.8 Medium Popup Builder Plugin popup-builder Cross-Site Scripting Admin+ Stored XSS < 4.3.5 Fixed in 4.3.5 CVE-2024-9428 WPScan
4.8 Medium ProfilePress Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.15 Fixed in 4.15.15 CVE-2024-10518 WPScan
4.8 Medium ProfilePress Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.15 Fixed in 4.15.15 CVE-2024-10517 WPScan
7.2 High AI-Engine Plugin SQL Injection Admin+ SQLi < 2.6.5 Fixed in 2.6.5 CVE-2024-10499 WPScan
4.8 Medium LearnPress Plugin learnpress Cross-Site Scripting Admin+ Stored XSS < 4.2.7.2 Fixed in 4.2.7.2 CVE-2024-10010 WPScan
4.3 Medium Child Theme Creator by Orbisius Plugin orbisius-child-theme-creator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Cloud Snippet Update/Delete ≤ 1.5.5 CVE-2024-12263 Wordfence
5.3 Medium Web3 Cryptocurrency Payments by DePay for WooCommerce Plugin Broken Access Control Missing Authorization to Information Exposure No login needed ≤ 2.12.17 CVE-2024-12265 Wordfence
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control Missing Authorization to Arbitrary Options Read ≤ 1.3.1 CVE-2024-12059 Wordfence
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed ≤ 3.8.19 CVE-2024-11052 Wordfence
6.4 Medium Integrate Firebase Plugin integrate-firebase Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.9.3 CVE-2024-11785 Wordfence
6.4 Medium WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more Plugin gs-books-showcase Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-11766 Wordfence
5.3 Medium Accept Stripe Payments Using Contact Form 7 Plugin accept-stripe-payments-using-contact-form-7 Information Disclosure Unauthenticated Information Exposure No login needed ≤ 2.5 CVE-2024-12255 Wordfence
6.4 Medium Social Media Shortcodes Plugin social-media-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.0 CVE-2024-11871 Wordfence
6.4 Medium WP GeoNames Plugin wp-geonames Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.0.1 CVE-2024-11757 Wordfence
7.5 High WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Plugin wp-courses Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed ≤ 3.2.21 CVE-2024-12172 Wordfence
6.4 Medium WordPress Portfolio Plugin – A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more Plugin gs-portfolio Cross-Site Scripting A Plugin for Making Filterable Portfolio Grid, Portfolio Slider and more <= 1.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.3 CVE-2024-11765 Wordfence
9.8 Critical Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce Plugin vayu-blocks Broken Access Control Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.1.1 CVE-2024-10124 Wordfence
6.1 Medium Analytics Cat – Google Analytics Made Easy Plugin analytics-cat Cross-Site Scripting Google Analytics Made Easy <= 1.1.2 - Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-12072 Wordfence
4.3 Medium Snippet Shortcodes Plugin shortcode-variables Broken Access Control Authenticated (Subscriber+) Shortcode Deletion ≤ 4.1.6 CVE-2024-12018 Wordfence
6.1 Medium Library Bookshelves Plugin library-bookshelves Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.8 CVE-2024-11359 Wordfence
8.8 High Product Carousel Slider & Grid Ultimate for WooCommerce Plugin woo-product-carousel-slider-and-grid-ultimate Local File Inclusion Authenticated (Contributor+) Local File Inclusion via 'theme' ≤ 1.9.10 CVE-2024-12040 Wordfence
6.4 Medium Smart Agenda – Prise de rendez-vous en ligne Plugin Cross-Site Scripting Prise de rendez-vous en ligne <= 4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.6 CVE-2024-11781 Wordfence
6.4 Medium FAQ And Answers – Create Frequently Asked Questions Area on WP Sites Plugin Cross-Site Scripting Create Frequently Asked Questions Area on WP Sites <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-11882 Wordfence
4.3 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Request Forgery Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update No login needed ≤ 0.4.1 CVE-2024-12526 Wordfence
6.1 Medium BP Email Assign Templates Plugin bp-email-assign-templates Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.5 CVE-2024-12441 Wordfence
4.3 Medium AI Post Generator | AutoWriter Plugin ai-post-generator Broken Access Control Missing Authorization to Authenticated (Contributor+) Post/Page Deletion ≤ 3.5 CVE-2024-11709 Wordfence
6.1 Medium Video & Photo Gallery for Ultimate Member Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2024-12162 Wordfence
6.1 Medium AI Content Writer, RSS Feed to Post, Autoblogging SEO Help Plugin seo-help Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.1.3 CVE-2024-12156 Wordfence
6.1 Medium Planaday API Plugin planaday-api Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 11.4 CVE-2024-11804 Wordfence
6.1 Medium Country Blocker Plugin country-blocker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.2 CVE-2024-11459 Wordfence
6.4 Medium Cognito Forms Plugin cognito-forms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 2.0.7 CVE-2024-10182 Wordfence
6.4 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode ≤ 0.4.1 CVE-2024-12463 Wordfence
6.4 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Scripting Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.3.0 CVE-2024-11384 Wordfence
6.4 Medium Top and footer bars for announcements, notifications, advertisements, promotions – YooBar Plugin yoo-bar Cross-Site Scripting YooBar <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-11410 Wordfence
8.8 High Opt-In Downloads Plugin Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.07 CVE-2024-10590 Wordfence
6.4 Medium Add infos to the events calendar Plugin add-infos-to-the-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-11875 Wordfence
7.3 High Grid Plus – Unlimited grid layout Plugin grid-plus Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed ≤ 1.3.5 CVE-2024-10910 Wordfence
6.5 Medium Library Management System Plugin library-management-system SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 3.2.0 CVE-2024-12406 Wordfence
6.4 Medium Perfect Font Awesome Integration Plugin perfect-font-awesome-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3 CVE-2024-11891 Wordfence
6.4 Medium ONLYOFFICE DocSpace Plugin onlyoffice-docspace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.1 CVE-2024-11750 Wordfence
6.1 Medium kvCORE IDX Plugin kvcore-idx Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.35 CVE-2024-11723 Wordfence
6.1 Medium WP Service Payment Form With Authorize.net Plugin wp-service-payment-form-with-authorizenet Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.6.3 CVE-2024-12258 Wordfence
6.1 Medium Newsletter Subscriptions Plugin newsletter-subscriptions Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1 CVE-2024-11683 Wordfence
6.1 Medium Website Toolbox Community Plugin website-toolbox-forums Cross-Site Scripting Reflected Cross-Site Scripting via websitetoolbox_username No login needed ≤ 2.0.1 CVE-2024-12338 Wordfence
6.1 Medium Ultimate Endpoints With Rest Api Plugin custom-wp-rest-api Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2.2 CVE-2024-12260 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only