WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 21,551–21,600 of 29,314 vulnerabilities

Known WordPress vulnerabilities, page 432 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Chameleoni Jobs Plugin chameleon-jobs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-52459 Patchstack
7.1 High TM Islamic Helper Plugin tm-islamic-helper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52458 Patchstack
7.1 High AtaraPay WooCommerce Payment Gateway Plugin atarapay-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.13 CVE-2024-52460 Patchstack
7.1 High WP e-Commerce Style Email Plugin wp-e-commerce-style-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.2 CVE-2024-52462 Patchstack
7.1 High Infinite Slider Plugin infinite-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-52461 Patchstack
7.1 High amr shortcodes Plugin amr-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7 CVE-2024-52464 Patchstack
7.1 High Post By Email Plugin post-by-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4b CVE-2024-52463 Patchstack
7.1 High Explara Events Plugin explara-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2024-52466 Patchstack
7.1 High LGPD Framework Plugin lgpd-framework Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.2 CVE-2024-52465 Patchstack
7.1 High LeadBoxer Plugin leadboxer Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2024-52468 Patchstack
7.1 High AI Responsive Gallery Album Plugin ai-responsive-gallery-album Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-52467 Patchstack
7.1 High WooCommerce Price Alert Plugin price-alert-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2024-52469 Patchstack
7.1 High Document & Data Automation Plugin document-data-automation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-52477 Patchstack
10.0 Critical Fediverse Embeds Plugin fediverse-embeds Arbitrary File Upload No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-52476 Patchstack
4.3 Medium Jobify Theme jobify Cross-Site Request Forgery No login needed ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52479 Patchstack
6.5 Medium Jobify Theme jobify Cross-Site Scripting ≤ 4.3.0 Fixed in 4.3.0 CVE-2024-52478 Patchstack
7.1 High LeanPress Plugin leanpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2024-52483 Patchstack
7.1 High Ortto Plugin autopilot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.19 Fixed in 1.0.21 CVE-2024-52482 Patchstack
6.5 Medium Elementor Portfolio Builder Plugin portfolio-builder-elementor Cross-Site Scripting ≤ 1.0.0 CVE-2024-52486 Patchstack
7.1 High Wc Recently viewed products Plugin wc-recently-viewed-products Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2024-52484 Patchstack
6.5 Medium Ultimate Classified Listings Plugin ultimate-classified-listings Cross-Site Scripting ≤ 1.7 CVE-2024-52487 Patchstack
5.9 Medium Sticky Social Icons Plugin sticky-social-icons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 CVE-2024-52491 Patchstack
5.9 Medium Add Chat App Button Plugin add-whatsapp-button Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.8 CVE-2024-52489 Patchstack
5.9 Medium Meteor Slides Plugin meteor-slides Cross-Site Scripting ≤ 1.5.7 CVE-2024-52493 Patchstack
5.9 Medium Image horizontal reel scroll slideshow Plugin image-horizontal-reel-scroll-slideshow Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 13.4 CVE-2024-52492 Patchstack
6.5 Medium ImbaChat Plugin imbachat-widget Cross-Site Scripting ≤ 3.1.4 CVE-2024-52502 Patchstack
5.9 Medium Dynamic "To Top Plugin dynamic-to-top Cross-Site Scripting 3.5.2 CVE-2024-52494 Patchstack
6.5 Medium Tailored Tools Plugin tailored-tools Cross-Site Scripting ≤ 1.8.4 CVE-2024-52503 Patchstack
5.3 Medium AI Quiz Plugin ai-quiz Broken Access Control No login needed ≤ 1.1 CVE-2024-53708 Patchstack
4.3 Medium Ahmeti Wp Güzel Sözler Plugin ahmeti-wp-guzel-sozler Cross-Site Request Forgery No login needed ≤ 4.0 CVE-2024-53707 Patchstack
7.1 High ITERAS Plugin iteras Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.8.0 Fixed in 1.8.1 CVE-2024-53710 Patchstack
6.5 Medium Generic Elements Plugin generic-elements-for-elementor Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-53709 Patchstack
7.1 High Kevin's Plugin kevins-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 CVE-2024-53712 Patchstack
7.1 High Hotlink2Watermark Plugin hotlink2watermark Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2024-53711 Patchstack
7.1 High Continue Shopping From Cart Plugin continue-shopping-from-cart-page Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2024-53714 Patchstack
7.1 High Silverlight Video Player Plugin smooth-streaming-player Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2024-53713 Patchstack
7.1 High wp auto top Plugin wp-auto-top Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.9.3 CVE-2024-53716 Patchstack
7.1 High Simple Travel Map Plugin simple-travel-map Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-53715 Patchstack
7.1 High Multi Feed Reader Plugin multi-feed-reader Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.2.4 CVE-2024-53718 Patchstack
7.1 High yPHPlista Plugin yphplista Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-53717 Patchstack
7.1 High Zajax – Ajax Navigation Plugin zajax-ajax-navigation Cross-Site Request Forgery Ajax Navigation plugin <= 0.4 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.4 CVE-2024-53719 Patchstack
6.5 Medium Advanced Event Manager Plugin advanced-event-manager Cross-Site Scripting ≤ 1.1.6 CVE-2024-53721 Patchstack
7.1 High WP-ISPConfig 3 Plugin wp-ispconfig3 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.6 CVE-2024-53720 Patchstack
7.1 High Google Plus Share and +1 Button Plugin google-plus-share-and-plusone-button Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-53723 Patchstack
7.1 High Favicon My Blog Plugin favicon-my-blog Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53722 Patchstack
7.1 High Post Hits Counter Plugin hits-counter Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.23 CVE-2024-53725 Patchstack
7.1 High IceStats Plugin icestats Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-53724 Patchstack
7.1 High LinkLaunder SEO Plugin linklaunder-seo-plugin Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 0.92.1 CVE-2024-53727 Patchstack
7.1 High RealtyCandy IDX Broker Extended Plugin realtycandy-idx-broker-extended Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2024-53726 Patchstack
7.1 High Protect Your Content Plugin protect-your-content Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53728 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only