WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,001–22,050 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 441 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Adventure Bucket List Plugin adventure-bucket-list Cross-Site Scripting ≤ 1.0.9 CVE-2024-51908 Patchstack
6.5 Medium Featured product by category name Plugin featured-product-by-category-name Cross-Site Scripting ≤ 1.1 CVE-2024-51911 Patchstack
6.5 Medium Assist24 Help Desk Plugin assist24it Cross-Site Scripting ≤ 20150401.2 CVE-2024-51910 Patchstack
6.5 Medium IntelliWidget Elements Plugin intelliwidget-elements Cross-Site Scripting ≤ 2.2.7 CVE-2024-51912 Patchstack
6.5 Medium drop in image slideshow gallery Plugin drop-in-image-slideshow-gallery Cross-Site Scripting ≤ 12.0 CVE-2024-51914 Patchstack
6.5 Medium Mapme Plugin mapme Cross-Site Scripting ≤ 1.3.2 CVE-2024-51913 Patchstack
6.5 Medium Multiple Votes in one page Plugin multiple-votes-in-one-page Cross-Site Scripting ≤ 1.0.4 CVE-2024-51917 Patchstack
6.5 Medium Multifox Plus Plugin multifox-plus Cross-Site Scripting ≤ 1.1.6 CVE-2024-51916 Patchstack
6.5 Medium Map Store Locator Plugin map-store-location Cross-Site Scripting ≤ 1.2.1 CVE-2024-51920 Patchstack
6.5 Medium Pay With Stripe Plugin payments-stripe-gateway Cross-Site Scripting ≤ 1.2.1 CVE-2024-51918 Patchstack
6.5 Medium VP Sitemap Plugin vp-sitemap Cross-Site Scripting ≤ 1.0 CVE-2024-51922 Patchstack
6.5 Medium scrollup Plugin scrollup Cross-Site Scripting ≤ 1.1 CVE-2024-51921 Patchstack
6.5 Medium WP Agenda Plugin wp-agenda Cross-Site Scripting ≤ 2.0 CVE-2024-51924 Patchstack
6.5 Medium Websand Subscription Form Plugin websand-subscription-form Cross-Site Scripting ≤ 1.0.3 CVE-2024-51923 Patchstack
6.5 Medium GreenCon Plugin greencon Cross-Site Scripting ≤ 1.0.1 CVE-2024-51926 Patchstack
6.5 Medium Testimonial Slider Shortcode Plugin testimonial-slider-shortcode Cross-Site Scripting ≤ 1.1.9 CVE-2024-51925 Patchstack
6.5 Medium Rig Elements For Elementor Plugin rig-elements Cross-Site Scripting ≤ 1.0 CVE-2024-51927 Patchstack
6.5 Medium Icon Widget Plugin icon-widget-with-links Cross-Site Scripting ≤ 1.1.0 CVE-2024-51929 Patchstack
6.5 Medium Blocks Post Grid Plugin blocks-post-grid Cross-Site Scripting ≤ 1.0.3 CVE-2024-51928 Patchstack
6.5 Medium AzonBox Plugin azonbox Cross-Site Scripting ≤ 1.1.2 CVE-2024-51931 Patchstack
6.5 Medium Custom URL Shortener Plugin custom-url-shorter Cross-Site Scripting ≤ 0.3.6 CVE-2024-51930 Patchstack
6.5 Medium Cookie Nonsense for YT Plugin yt-cookie-nonsense Cross-Site Scripting ≤ 1.2.0 CVE-2024-51933 Patchstack
6.5 Medium Kings Tab Slider Plugin kings-tab-slider Cross-Site Scripting ≤ 1.0 CVE-2024-51932 Patchstack
6.5 Medium Fast Video and Image Display Plugin fast-video-and-image-display Cross-Site Scripting ≤ 2.5.2 CVE-2024-51935 Patchstack
6.5 Medium Ekiline Block Collection Plugin ekiline-block-collection Cross-Site Scripting ≤ 1.0.5 Fixed in 1.0.7 CVE-2024-51934 Patchstack
6.5 Medium IA Map Analytics Basic Plugin ia-map-analytics-basic Cross-Site Scripting ≤ 20170413 CVE-2024-51937 Patchstack
6.5 Medium ESB Testimonials Plugin esb-testimonials Cross-Site Scripting ≤ 1.0.0 CVE-2024-51936 Patchstack
6.5 Medium Charity Addon for Elementor Plugin charity-addon-for-elementor Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-51938 Patchstack
5.4 Medium HD Quiz – Save Results Light Plugin hd-quiz-save-results-light Broken Access Control Save Results Light plugin <= 0.5 - Broken Access Control ≤ 0.5 Fixed in 0.6 CVE-2024-49689 Patchstack
4.3 Medium WP VR Plugin wpvr Broken Access Control ≤ 8.5.5 Fixed in 8.5.6 CVE-2024-49680 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.2.9 Fixed in 3.2.10 CVE-2024-49697 Patchstack
4.3 Medium Easy Accordion Gutenberg Block Plugin easy-accordion-block Broken Access Control ≤ 1.2.3 Fixed in 1.2.5 CVE-2024-51660 Patchstack
4.3 Medium Bold Page Builder Plugin bold-page-builder Broken Access Control ≤ 5.1.3 Fixed in 5.1.4 CVE-2024-50417 Patchstack
5.4 Medium Combo WP Rewrite Slugs Plugin combo-wp-rewrite-slugs Broken Access Control Settings Change ≤ 1.0 CVE-2024-51817 Patchstack
2.7 Low Otter - Gutenberg Block Plugin otter-blocks Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-51671 Patchstack
5.3 Medium Floating Buttons for WooCommerce Plugin shop-assistant-for-woocommerce-jarvis Broken Access Control No login needed ≤ 2.8.8 Fixed in 2.9.2 CVE-2024-52395 Patchstack
6.1 Medium Ashe Theme ashe Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 2.243 CVE-2024-9777 Wordfence
6.1 Medium Bard Theme bard Cross-Site Scripting Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 2.216 CVE-2024-9830 Wordfence
6.4 Medium GD Rating System Plugin gd-rating-system Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via extra_class Parameter ≤ 3.6.1 CVE-2024-11198 Wordfence
6.4 Medium Parallax Image Plugin parallax-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via position Parameter ≤ 1.9 CVE-2024-11224 Wordfence
8.8 High Classified Listing – Classified ads & Business Directory Plugin classified-listing Broken Access Control Classified ads & Business Directory Plugin <= 3.1.15.1 - Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 3.1.15.1 CVE-2024-11194 Wordfence
6.4 Medium Email Subscription Popup Plugin email-subscribe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via print_email_subscribe_form Shortcode ≤ 1.2.22 CVE-2024-11195 Wordfence
7.3 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin gamipress Arbitrary Shortcode Execution The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings No login needed ≤ 7.1.5 CVE-2024-11036 Wordfence
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
7.2 High WordPress GDPR Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.2 CVE-2024-10388 Wordfence
6.5 Medium WordPress GDPR Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary User Deletion No login needed ≤ 2.0.2 CVE-2024-11069 Wordfence
6.4 Medium MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting Music Player, Podcast Player & Radio by Sonaar <= 5.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode ≤ 5.8 CVE-2024-10268 Wordfence
5.5 Medium SVG Block Plugin svg-block Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.24 CVE-2024-11098 Wordfence
6.1 Medium MailPoet Plugin mailpoet Cross-Site Scripting Admin+ Stored XSS No login needed < 5.3.2 Fixed in 5.3.2 CVE-2024-10103 WPScan
6.5 Medium Stylish Internal Links Plugin stylish-internal-links Cross-Site Scripting ≤ 1.9 CVE-2024-51939 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only