WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,051–22,100 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 442 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP Responsive Video Plugin my-wp-responsive-video Cross-Site Scripting ≤ 1.0 CVE-2024-51940 Patchstack
6.5 Medium Mage Front End Forms Plugin mage-forms Cross-Site Scripting ≤ 1.1.4 CVE-2024-52339 Patchstack
6.5 Medium Photographer Connections Plugin photographer-connections Cross-Site Scripting ≤ 1.3.1 CVE-2024-52340 Patchstack
6.5 Medium OS Our Team Plugin os-our-team Cross-Site Scripting ≤ 1.7 CVE-2024-52341 Patchstack
6.5 Medium OS BXSlider Plugin os-bxslider Cross-Site Scripting ≤ 2.6 CVE-2024-52342 Patchstack
6.5 Medium OS Pricing Tables Plugin os-pricing-tables Cross-Site Scripting ≤ 1.2 CVE-2024-52343 Patchstack
6.5 Medium Provide Forex Signals Plugin provide-forex-signals Cross-Site Scripting ≤ 1.0 CVE-2024-52344 Patchstack
6.5 Medium ra_qrcode Plugin ra-qrcode Cross-Site Scripting ≤ 2.1.0 CVE-2024-52345 Patchstack
6.5 Medium SimpleGMaps Plugin simplegmaps Cross-Site Scripting ≤ 1.0 CVE-2024-52346 Patchstack
6.5 Medium Website remote Install vor Gravity, WPForms, Formidable, Ninja, Caldera Plugin wp-website-creator Cross-Site Scripting ≤ 4.0 CVE-2024-52347 Patchstack
6.5 Medium AA Audio Player Plugin aa-audio-player Cross-Site Scripting ≤ 1.0 CVE-2024-52348 Patchstack
6.5 Medium Awesome Tool Tip Plugin awesome-tool-tip Cross-Site Scripting ≤ 1.0 CVE-2024-52349 Patchstack
5.3 Medium Google for WooCommerce Plugin google-listings-and-ads Information Disclosure Information Disclosure via Publicly Accessible PHP Info File No login needed ≤ 2.8.6 CVE-2024-10486 Wordfence
6.5 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-52389 Patchstack
4.9 Medium CYAN Backup Plugin cyan-backup Path Traversal Arbitrary File Download ≤ 2.5.3 Fixed in 2.5.4 CVE-2024-52390 Patchstack
6.5 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.6 Fixed in 1.2.0 CVE-2024-52394 Patchstack
7.1 High ReConstruction Plugin reconstruction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.7 CVE-2024-52417 Patchstack
7.1 High Gameplan Plugin gameplan Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.10 CVE-2024-52418 Patchstack
6.4 Medium Elfsight Telegram Chat CC Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2024-10390 Wordfence
6.5 Medium Copy Anything to Clipboard Plugin copy-the-code Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2024-52419 Patchstack
6.5 Medium WP Githuber MD Plugin wp-githuber-md Cross-Site Scripting ≤ 1.16.3 CVE-2024-52422 Patchstack
6.5 Medium Themify Builder Plugin themify-builder Cross-Site Scripting ≤ 7.6.5 Fixed in 7.6.6 CVE-2024-52423 Patchstack
7.1 High wp-login customizer Plugin wp-login-customizer Cross-Site Scripting No login needed ≤ 1.0 CVE-2024-52424 Patchstack
6.5 Medium Drozd – Addons for Elementor Plugin drozd-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-52425 Patchstack
6.5 Medium Linear Plugin linear Cross-Site Scripting ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-52426 Patchstack
9.3 Critical WordPress Video Robot - The Ultimate Video Importer Plugin SQL Injection No login needed ≤ 1.20.0 CVE-2024-52431 Patchstack
7.6 High WPDM – Premium Packages Plugin wpdm-premium-packages SQL Injection Sell Digital Products Securely plugin <= 6.0.5 - SQL Injection ≤ 6.0.5 Fixed in 6.0.6 CVE-2024-52435 Patchstack
7.6 High Post SMTP Plugin post-smtp SQL Injection ≤ 2.9.9 Fixed in 2.9.10 CVE-2024-52436 Patchstack
8.1 High Ads Booster by Ads Pro Plugin free-wp-booster-by-ads-pro Local File Inclusion No login needed ≤ 1.12 CVE-2024-52428 Patchstack
9.8 Critical Lis Video Gallery Plugin lis-video-gallery PHP Object Injection No login needed ≤ 0.2.1 CVE-2024-52430 Patchstack
9.8 Critical NIX Anti-Spam Light Plugin nix-anti-spam-light PHP Object Injection No login needed ≤ 0.0.4 CVE-2024-52432 Patchstack
9.8 Critical My Geo Posts Free Plugin my-geo-posts-free PHP Object Injection No login needed ≤ 1.2 CVE-2024-52433 Patchstack
9.9 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution ≤ 2.3.11 Fixed in 2.3.12 CVE-2024-52427 Patchstack
9.9 Critical WP Quick Setup Plugin wp-quick-setup Remote Code Execution Arbitrary Plugin and Theme Installation to Remote Code Execution ≤ 2.0 CVE-2024-52429 Patchstack
9.1 Critical Popup by Supsystic Plugin popup-by-supsystic Remote Code Execution ≤ 1.10.29 Fixed in 1.10.30 CVE-2024-52434 Patchstack
3.8 Low CM Table Of Contents – WordPress TOC Plugin Cross-Site Request Forgery WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF < 1.2.3 Fixed in 1.2.3 CVE-2024-5030 WPScan
9.1 Critical Convert Docx2post Plugin convert-docx2post Arbitrary File Upload ≤ 1.4 CVE-2024-52397 Patchstack
9.1 Critical CDI Plugin collect-and-deliver-interface-for-woocommerce Arbitrary File Upload ≤ 5.5.3 Fixed in 5.5.6 CVE-2024-52398 Patchstack
9.9 Critical Writer Helper Plugin writer-helper Arbitrary File Upload ≤ 3.1.6 CVE-2024-52399 Patchstack
9.9 Critical Gallerio Plugin gallerio Arbitrary File Upload ≤ 1.01 CVE-2024-52400 Patchstack
9.9 Critical User Management Plugin user-management Arbitrary File Upload ≤ 1.1 Fixed in 1.2 CVE-2024-52403 Patchstack
9.9 Critical CF7 Reply Manager Plugin cf7-reply-manager Arbitrary File Upload ≤ 1.2.3 CVE-2024-52404 Patchstack
9.9 Critical B-Banner Slider Plugin b-banner-slider Arbitrary File Upload ≤ 1.1 CVE-2024-52405 Patchstack
9.9 Critical CSV to html Plugin csv-to-html Arbitrary File Upload ≤ 3.26 Fixed in 3.27 CVE-2024-52406 Patchstack
9.9 Critical BasePress Migration Tools Plugin basepress-migration-tools Arbitrary File Upload ≤ 1.0.0 CVE-2024-52407 Patchstack
9.9 Critical Push Notifications for WordPress by PushAssist Plugin push-notification-for-wp-by-pushassist Arbitrary File Upload ≤ 3.0.8 CVE-2024-52408 Patchstack
9.8 Critical AJAX Random Posts Plugin ajax-random-posts PHP Object Injection No login needed ≤ 0.3.3 CVE-2024-52409 Patchstack
9.8 Critical Referrer Detector Plugin referrer-detector PHP Object Injection No login needed ≤ 4.2.1.0 CVE-2024-52410 Patchstack
9.8 Critical Advanced Personalization Plugin personalization-by-flowcraft PHP Object Injection No login needed ≤ 1.1.2 CVE-2024-52411 Patchstack
9.8 Critical Xin Theme xin PHP Object Injection No login needed ≤ 1.0.8.1 CVE-2024-52412 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only