WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,101–22,150 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 443 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.8 Critical Airin Blog Plugin airin-blog PHP Object Injection No login needed ≤ 1.6.1 Fixed in 1.6.3 CVE-2024-52413 Patchstack
9.8 Critical WDES Responsive Mobile Menu Plugin wdes-responsive-mobile-menu PHP Object Injection No login needed ≤ 5.3.18 CVE-2024-52414 Patchstack
5.3 Medium Classified Listing Plugin classified-listing Local File Inclusion ≤ 3.1.16 Fixed in 3.1.17 CVE-2024-52386 Patchstack
8.8 High SK WP Settings Backup Plugin sk-wp-settings-backup Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 1.0 CVE-2024-52415 Patchstack
10.0 Critical Debug Tool Plugin debug-tool Remote Code Execution No login needed ≤ 2.2 CVE-2024-52416 Patchstack
5.3 Medium 404 Solution Plugin 404-solution Information Disclosure Missing Authentication to Sensitive Information Exposure No login needed ≤ 2.35.17 CVE-2024-11094 Wordfence
6.4 Medium Mapster WP Maps Plugin mapster-wp-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.0 CVE-2024-10592 Wordfence
7.2 High Login using WordPress Users ( WP as SAML IDP ) Plugin miniorange-wp-as-saml-idp SQL Injection Authenticated (Administrator+) SQL Injection ≤ 1.15.6 CVE-2024-9887 Wordfence
7.5 High Blogger 301 Redirect Plugin blogger-301-redirect SQL Injection Unauthenticated SQL Injection via br No login needed ≤ 2.5.3 CVE-2024-10645 Wordfence
4.3 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Import Cancellation ≤ 5.61.0 CVE-2024-10614 Wordfence
8.8 High PostX Plugin ultimate-post Broken Access Control Missing Authorization to Arbitrary Plugin Installation/Activation ≤ 4.1.16 CVE-2024-10728 Wordfence
9.8 Critical Backup and Staging by WP Time Capsule Plugin wp-time-capsule Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.22.21 CVE-2024-8856 Wordfence
4.3 Medium WP Chat App Plugin wp-whatsapp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Filebird Plugin Installation ≤ 3.6.8 CVE-2024-10533 Wordfence
6.3 Medium Drop Shadow Boxes Plugin drop-shadow-boxes Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 1.7.14 CVE-2024-10262 Wordfence
7.3 High Uix Slideshow Plugin uix-slideshow Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.5 CVE-2024-9839 Wordfence
5.4 Medium WP Log Viewer Plugin wp-log-viewer Broken Access Control Missing Authorization ≤ 1.2.1 CVE-2024-11085 Wordfence
6.1 Medium PeproDev WooCommerce Receipt Uploader Plugin pepro-bacs-receipt-upload-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.6.9 CVE-2024-8873 Wordfence
6.1 Medium Bounce Handler MailPoet 3 Plugin bounce-handler-mailpoet Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3.21 CVE-2024-9938 Wordfence
6.4 Medium SVG Case Study Plugin case-study Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9850 Wordfence
6.4 Medium ConvertCalculator Plugin convertcalculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id and type Parameter ≤ 1.1.1 CVE-2024-10015 Wordfence
4.3 Medium EleForms – All In One Form Integration including DB for Elementor Plugin all-contact-form-integration-for-elementor Cross-Site Request Forgery All In One Form Integration including DB for Elementor <= 2.9.9.9 - Cross-Site Request Forgery No login needed ≤ 2.9.9.9 CVE-2024-6628 Wordfence
6.4 Medium Steel Plugin steel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via btn Shortcode ≤ 1.3.0 CVE-2024-10147 Wordfence
6.1 Medium BulkPress Plugin bulkpress Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.3.5 CVE-2024-9615 Wordfence
6.4 Medium SVGPlus Plugin svgplus Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.0 CVE-2024-11092 Wordfence
6.4 Medium Exclusive Divi – Divi Preloader, Modules for Divi & Extra Plugin exclusive-divi Cross-Site Scripting Divi Preloader, Modules for Divi & Extra Theme <= 1.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.4 CVE-2024-9386 Wordfence
5.3 Medium 404 Error Monitor Plugin 404-error-monitor Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update via updatePluginSettings Function No login needed ≤ 1.1 CVE-2024-11118 Wordfence
6.1 Medium Gallery Manager Plugin fancy-gallery Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.58 CVE-2024-10875 Wordfence
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 2.0.0 CVE-2024-9935 Wordfence
6.4 Medium PJW Mime Config Plugin pjw-mime-config Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-10017 Wordfence
8.8 High WP Video Robot Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via User Meta Update ≤ 1.20.0 CVE-2024-9192 Wordfence
8.8 High Real3D Flipbook Lite – 3D FlipBook, PDF Viewer, PDF Embedder Plugin real3d-flipbook-lite Arbitrary File Upload Authenticated (Author+) Arbitrary File Upload ≤ 4.8 CVE-2024-9849 Wordfence
6.1 Medium SimpleForm Contact Form Submissions Plugin simpleform-contact-form-submissions Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.0 CVE-2024-10884 Wordfence
6.1 Medium SimpleForm – Contact form made simple Plugin simpleform Cross-Site Scripting Contact form made simple <= 2.2.0 - Reflected Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-10883 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Cache Clearing ≤ 2.7.11 CVE-2024-10786 Wordfence
5.3 Medium Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Plugin ays-popup-box Broken Access Control Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update No login needed ≤ 4.9.7 CVE-2024-10861 Wordfence
4.3 Medium Popularis Extra Plugin popularis-extra Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 1.2.7 CVE-2024-10795 Wordfence
7.5 High External Database Based Actions Plugin external-database-based-actions Authentication Bypass Authenticated (Subscriber+) Authentication Bypass ≤ 0.1 CVE-2024-10311 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
5.7 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 6.0.9 CVE-2024-8978 Wordfence
6.1 Medium Hide My WP Ghost – Security & Firewall Plugin hide-my-wp Cross-Site Scripting Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL No login needed ≤ 5.3.01 CVE-2024-10825 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.7 CVE-2024-8961 Wordfence
6.6 Medium Secure Custom Fields Plugin secure-custom-fields Remote Code Execution Admin+ Remote Code Execution 6.3.7 – < 6.3.9, < 6.3.6.3, < 6.3.9 Fixed in 6.3.9 CVE-2024-9529 WPScan
5.9 Medium Jobs Plugin Cross-Site Scripting Contributor+ Stored XSS < 2.7.8 Fixed in 2.7.8 CVE-2024-10104 WPScan
7.2 High WP Activity Log Plugin wp-security-audit-log Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via User_id Parameter No login needed ≤ 5.2.1 CVE-2024-10793 Wordfence
7.2 High Tripetto Plugin tripetto Cross-Site Scripting Unauthentiated Stored Cross-Site Scripting via Form File Upload No login needed ≤ 8.0.11 CVE-2024-10260 Wordfence
4.3 Medium Music Player for Elementor – Audio Player & Podcast Player Plugin music-player-for-elementor Broken Access Control Audio Player & Podcast Player <= 2.4.1 - Missing Authorization to Authenticated (Subscriber+) Template Import ≤ 2.4.1 CVE-2024-10582 Wordfence
6.1 Medium Yotpo: Product & Photo Reviews for WooCommerce Plugin yotpo-social-reviews-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.9 CVE-2024-9356 Wordfence
6.4 Medium WP AdCenter – Ad Manager & Adsense Ads Plugin wpadcenter Cross-Site Scripting Ad Manager & Adsense Ads <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpadcenter_ad Shortcode ≤ 2.5.7 CVE-2024-10113 Wordfence
6.1 Medium LearnPress Export Import – WordPress extension for LearnPress Plugin learnpress-import-export Cross-Site Scripting WordPress extension for LearnPress <= 4.0.4 - Reflected Cross-Site Scripting No login needed ≤ 4.0.4 CVE-2024-9609 Wordfence
4.3 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation ≤ 2.1.5 CVE-2024-10897 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only