WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,201–22,250 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 445 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High GPX Viewer Plugin gpx-viewer Broken Access Control Authenticated (Subscriber+) Arbitrary File Creation ≤ 2.2.9 CVE-2024-10629 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Import ≤ 2.2.9 CVE-2024-10854 Wordfence
6.1 Medium AJAX Login and Registration modal popup + inline form Plugin ajax-login-and-registration-modal-popup Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.24 CVE-2024-8874 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Deletion ≤ 2.2.9 CVE-2024-10853 Wordfence
6.5 Medium Styler for Ninja Forms Plugin styler-for-ninja-forms-lite Broken Access Control Authenticated (Subscriber+) Arbitrary Option Deletion via deactivate_license ≤ 3.3.4 CVE-2024-10717 Wordfence
6.1 Medium Razorpay Payment Button for Elementor Plugin razorpay-payment-button-elementor Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.5 CVE-2024-10850 Wordfence
6.1 Medium WP-Strava Plugin Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting No login needed ≤ 2.12.1 CVE-2024-10038 Wordfence
6.1 Medium Constant Contact Forms by MailMunch Plugin constant-contact-forms-by-mailmunch Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.2 CVE-2024-9614 Wordfence
6.4 Medium NiceJob Plugin nicejob Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.7.1 CVE-2024-10887 Wordfence
6.1 Medium Fat Rat Collect Plugin fat-rat-collect Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.3 CVE-2024-10577 Wordfence
6.1 Medium Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.6 CVE-2024-10851 Wordfence
6.4 Medium Social Proof (Testimonials) Slider Plugin social-proof-testimonials-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spslider-block Shortcode ≤ 2.2.4 CVE-2024-8985 Wordfence
5.3 Medium Hide Links Plugin hide-links Arbitrary Shortcode Execution Unauthenticated Shortcode Execution No login needed ≤ 1.4.2 CVE-2024-9578 Wordfence
4.3 Medium Buy one click WooCommerce Plugin buy-one-click-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Export ≤ 2.2.9 CVE-2024-10852 Wordfence
4.3 Medium BuddyPress Builder for Elementor – BuddyBuilder Plugin stax-buddy-builder Information Disclosure BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.7.4 CVE-2024-10778 Wordfence
9.8 Critical Relais 2FA Plugin relais-2fa Authentication Bypass No login needed ≤ 1.0 CVE-2024-10245 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.18 CVE-2024-10323 Wordfence
6.4 Medium Slickstream: Engagement and Conversions Plugin slick-engagement Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slick-grid Shortcode ≤ 1.4.4 CVE-2024-10179 Wordfence
5.9 Medium RSS Feed Widget Plugin rss-feed-widget Cross-Site Scripting Contributor+ Stored XSS < 3.0.0 Fixed in 3.0.0 CVE-2024-9836 WPScan
4.8 Medium RSS Feed Widget Plugin rss-feed-widget Cross-Site Scripting Reflected XSS < 3.0.1 Fixed in 3.0.1 CVE-2024-9835 WPScan
5.4 Medium Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Cross-Site Scripting Authenticated Stored Cross-Site Scripting via SVG ≤ 7.5.1 CVE-2024-10790 Wordfence
6.1 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.12.04 CVE-2024-9357 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison ≤ 3.12.5 CVE-2024-10538 Wordfence
6.1 Medium Contact Form 7 Redirect & Thank You Page Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2024-10685 Wordfence
2.7 Low Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Path Traversal MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion ≤ 4.0.2 CVE-2024-10672 Wordfence
4.3 Medium Futurio Extra Plugin futurio-extra Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.0.13 CVE-2024-10695 Wordfence
6.5 Medium CRM 2go Plugin crm2go Cross-Site Scripting ≤ 1.0 CVE-2024-52350 Patchstack
6.5 Medium BU Slideshow Plugin bu-slideshow Cross-Site Scripting ≤ 2.3.10 CVE-2024-52351 Patchstack
6.5 Medium Postcasa Shortcode Plugin postcasa Cross-Site Scripting ≤ 1.0 CVE-2024-52352 Patchstack
6.5 Medium Christian Science Bible Lesson Subjects Plugin christian-science-bible-lesson-subjects Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-52353 Patchstack
6.5 Medium Web Stories Widgets For Elementor Plugin shortcodes-for-amp-web-stories-and-elementor-widget Cross-Site Scripting ≤ 1.1 Fixed in 1.1.1 CVE-2024-52354 Patchstack
6.5 Medium OSM Plugin osm Cross-Site Scripting OpenStreetMap plugin <= 6.1.2 - Cross Site Scripting (XSS) ≤ 6.1.2 Fixed in 6.1.3 CVE-2024-52355 Patchstack
6.5 Medium The Pack Elementor addons Plugin the-pack-addon Cross-Site Scripting ≤ 2.1.0 Fixed in 2.1.1 CVE-2024-52356 Patchstack
6.5 Medium LIQUID BLOCKS Plugin liquid-blocks Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-52357 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.5.4 Fixed in 1.6.0 CVE-2024-52358 Patchstack
8.5 High L Squared Hub WP Plugin l-squared-hub-wp-virtual-device SQL Injection ≤ 1.0 CVE-2024-51820 Patchstack
8.5 High WP Contest Plugin wp-contest SQL Injection ≤ 1.0.0 CVE-2024-51837 Patchstack
8.5 High Horsemanager Plugin fruitcake-horsemanager SQL Injection ≤ 1.3 CVE-2024-51843 Patchstack
8.5 High Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection ≤ 1.0.2 CVE-2024-51845 Patchstack
8.5 High Gboy Custom Google Map Plugin gboy-custom-google-map SQL Injection ≤ 1.2 CVE-2024-51882 Patchstack
10.0 Critical The Novel Design Store Directory Plugin noveldesign-store-directory Arbitrary File Upload No login needed ≤ 4.3.0 CVE-2024-51788 Patchstack
10.0 Critical Image Classify Plugin image-classify Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-51789 Patchstack
10.0 Critical HB AUDIO GALLERY Plugin hb-audio-gallery Arbitrary File Upload No login needed ≤ 3.0 CVE-2024-51790 Patchstack
10.0 Critical Forms Plugin forms-by-made-it Arbitrary File Upload No login needed ≤ 2.8.0 Fixed in 2.8.1 CVE-2024-51791 Patchstack
10.0 Critical Audio Record Plugin audio-record Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-51792 Patchstack
10.0 Critical RepairBuddy Plugin computer-repair-shop Arbitrary File Upload No login needed ≤ 3.8115 Fixed in 3.8116 CVE-2024-51793 Patchstack
6.5 Medium MasterBip para Elementor Plugin masterbip-for-elementor Cross-Site Scripting ≤ 1.6.3 CVE-2024-51571 Patchstack
6.5 Medium LH QR Codes Plugin lh-qr-codes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.06 CVE-2024-51572 Patchstack
6.5 Medium ML Responsive Audio player with playlist Shortcode Plugin mlr-audio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2 CVE-2024-51573 Patchstack
6.5 Medium Simple Goods Plugin simple-goods Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.1.3 CVE-2024-51574 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only