WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 22,201–22,250 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.8 High | GPX Viewer | Broken Access Control Authenticated (Subscriber+) Arbitrary File Creation |
≤ 2.2.9 |
CVE-2024-10629 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Import |
≤ 2.2.9 |
CVE-2024-10854 |
Wordfence | |
| 6.1 Medium | AJAX Login and Registration modal popup + inline form | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.24 |
CVE-2024-8874 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Order Deletion |
≤ 2.2.9 |
CVE-2024-10853 |
Wordfence | |
| 6.5 Medium | Styler for Ninja Forms | Broken Access Control Authenticated (Subscriber+) Arbitrary Option Deletion via deactivate_license |
≤ 3.3.4 |
CVE-2024-10717 |
Wordfence | |
| 6.1 Medium | Razorpay Payment Button for Elementor | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.5 |
CVE-2024-10850 |
Wordfence | |
| 6.1 Medium | WP-Strava | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting No login needed |
≤ 2.12.1 |
CVE-2024-10038 |
Wordfence | |
| 6.1 Medium | Constant Contact Forms by MailMunch | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.2 |
CVE-2024-9614 |
Wordfence | |
| 6.4 Medium | NiceJob | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.7.1 |
CVE-2024-10887 |
Wordfence | |
| 6.1 Medium | Fat Rat Collect | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-10577 |
Wordfence | |
| 6.1 Medium | Razorpay Payment Button | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.4.6 |
CVE-2024-10851 |
Wordfence | |
| 6.4 Medium | Social Proof (Testimonials) Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via spslider-block Shortcode |
≤ 2.2.4 |
CVE-2024-8985 |
Wordfence | |
| 5.3 Medium | Hide Links | Arbitrary Shortcode Execution Unauthenticated Shortcode Execution No login needed |
≤ 1.4.2 |
CVE-2024-9578 |
Wordfence | |
| 4.3 Medium | Buy one click WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Export |
≤ 2.2.9 |
CVE-2024-10852 |
Wordfence | |
| 4.3 Medium | BuddyPress Builder for Elementor – BuddyBuilder | Information Disclosure BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclosure |
≤ 1.7.4 |
CVE-2024-10778 |
Wordfence | |
| 9.8 Critical | Relais 2FA | Authentication Bypass No login needed |
≤ 1.0 |
CVE-2024-10245 |
Wordfence | |
| 6.4 Medium | JetWidgets For Elementor | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.18 |
CVE-2024-10323 |
Wordfence | |
| 6.4 Medium | Slickstream: Engagement and Conversions | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slick-grid Shortcode |
≤ 1.4.4 |
CVE-2024-10179 |
Wordfence | |
| 5.9 Medium | RSS Feed Widget | Cross-Site Scripting Contributor+ Stored XSS |
< 3.0.0 Fixed in 3.0.0 |
CVE-2024-9836 |
WPScan | |
| 4.8 Medium | RSS Feed Widget | Cross-Site Scripting Reflected XSS |
< 3.0.1 Fixed in 3.0.1 |
CVE-2024-9835 |
WPScan | |
| 5.4 Medium | Admin and Site Enhancements (ASE) | Cross-Site Scripting Authenticated Stored Cross-Site Scripting via SVG |
≤ 7.5.1 |
CVE-2024-10790 |
Wordfence | |
| 6.1 Medium | xili-tidy-tags | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.12.04 |
CVE-2024-9357 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison |
≤ 3.12.5 |
CVE-2024-10538 |
Wordfence | |
| 6.1 Medium | Contact Form 7 Redirect & Thank You Page | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.6 |
CVE-2024-10685 |
Wordfence | |
| 2.7 Low | Multiple Page Generator Plugin – MPG | Path Traversal MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion |
≤ 4.0.2 |
CVE-2024-10672 |
Wordfence | |
| 4.3 Medium | Futurio Extra | Information Disclosure Authenticated (Contributor+) Post Disclosure |
≤ 2.0.13 |
CVE-2024-10695 |
Wordfence | |
| 6.5 Medium | CRM 2go | Cross-Site Scripting |
≤ 1.0 |
CVE-2024-52350 |
Patchstack | |
| 6.5 Medium | BU Slideshow | Cross-Site Scripting |
≤ 2.3.10 |
CVE-2024-52351 |
Patchstack | |
| 6.5 Medium | Postcasa Shortcode | Cross-Site Scripting |
≤ 1.0 |
CVE-2024-52352 |
Patchstack | |
| 6.5 Medium | Christian Science Bible Lesson Subjects | Cross-Site Scripting |
≤ 2.0 Fixed in 2.1 |
CVE-2024-52353 |
Patchstack | |
| 6.5 Medium | Web Stories Widgets For Elementor | Cross-Site Scripting |
≤ 1.1 Fixed in 1.1.1 |
CVE-2024-52354 |
Patchstack | |
| 6.5 Medium | OSM | Cross-Site Scripting OpenStreetMap plugin <= 6.1.2 - Cross Site Scripting (XSS) |
≤ 6.1.2 Fixed in 6.1.3 |
CVE-2024-52355 |
Patchstack | |
| 6.5 Medium | The Pack Elementor addons | Cross-Site Scripting |
≤ 2.1.0 Fixed in 2.1.1 |
CVE-2024-52356 |
Patchstack | |
| 6.5 Medium | LIQUID BLOCKS | Cross-Site Scripting |
≤ 1.2.0 Fixed in 1.3.0 |
CVE-2024-52357 |
Patchstack | |
| 6.5 Medium | Responsive Addons for Elementor | Cross-Site Scripting |
≤ 1.5.4 Fixed in 1.6.0 |
CVE-2024-52358 |
Patchstack | |
| 8.5 High | L Squared Hub WP | SQL Injection |
≤ 1.0 |
CVE-2024-51820 |
Patchstack | |
| 8.5 High | WP Contest | SQL Injection |
≤ 1.0.0 |
CVE-2024-51837 |
Patchstack | |
| 8.5 High | Horsemanager | SQL Injection |
≤ 1.3 |
CVE-2024-51843 |
Patchstack | |
| 8.5 High | Share Buttons – Social Media | SQL Injection Social Media plugin <= 1.0.2 - SQL Injection |
≤ 1.0.2 |
CVE-2024-51845 |
Patchstack | |
| 8.5 High | Gboy Custom Google Map | SQL Injection |
≤ 1.2 |
CVE-2024-51882 |
Patchstack | |
| 10.0 Critical | The Novel Design Store Directory | Arbitrary File Upload No login needed |
≤ 4.3.0 |
CVE-2024-51788 |
Patchstack | |
| 10.0 Critical | Image Classify | Arbitrary File Upload No login needed |
≤ 1.0.0 |
CVE-2024-51789 |
Patchstack | |
| 10.0 Critical | HB AUDIO GALLERY | Arbitrary File Upload No login needed |
≤ 3.0 |
CVE-2024-51790 |
Patchstack | |
| 10.0 Critical | Forms | Arbitrary File Upload No login needed |
≤ 2.8.0 Fixed in 2.8.1 |
CVE-2024-51791 |
Patchstack | |
| 10.0 Critical | Audio Record | Arbitrary File Upload No login needed |
≤ 1.0 |
CVE-2024-51792 |
Patchstack | |
| 10.0 Critical | RepairBuddy | Arbitrary File Upload No login needed |
≤ 3.8115 Fixed in 3.8116 |
CVE-2024-51793 |
Patchstack | |
| 6.5 Medium | MasterBip para Elementor | Cross-Site Scripting |
≤ 1.6.3 |
CVE-2024-51571 |
Patchstack | |
| 6.5 Medium | LH QR Codes | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.06 |
CVE-2024-51572 |
Patchstack | |
| 6.5 Medium | ML Responsive Audio player with playlist Shortcode | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 0.2 |
CVE-2024-51573 |
Patchstack | |
| 6.5 Medium | Simple Goods | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 0.1.3 |
CVE-2024-51574 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.