WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,701–22,750 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 455 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Bet WC 2018 Russia Plugin bet-wc-2018-russia Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2024-49637 Patchstack
7.1 High Risk Warning Bar Plugin risk-warning-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49638 Patchstack
7.1 High Monitor.chat Plugin monitor-chat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2024-49639 Patchstack
7.1 High ACL Floating Cart for WooCommerce Plugin acl-floating-cart-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9 CVE-2024-49640 Patchstack
7.1 High Tida URL Screenshot Plugin tida-url-screenshot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2024-49641 Patchstack
7.1 High Whitelist Plugin fifthsegment-whitelist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5 CVE-2024-49643 Patchstack
7.1 High Affiliate Platform Plugin smdp-affiliate-platform Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.8 CVE-2024-49645 Patchstack
7.1 High Code Generate Plugin code-generator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49646 Patchstack
7.1 High Simple Custom Admin Plugin simple-custom-admin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49647 Patchstack
7.1 High SVG Captcha Plugin svg-captcha Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.11 CVE-2024-49648 Patchstack
7.1 High BuddyPress Greeting Message Plugin bp-greeting-message Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2024-49650 Patchstack
7.1 High WooCommerce Maintenance Mode Plugin woocommerce-maintenance-mode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-49651 Patchstack
7.1 High Extra Privacy for Elementor Plugin extra-privacy-for-elementor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2024-49654 Patchstack
7.1 High DocumentPress Plugin documentpress-display-any-document-on-your-site Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2024-49656 Patchstack
6.5 Medium Coub Plugin coub Cross-Site Scripting ≤ 1.4 CVE-2024-49659 Patchstack
7.1 High Campus Explorer Widget Plugin campus-explorer-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2024-49660 Patchstack
7.1 High leenk.me Plugin leenkme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16.0 CVE-2024-49661 Patchstack
7.1 High Simple Load More Plugin simple-load-more Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49662 Patchstack
7.1 High uCAT – Next Story Plugin ucat-next-story Cross-Site Scripting Next Story plugin <= 2.0.0 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2024-49663 Patchstack
6.4 Medium Newsletters Plugin newsletters-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via newsletters_video Shortcode ≤ 4.9.9.4 CVE-2024-10181 Wordfence
7.1 High chatplusjp Plugin chatplusjp Cross-Site Scripting No login needed ≤ 1.02 CVE-2024-49664 Patchstack
6.5 Medium Web Bricks Addons for Elementor Plugin webbricks-addons Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.1 CVE-2024-49665 Patchstack
6.5 Medium Local Business Addons For Elementor Plugin map-addons-for-elementor-waze-map Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.5 CVE-2024-49667 Patchstack
7.1 High Client Power Tools Portal Plugin client-power-tools Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2024-49670 Patchstack
7.1 High Google Docs RSVP Plugin google-docs-rsvp-guestlist Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2024-49672 Patchstack
7.1 High LaTeX2HTML Plugin latex2html Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.4 Fixed in 2.5.5 CVE-2024-49673 Patchstack
7.1 High js paper Theme js-paper Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.7 CVE-2024-49678 Patchstack
4.3 Medium Move Addons for Elementor Plugin move-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 1.3.5 CVE-2024-10360 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Video Box Widget ≤ 4.10.60 CVE-2024-10266 Wordfence
6.4 Medium SMSAlert - WooCommerce Plugin sms-alert Cross-Site Scripting WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_subscribe Shortcode ≤ 3.7.5 CVE-2024-10233 Wordfence
6.4 Medium StreamWeasels YouTube Integration Plugin streamweasels-youtube-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sw-youtube-embed Shortcode ≤ 1.3.2 CVE-2024-10185 Wordfence
6.4 Medium SW Kick Integration - Blocks and Shortcodes for Embedding Kick Streams Plugin streamweasels-kick-integration Cross-Site Scripting Blocks and Shortcodes for Embedding Kick Streams <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via sw-kick-embed Shortcode ≤ 1.1.1 CVE-2024-10184 Wordfence
5.9 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-49679 Patchstack
6.5 Medium AffiliateX Plugin affiliatex Cross-Site Scripting ≤ 1.2.9 Fixed in 1.2.9.1 CVE-2024-49692 Patchstack
7.1 High Namaste! LMS Plugin namaste-lms Cross-Site Scripting No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-50407 Patchstack
6.5 Medium Namaste! LMS Plugin namaste-lms Cross-Site Scripting ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-50409 Patchstack
6.5 Medium Namaste! LMS Plugin namaste-lms Cross-Site Scripting ≤ 2.6.4 Fixed in 2.6.4.1 CVE-2024-50410 Patchstack
8.1 High LiteSpeed Cache Plugin litespeed-cache Privilege Escalation No login needed ≤ 6.5.1 Fixed in 6.5.2 CVE-2024-50550 Patchstack
4.3 Medium WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Broken Access Control Missing Authorization to Authenticated (Subscriber+) Message Activation/Deactivation ≤ 4.2.1 CVE-2024-10437 Wordfence
6.4 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via atkp_product Shortcode ≤ 3.6.5 CVE-2024-10227 Wordfence
8.8 High WPC Smart Messages for WooCommerce Plugin wpc-smart-messages Local File Inclusion Authenticated (Subscriber+) Local File Inclusion ≤ 4.2.1 CVE-2024-10436 Wordfence
6.4 Medium Kata Plus – Addons for Elementor – Widgets, Extensions and Templates Plugin kata-plus Cross-Site Scripting Addons for Elementor – Widgets, Extensions and Templates <= 1.4.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.4.7 CVE-2024-9376 Wordfence
7.1 High Todo Custom Field Plugin todo-custom-field Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.4 CVE-2024-49642 Patchstack
5.9 Medium WP Abstracts Plugin wp-abstracts-manuscripts-manager Cross-Site Scripting ≤ 2.7.1 Fixed in 2.7.2 CVE-2024-50411 Patchstack
5.9 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Cross-Site Scripting ≤ 2.4.15 Fixed in 2.5 CVE-2024-50412 Patchstack
5.9 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting ≤ 1.27.5 Fixed in 1.27.6 CVE-2024-50413 Patchstack
5.9 Medium Button contact VR Plugin button-contact-vr Cross-Site Scripting ≤ 4.7.9.1 Fixed in 4.7.10 CVE-2024-50414 Patchstack
5.9 Medium Ads.txt & App-ads.txt Manager Plugin app-ads-txt Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1.7.1 Fixed in 1.1.8 CVE-2024-50415 Patchstack
6.5 Medium Time Slot Plugin timeslot Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-50418 Patchstack
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2024-50426 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only