WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,801–22,850 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 457 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Themes4WP YouTube External Subtitles Plugin themes4wp-youtube-external-subtitles Cross-Site Scripting ≤ 1.0 CVE-2024-50470 Patchstack
6.5 Medium Trip Plan Plugin tripplan Cross-Site Scripting ≤ 1.0.10 Fixed in 2.0.0 CVE-2024-50471 Patchstack
6.5 Medium Amilia Store Plugin amilia-store Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.9.8 CVE-2024-50472 Patchstack
6.5 Medium Kata Plus Plugin kata-plus Cross-Site Scripting ≤ 1.4.7 Fixed in 1.5.0 CVE-2024-50501 Patchstack
6.5 Medium Cozy Blocks Plugin cozy-addons Cross-Site Scripting ≤ 2.0.18 Fixed in 2.0.19 CVE-2024-50502 Patchstack
8.5 High Premium SEO Pack Plugin premium-seo-pack SQL Injection ≤ 1.6.001 CVE-2024-50465 Patchstack
9.3 Critical Woocommerce Quote Calculator Plugin woo-quote-calculator-order SQL Injection No login needed ≤ 1.1 CVE-2024-50479 Patchstack
9.3 Critical RSVP ME Plugin rsvp-me SQL Injection No login needed ≤ 1.9.9 CVE-2024-50491 Patchstack
8.1 High Advanced Online Ordering and Delivery Platform Plugin advanced-online-ordering-and-delivery-platform Local File Inclusion No login needed ≤ 2.0.0 CVE-2024-50497 Patchstack
4.7 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Open Redirect No login needed ≤ 3.2.9 Fixed in 3.2.11 CVE-2024-50463 Patchstack
9.8 Critical 1-Click Login: Passwordless Authentication Plugin swoop-password-free-authentication Authentication Bypass Broken Authentication No login needed 1.4.5 CVE-2024-50478 Patchstack
9.8 Critical Meetup Plugin meetup Authentication Bypass Broken Authentication No login needed ≤ 0.1 CVE-2024-50483 Patchstack
8.8 High Token Login Plugin token-login Authentication Bypass Broken Authentication ≤ 1.0.3 CVE-2024-50488 Patchstack
8.8 High Namaste! LMS Plugin namaste-lms PHP Object Injection ≤ 2.6.3 Fixed in 2.6.4 CVE-2024-50408 Patchstack
8.8 High WPC Shop as a Customer for WooCommerce Plugin wpc-shop-as-customer PHP Object Injection ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-50416 Patchstack
7.3 High MDTF Plugin wp-meta-data-filter-and-taxonomy-filter Remote Code Execution Meta Data and Taxonomies Filter plugin <= 1.3.3.4 - Bypass Vulnerability No login needed ≤ 1.3.3.4 Fixed in 1.3.3.5 CVE-2024-50450 Patchstack
8.3 High ScottCart Plugin scottcart Remote Code Execution No login needed ≤ 1.1 CVE-2024-50492 Patchstack
10.0 Critical WP Query Console Plugin wp-query-console Remote Code Execution No login needed ≤ 1.0 CVE-2024-50498 Patchstack
9.8 Critical Stacks Mobile App Builder Plugin stacks-mobile-app-builder Privilege Escalation Account Takeover No login needed ≤ 5.2.3 CVE-2024-50477 Patchstack
9.8 Critical Acnoo Flutter API Plugin acnoo-flutter-api Privilege Escalation Account Takeover No login needed ≤ 1.0.5 CVE-2024-50486 Patchstack
9.8 Critical MaanStore API Plugin maanstore-api Privilege Escalation Account Takeover No login needed ≤ 1.0.1 CVE-2024-50487 Patchstack
9.8 Critical Realty Workstation Plugin realty-workstation Privilege Escalation Account Takeover No login needed ≤ 1.0.45 CVE-2024-50489 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons XML External Entity ≤ 1.3.980 Fixed in 1.3.981 CVE-2024-50442 Patchstack
7.2 High All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Remote Code Execution Authenticated (Administrator+) Arbitrary PHP Code Injection ≤ 7.86 CVE-2024-9162 Wordfence
9.8 Critical Wp Social Login and Register Social Counter Plugin wp-social Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 3.0.7 CVE-2024-9501 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation ≤ 1.35.1 CVE-2024-10402 Wordfence
6.4 Medium WP Crowdfunding Plugin wp-crowdfunding Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpcf_donate Shortcode ≤ 2.1.11 CVE-2024-10117 Wordfence
4.3 Medium Clever Addons for Elementor Plugin cafe-lite Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates ≤ 2.2.1 CVE-2024-10357 Wordfence
6.4 Medium Monkee-Boy Essentials Plugin monkee-boy-wp-essentials Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1 CVE-2024-9116 Wordfence
7.3 High Uix Shortcodes – Compatible with Gutenberg Plugin uix-shortcodes Arbitrary Shortcode Execution Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.9.9 CVE-2024-9772 Wordfence
6.4 Medium Editor Custom Color Palette Plugin editor-custom-color-palette Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 3.3.7 CVE-2024-9642 Wordfence
7.2 High WordPress Post Grid Layouts with Pagination – Sogrid Plugin sogrid Local File Inclusion Sogrid <= 1.5.6 - Authenticated (Admin+) Local File Inclusion ≤ 1.5.6 CVE-2024-8392 Wordfence
8.8 High School Management System – WPSchoolPress Plugin wpschoolpress Broken Access Control WPSchoolPress <= 2.2.10 - Insecure Direct Object Reference to Authenticated (Teacher+) Account Takeover/Privilege Escalation ≤ 2.2.10 CVE-2024-9637 Wordfence
6.4 Medium WP show more Plugin wp-show-more Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via show_more Shortcode ≤ 1.0.7 CVE-2024-9967 Wordfence
6.4 Medium ID-SK Toolkit Plugin idsk-toolkit Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.7.2 CVE-2024-9853 Wordfence
4.3 Medium Download Monitor Plugin download-monitor Broken Access Control Missing Authorization to API Key Manipulation ≤ 5.0.12 CVE-2024-10092 Wordfence
6.4 Medium WP Awesome Login Plugin wp-awesome-login Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 0.4.0 CVE-2024-9456 Wordfence
6.1 Medium Forms for Mailchimp by Optin Cat – Grow Your MailChimp List Plugin mailchimp-wp Cross-Site Scripting Grow Your MailChimp List <= 2.5.7 - Reflected Cross-Site Scripting No login needed ≤ 2.5.6 CVE-2024-8870 Wordfence
6.1 Medium FormFacade – WordPress plugin for Google Forms Plugin formfacade Cross-Site Scripting WordPress plugin for Google Forms <= 1.3.6 - Reflected Cross-Site Scripting No login needed ≤ 1.3.6 CVE-2024-9613 Wordfence
6.4 Medium PriPre Plugin pripre Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 0.4.11 CVE-2024-9454 Wordfence
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison Widget ≤ 3.2.9 CVE-2024-10091 Wordfence
9.8 Critical Extensions by HocWP Team Plugin sb-core Authentication Bypass No login needed ≤ 0.2.3.2 CVE-2024-9930 Wordfence
9.8 Critical Wux Blog Editor Plugin wux-blog-editor Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.0.0 CVE-2024-9932 Wordfence
5.5 Medium Poll Maker – Versus Polls, Anonymous Polls, Image Polls Plugin poll-maker Cross-Site Scripting Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via Poll Settings ≤ 5.4.6 CVE-2024-9462 Wordfence
4.3 Medium Editorial Assistant by Sovrn Plugin zemanta Broken Access Control Missing Authorization to Authenticated (Subscriber+) Attachment Upload and Set Post Featured Image ≤ 1.3.3 CVE-2024-9626 Wordfence
4.9 Medium Poll Maker – Versus Polls, Anonymous Polls, Image Polls Plugin poll-maker SQL Injection Versus Polls, Anonymous Polls, Image Polls <= 5.4.6 - Authenticated (Administrator+) SQL Injection via Order_by Parameter ≤ 5.4.6 CVE-2024-9475 Wordfence
9.8 Critical WatchTowerHQ Plugin watchtowerhq Authentication Bypass Authentication Bypass to Administrator due to Missing Empty Value Check No login needed ≤ 3.10.1 CVE-2024-9933 Wordfence
8.8 High User Toolkit Plugin user-toolkit Authentication Bypass Authenticated (Subscriber+) Authentication Bypass ≤ 1.2.3 CVE-2024-9890 Wordfence
9.8 Critical Wux Blog Editor Plugin wux-blog-editor Authentication Bypass Authentication Bypass to Administrator No login needed ≤ 3.0.0 CVE-2024-9931 Wordfence
6.4 Medium Image Map Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.0.20 CVE-2024-9585 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only