WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,851–22,900 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 458 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Image Map Pro Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Map Project Add/Update/Delete ≤ 6.0.20 CVE-2024-9584 Wordfence
6.4 Medium WP-Members Plugin wp-members Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpmem_loginout Shortcode ≤ 3.4.9.5 CVE-2024-10374 Wordfence
6.4 Medium Simple News Plugin simple-news Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via news Shortcode ≤ 2.8 CVE-2024-10112 Wordfence
6.4 Medium Shoutcast Icecast HTML5 Radio Player Plugin shoutcast-icecast-html5-radio-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.7 CVE-2024-8666 Wordfence
6.4 Medium Beek Widget Extention Plugin beek-widget-extention Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.9.5 CVE-2024-10343 Wordfence
6.4 Medium File Upload Types by WPForms Plugin file-upload-types Arbitrary File Upload Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.4.0 CVE-2024-10016 Wordfence
5.4 Medium WPS Telegram Chat Plugin wps-telegram-chat Broken Access Control Missing Authorization to Information Exposure ≤ 4.6.0 CVE-2024-9630 Wordfence
6.3 Medium WPS Telegram Chat Plugin wps-telegram-chat Broken Access Control Authenticated (Subscriber+) Unauthorized Access to Telegram Bot API ≤ 4.6.0 CVE-2024-9628 Wordfence
6.4 Medium Bamazoo – Button Generator Plugin bamazoo-button-generator Cross-Site Scripting Button Generator <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via dgs Shortcode ≤ 1.0 CVE-2024-10150 Wordfence
8.8 High AMP for WP – Accelerated Mobile Pages Plugin accelerated-mobile-pages Cross-Site Request Forgery Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 1.0.99.1 CVE-2024-9598 Wordfence
6.4 Medium League of Legends Shortcodes Plugin league-of-legends-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2024-10342 Wordfence
6.5 Medium League of Legends Shortcodes Plugin league-of-legends-shortcodes SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.0.1 CVE-2024-10341 Wordfence
6.1 Medium 10Web Social Post Feed Plugin wd-facebook-feed Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.9 CVE-2024-9607 Wordfence
8.8 High Mapster WP Maps Plugin mapster-wp-maps Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Arbitrary Options Update ≤ 1.5.0 CVE-2024-9235 Wordfence
6.4 Medium Awesome buttons Plugin wp-awesome-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via btn2 Shortcode ≤ 1.0 CVE-2024-10148 Wordfence
8.1 High BuddyPress Plugin buddypress Path Traversal Authenticated (Subscriber+) Directory Traversal ≤ 14.1.0 CVE-2024-10011 Wordfence
8.1 High App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 5.3.7 CVE-2024-9302 Wordfence
9.8 Critical Comments – wpDiscuz Plugin wpdiscuz Authentication Bypass wpDiscuz <= 7.6.24 - Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 7.6.24 CVE-2024-9488 Wordfence
4.3 Medium UPS Live Rates and Access Points Plugin flexible-shipping-ups Broken Access Control Missing Authorization to Plugin API key reset ≤ 2.3.12 CVE-2024-9109 Wordfence
5.3 Medium Order Notification for Telegram Plugin order-notification-for-telegram Broken Access Control Missing Authorization to Unauthenticated Send Telegram Test Message No login needed ≤ 1.0.1 CVE-2024-9686 Wordfence
6.5 Medium Mega Elements Plugin mega-elements-addons-for-elementor Cross-Site Scripting Addons for Elementor plugin <= 1.2.6 - Cross Site Scripting (XSS) ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-49693 Patchstack
6.5 Medium WP Flow Plus Plugin wp-imageflow2 Cross-Site Scripting ≤ 5.2.3 Fixed in 5.2.4 CVE-2024-49695 Patchstack
6.4 Medium Contact Form 7 - Repeatable Fields Plugin cf7-repeatable-fields Cross-Site Scripting Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via field_group Shortcode ≤ 2.0.1 CVE-2024-10180 Wordfence
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 3.2.21 Fixed in 3.2.22 CVE-2024-49696 Patchstack
6.5 Medium myCred Elementor Plugin mycred-for-elementor Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2024-49702 Patchstack
6.5 Medium WpEvently Plugin mage-eventpress Cross-Site Scripting ≤ 4.2.5 Fixed in 4.2.6 CVE-2024-49703 Patchstack
9.3 Critical WP Sessions Time Monitoring Full Automatic Plugin activitytime SQL Injection No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2024-49681 Patchstack
7.6 High Product Filter by WBW Plugin woo-product-filter SQL Injection ≤ 2.7.0 Fixed in 2.7.1 CVE-2024-49691 Patchstack
5.3 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.5 Fixed in 1.36 CVE-2024-49683 Patchstack
4.7 Medium Simple Membership Plugin simple-membership Open Redirect No login needed ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-49682 Patchstack
6.4 Medium WP Adminify – Best WordPress Custom Dashboard Plugin adminify Cross-Site Scripting Best WordPress Custom Dashboard Plugin <= 4.0.1.6 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 4.0.1.6 CVE-2024-8959 Wordfence
6.4 Medium Compact WP Audio Player Plugin compact-wp-audio-player Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_embed_player Shortcode ≤ 1.9.13 CVE-2024-10176 Wordfence
6.1 Medium Extra Product Options Builder for WooCommerce Plugin additional-product-fields-for-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2.133 CVE-2024-9214 Wordfence
6.5 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'tooltip' ≤ 9.6.1 CVE-2024-9650 Wordfence
6.1 Medium PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer – DearFlip Plugin 3d-flipbook-dflip-lite Cross-Site Scripting DearFlip <= 2.3.32 - Reflected Cross-Site Scripting No login needed ≤ 2.3.32 CVE-2024-8717 Wordfence
4.3 Medium Elementor Header & Footer Builder Plugin header-footer-elementor Information Disclosure Authenticated (Contributor+) Information Disclosure via Shortcode ≤ 1.6.43 CVE-2024-10050 Wordfence
6.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Request Forgery The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Cross-Site Request Forgery to Vendor Updates No login needed ≤ 4.2.4 CVE-2024-9943 Wordfence
4.3 Medium HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce Plugin hurrytimer Broken Access Control An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce <= 2.10.0 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Publication ≤ 2.10.0 CVE-2024-8667 Wordfence
4.3 Medium MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.4 - Missing Authorization to Forged Vendor Profile Deletion Email Sending ≤ 4.2.4 CVE-2024-9531 Wordfence
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.4.7 CVE-2024-9864 Wordfence
6.1 Medium EventPrime – Modern Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed ≤ 4.0.4.7 CVE-2024-9865 Wordfence
6.1 Medium Terms descriptions Plugin terms-descriptions Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.4.6 CVE-2024-9374 Wordfence
9.9 Critical 3D Work In Progress Plugin renee-work-in-progress Arbitrary File Upload ≤ 1.0.3 CVE-2024-49652 Patchstack
9.9 Critical Portfolleo Plugin portfolleo Arbitrary File Upload ≤ 1.2 CVE-2024-49653 Patchstack
9.9 Critical Woocommerce Custom Profile Picture Plugin woo-custom-profile-picture Arbitrary File Upload ≤ 1.0 CVE-2024-49658 Patchstack
10.0 Critical Verbalize WP Plugin verbalize-wp Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49668 Patchstack
9.9 Critical INK Official Plugin ink-official Arbitrary File Upload ≤ 4.1.2 CVE-2024-49669 Patchstack
9.9 Critical AI Image Generator for Your Content & Featured Images – AI Postpix Plugin ai-postpix Arbitrary File Upload ≤ 1.1.8 Fixed in 1.1.8.1 CVE-2024-49671 Patchstack
6.6 Medium Custom Icons for Elementor Plugin custom-icons-for-elementor Arbitrary File Upload ≤ 0.3.3 Fixed in 0.3.4 CVE-2024-49676 Patchstack
7.5 High Qi Blocks Plugin qi-blocks Local File Inclusion ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-49690 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only