WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 22,951–23,000 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 460 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Rate Own Post Plugin rate-own-post SQL Injection ≤ 1.0 CVE-2024-49616 Patchstack
8.2 High Back Link Tracker Plugin back-link-tracker Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49617 Patchstack
8.5 High MyTweetLinks Plugin mytweetlinks SQL Injection ≤ 1.1.1 CVE-2024-49618 Patchstack
8.5 High Social Link Groups Plugin social-link-groups SQL Injection ≤ 1.1.0 CVE-2024-49619 Patchstack
8.5 High FERMA.ru.net Plugin ferma-ru-net-checkout SQL Injection ≤ 1.3.3 CVE-2024-49620 Patchstack
7.1 High EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 2.12.14 Fixed in 3.0.0 CVE-2024-44061 Patchstack
8.2 High APA Register Newsletter Form Plugin apa-register-newsletter-form Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49621 Patchstack
8.2 High Apa Banner Slider Plugin apa-banner-slider Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 1.0.0 CVE-2024-49622 Patchstack
8.5 High Duplicate Title Validate Plugin duplicate-title-validate SQL Injection ≤ 1.0 Fixed in 1.4 CVE-2024-49623 Patchstack
8.8 High GERRYWORKS Post by Mail Plugin gerryworks-post-by-mail Privilege Escalation ≤ 1.0 CVE-2024-49608 Patchstack
10.0 Critical Sovratec Case Management Plugin sovratec-case-management Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49324 Patchstack
10.0 Critical Affiliator Plugin affiliator-lite Arbitrary File Upload No login needed ≤ 2.1.3 CVE-2024-49326 Patchstack
10.0 Critical Woostagram Connect Plugin woostagram-connect Arbitrary File Upload No login needed ≤ 1.0.2 CVE-2024-49327 Patchstack
10.0 Critical WP REST API FNS Plugin rest-api-fns Arbitrary File Upload No login needed ≤ 1.0.0 CVE-2024-49329 Patchstack
10.0 Critical Nice Backgrounds Plugin nicebackgrounds Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49330 Patchstack
9.9 Critical Property Lot Management System Plugin plms Arbitrary File Upload ≤ 4.2.38 CVE-2024-49331 Patchstack
10.0 Critical WP Dropbox Dropins Plugin wp-dropbox-dropins Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49607 Patchstack
10.0 Critical photokit Plugin photokit Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49610 Patchstack
9.8 Critical Giveaway Boost Plugin giveaway-boost PHP Object Injection No login needed ≤ 2.1.4 CVE-2024-49332 Patchstack
9.8 Critical Advanced Advertising System Plugin advanced-advertising-system PHP Object Injection No login needed ≤ 1.3.1 CVE-2024-49624 Patchstack
9.8 Critical SiteBuilder Dynamic Components Plugin sitebuilder-dynamic-components PHP Object Injection No login needed ≤ 1.0 CVE-2024-49625 Patchstack
9.8 Critical Shipyaari Shipping Management Plugin shipyaari-shipping-managment PHP Object Injection No login needed ≤ 1.2 CVE-2024-49626 Patchstack
9.6 Critical SSV Events Plugin ssv-events Local File Inclusion Local File Inclusion to RCE No login needed ≤ 3.2.7 CVE-2024-49286 Patchstack
10.0 Critical Product Website Showcase Plugin product-websites-showcase Arbitrary File Upload No login needed ≤ 1.0 CVE-2024-49611 Patchstack
9.8 Critical WP REST API FNS Plugin rest-api-fns Privilege Escalation Account Takeover No login needed ≤ 1.0.0 CVE-2024-49328 Patchstack
9.8 Critical Simple User Registration Plugin wp-registration Authentication Bypass Broken Authentication No login needed ≤ 6.7 Fixed in 6.8 CVE-2024-49604 Patchstack
6.5 Medium Mighty Builder Plugin mighty-builder Cross-Site Scripting ≤ 1.0.2 CVE-2024-48049 Patchstack
7.1 High All in One Slider Plugin all-in-one-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-49323 Patchstack
7.1 High jLayer Parallax Slider Plugin jlayer-parallax-slider-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49334 Patchstack
7.1 High Google Map Locations Plugin google-map-locations Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49606 Patchstack
6.5 Medium WP Education Plugin wp-education Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-49630 Patchstack
6.5 Medium Easy Addons for Elementor Plugin easy-addons-for-elementor Cross-Site Scripting ≤ 1.5.0 CVE-2024-49631 Patchstack
6.4 Medium StreamWeasels Twitch Integration Plugin streamweasels-twitch-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sw-twitch-embed Shortcode ≤ 1.8.6 CVE-2024-9897 Wordfence
4.3 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Information Disclosure Authenticated (Contributor+) Information Exposure ≤ 1.2.9 CVE-2024-9889 Wordfence
4.3 Medium EventON PRO - WordPress Virtual Event Calendar Plugin Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed ≤ 4.6.8 CVE-2023-6243 Wordfence
4.9 Medium Photo Gallery Slideshow & Masonry Tiled Gallery Plugin wp-responsive-photo-gallery SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.3 CVE-2019-25218 Wordfence
6.1 Medium WordPress Social Share Buttons Plugin tags Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.19 CVE-2024-9219 Wordfence
8.3 High Time Clock Plugin time-clock Remote Code Execution Unauthenticated (Limited) Remote Code Execution No login needed ≤ 1.1.4, ≤ 1.2.2 CVE-2024-9593 Wordfence
6.4 Medium Debrandify · Remove or Replace WordPress Branding Plugin debrandify Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.2 CVE-2024-9674 Wordfence
5.9 Medium Movie Database Plugin movie-database Cross-Site Scripting ≤ 1.0.11 CVE-2024-43300 Patchstack
7.1 High Mitm Bug Tracker Plugin mitm-bug-tracker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-49224 Patchstack
6.5 Medium wpPricing Builder Plugin wppricing-builder-lite-responsive-pricing-table-builder Cross-Site Scripting ≤ 1.5.0 CVE-2024-49225 Patchstack
6.5 Medium bVerse Convert Plugin bverse-convert Cross-Site Scripting ≤ 1.3.7.1 CVE-2024-49228 Patchstack
6.5 Medium Ajax Custom CSS/JS Plugin ajax-awesome-css Cross-Site Scripting Reflected Cross Site Scripting (XSS) ≤ 2.0.4 CVE-2024-49230 Patchstack
6.5 Medium WordPress Video Plugin wordpress-video Cross-Site Scripting ≤ 1.0 CVE-2024-49231 Patchstack
6.5 Medium El mejor Cluster Plugin mejorcluster Cross-Site Scripting ≤ 1.1.15 Fixed in 1.1.16 CVE-2024-49232 Patchstack
6.5 Medium MAS Elementor Plugin mas-addons-for-elementor Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-49233 Patchstack
6.5 Medium Plexx Elementor Extension Plugin plexx-elementor-extension Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-49234 Patchstack
6.5 Medium Crazy Call To Action Box Plugin crazy-call-to-action-box Cross-Site Scripting ≤ 1.0.5 CVE-2024-49236 Patchstack
7.1 High ADIF Log Search Widget Plugin adif-log-search-widget Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0f CVE-2024-49238 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only