WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,101–23,150 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 463 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Encyclopedia / Glossary / Wiki Plugin encyclopedia-lexicon-glossary-wiki-dictionary Cross-Site Scripting No login needed ≤ 1.7.60 Fixed in 1.7.61 CVE-2024-49320 Patchstack
6.4 Medium Parallax Image Plugin parallax-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via dd-parallax Shortcode ≤ 1.8 CVE-2024-9898 Wordfence
7.2 High SendPulse Free Web Push Plugin sendpulse-web-push Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.6 CVE-2024-9184 Wordfence
6.4 Medium Fonto – Custom Web Fonts Manager Plugin fonto Cross-Site Scripting Custom Web Fonts Manager <= 1.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.1 CVE-2024-8920 Wordfence
6.1 Medium Wordpress Photo Album Plus Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 8.8.05.003 CVE-2024-9951 Wordfence
6.1 Medium Persian WooCommerce SMS Plugin persian-woocommerce-sms Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.0.2 CVE-2024-9213 Wordfence
7.6 High Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-5429 WPScan
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Quiz Creation No login needed ≤ 1.35.1 CVE-2024-9351 Wordfence
4.3 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Request Forgery Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Cross-Site Request Forgery to Draft Custom Form Creation No login needed ≤ 1.35.1 CVE-2024-9352 Wordfence
6.1 Medium Flexmls® IDX Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.14.22 CVE-2024-8719 Wordfence
4.3 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Information Disclosure Authenticated (Subscriber+) Private Post Disclosure ≤ 1.3.986 CVE-2024-7417 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.9 - Reflected Cross-Site Scripting No login needed ≤ 3.0.9, 2.0.12, 3.0.11 CVE-2024-9347 Wordfence
9.8 Critical WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin timetics Broken Access Control Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover No login needed ≤ 1.0.25 CVE-2024-9263 Wordfence
5.3 Medium Calculated Fields Form Plugin calculated-fields-form Content Injection HTML Injection No login needed ≤ 5.2.45 CVE-2024-9940 Wordfence
9.8 Critical Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Privilege Escalation Privilege Escalation via Registration due to Administrator Default User Role Value No login needed ≤ 3.6.0 CVE-2024-9863 Wordfence
8.8 High Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors Plugin publishpress-authors Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Arbitrary User Email Update and Account Takeover ≤ 4.7.1 CVE-2024-9215 Wordfence
9.8 Critical Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Broken Access Control Unauthenticated Arbitrary User Password Change No login needed ≤ 3.6.0 CVE-2024-9862 Wordfence
6.1 Medium ReDi Restaurant Reservation Plugin redi-restaurant-reservation Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 24.0902 CVE-2024-9240 Wordfence
8.1 High Miniorange OTP Verification with Firebase Plugin miniorange-firebase-sms-otp-verification Authentication Bypass No login needed ≤ 3.6.0 CVE-2024-9861 Wordfence
5.3 Medium advanced-custom-fields Plugin advanced-custom-fields Cross-Site Scripting In Advanced Custom Fields (ACF) before 6.3.9 and Secure Custom Fields before 6.3.6.3 (plugins for WordPress), using the Field Group editor to edit one of the plugin's fields can r… No login needed Not stated CVE-2024-49593 mitre
6.5 Medium Booking.com Banner Creator Plugin bookingcom-banner-creator Cross-Site Scripting ≤ 1.4.6 CVE-2024-49265 Patchstack
5.9 Medium WP-Spreadplugin Plugin wp-spreadplugin Cross-Site Scripting ≤ 4.8.9 CVE-2024-49266 Patchstack
6.5 Medium Unlimited Addon For Elementor Plugin unlimited-addon-for-elementor Cross-Site Scripting ≤ 2.0.0 CVE-2024-49267 Patchstack
7.1 High disconnected Theme disconnected Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-49268 Patchstack
9.8 Critical Nextend Social Login Pro Plugin nextend-facebook-connect Authentication Bypass Authentication Bypass via WordPress.com OAuth provider No login needed ≤ 3.1.14 CVE-2024-9893 Wordfence
6.5 Medium Smart Blocks Plugin smart-blocks Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-49270 Patchstack
5.3 Medium Leyka Plugin leyka Broken Access Control No login needed ≤ 3.31.6 Fixed in 3.31.7 CVE-2024-49252 Patchstack
7.5 High Ahime Image Printer Plugin ahime-image-printer Path Traversal Arbitrary File Download No login needed ≤ 1.0.0 CVE-2024-49245 Patchstack
6.5 Medium WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Path Traversal Arbitrary File Download ≤ 1.5.7 CVE-2024-49258 Patchstack
9.9 Critical Creates 3D Flipbook, PDF Flipbook Plugin create-flipbook-from-pdf Arbitrary File Upload ≤ 1.2 CVE-2024-48034 Patchstack
10.0 Critical Feed Comments Number Plugin feed-comments-number Arbitrary File Upload No login needed ≤ 0.2.1 CVE-2024-49216 Patchstack
10.0 Critical Digital Lottery Plugin digital-lottery Arbitrary File Upload No login needed ≤ 3.0.5 CVE-2024-49242 Patchstack
9.9 Critical WordPress Gallery Plugin – Limb Image Gallery Plugin limb-gallery Arbitrary File Upload ≤ 1.5.7 CVE-2024-49260 Patchstack
7.5 High MaxSlider Plugin maxslider Local File Inclusion ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-47351 Patchstack
7.5 High Top Bar – PopUps – by WPOptin Plugin wpoptin Local File Inclusion No login needed ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-47645 Patchstack
7.5 High SB Random Posts Widget Plugin sb-random-posts-widget Local File Inclusion ≤ 1.0 Fixed in 1.1 CVE-2024-48029 Patchstack
7.5 High Maan Addons For Elementor Plugin maan-elementor-addons Local File Inclusion ≤ 1.0.1 CVE-2024-49251 Patchstack
9.8 Critical Disc Golf Manager Plugin disc-golf-manager PHP Object Injection No login needed ≤ 1.0.0 CVE-2024-48026 Patchstack
9.8 Critical IP Loc8 Plugin ip-loc8 PHP Object Injection No login needed ≤ 1.1 CVE-2024-48028 Patchstack
9.8 Critical Telecash Ricaricaweb Plugin telecash-ricaricaweb PHP Object Injection No login needed ≤ 2.2 CVE-2024-48030 Patchstack
9.8 Critical Recently Plugin recently-viewed-most-viewed-and-sold-products-for-woocommerce PHP Object Injection No login needed ≤ 1.1 CVE-2024-49218 Patchstack
8.8 High TAKETIN To WP Membership Plugin taketin-to-wp-membership PHP Object Injection ≤ 2.8.17 CVE-2024-49226 Patchstack
8.8 High Free Stock Photos Foter Plugin free-stock-photos-foter PHP Object Injection No login needed ≤ 1.5.4 CVE-2024-49227 Patchstack
10.0 Critical ajax-extend Plugin ajax-extend Remote Code Execution No login needed ≤ 1.0 CVE-2024-49254 Patchstack
8.8 High LiteSpeed Cache Plugin litespeed-cache Path Traversal ≤ 6.4.1 Fixed in 6.5.1 CVE-2024-47637 Patchstack
8.6 High Analyse Uploads Plugin analyse-uploads Arbitrary File Deletion No login needed ≤ 0.5 CVE-2024-49253 Patchstack
9.1 Critical Iconize Plugin iconize Remote Code Execution ≤ 1.2.4 CVE-2024-47649 Patchstack
9.9 Critical External featured image from bing Plugin external-featured-image-from-bing Remote Code Execution ≤ 1.0.2 CVE-2024-48027 Patchstack
9.9 Critical ACF Images Search And Insert Plugin acf-images-search-and-insert Arbitrary File Upload ≤ 1.1.4 CVE-2024-48035 Patchstack
9.1 Critical Contact Form by Supsystic Plugin contact-form-by-supsystic Remote Code Execution ≤ 1.7.28 Fixed in 1.7.29 CVE-2024-48042 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only