WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 23,251–23,300 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Easy PayPal Gift Certificate | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options No login needed |
≤ 1.2.3 |
CVE-2024-9592 |
Wordfence | |
| 6.5 Medium | CM Tooltip Glossary | Cross-Site Scripting Stored Cross-Site Scripting |
≤ 4.3.9 Fixed in 4.3.11 |
CVE-2024-48041 |
Patchstack | |
| 8.5 High | Tainacan | SQL Injection |
≤ 0.21.8 Fixed in 0.21.9 |
CVE-2024-48040 |
Patchstack | |
| 9.8 Critical | Talkback | PHP Object Injection No login needed |
≤ 1.0 |
CVE-2024-48033 |
Patchstack | |
| 9.3 Critical | Multi Step for Contact Form | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 2.7.7 Fixed in 2.7.8 |
CVE-2024-47331 |
Patchstack | |
| 8.5 High | Backup and Staging by WP Time Capsule | SQL Injection |
≤ 1.22.21 Fixed in 1.22.22 |
CVE-2024-48020 |
Patchstack | |
| 4.7 Medium | ElementsReady Addons for Elementor | Open Redirect No login needed |
≤ 6.4.2 Fixed in 6.4.3 |
CVE-2024-47353 |
Patchstack | |
| 4.3 Medium | ShopLentor | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template |
≤ 2.9.8 |
CVE-2024-9538 |
Wordfence | |
| 4.3 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template |
≤ 5.6.11 |
CVE-2024-8913 |
Wordfence | |
| 6.5 Medium | WordPress Comments Import & Export | Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal |
≤ 2.3.7 |
CVE-2024-7514 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode |
≤ 3.9.3 |
CVE-2024-9051 |
Wordfence | |
| 4.9 Medium | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Path Traversal Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read |
≤ 2.15.2 |
CVE-2024-9507 |
Wordfence | |
| 6.1 Medium | FULL – Cliente | Cross-Site Scripting Cliente <= 3.1.22 - Reflected Cross-Site Scripting No login needed |
≤ 3.1.22 |
CVE-2024-9211 |
Wordfence | |
| 6.1 Medium | Language Switcher | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.7.13 |
CVE-2024-9610 |
Wordfence | |
| 9.8 Critical | GutenKit | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 2.1.0 |
CVE-2024-9234 |
Wordfence | |
| 6.1 Medium | Download Plugins and Themes in ZIP from Dashboard | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.9.1 |
CVE-2024-9232 |
Wordfence | |
| 9.8 Critical | Hunk Companion | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed |
≤ 1.8.4 |
CVE-2024-9707 |
Wordfence | |
| 6.1 Medium | PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.5.14 |
CVE-2024-9436 |
Wordfence | |
| 6.1 Medium | Tainacan | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.21.10 |
CVE-2024-9221 |
Wordfence | |
| 6.1 Medium | BlockMeister – Block Pattern Builder | Cross-Site Scripting Block Pattern Builder <= 3.1.10 - Reflected Cross-Site Scripting No login needed |
≤ 3.1.10 |
CVE-2024-9616 |
Wordfence | |
| 6.1 Medium | Increase upload file size & Maximum Execution Time limit | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0 |
CVE-2024-9611 |
Wordfence | |
| 6.1 Medium | Embed videos and respect privacy | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2 |
CVE-2024-9346 |
Wordfence | |
| 5.4 Medium | Linkz.ai | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update via AJAX |
≤ 1.1.8 |
CVE-2024-9587 |
Wordfence | |
| 6.5 Medium | Linkz.ai | Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed |
≤ 1.1.8 |
CVE-2024-9586 |
Wordfence | |
| 6.4 Medium | Powerpress | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode |
≤ 11.9.18 |
CVE-2024-9543 |
Wordfence | |
| 9.8 Critical | Pedalo Connector | Authentication Bypass Authentication Bypass to Administrator No login needed |
≤ 2.0.5 |
CVE-2024-9822 |
Wordfence | |
| 4.7 Medium | Simple Membership After Login Redirection | Open Redirect No login needed |
≤ 1.6 Fixed in 1.7 |
CVE-2024-47354 |
Patchstack | |
| 4.7 Medium | EventPrime | Open Redirect No login needed |
≤ 4.0.4.5 Fixed in 4.0.4.6 |
CVE-2024-47648 |
Patchstack | |
| 9.8 Critical | JobSearch | PHP Object Injection No login needed |
≤ 2.5.9 Fixed in 2.6.1 |
CVE-2024-47636 |
Patchstack | |
| 5.9 Medium | WP-Advanced-Search | SQL Injection Unauthenticated SQL Injection No login needed |
< 3.3.9.2 Fixed in 3.3.9.2 |
CVE-2024-9796 |
WPScan | |
| 5.9 Medium | TI WooCommerce Wishlist | SQL Injection Unauthenticated SQL Injection via lang parameters No login needed |
≤ 2.8.2 |
CVE-2024-9156 |
WPScan | |
| 6.3 Medium | UserPlus | Broken Access Control Missing Authorization via Multiple Functions |
≤ 2.0 |
CVE-2024-9520 |
Wordfence | |
| 6.4 Medium | Advanced Blocks Pro | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.0 |
CVE-2024-9074 |
Wordfence | |
| 4.3 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership | Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion |
≤ 1.3.0 |
CVE-2024-9067 |
Wordfence | |
| 4.3 Medium | Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) | Cross-Site Request Forgery No login needed |
≤ 3.1.87 |
CVE-2024-8477 |
Wordfence | |
| 7.2 High | TS Poll – Survey, Versus Poll, Image Poll, Video Poll | SQL Injection Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter |
≤ 2.4.0 |
CVE-2024-9022 |
Wordfence | |
| 4.3 Medium | Notification for Telegram | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Send Telegram Test Message |
≤ 3.3.1 |
CVE-2024-9685 |
Wordfence | |
| 6.1 Medium | Easy Social Share Buttons | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.4.5 |
CVE-2024-8729 |
Wordfence | |
| 7.3 High | Shortcodes AnyWhere | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.0.1 |
CVE-2024-9581 |
Wordfence | |
| 6.4 Medium | Curator.io: Show all your social media posts in a beautiful feed. | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute |
≤ 1.9.1 |
CVE-2024-9057 |
Wordfence | |
| 6.1 Medium | Products, Order & Customers Export for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.0.15 |
CVE-2024-9377 |
Wordfence | |
| 5.3 Medium | WP Helper Premium | Broken Access Control Missing Authorization in whp_smtp_send_mail_test No login needed |
≤ 4.6.1 |
CVE-2024-9065 |
Wordfence | |
| 6.4 Medium | Elementor Inline SVG | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.2.0 |
CVE-2024-9064 |
Wordfence | |
| 8.8 High | WP Users Masquerade | Authentication Bypass Authenticated (Subscriber+) Authentication Bypass |
≤ 2.0.0 |
CVE-2024-9522 |
Wordfence | |
| 6.4 Medium | Marketing and SEO Booster | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.9.10 |
CVE-2024-9066 |
Wordfence | |
| 9.8 Critical | UserPlus | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 2.0 |
CVE-2024-9518 |
Wordfence | |
| 6.4 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership | Cross-Site Scripting BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode |
≤ 1.3.0 |
CVE-2024-8987 |
Wordfence | |
| 6.1 Medium | Maximum Products per User for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.2.8 |
CVE-2024-9205 |
Wordfence | |
| 5.3 Medium | QA Analytics | Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed |
≤ 4.1.1.1 |
CVE-2024-8513 |
Wordfence | |
| 7.2 High | UserPlus | Privilege Escalation Authenticated (Editor+) Registration Form Update to Privilege Escalation |
≤ 2.0 |
CVE-2024-9519 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.