WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,251–23,300 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 466 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Easy PayPal Gift Certificate Plugin paypal-gift-certificate Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via wpppgc_plugin_options No login needed ≤ 1.2.3 CVE-2024-9592 Wordfence
6.5 Medium CM Tooltip Glossary Plugin enhanced-tooltipglossary Cross-Site Scripting Stored Cross-Site Scripting ≤ 4.3.9 Fixed in 4.3.11 CVE-2024-48041 Patchstack
8.5 High Tainacan Plugin tainacan SQL Injection ≤ 0.21.8 Fixed in 0.21.9 CVE-2024-48040 Patchstack
9.8 Critical Talkback Plugin talkback-secure-linkback-protocol PHP Object Injection No login needed ≤ 1.0 CVE-2024-48033 Patchstack
9.3 Critical Multi Step for Contact Form Plugin cf7-multi-step SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2024-47331 Patchstack
8.5 High Backup and Staging by WP Time Capsule Plugin wp-time-capsule SQL Injection ≤ 1.22.21 Fixed in 1.22.22 CVE-2024-48020 Patchstack
4.7 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Open Redirect No login needed ≤ 6.4.2 Fixed in 6.4.3 CVE-2024-47353 Patchstack
4.3 Medium ShopLentor Plugin woolentor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template ≤ 2.9.8 CVE-2024-9538 Wordfence
4.3 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Information Disclosure Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.6.11 - Authenticated (Contributor+) Sensitive Information Exposure via content_template ≤ 5.6.11 CVE-2024-8913 Wordfence
6.5 Medium WordPress Comments Import & Export Plugin comments-import-export-woocommerce Path Traversal Authenticated (Author+) Arbitrary File Read via Directory Traversal ≤ 2.3.7 CVE-2024-7514 Wordfence
6.4 Medium WP Ultimate Post Grid Plugin wp-ultimate-post-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode ≤ 3.9.3 CVE-2024-9051 Wordfence
4.9 Medium Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Path Traversal Authenticated (Administrator+) Improper Input Validation via iconUpload Function to Arbitrary File Read ≤ 2.15.2 CVE-2024-9507 Wordfence
6.1 Medium FULL – Cliente Plugin full-customer Cross-Site Scripting Cliente <= 3.1.22 - Reflected Cross-Site Scripting No login needed ≤ 3.1.22 CVE-2024-9211 Wordfence
6.1 Medium Language Switcher Plugin language-switcher Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.7.13 CVE-2024-9610 Wordfence
9.8 Critical GutenKit Plugin gutenkit-blocks-addon Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.1.0 CVE-2024-9234 Wordfence
6.1 Medium Download Plugins and Themes in ZIP from Dashboard Plugin download-plugins-dashboard Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.9.1 CVE-2024-9232 Wordfence
9.8 Critical Hunk Companion Plugin hunk-companion Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation No login needed ≤ 1.8.4 CVE-2024-9707 Wordfence
6.1 Medium PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes Plugin revisionary Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.5.14 CVE-2024-9436 Wordfence
6.1 Medium Tainacan Plugin tainacan Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.21.10 CVE-2024-9221 Wordfence
6.1 Medium BlockMeister – Block Pattern Builder Plugin blockmeister Cross-Site Scripting Block Pattern Builder <= 3.1.10 - Reflected Cross-Site Scripting No login needed ≤ 3.1.10 CVE-2024-9616 Wordfence
6.1 Medium Increase upload file size & Maximum Execution Time limit Plugin increase-upload-file-size-maximum-execution-time-limit Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0 CVE-2024-9611 Wordfence
6.1 Medium Embed videos and respect privacy Plugin video-embed-privacy Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2 CVE-2024-9346 Wordfence
5.4 Medium Linkz.ai Plugin linkz-ai Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update via AJAX ≤ 1.1.8 CVE-2024-9587 Wordfence
6.5 Medium Linkz.ai Plugin linkz-ai Broken Access Control Missing Authorization to Unauthenticated Plugin Settings Update No login needed ≤ 1.1.8 CVE-2024-9586 Wordfence
6.4 Medium Powerpress Plugin powerpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via skipto Shortcode ≤ 11.9.18 CVE-2024-9543 Wordfence
9.8 Critical Pedalo Connector Plugin pedalo-connector Authentication Bypass Authentication Bypass to Administrator No login needed ≤ 2.0.5 CVE-2024-9822 Wordfence
4.7 Medium Simple Membership After Login Redirection Plugin simple-membership-after-login-redirection Open Redirect No login needed ≤ 1.6 Fixed in 1.7 CVE-2024-47354 Patchstack
4.7 Medium EventPrime Plugin eventprime-event-calendar-management Open Redirect No login needed ≤ 4.0.4.5 Fixed in 4.0.4.6 CVE-2024-47648 Patchstack
9.8 Critical JobSearch Plugin wp-jobsearch PHP Object Injection No login needed ≤ 2.5.9 Fixed in 2.6.1 CVE-2024-47636 Patchstack
5.9 Medium WP-Advanced-Search Plugin SQL Injection Unauthenticated SQL Injection No login needed < 3.3.9.2 Fixed in 3.3.9.2 CVE-2024-9796 WPScan
5.9 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist SQL Injection Unauthenticated SQL Injection via lang parameters No login needed ≤ 2.8.2 CVE-2024-9156 WPScan
6.3 Medium UserPlus Plugin userplus Broken Access Control Missing Authorization via Multiple Functions ≤ 2.0 CVE-2024-9520 Wordfence
6.4 Medium Advanced Blocks Pro Plugin advanced-blocks-pro Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.0 CVE-2024-9074 Wordfence
4.3 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion ≤ 1.3.0 CVE-2024-9067 Wordfence
4.3 Medium Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) Plugin mailin Cross-Site Request Forgery No login needed ≤ 3.1.87 CVE-2024-8477 Wordfence
7.2 High TS Poll – Survey, Versus Poll, Image Poll, Video Poll Plugin poll-wp SQL Injection Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL Injection via orderby Parameter ≤ 2.4.0 CVE-2024-9022 Wordfence
4.3 Medium Notification for Telegram Plugin notification-for-telegram Broken Access Control Missing Authorization to Authenticated (Subscriber+) Send Telegram Test Message ≤ 3.3.1 CVE-2024-9685 Wordfence
6.1 Medium Easy Social Share Buttons Plugin easy-social-share-buttons Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-8729 Wordfence
7.3 High Shortcodes AnyWhere Plugin shortcodes-anywhere Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0.1 CVE-2024-9581 Wordfence
6.4 Medium Curator.io: Show all your social media posts in a beautiful feed. Plugin curatorio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute ≤ 1.9.1 CVE-2024-9057 Wordfence
6.1 Medium Products, Order & Customers Export for WooCommerce Plugin export-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.15 CVE-2024-9377 Wordfence
5.3 Medium WP Helper Premium Plugin wp-helper-lite Broken Access Control Missing Authorization in whp_smtp_send_mail_test No login needed ≤ 4.6.1 CVE-2024-9065 Wordfence
6.4 Medium Elementor Inline SVG Plugin inline-svg-elementor Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.2.0 CVE-2024-9064 Wordfence
8.8 High WP Users Masquerade Plugin wp-users-masquerade Authentication Bypass Authenticated (Subscriber+) Authentication Bypass ≤ 2.0.0 CVE-2024-9522 Wordfence
6.4 Medium Marketing and SEO Booster Plugin marketing-and-seo-booster Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.9.10 CVE-2024-9066 Wordfence
9.8 Critical UserPlus Plugin userplus Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 2.0 CVE-2024-9518 Wordfence
6.4 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify Cross-Site Scripting BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode ≤ 1.3.0 CVE-2024-8987 Wordfence
6.1 Medium Maximum Products per User for WooCommerce Plugin maximum-products-per-user-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.2.8 CVE-2024-9205 Wordfence
5.3 Medium QA Analytics Plugin qa-heatmap-analytics Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 4.1.1.1 CVE-2024-8513 Wordfence
7.2 High UserPlus Plugin userplus Privilege Escalation Authenticated (Editor+) Registration Form Update to Privilege Escalation ≤ 2.0 CVE-2024-9519 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only