WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,401–23,450 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 469 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.20.13 Fixed in 6.21.01 CVE-2024-47384 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.8.4 Fixed in 4.9.0 CVE-2024-47385 Patchstack
7.1 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-47386 Patchstack
5.9 Medium Search Atlas SEO Plugin metasync Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-47387 Patchstack
7.1 High SliceWP Plugin slicewp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.18 Fixed in 1.1.19 CVE-2024-47388 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.7.3 Fixed in 8.7.4 CVE-2024-47389 Patchstack
6.5 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting ≤ 2.6.8 Fixed in 2.6.9 CVE-2024-47390 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.1.1 Fixed in 5.1.1 CVE-2024-47391 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.7.5 Fixed in 5.7.6 CVE-2024-47392 Patchstack
6.5 Medium Quill Forms Plugin quillforms Cross-Site Scripting ≤ 3.7.0 Fixed in 3.8.0 CVE-2024-47393 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.9 Fixed in 2.6.1 CVE-2024-47394 Patchstack
7.1 High Robokassa payment gateway for Woocommerce Plugin robokassa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-47395 Patchstack
6.5 Medium Zotpress Plugin zotpress Cross-Site Scripting ≤ 7.3.10 Fixed in 7.3.11 CVE-2024-47621 Patchstack
6.5 Medium Advanced Woo Labels Plugin advanced-woo-labels Cross-Site Scripting ≤ 2.01 Fixed in 2.02 CVE-2024-47622 Patchstack
5.9 Medium Gallery Lightbox Plugin gallery-lightbox-slider Cross-Site Scripting ≤ 1.0.0.39 Fixed in 1.0.0.41 CVE-2024-47623 Patchstack
7.1 High BSK Forms Blacklist Plugin bsk-gravityforms-blacklist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.8.1 Fixed in 3.9 CVE-2024-47624 Patchstack
6.5 Medium Enter Addons Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor plugin <= 2.1.8 - Cross Site Scripting (XSS) ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-47625 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-47626 Patchstack
6.5 Medium WP Travel Gutenberg Blocks Plugin wp-travel-blocks Cross-Site Scripting ≤ 3.6.0 Fixed in 3.7.0 CVE-2024-47627 Patchstack
6.5 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting ≤ 1.3.9.3 Fixed in 1.3.9.7 CVE-2024-47628 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2024-47629 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-47630 Patchstack
6.5 Medium Logo Carousel – Clients logo carousel for WP Plugin responsive-client-logo-carousel-slider Cross-Site Scripting Clients logo carousel for WP plugin <= 1.2 - Cross Site Scripting (XSS) ≤ 1.2 Fixed in 1.3.0 CVE-2024-47631 Patchstack
6.5 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Cross-Site Scripting ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-47632 Patchstack
6.5 Medium Zoho Forms Plugin zoho-forms Cross-Site Scripting ≤ 4.0 Fixed in 4.0.1 CVE-2024-47633 Patchstack
5.4 Medium TinyPNG Plugin tiny-compress-images Cross-Site Request Forgery No login needed ≤ 3.4.3 Fixed in 3.4.4 CVE-2024-47635 Patchstack
7.1 High Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.6 Fixed in 4.5 CVE-2024-47638 Patchstack
6.5 Medium VdoCipher Plugin vdocipher Cross-Site Scripting ≤ 1.29 Fixed in 1.30 CVE-2024-47639 Patchstack
6.5 Medium Keap Official Opt-in Forms Plugin infusionsoft-official-opt-in-forms Cross-Site Scripting ≤ 2.0.3 CVE-2024-47642 Patchstack
6.5 Medium Include Fussball.de Widgets Plugin include-fussball-de-widgets Cross-Site Scripting ≤ 4.0.0 CVE-2024-47643 Patchstack
7.1 High Copyscape Premium Plugin copyscape-premium Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-47644 Patchstack
4.7 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Open Redirect No login needed ≤ 2.6.1 Fixed in 2.6.2 CVE-2024-47646 Patchstack
5.9 Medium Helpie FAQ Plugin helpie-faq Cross-Site Scripting Helpie WordPress FAQ Accordion plugin plugin <= 1.27 - Cross Site Scripting (XSS) ≤ 1.27 Fixed in 1.28 CVE-2024-47647 Patchstack
7.5 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Local File Inclusion ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47324 Patchstack
8.1 High WP Timeline – Vertical and Horizontal timeline Plugin wp-timelines Local File Inclusion No login needed ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-47323 Patchstack
8.0 High Bit Form Plugin bit-form Arbitrary File Upload ≤ 2.13.10 Fixed in 2.13.11 CVE-2024-47319 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Broken Access Control Insecure Direct Object References (IDOR) ≤ 10.9 Fixed in 10.9.1 CVE-2024-47316 Patchstack
6.6 Medium Cities Shipping Zones for WooCommerce Plugin cities-shipping-zones-for-woocommerce Local File Inclusion ≤ 1.2.7 Fixed in 1.2.8 CVE-2024-47309 Patchstack
7.5 High WPSPX Plugin wpspx Local File Inclusion No login needed ≤ 1.0.2 CVE-2024-44034 Patchstack
8.1 High ABCApp Creator Plugin abcapp-creator Local File Inclusion No login needed ≤ 1.1.2 CVE-2024-44023 Patchstack
7.5 High Instant Chat Floating Button for WordPress Websites Plugin instant-chat-wp Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44018 Patchstack
7.2 High Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math PHP Object Injection AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) PHP Object Injection ≤ 1.0.228 CVE-2024-9314 Wordfence
6.5 Medium Rank Math SEO – AI SEO Tools to Dominate SEO Rankings Plugin seo-by-rank-math Broken Access Control AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthenticated User and Term Metadata Insert, Update, and Delete No login needed ≤ 1.0.228 CVE-2024-9161 Wordfence
7.5 High Podiant Plugin podiant Local File Inclusion No login needed ≤ 1.1 CVE-2024-44016 Patchstack
7.5 High Users Control Plugin users-control Local File Inclusion No login needed ≤ 1.0.16 CVE-2024-44015 Patchstack
9.6 Critical Vmax Project Manager Plugin vmax-project-manager Local File Inclusion Local File Inclusion to RCE No login needed ≤ 1.0 CVE-2024-44014 Patchstack
7.5 High VR Calendar Plugin vr-calendar-sync Local File Inclusion No login needed ≤ 2.4.0 Fixed in 2.4.5 CVE-2024-44013 Patchstack
7.5 High WP Newsletter Subscription Plugin wp-newsletter-subscription Local File Inclusion No login needed ≤ 1.1 CVE-2024-44012 Patchstack
7.5 High WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44011 Patchstack
4.9 Medium CSS JS Files Plugin css-js-files Path Traversal Directory Traversal to File Read ≤ 1.5.0 Fixed in 1.5.1 CVE-2024-9146 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only