WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 23,451–23,500 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Hash Form - Drag & Drop Form Builder | Arbitrary File Upload Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload No login needed |
≤ 1.1.9 |
CVE-2024-9417 |
Wordfence | |
| 6.4 Medium | Shortcodes and extra features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Modern Heading and Icon Picker Widgets |
≤ 2.16.3 |
CVE-2024-8486 |
Wordfence | |
| 6.8 Medium | Bit File Manager – 100% Free & Open Source File Manager and Code Editor | Arbitrary File Upload Authenticated (Subscriber+) Limited JavaScript File Upload |
≤ 6.5.7 |
CVE-2024-8743 |
Wordfence | |
| 4.9 Medium | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | Cross-Site Scripting Authenticated (Form Manager+) Stored Cross-Site Scripting |
≤ 5.1.19 |
CVE-2024-9528 |
Wordfence | |
| 6.1 Medium | Themify Builder | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 7.6.2 |
CVE-2024-9385 |
Wordfence | |
| 6.4 Medium | WP Cleanup and Basic Functions | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.2.1 |
CVE-2024-9455 |
Wordfence | |
| 4.7 Medium | Checkout Field Editor (Checkout Manager) for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting via render_review_request_notice No login needed |
≤ 2.0.3 |
CVE-2024-8499 |
Wordfence | |
| 6.4 Medium | Re:WP | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.1 |
CVE-2024-9271 |
Wordfence | |
| 6.4 Medium | Easy Demo Importer – A Modern One-Click Demo Import Solution | Cross-Site Scripting A Modern One-Click Demo Import Solution <= 1.1.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.1.2 |
CVE-2024-9071 |
Wordfence | |
| 6.1 Medium | ShiftController Employee Shift Scheduling | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.9.66 |
CVE-2024-9435 |
Wordfence | |
| 4.4 Medium | WP Booking Calendar | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 10.6 |
CVE-2024-9306 |
Wordfence | |
| 6.4 Medium | Memberful – Membership | Cross-Site Scripting Membership Plugin <= 1.73.7 - Authenticated (contributor+) Stored Cross-Site Scripting |
≤ 1.73.7 |
CVE-2024-9242 |
Wordfence | |
| 6.4 Medium | Code Embed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4 |
CVE-2024-8804 |
Wordfence | |
| 6.1 Medium | Fish and Ships | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5.9 |
CVE-2024-9237 |
Wordfence | |
| 6.4 Medium | Ultimate Member | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.6 |
CVE-2024-8519 |
Wordfence | |
| 5.3 Medium | Ultimate Member | Cross-Site Request Forgery Cross-Site Request Forgery to Membership Status Change No login needed |
≤ 2.8.6 |
CVE-2024-8520 |
Wordfence | |
| 6.1 Medium | Quantity Dynamic Pricing & Bulk Discounts for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.8.0 |
CVE-2024-9384 |
Wordfence | |
| 6.4 Medium | Display Medium Posts | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via display_medium_posts Shortcode |
≤ 5.0.1 |
CVE-2024-9445 |
Wordfence | |
| 6.1 Medium | WordPress Captcha Plugin by Captcha Bank | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.0.36 |
CVE-2024-9375 |
Wordfence | |
| 6.1 Medium | Smart Custom 404 Error Page | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 11.4.7 |
CVE-2024-9204 |
Wordfence | |
| 6.4 Medium | Login Logout Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via class Parameter |
≤ 1.1.0 |
CVE-2024-9421 |
Wordfence | |
| 6.4 Medium | Aggregator Advanced Settings | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.2.1 |
CVE-2024-9368 |
Wordfence | |
| 6.4 Medium | WP Blocks Hub | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.2 |
CVE-2024-9372 |
Wordfence | |
| 6.1 Medium | Auto Amazon Links – Amazon Associates Affiliate | Cross-Site Scripting Amazon Associates Affiliate Plugin <= 5.4.2 - Reflected Cross-Site Scripting No login needed |
≤ 5.4.2 |
CVE-2024-9349 |
Wordfence | |
| 6.1 Medium | Popularis Extra | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.2.6 |
CVE-2024-9353 |
Wordfence | |
| 6.1 Medium | Product Delivery Date for WooCommerce – Lite | Cross-Site Scripting Lite <= 2.7.3 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.3 |
CVE-2024-9345 |
Wordfence | |
| 6.1 Medium | Clio Grow | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.2 |
CVE-2024-8802 |
Wordfence | |
| 7.5 High | Social Web Suite – Social Media Auto Post, Social Media Auto Publish | Path Traversal Social Media Auto Post, Social Media Auto Publish <= 4.1.11 - Directory Traversal to Arbitrary File Download No login needed |
≤ 4.1.11 |
CVE-2024-8352 |
Wordfence | |
| 6.4 Medium | WordPress Infinite Scroll - Ajax Load More | Cross-Site Scripting Ajax Load More <= 7.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via button_label Parameter |
≤ 7.1.2 |
CVE-2024-8505 |
Wordfence | |
| 6.4 Medium | Ibtana – WordPress Website Builder | Cross-Site Scripting WordPress Website Builder <= 1.2.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 1.2.4.4 |
CVE-2024-8282 |
Wordfence | |
| 7.5 High | MH Board | Local File Inclusion No login needed |
≤ 1.3.2.1 |
CVE-2024-44017 |
Patchstack | |
| 7.2 High | Checkout Mestres WP | Local File Inclusion |
≤ 8.6 Fixed in 8.6.1 |
CVE-2024-44030 |
Patchstack | |
| 6.1 Medium | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | Cross-Site Scripting Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.14 |
CVE-2024-9218 |
Wordfence | |
| 6.1 Medium | YML for Yandex Market | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 4.7.2 |
CVE-2024-9378 |
Wordfence | |
| 6.1 Medium | BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript | Cross-Site Scripting Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript <= 2.1.1 - Reflected Cross-Site Scripting No login needed |
≤ 2.1.1 |
CVE-2024-9344 |
Wordfence | |
| 6.1 Medium | RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more | Cross-Site Scripting Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more <= 2.21.0 - Reflected Cross-Site Scripting No login needed |
≤ 2.21.0 |
CVE-2024-8800 |
Wordfence | |
| 6.1 Medium | Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction | Cross-Site Scripting Effortless Memberships, Recurring Payments & Content Restriction <= 2.12.8 - Reflected Cross-Site Scripting No login needed |
≤ 2.12.8 |
CVE-2024-9222 |
Wordfence | |
| 6.1 Medium | MC4WP: Mailchimp Top Bar | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.0 |
CVE-2024-9210 |
Wordfence | |
| 6.1 Medium | SEOPress – On-site SEO | Cross-Site Scripting On-site SEO <= 8.1.1 - Reflected Cross-Site Scripting No login needed |
≤ 8.1.1 |
CVE-2024-9225 |
Wordfence | |
| 6.4 Medium | Demo Importer Plus | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.0.1 |
CVE-2024-9172 |
Wordfence | |
| 6.4 Medium | PWA — easy way to Progressive Web App | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.6.3 |
CVE-2024-8967 |
Wordfence | |
| 5.4 Medium | Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce | Arbitrary Shortcode Execution Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.34 - Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 5.7.34 |
CVE-2024-8254 |
Wordfence | |
| 7.5 High | Migration, Backup, Staging – WPvivid | Information Disclosure WPvivid < 0.9.106 - Unauthenticated Sensitive Data Exposure No login needed |
0.9.103 – < 0.9.106 Fixed in 0.9.106 |
CVE-2024-7315 |
WPScan | |
| 8.8 High | WP Hotel Booking | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 2.1.2 |
CVE-2024-7855 |
Wordfence | |
| 6.4 Medium | QS Dark Mode | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.9 |
CVE-2024-9118 |
Wordfence | |
| 6.4 Medium | AVIF & SVG Uploader | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
1.1.0 |
CVE-2024-9060 |
Wordfence | |
| 9.8 Critical | WordPress & WooCommerce Affiliate Program | Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed |
≤ 8.4.1 |
CVE-2024-9289 |
Wordfence | |
| 5.3 Medium | Spice Starter Sites | Broken Access Control Missing Authorization to Unauthenticated Demo Content Import No login needed |
≤ 1.2.5 |
CVE-2024-8430 |
Wordfence | |
| 9.8 Critical | Echo RSS Feed Post Generator | Privilege Escalation Unauthenticated Privilege Escalation No login needed |
≤ 5.4.6 |
CVE-2024-9265 |
Wordfence | |
| 6.1 Medium | Auto Featured Image from Title | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.3 |
CVE-2024-8786 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.