WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 23,501–23,550 of 29,262 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | XO Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.8.6 |
CVE-2024-8324 |
Wordfence | |
| 6.1 Medium | LH Copy Media File | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.08 |
CVE-2024-9220 |
Wordfence | |
| 8.8 High | WP Easy Gallery | SQL Injection Authenticated (Contributor+) SQL Injection via key Parameter |
≤ 4.8.5 |
CVE-2024-9018 |
Wordfence | |
| 6.1 Medium | Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More | Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed |
≤ 2.7.2.1 |
CVE-2024-8793 |
Wordfence | |
| 6.4 Medium | Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg | Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 1.2.4 |
CVE-2024-8288 |
Wordfence | |
| 6.1 Medium | Loggedin – Limit Active Logins | Cross-Site Scripting Limit Active Logins <= 1.3.1 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.1 |
CVE-2024-9228 |
Wordfence | |
| 6.1 Medium | Custom Banners | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 3.3 |
CVE-2024-8799 |
Wordfence | |
| 6.5 Medium | Hello World | Path Traversal Authenticated (Subscriber+) Arbitrary File Read |
≤ 2.1.1 |
CVE-2024-9224 |
Wordfence | |
| 6.1 Medium | WP Search Analytics | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.4.10 |
CVE-2024-9209 |
Wordfence | |
| 6.1 Medium | PDF Image Generator | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5.6 |
CVE-2024-9241 |
Wordfence | |
| 6.1 Medium | Easy Load More | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.3 |
CVE-2024-8728 |
Wordfence | |
| 6.1 Medium | DK PDF | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.9.6 |
CVE-2024-8727 |
Wordfence | |
| 8.8 High | UltraPress | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.2.2 |
CVE-2024-7434 |
Wordfence | |
| 6.1 Medium | Easy WordPress Subscribe – Optin Hound | Cross-Site Scripting Optin Hound <= 1.4.3 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed |
≤ 1.4.3 |
CVE-2024-9267 |
Wordfence | |
| 6.4 Medium | Stars Testimonials | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode |
≤ 3.3.1 |
CVE-2024-8989 |
Wordfence | |
| 6.4 Medium | LocateAndFilter | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.6.14 |
CVE-2024-9304 |
Wordfence | |
| 4.3 Medium | Soumettre.fr | Broken Access Control Missing Authorization |
≤ 2.1.3 |
CVE-2024-8675 |
Wordfence | |
| 6.4 Medium | Geo Mashup | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via geo_mashup_visible_posts_list Shortcode |
≤ 1.13.13 |
CVE-2024-8990 |
Wordfence | |
| 6.5 Medium | KB Support – WordPress Help Desk and Knowledge Base | Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure No login needed |
≤ 1.6.6 |
CVE-2024-8632 |
Wordfence | |
| 6.4 Medium | R Animated Icon | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0 |
CVE-2024-9272 |
Wordfence | |
| 8.1 High | KB Support – WordPress Help Desk and Knowledge Base | Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions |
≤ 1.6.6 |
CVE-2024-8548 |
Wordfence | |
| 6.4 Medium | RumbleTalk Live Group Chat – HTML5 | Cross-Site Scripting HTML5 <= 6.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.3.0 |
CVE-2024-8720 |
Wordfence | |
| 6.1 Medium | Gravity Forms Toolbar | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.7.0 |
CVE-2024-8718 |
Wordfence | |
| 6.4 Medium | Elastik Page Builder | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 0.27.4 |
CVE-2024-9274 |
Wordfence | |
| 8.8 High | Empowerment | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.0.2 |
CVE-2024-7433 |
Wordfence | |
| 9.8 Critical | Wechat Social login | Authentication Bypass No login needed |
≤ 1.3.0 |
CVE-2024-9106 |
Wordfence | |
| 7.2 High | 123.chat - Video Chat | Cross-Site Scripting Video Chat <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 1.3.1 |
CVE-2024-7869 |
Wordfence | |
| 6.4 Medium | Relogo | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 0.4.2 |
CVE-2024-9269 |
Wordfence | |
| 8.8 High | Unseen Blog | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.0.0 |
CVE-2024-7432 |
Wordfence | |
| 6.4 Medium | SVG Complete | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.0.2 |
CVE-2024-9119 |
Wordfence | |
| 9.8 Critical | Wechat Social login | Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed |
≤ 1.3.0 |
CVE-2024-9108 |
Wordfence | |
| 6.4 Medium | Slider Revolution | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 6.7.18 |
CVE-2024-8107 |
Wordfence | |
| 7.1 High | Broken Link Checker | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.4.0 |
CVE-2024-8981 |
Wordfence | |
| 6.5 Medium | Move Addons for Elementor | Cross-Site Scripting |
≤ 1.3.3 Fixed in 1.3.4 |
CVE-2024-47396 |
Patchstack | |
| 6.5 Medium | Confetti Fall Animation | Cross-Site Scripting |
≤ 1.3.0 Fixed in 1.3.1 |
CVE-2024-47641 |
Patchstack | |
| 5.4 Medium | Ultimate Blocks | Cross-Site Scripting Contributor+ Stored XSS |
< 3.2.2 Fixed in 3.2.2 |
CVE-2024-8536 |
WPScan | |
| 7.2 High | Cost Calculator Builder | SQL Injection Admin+ SQL Injection |
< 3.2.29 Fixed in 3.2.29 |
CVE-2024-8379 |
WPScan | |
| 4.8 Medium | Slider by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.2.59 Fixed in 1.2.59 |
CVE-2024-8283 |
WPScan | |
| 5.4 Medium | Starbox | Cross-Site Scripting Contributor+ Stored XSS |
< 3.5.3 Fixed in 3.5.3 |
CVE-2024-8239 |
WPScan | |
| 4.8 Medium | The Post Grid | Cross-Site Scripting Editor+ Stored XSS via Grid Creation |
< 7.5.0 Fixed in 7.5.0 |
CVE-2024-3635 |
WPScan | |
| 4.4 Medium | WP MultiTasking - WP Utilities | Cross-Site Scripting WP Utilities <= 0.1.17 - Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 0.1.17 |
CVE-2024-8189 |
Wordfence | |
| 6.1 Medium | GTM Server Side | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.1.19 |
CVE-2024-8712 |
Wordfence | |
| 6.1 Medium | Simple LDAP Login | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.6.0 |
CVE-2024-8715 |
Wordfence | |
| 5.3 Medium | EU/UK VAT Manager for WooCommerce | Broken Access Control Missing Authorization No login needed |
≤ 2.12.12 |
CVE-2024-9189 |
Wordfence | |
| 9.8 Critical | GiveWP – Donation Plugin and Fundraising Platform | PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection No login needed |
≤ 3.16.1 |
CVE-2024-8353 |
Wordfence | |
| 6.4 Medium | WP-WebAuthn | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wwa_login_form Shortcode |
≤ 1.3.3 |
CVE-2024-9023 |
Wordfence | |
| 6.1 Medium | EU/UK VAT Manager for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 2.12.12 |
CVE-2024-8788 |
Wordfence | |
| 6.4 Medium | Simple Popup | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.5 |
CVE-2024-8547 |
Wordfence | |
| 8.8 High | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion |
≤ 4.0.8 |
CVE-2024-7149 |
Wordfence | |
| 7.2 High | The Events Calendar | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 6.6.3 |
CVE-2024-6931 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.