WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,501–23,550 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 471 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium XO Slider Plugin xo-liteslider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.8.6 CVE-2024-8324 Wordfence
6.1 Medium LH Copy Media File Plugin lh-copy-media-file Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.08 CVE-2024-9220 Wordfence
8.8 High WP Easy Gallery Plugin wp-easy-gallery SQL Injection Authenticated (Contributor+) SQL Injection via key Parameter ≤ 4.8.5 CVE-2024-9018 Wordfence
6.1 Medium Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More Plugin woocommerce-exporter Cross-Site Scripting Export Products, Export Orders, Export Subscriptions, and More <= 2.7.2.1 - Reflected Cross-Site Scripting No login needed ≤ 2.7.2.1 CVE-2024-8793 Wordfence
6.4 Medium Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg Plugin guten-post-layout Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.2.4 CVE-2024-8288 Wordfence
6.1 Medium Loggedin – Limit Active Logins Plugin loggedin Cross-Site Scripting Limit Active Logins <= 1.3.1 - Reflected Cross-Site Scripting No login needed ≤ 1.3.1 CVE-2024-9228 Wordfence
6.1 Medium Custom Banners Plugin custom-banners Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.3 CVE-2024-8799 Wordfence
6.5 Medium Hello World Plugin hello-world Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 2.1.1 CVE-2024-9224 Wordfence
6.1 Medium WP Search Analytics Plugin search-analytics Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.4.10 CVE-2024-9209 Wordfence
6.1 Medium PDF Image Generator Plugin pdf-image-generator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.5.6 CVE-2024-9241 Wordfence
6.1 Medium Easy Load More Plugin easy-load-more Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2024-8728 Wordfence
6.1 Medium DK PDF Plugin dk-pdf Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.9.6 CVE-2024-8727 Wordfence
8.8 High UltraPress Theme ultrapress PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.2.2 CVE-2024-7434 Wordfence
6.1 Medium Easy WordPress Subscribe – Optin Hound Plugin opt-in-hound Cross-Site Scripting Optin Hound <= 1.4.3 - Reflected Cross-Site Scripting via add_query_arg Parameter No login needed ≤ 1.4.3 CVE-2024-9267 Wordfence
6.4 Medium Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode ≤ 3.3.1 CVE-2024-8989 Wordfence
6.4 Medium LocateAndFilter Plugin locateandfilter Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.6.14 CVE-2024-9304 Wordfence
4.3 Medium Soumettre.fr Plugin soumettre-fr Broken Access Control Missing Authorization ≤ 2.1.3 CVE-2024-8675 Wordfence
6.4 Medium Geo Mashup Plugin geo-mashup Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via geo_mashup_visible_posts_list Shortcode ≤ 1.13.13 CVE-2024-8990 Wordfence
6.5 Medium KB Support – WordPress Help Desk and Knowledge Base Plugin Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure No login needed ≤ 1.6.6 CVE-2024-8632 Wordfence
6.4 Medium R Animated Icon Plugin r-animated-icon Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0 CVE-2024-9272 Wordfence
8.1 High KB Support – WordPress Help Desk and Knowledge Base Plugin Broken Access Control WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions ≤ 1.6.6 CVE-2024-8548 Wordfence
6.4 Medium RumbleTalk Live Group Chat – HTML5 Plugin rumbletalk-chat-a-chat-with-themes Cross-Site Scripting HTML5 <= 6.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.3.0 CVE-2024-8720 Wordfence
6.1 Medium Gravity Forms Toolbar Plugin gravity-forms-toolbar Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2024-8718 Wordfence
6.4 Medium Elastik Page Builder Plugin elastik-page-builder Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 0.27.4 CVE-2024-9274 Wordfence
8.8 High Empowerment Theme empowerment PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.0.2 CVE-2024-7433 Wordfence
9.8 Critical Wechat Social login Plugin wechat-social-login Authentication Bypass No login needed ≤ 1.3.0 CVE-2024-9106 Wordfence
7.2 High 123.chat - Video Chat Plugin 123-chat-videochat Cross-Site Scripting Video Chat <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.3.1 CVE-2024-7869 Wordfence
6.4 Medium Relogo Plugin relogo Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 0.4.2 CVE-2024-9269 Wordfence
8.8 High Unseen Blog Theme unseen-blog PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.0.0 CVE-2024-7432 Wordfence
6.4 Medium SVG Complete Plugin svg-complete Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9119 Wordfence
9.8 Critical Wechat Social login Plugin wechat-social-login Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.3.0 CVE-2024-9108 Wordfence
6.4 Medium Slider Revolution Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 6.7.18 CVE-2024-8107 Wordfence
7.1 High Broken Link Checker Plugin broken-link-checker Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.0 CVE-2024-8981 Wordfence
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2024-47396 Patchstack
6.5 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-47641 Patchstack
5.4 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Contributor+ Stored XSS < 3.2.2 Fixed in 3.2.2 CVE-2024-8536 WPScan
7.2 High Cost Calculator Builder Plugin cost-calculator-builder SQL Injection Admin+ SQL Injection < 3.2.29 Fixed in 3.2.29 CVE-2024-8379 WPScan
4.8 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Admin+ Stored XSS < 1.2.59 Fixed in 1.2.59 CVE-2024-8283 WPScan
5.4 Medium Starbox Plugin starbox Cross-Site Scripting Contributor+ Stored XSS < 3.5.3 Fixed in 3.5.3 CVE-2024-8239 WPScan
4.8 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting Editor+ Stored XSS via Grid Creation < 7.5.0 Fixed in 7.5.0 CVE-2024-3635 WPScan
4.4 Medium WP MultiTasking - WP Utilities Plugin wp-multitasking Cross-Site Scripting WP Utilities <= 0.1.17 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 0.1.17 CVE-2024-8189 Wordfence
6.1 Medium GTM Server Side Plugin gtm-server-side Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.1.19 CVE-2024-8712 Wordfence
6.1 Medium Simple LDAP Login Plugin simple-ldap-login Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-8715 Wordfence
5.3 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Broken Access Control Missing Authorization No login needed ≤ 2.12.12 CVE-2024-9189 Wordfence
9.8 Critical GiveWP – Donation Plugin and Fundraising Platform Plugin give PHP Object Injection Donation Plugin and Fundraising Platform <= 3.16.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.16.1 CVE-2024-8353 Wordfence
6.4 Medium WP-WebAuthn Plugin wp-webauthn Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wwa_login_form Shortcode ≤ 1.3.3 CVE-2024-9023 Wordfence
6.1 Medium EU/UK VAT Manager for WooCommerce Plugin eu-vat-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.12.12 CVE-2024-8788 Wordfence
6.4 Medium Simple Popup Plugin simple-popup-plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5 CVE-2024-8547 Wordfence
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.8 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.8 CVE-2024-7149 Wordfence
7.2 High The Events Calendar Plugin the-events-calendar Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 6.6.3 CVE-2024-6931 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only