WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 23,601–23,650 of 29,262 vulnerabilities

Known WordPress vulnerabilities, page 473 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.1 Critical WordPress Simple HTML Sitemap Plugin wp-simple-html-sitemap SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.1 CVE-2024-7385 Wordfence
4.3 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Information Disclosure Authenticated (Contributor+) Information Exposure ≤ 2.2.1 CVE-2024-8516 Wordfence
6.4 Medium Themesflat Addons For Elementor Plugin themesflat-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-8515 Wordfence
9.1 Critical Prisna GWT - Google Website Translator Plugin google-website-translator PHP Object Injection Google Website Translator <= 1.4.11 - Authenticated (Admin+) PHP Object Injection ≤ 1.4.11 CVE-2024-8514 Wordfence
2.7 Low Uncanny Groups for LearnDash Plugin Broken Access Control Missing Authorization to Authenticated (Group Leader+) User Group Add ≤ 6.1.0.1 CVE-2024-8350 Wordfence
7.2 High Uncanny Groups for LearnDash Plugin Privilege Escalation Authenticated (Group Leader+) Privilege Escalation ≤ 6.1.0.1 CVE-2024-8349 Wordfence
6.4 Medium GutenGeek Free Gutenberg Blocks Plugin gtg-advanced-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.1.3 CVE-2024-9073 Wordfence
5.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.6.1 - Insecure Direct Object Reference to Unsubscribe No login needed ≤ 1.3.6.1 CVE-2024-7491 Wordfence
6.3 Medium WPGSI: Spreadsheet Integration Plugin wpgsi Broken Access Control Automate Google Sheets With WordPress, WooCommerce & Most Popular Form Plugins. Also, Display Google sheet as a Table. <= 3.8.0 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 3.8.0 CVE-2024-6590 Wordfence
4.3 Medium Easy Mega Menu Plugin for WordPress – ThemeHunk Plugin themehunk-megamenu-plus Broken Access Control ThemeHunk <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Settings Updates ≤ 1.0.9 CVE-2024-8434 Wordfence
9.8 Critical REST API TO MiniProgram Plugin rest-api-to-miniprogram Privilege Escalation Unauthenticated Arbitrary User Email Update and Privilege Escalation via Account Takeover No login needed ≤ 4.7.1 CVE-2024-8485 Wordfence
6.4 Medium Material Design Icons Plugin material-design-icons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mdi-icon Shortcode ≤ 0.0.5 CVE-2024-9024 Wordfence
6.4 Medium WP GPX Maps Plugin wp-gpx-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sgpx Shortcode ≤ 1.7.08 CVE-2024-9028 Wordfence
9.9 Critical Daily Prayer Time Plugin daily-prayer-time-for-mosques SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2024.08.26 CVE-2024-8621 Wordfence
4.3 Medium MAS Static Content Plugin mas-static-content Information Disclosure Authenticated (Contributor+) Private Static Content Page Disclosure ≤ 1.0.8 CVE-2024-8483 Wordfence
7.5 High REST API TO MiniProgram Plugin rest-api-to-miniprogram SQL Injection Unauthenticated SQL Injection No login needed ≤ 4.7.1 CVE-2024-8484 Wordfence
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2024-8476 Wordfence
6.1 Medium Kodex Posts likes Plugin kodex-posts-likes Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.5.0 CVE-2024-8713 Wordfence
6.4 Medium OneElements – Best Elementor Addons Plugin oneelements-ultimate-addons-for-elementor Cross-Site Scripting Best Elementor Addons <= 1.3.7 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.3.7 CVE-2024-9068 Wordfence
7.2 High Contact Form to Any API Plugin contact-form-to-any-api Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Contact Form No login needed ≤ 1.2.4 CVE-2024-7617 Wordfence
6.4 Medium Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) Plugin graphicsly Cross-Site Scripting The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) <= 1.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 1.0.2 CVE-2024-9069 Wordfence
6.1 Medium Beam me up Scotty – Back to Top Button Plugin beam-me-up-scotty Cross-Site Scripting Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting No login needed ≤ 1.0.21 CVE-2024-8741 Wordfence
5.3 Medium Community by PeepSo – Social Network, Membership, Registration, User Profiles Plugin peepso-core Information Disclosure Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthenticated Full Path Disclosure No login needed ≤ 6.4.6.0 CVE-2024-7426 Wordfence
6.4 Medium WPZOOM Shortcodes Plugin wpzoom-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via box Shortcode ≤ 1.0.5 CVE-2024-9027 Wordfence
6.1 Medium Simple Calendar – Google Calendar Plugin google-calendar-events Cross-Site Scripting Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting No login needed ≤ 3.4.2 CVE-2024-8549 Wordfence
7.3 High Special Text Boxes Plugin tags Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 6.2.4 CVE-2024-8481 Wordfence
4.3 Medium Premium Packages – Sell Digital Products Securely Plugin wpdm-premium-packages Cross-Site Request Forgery Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery No login needed ≤ 5.9.1 CVE-2024-7386 Wordfence
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 3.12.2 CVE-2024-8801 Wordfence
9.9 Critical WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery SQL Injection WordPress Gallery Plugin <= 4.8.5 - Authenticated (Subscriber+) SQL Injection ≤ 4.8.5 CVE-2024-8436 Wordfence
4.3 Medium WP Easy Gallery – WordPress Gallery Plugin wp-easy-gallery Broken Access Control WordPress Gallery Plugin <= 4.8.5 - Missing Authorization to Authenticated (Subscriber+) Gallery Manipulation ≤ 4.8.5 CVE-2024-8437 Wordfence
3.7 Low W3 Total Cache Plugin w3-total-cache Information Disclosure Sensitive Credentials Stored in Plaintext No login needed ≤ 2.7.5 CVE-2023-5359 Wordfence
7.2 High Thanh Toán Quét Mã QR Code Tự Động – MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam Plugin bck-tu-dong-xac-nhan-thanh-toan-chuyen-khoan-ngan-hang Cross-Site Scripting MoMo, ViettelPay, VNPay và 40 ngân hàng Việt Nam <= 2.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.0.1 CVE-2024-8914 Wordfence
6.4 Medium WP Category Dropdown Plugin wp-category-dropdown Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter ≤ 1.8 CVE-2024-8103 Wordfence
6.4 Medium Confetti Fall Animation Plugin confetti-fall-animation Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via confetti-fall-animation Shortcode ≤ 1.3.1 CVE-2024-8919 Wordfence
6.4 Medium Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player Plugin radio-player Cross-Site Scripting Live Shoutcast, Icecast and Any Audio Stream Player for WordPress <= 2.0.78 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 2.0.78 CVE-2024-8267 Wordfence
6.4 Medium AnWP Football Leagues Plugin football-leagues-by-anwppro Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 0.16.7 CVE-2024-8917 Wordfence
5.4 Medium Popup, Optin Form & Email Newsletters for Mailchimp, HubSpot, AWeber – MailOptin Plugin mailoptin Cross-Site Scripting MailOptin <= 1.2.70.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.70.3 CVE-2024-8628 Wordfence
7.2 High Easy Digital Downloads – Simple eCommerce for Selling Digital Files Plugin easy-digital-downloads PHP Object Injection Simple eCommerce for Selling Digital Files <= 3.3.3 - Authenticated (Admin+) PHAR Deserialization ≤ 3.3.3 CVE-2022-2439 Wordfence
9.1 Critical WooEvents Plugin Remote Code Execution Unauthenticated Arbitrary File Overwrite No login needed ≤ 4.1.2 CVE-2024-8671 Wordfence
7.3 High MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter Arbitrary Shortcode Execution Meta Data and Taxonomies Filter <= 1.3.3.3 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.3.3.3 CVE-2024-8623 Wordfence
5.3 Medium BA Book Everything Plugin ba-book-everything Privilege Escalation Unauthenticated Arbitrary User Password Reset No login needed ≤ 1.6.20 CVE-2024-8794 Wordfence
9.9 Critical MDTF – Meta Data and Taxonomies Filter Plugin wp-meta-data-filter-and-taxonomy-filter SQL Injection Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL Injection ≤ 1.3.3.3 CVE-2024-8624 Wordfence
9.8 Critical Donation Forms by Charitable – Donations Plugin & Fundraising Platform Plugin charitable Broken Access Control Donations Plugin & Fundraising Platform for WordPress <= 1.8.1.14 - Insecure Direct Object Reference to Account Takeover and Privilege Escalation No login needed ≤ 1.8.1.14 CVE-2024-8791 Wordfence
6.1 Medium Seriously Simple Stats Plugin seriously-simple-stats Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2024-8738 Wordfence
6.1 Medium Pixel Cat – Conversion Pixel Manager Plugin facebook-conversion-pixel Cross-Site Scripting Conversion Pixel Manager <= 3.0.5 - Reflected Cross-Site Scripting No login needed ≤ 3.0.5 CVE-2024-8544 Wordfence
8.8 High BA Book Everything Plugin ba-book-everything Cross-Site Request Forgery Cross-Site Request Forgery to Email Address Update/Account Takeover No login needed ≤ 1.6.20 CVE-2024-8795 Wordfence
6.1 Medium Koko Analytics Plugin koko-analytics Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3.12 CVE-2024-8662 Wordfence
6.1 Medium XT Ajax Add To Cart for WooCommerce Plugin xt-woo-ajax-add-to-cart Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.2 CVE-2024-8716 Wordfence
6.4 Medium Garden Gnome Package Plugin garden-gnome-package Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.9 CVE-2024-8657 Wordfence
4.3 Medium Appointment & Event Booking Calendar Plugin – Webba Booking Plugin webba-booking-lite Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update ≤ 5.0.48 CVE-2024-8432 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only