WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 23,651–23,700 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 474 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.8 Medium Enhanced Search Box Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 0.6.1 CVE-2024-8091 WPScan
4.8 Medium Review Ratings Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.6 CVE-2024-8052 WPScan
5.7 Medium Special Feed Items Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.0.1 CVE-2024-8051 WPScan
5.7 Medium Visual Sound (old) Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 1.06 CVE-2024-8047 WPScan
5.7 Medium infolinks Ad Wrap Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 1.0.2 CVE-2024-8044 WPScan
5.7 Medium Vikinghammer Tweet Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 0.2.4 CVE-2024-8043 WPScan
5.7 Medium Logo Manager For Enamad Plugin logo-manager-for-enamad Cross-Site Scripting Admin+ Stored XSS via Widget ≤ 0.7.1 CVE-2024-5170 WPScan
7.1 High Opor Ayam Theme opor-ayam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8 CVE-2024-44053 Patchstack
6.5 Medium Fluida Theme fluida Cross-Site Scripting ≤ 1.8.8 CVE-2024-44054 Patchstack
6.5 Medium Mantra Theme mantra Cross-Site Scripting ≤ 3.3.2 CVE-2024-44056 Patchstack
6.5 Medium Nirvana Theme nirvana Cross-Site Scripting ≤ 1.6.3 CVE-2024-44057 Patchstack
6.5 Medium Parabola Theme parabola Cross-Site Scripting ≤ 2.4.1 CVE-2024-44058 Patchstack
6.5 Medium Custom Query Blocks Plugin post-type-archive-mapping Cross-Site Scripting ≤ 5.3.1 Fixed in 5.4.0 CVE-2024-44059 Patchstack
7.1 High Filmix Theme filmix Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2024-44060 Patchstack
6.5 Medium Custom Field Template Plugin custom-field-template Cross-Site Scripting ≤ 2.6.5 CVE-2024-44062 Patchstack
6.5 Medium Happyforms Plugin happyforms Cross-Site Scripting ≤ 1.26.0 Fixed in 1.26.1 CVE-2024-44063 Patchstack
5.9 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45455 Patchstack
6.5 Medium WP Meta SEO Plugin wp-meta-seo Cross-Site Scripting ≤ 4.5.13 Fixed in 4.5.14 CVE-2024-45456 Patchstack
6.5 Medium Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45457 Patchstack
7.1 High Spiffy Calendar Plugin spiffy-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.9.13 Fixed in 4.9.14 CVE-2024-45458 Patchstack
7.1 High Product Slider for WooCommerce Plugin woocommerce-products-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.13.50 Fixed in 1.13.51 CVE-2024-45459 Patchstack
5.9 Medium Flipping Cards Plugin flipping-cards Cross-Site Scripting ≤ 1.30 Fixed in 1.31 CVE-2024-45460 Patchstack
8.8 High Login with phone number Plugin login-with-phone-number Broken Access Control Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation ≤ 1.7.49 CVE-2024-6482 Wordfence
5.4 Medium Bricks Theme Cross-Site Scripting Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting ≤ 1.10.1 CVE-2023-3410 Wordfence
6.1 Medium WP Booking System – Booking Calendar Plugin wp-booking-system Cross-Site Scripting Booking Calendar <= 2.0.19.8 - Reflected Cross-Site Scripting No login needed ≤ 2.0.19.8 CVE-2024-8797 Wordfence
9.1 Critical Backuply – Backup, Restore, Migrate and Clone Plugin backuply SQL Injection Backup, Restore, Migrate and Clone <= 1.3.4 - Authenticated (Admin+) SQL Injection ≤ 1.3.4 CVE-2024-8669 Wordfence
6.1 Medium Waitlist Woocommerce ( Back in stock notifier ) Plugin waitlist-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2024-8724 Wordfence
7.3 High Simple Spoiler Plugin simple-spoiler Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed 1.2 – 1.3 CVE-2024-8479 Wordfence
8.8 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Privilege Escalation Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.11 - Authenticated (Contributor+) Privilege Escalation ≤ 2.8.11 CVE-2024-8246 Wordfence
7.3 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Arbitrary Shortcode Execution Currency Switcher Professional for WooCommerce <= 1.4.2.1 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.4.2.1 CVE-2024-8271 Wordfence
5.3 Medium WooCommerce Multiple Free Gift Plugin woocommerce-multiple-free-gift Broken Access Control Insufficient Server-Side Validation to Arbitrary Gift Adding No login needed ≤ 1.2.3 CVE-2022-3459 Wordfence
4.3 Medium MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Arbitrary File Upload Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload ≤ 4.15.3 CVE-2024-8242 Wordfence
6.4 Medium Tweaker5 Theme tweaker5 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.2 CVE-2024-5870 Wordfence
6.4 Medium Neighborly Theme neighborly Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.4 CVE-2024-5869 Wordfence
6.1 Medium Exit Notifier Plugin exit-notifier Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.10.4 CVE-2024-8730 Wordfence
7.2 High WP Editor Plugin wp-editor PHP Object Injection Authenticated (Admin+) PHAR Deserialization ≤ 1.2.9 CVE-2022-2446 Wordfence
6.1 Medium Lucas String Replace Plugin lucas-string-replace Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.5 CVE-2024-8734 Wordfence
6.4 Medium Delicate Theme delicate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 3.5.5 CVE-2024-5867 Wordfence
6.1 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3 CVE-2024-8737 Wordfence
6.4 Medium Beauty Theme beauty Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via tpl_featured_cat_id Parameter ≤ 1.1.4 CVE-2024-5884 Wordfence
8.8 High Stream Plugin stream Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 4.0.1 CVE-2024-7423 Wordfence
5.3 Medium Custom Post Limits Plugin custom-post-limits Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 4.4.1 CVE-2024-6544 Wordfence
6.4 Medium Email Obfuscate Shortcode Plugin email-obfuscate-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2024-8747 Wordfence
6.1 Medium Cron Jobs Plugin leira-cron-jobs Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2.9 CVE-2024-8731 Wordfence
6.1 Medium WordPress Affiliates Plugin — SliceWP Affiliates Plugin slicewp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.20 CVE-2024-8714 Wordfence
7.3 High MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Broken Access Control Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration No login needed ≤ 4.15.3 CVE-2024-8269 Wordfence
6.1 Medium Roles & Capabilities Plugin leira-roles Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.9 CVE-2024-8732 Wordfence
6.4 Medium Triton Lite Theme triton-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.3 CVE-2024-5789 Wordfence
6.1 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.0.10 CVE-2024-8663 Wordfence
6.4 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Widget ≤ 6.0.3 CVE-2024-8742 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only