WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 23,701–23,750 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 475 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WP Test Email Plugin wp-test-email Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2024-8664 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File ≤ 27.5.5 CVE-2024-5567 Wordfence
6.1 Medium YITH Custom Login Plugin yith-custom-login Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.3 CVE-2024-8665 Wordfence
6.3 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Broken Access Control Classified ads & Business Directory Plugin <= 3.1.7 - Missing Authorization ≤ 3.1.7 CVE-2024-7888 Wordfence
6.5 Medium Favicon Generator Plugin Arbitrary File Deletion Arbitrary File Deletion via CSRF No login needed < 2.1 Fixed in 2.1 CVE-2024-7864 WPScan
8.1 High Favicon Generator Plugin Arbitrary File Upload Arbitrary File Upload via CSRF < 2.1 Fixed in 2.1 CVE-2024-7863 WPScan
4.8 Medium My Sticky Bar Plugin mystickymenu Cross-Site Scripting Admin+ Stored XSS < 2.7.3 Fixed in 2.7.3 CVE-2024-7133 WPScan
7.2 High Appointment Booking Calendar Plugin appointment-booking-calendar Remote Code Execution Admin+ Template Injection to RCE < 1.6.7.43 Fixed in 1.6.7.43 CVE-2024-7129 WPScan
4.8 Medium Carousel Slider Plugin carousel-slider Cross-Site Scripting Editor+ Stored XSS < 2.2.4 Fixed in 2.2.4 CVE-2024-6850 WPScan
4.7 Medium AI Engine Plugin ai-engine SQL Injection Admin+ SQLi < 2.4.8 Fixed in 2.4.8 CVE-2024-6723 WPScan
4.8 Medium NinjaTeam Header Footer Custom Code Plugin header-footer-code Cross-Site Scripting Admin+ Stored XSS via CSS Styles < 1.2 Fixed in 1.2 CVE-2024-6617 WPScan
4.8 Medium NinjaTeam Header Footer Custom Code Plugin header-footer-code Cross-Site Scripting Admin+ Stored XSS < 1.2 Fixed in 1.2 CVE-2024-6493 WPScan
6.4 Medium Avada | Website Builder For WordPress & eCommerce Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fusion_button Shortcode ≤ 3.11.9 CVE-2024-5628 Wordfence
6.1 Medium WPFactory Helper Plugin wpcodefactory-helper Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2024-8656 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields' No login needed ≤ 4.2.7 CVE-2024-8529 Wordfence
10.0 Critical LearnPress – WordPress LMS Plugin learnpress SQL Injection WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields' No login needed ≤ 4.2.7 CVE-2024-8522 Wordfence
6.1 Medium amCharts: Charts and Maps Plugin amcharts-charts-and-maps Cross-Site Scripting Reflected Cross-Site Scripting via Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2024-8622 Wordfence
6.1 Medium MM-Breaking News Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.7.9 CVE-2024-8056 WPScan
6.1 Medium MM-Breaking News Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.7.9 CVE-2024-8054 WPScan
4.3 Medium Blog Introduction Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 0.3.0 CVE-2024-7862 WPScan
6.1 Medium Misiek Paypal Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.1.20090324 CVE-2024-7861 WPScan
6.1 Medium Simple Headline Rotator Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7860 WPScan
6.5 Medium Visual Sound Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.03 CVE-2024-7859 WPScan
6.1 Medium Quick Code Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7822 WPScan
4.3 Medium ILC Thickbox Plugin Cross-Site Request Forgery Settings update via CSRF No login needed ≤ 1.0 CVE-2024-7820 WPScan
6.1 Medium Misiek Photo Album Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.4.3 CVE-2024-7818 WPScan
6.5 Medium Misiek Photo Album Plugin Cross-Site Request Forgery Album Deletion via CSRF No login needed ≤ 1.4.3 CVE-2024-7817 WPScan
6.1 Medium Gixaw Chat Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2024-7816 WPScan
7.2 High Adicon Server Plugin adicon-server-16x16 SQL Injection Admin+ SQL Injection ≤ 1.2 CVE-2024-7766 WPScan
4.8 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Scripting Editor+ Stored XSS < 1.12.16 Fixed in 1.12.16 CVE-2024-6887 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Unauthenticated Stored XSS No login needed ≤ 1.3 CVE-2024-6019 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.3 CVE-2024-6018 WPScan
6.1 Medium Music Request Manager Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.3 CVE-2024-6017 WPScan
4.8 Medium CM Pop-Up Banners Plugin Cross-Site Scripting Contributor+ Stored XSS < 1.7.3 Fixed in 1.7.3 CVE-2024-5799 WPScan
4.3 Medium Easy Property Listings Plugin easy-property-listings Cross-Site Request Forgery Arbitrary Contact Deletion via CSRF No login needed < 3.5.4 Fixed in 3.5.4 CVE-2024-3163 WPScan
5.4 Medium Elementor Website Builder – More than Just a Page Builder Plugin elementor Cross-Site Scripting More than Just a Page Builder <= 3.23.4 - Authenticated (Contributor+) Stored Cross-Site Scripting in the URL Parameter in Multiple Widgets ≤ 3.23.4 CVE-2024-5416 Wordfence
9.8 Critical WooCommerce Photo Reviews Premium Plugin Authentication Bypass Authentication Bypass to Account Takeover and Privilege Escalation No login needed ≤ 1.3.13.2 CVE-2024-8277 Wordfence
4.9 Medium video carousel slider with lightbox Plugin wp-responsive-video-gallery-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.6 CVE-2019-25212 Wordfence
6.4 Medium Advanced WordPress Backgrounds Plugin advanced-backgrounds Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via imageTag Parameter ≤ 1.12.3 CVE-2024-8045 Wordfence
8.1 High WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) Plugin delicious-recipes Remote Code Execution Recipe Plugin for Food Bloggers (formerly Delicious Recipes) <= 1.6.9 - Improper Path Validation to Authenticated (Subscriber+) Arbitrary File Move and Read ≤ 1.6.9 CVE-2024-7626 Wordfence
6.4 Medium Essential Addons for Elementor -- Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget ≤ 6.0.3 CVE-2024-8440 Wordfence
4.8 Medium GS Logo Slider Lite Plugin Cross-Site Scripting Admin+ Stored XSS < 3.6.9 Fixed in 3.6.9 CVE-2024-7716 WPScan
4.8 Medium Envira Gallery Plugin envira-gallery-lite Cross-Site Scripting Author+ Stored XSS < 1.8.15 Fixed in 1.8.15 CVE-2024-3899 WPScan
5.3 Medium HTML5 Video Player – mp4 Video Player Plugin and Block Plugin html5-video-player Broken Access Control mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler No login needed ≤ 2.5.32 CVE-2024-7727 Wordfence
4.3 Medium HTML5 Video Player – mp4 Video Player Plugin and Block Plugin html5-video-player Broken Access Control mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 2.5.34 CVE-2024-7721 Wordfence
8.8 High Post Grid and Gutenberg Blocks Plugin post-grid Privilege Escalation Authenticated (Subscriber+) Privilege Escalation 2.2.87 – 2.2.90 CVE-2024-8253 Wordfence
5.3 Medium EventPrime Plugin eventprime-event-calendar-management Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed ≤ 4.0.4.3 CVE-2024-8369 Wordfence
5.4 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via data-jltma-wrapper-link Element ≤ 2.0.6.4 CVE-2024-6282 Wordfence
8.8 High Bit File Manager – 100% Free & Open Source File Manager and Code Editor Plugin file-manager Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 6.5.5 CVE-2024-7770 Wordfence
4.3 Medium Tutor LMS Plugin tutor Cross-Site Request Forgery Cross-Site Request Forgery via 'addon_enable_disable' No login needed ≤ 2.7.4 CVE-2023-2919 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only