WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 23,751–23,800 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Slider comparison image before and after | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.8.3 |
CVE-2024-8543 |
Wordfence | |
| 6.4 Medium | Nova Blocks by Pixelgrade | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 2.1.7 |
CVE-2024-8241 |
Wordfence | |
| 4.4 Medium | Community by PeepSo – Social Network, Membership, Registration, User Profiles | Cross-Site Scripting Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via content Parameter |
≤ 6.4.5.0 |
CVE-2024-7618 |
Wordfence | |
| 4.4 Medium | Community by PeepSo – Social Network, Membership, Registration, User Profiles | Cross-Site Scripting Social Network, Membership, Registration, User Profiles <= 6.4.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 6.4.5.0 |
CVE-2024-7655 |
Wordfence | |
| 4.8 Medium | Starbox | Cross-Site Scripting Admin+ Stored XSS |
< 3.5.2 Fixed in 3.5.2 |
CVE-2024-7955 |
WPScan | |
| 4.8 Medium | Floating Contact Button | Cross-Site Scripting Admin+ Stored XSS |
< 2.8 Fixed in 2.8 |
CVE-2024-7891 |
WPScan | |
| 7.3 High | Affiliate Super Assistent | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 1.5.3 |
CVE-2024-8478 |
Wordfence | |
| 8.8 High | Frontend Dashboard | Broken Access Control Authenticated (Subscriber+) Arbitrary Function Call |
≤ 2.2.4 |
CVE-2024-8268 |
Wordfence | |
| 4.8 Medium | Pocket Widget | Cross-Site Scripting Admin+ Stored XSS |
≤ 0.1.3 |
CVE-2024-7918 |
WPScan | |
| 4.7 Medium | Snapshot Backup | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 2.1.1 |
CVE-2024-7689 |
WPScan | |
| 6.5 Medium | AZIndex | Cross-Site Request Forgery Index Deletion via CSRF No login needed |
≤ 0.8.1 |
CVE-2024-7688 |
WPScan | |
| 6.1 Medium | AZIndex | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 0.8.1 |
CVE-2024-7687 |
WPScan | |
| 4.8 Medium | EventON | Cross-Site Scripting Admin+ Stored XSS |
< 2.2.17 Fixed in 2.2.17 |
CVE-2024-6910 |
WPScan | |
| 4.8 Medium | Popup Maker | Cross-Site Scripting Admin+ Stored XSS |
< 1.19.1 Fixed in 1.19.1 |
CVE-2024-5561 |
WPScan | |
| 6.1 Medium | Forminator | Cross-Site Scripting Cross-site scripting vulnerability exists in Forminator versions prior to 1.34.1. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the… No login needed |
prior to 1.34.1 |
CVE-2024-45625 |
jpcert | |
| 9.8 Critical | Opti Marketing | SQL Injection Unauthenticated SQLi No login needed |
≤ 2.0.9 |
CVE-2024-6928 |
WPScan | |
| 4.3 Medium | TrueBooker | Cross-Site Request Forgery Settings Update via CSRF No login needed |
< 1.0.3 Fixed in 1.0.3 |
CVE-2024-6925 |
WPScan | |
| 9.8 Critical | TrueBooker | SQL Injection Multiple Unauthenticated SQLi No login needed |
< 1.0.3 Fixed in 1.0.3 |
CVE-2024-6924 |
WPScan | |
| 5.4 Medium | WP MultiTasking | Cross-Site Scripting Reflected XSS via Shortcode |
≤ 0.1.12 |
CVE-2024-6859 |
WPScan | |
| 6.5 Medium | WP MultiTasking | Cross-Site Request Forgery SMTP Settings Update via CSRF No login needed |
≤ 0.1.12 |
CVE-2024-6856 |
WPScan | |
| 6.5 Medium | WP MultiTasking | Cross-Site Request Forgery Exit Popup Update via CSRF No login needed |
≤ 0.1.12 |
CVE-2024-6855 |
WPScan | |
| 6.5 Medium | WP MultiTasking | Cross-Site Request Forgery Welcome Popup Update via CSRF No login needed |
≤ 0.1.12 |
CVE-2024-6853 |
WPScan | |
| 6.5 Medium | WP MultiTasking | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.1.12 |
CVE-2024-6852 |
WPScan | |
| 5.3 Medium | Cost Calculator Builder PRO | Price Manipulation Unauthenticated Price Manipulation No login needed |
≤ 3.2.1 |
CVE-2024-6010 |
Wordfence | |
| 6.6 Medium | Customizer Export/Import | Arbitrary File Upload Authenticated (Admin+) Arbitrary File Upload via Customization Settings Import |
≤ 0.9.7 |
CVE-2024-7620 |
Wordfence | |
| 8.8 High | Pinpoint Booking System | SQL Injection Pinpoint Booking System <= 2.9.9.5.0- Authenticated (Subscriber+) SQL Injection |
≤ 2.9.9.5.0 |
CVE-2024-7112 |
Wordfence | |
| 7.2 High | Ninja Forms File Uploads | Arbitrary File Upload Unauthenticated Stored Cross-Site Scripting via File Upload No login needed |
≤ 3.3.16 |
CVE-2024-1596 |
Wordfence | |
| 6.4 Medium | Preloader Plus – WordPress Loading Screen | Cross-Site Scripting WordPress Loading Screen Plugin <= 2.2.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 2.2.1 |
CVE-2024-6849 |
Wordfence | |
| 4.3 Medium | Big File Uploads | Arbitrary File Upload Authenticated (Author+) Full Path Disclosure |
≤ 2.1.2 |
CVE-2024-8538 |
Wordfence | |
| 6.4 Medium | Enter Addons – Ultimate Template Builder for Elementor | Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget |
≤ 2.1.8 |
CVE-2024-7611 |
Wordfence | |
| 9.8 Critical | WPCOM Member | Privilege Escalation Unauthenticated Privilege Escalation via User Meta No login needed |
≤ 1.5.2.1 |
CVE-2024-7493 |
Wordfence | |
| 8.8 High | ForumWP – Forum & Discussion Board | Broken Access Control Forum & Discussion Board Plugin <= 2.0.2 - Insecure Direct Object Reference to Authenticated (Subscriber+) Privilege Escalation via Account Takeover |
≤ 2.0.2 |
CVE-2024-8428 |
Wordfence | |
| 6.4 Medium | Advanced Sermons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.3 |
CVE-2024-7599 |
Wordfence | |
| 4.3 Medium | Revision Manager TMC | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
≤ 2.8.19 |
CVE-2024-7622 |
Wordfence | |
| 4.3 Medium | Frontend Post Submission Manager Lite – Frontend Posting | Broken Access Control Frontend Posting WordPress Plugin <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.2.2 |
CVE-2024-8427 |
Wordfence | |
| 6.4 Medium | WP AdCenter – Ad Manager & Adsense Ads | Cross-Site Scripting Ad Manager & Adsense Ads <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ad_alignment Attribute |
≤ 2.5.6 |
CVE-2024-8317 |
Wordfence | |
| 9.8 Critical | WP-Recall – Registration, Profile, Commerce & More | Broken Access Control Registration, Profile, Commerce & More <= 16.26.8 - Insecure Direct Object Reference to Unauthenticated Arbitrary Password Update No login needed |
≤ 16.26.8 |
CVE-2024-8292 |
Wordfence | |
| 7.2 High | LifterLMS | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 7.7.5 |
CVE-2024-7349 |
Wordfence | |
| 3.5 Low | WP ULike | Cross-Site Scripting Subscriber+ Stored-XSS |
4.7.1 – < 4.7.2.1 Fixed in 4.7.2.1 |
CVE-2024-6792 |
WPScan | |
| 8.8 High | Image Optimizer, Resizer and CDN – Sirv | Broken Access Control Sirv <= 7.2.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.2.7 |
CVE-2024-8480 |
Wordfence | |
| 8.8 High | Newsletters | Privilege Escalation Authenticated Privilege Escalation |
≤ 4.9.9.2 |
CVE-2024-8247 |
Wordfence | |
| 5.3 Medium | Remember Me Controls | Information Disclosure Unauthenticated Full Path Disclosure No login needed |
≤ 2.0.1 |
CVE-2024-7415 |
Wordfence | |
| 5.3 Medium | Geo Controller | Broken Access Control Missing Authorization to Unauthenticated Shortcode Execution No login needed |
≤ 8.6.9 |
CVE-2024-7381 |
Wordfence | |
| 5.3 Medium | Security, Antivirus, Firewall – S.A.F | Other S.A.F <= 2.3.5 - IP Address Spoofing to Protection Mechanism Bypass No login needed |
≤ 2.3.5 |
CVE-2022-4529 |
Wordfence | |
| 4.3 Medium | Geo Controller | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Menu Creation/Deletion |
≤ 8.7.3 |
CVE-2024-7380 |
Wordfence | |
| 4.4 Medium | Cab fare calculator | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.1.6 |
CVE-2022-3556 |
Wordfence | |
| 4.3 Medium | HelloAsso | Broken Access Control Missing Authorization to Authenticated (Contributor+) Limited Options Update |
≤ 1.1.10 |
CVE-2024-7605 |
Wordfence | |
| 6.4 Medium | Dynamic Featured Image | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via dfiFeatured Parameter |
≤ 3.7.0 |
CVE-2024-6929 |
Wordfence | |
| 6.4 Medium | RD Station | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.3.2 |
CVE-2024-6894 |
Wordfence | |
| 6.5 Medium | Booking for Appointments and Events Calendar – Amelia Premium | Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed |
≤ 1.2.4, ≤ 7.7 |
CVE-2024-6332 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.