WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 23,801–23,850 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 477 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Share This Image Plugin share-this-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via STI Buttons Shortcode ≤ 2.02 CVE-2024-8363 Wordfence
5.4 Medium Form Vibes – Database Manager for Forms Plugin Broken Access Control Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple Functions ≤ 1.4.12 CVE-2024-5309 Wordfence
5.3 Medium Ivory Search – WordPress Search Plugin add-search-to-menu Information Disclosure WordPress Search Plugin <= 5.5.6 - Information Exposure via AJAX Search Form No login needed ≤ 5.5.6 CVE-2024-6835 Wordfence
5.3 Medium SmartSearchWP Plugin Broken Access Control Unauthenticated Log Purge No login needed < 2.4.5 Fixed in 2.4.5 CVE-2024-6846 WPScan
8.1 High Bit File Manager Plugin file-manager Remote Code Execution Unauthenticated Remote Code Execution via Race Condition No login needed 6.0 – 6.5.5 CVE-2024-7627 Wordfence
6.1 Medium Advanced Custom Fields Plugin advanced-custom-fields Cross-Site Scripting Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the '… No login needed 6.3.5 and earlier CVE-2024-45429 jpcert
9.8 Critical MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Broken Access Control The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.0 - Missing Authorization to Limited Vendor Privilege Escalation/Account Takeover No login needed ≤ 4.2.0 CVE-2024-8289 Wordfence
6.5 Medium PixelYourSite – Your smart PIXEL (TAG) & API Manager Plugin pixelyoursite Information Disclosure Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion No login needed ≤ 9.7.1, ≤ 10.4.2 CVE-2024-7870 Wordfence
6.4 Medium Attributes for Blocks Plugin attributes-for-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via attributesForBlocks Parameter ≤ 1.0.6 CVE-2024-8318 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Missing Authorization to Admin Username Change ≤ 3.0.8 CVE-2024-8121 Wordfence
5.4 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Insecure Direct Object Reference ≤ 3.0.8 CVE-2024-8123 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Broken Access Control WP Extended <= 3.0.8 - Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.0.8 CVE-2024-8102 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via page No login needed ≤ 3.0.8 CVE-2024-8119 Wordfence
6.5 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Information Disclosure WP Extended <= 3.0.8 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 3.0.8 CVE-2024-8106 Wordfence
8.8 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Path Traversal WP Extended <= 3.0.8 - Directory Traversal to Authenticated (Subscriber+) Arbitrary File Download ≤ 3.0.8 CVE-2024-8104 Wordfence
6.1 Medium The Ultimate WordPress Toolkit – WP Extended Plugin wpextended Cross-Site Scripting WP Extended <= 3.0.8 - Reflected Cross-Site Scripting via selected_option No login needed ≤ 3.0.8 CVE-2024-8117 Wordfence
7.5 High Sensei LMS Plugin sensei-lms Broken Access Control Unauthenticated Email Template Leak No login needed < 4.24.2 Fixed in 4.24.2 CVE-2024-7786 WPScan
9.8 Critical Viral Signup Plugin SQL Injection Unauthenticated SQLi No login needed ≤ 2.1 CVE-2024-6926 WPScan
4.8 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Admin+ Stored XSS < 4.1.7 Fixed in 4.1.7 CVE-2024-6889 WPScan
4.8 Medium Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting Admin+ Stored XSS < 4.1.7 Fixed in 4.1.7 CVE-2024-6888 WPScan
4.8 Medium Chatbot Support AI Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.2 CVE-2024-6722 WPScan
6.1 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Scripting Reflected XSS No login needed < 2.2.13 Fixed in 2.2.13 CVE-2024-6020 WPScan
6.4 Medium Gutenberg Page Builder Blocks & Ready-Made Patterns Library Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.4 CVE-2024-8325 Wordfence
9.8 Critical WP Job Portal Plugin wp-job-portal Broken Access Control Missing Authorization to Unauthenticated Local File Inclusion, Arbitrary Settings Update, and User Creation No login needed ≤ 2.1.6 CVE-2024-7950 Wordfence
6.1 Medium Flaming Forms Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.1 CVE-2024-7692 WPScan
5.4 Medium Flaming Forms Plugin Cross-Site Scripting Unauthenticated Stored XSS ≤ 1.0.1 CVE-2024-7691 WPScan
5.4 Medium DN Popup Plugin Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.2.2 CVE-2024-7690 WPScan
6.1 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting Reflected XSS No login needed 3.8.6 – < 3.8.11 Fixed in 3.8.11 CVE-2024-7354 WPScan
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Hero image selection feature. While logged in to the WordPress s… No login needed prior to 2.2.4 CVE-2024-45270 jpcert
4.3 Medium Carousel Slider Plugin carousel-slider Cross-Site Request Forgery WordPress plugin "Carousel Slider" provided by Sayful Islam contains a cross-site request forgery vulnerability on Carousel image selection feature. While logged in to the WordPre… No login needed prior to 2.0 CVE-2024-45269 jpcert
4.2 Medium Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Authenticated (Subscriber+) Mailchimp Integration Modification ≤ 5.1.18 CVE-2024-5053 Wordfence
5.3 Medium Web Application Firewall Plugin web-application-firewall Other IP Address Spoofing to Protection Mechanism Bypass No login needed ≤ 2.1.2 CVE-2022-4539 Wordfence
8.8 High WP Events Manager Plugin wp-events-manager SQL Injection Authenticated (Subscriber+) Time-Based SQL Injection ≤ 2.1.11 CVE-2024-7717 Wordfence
5.3 Medium IP Vault – WP Firewall Plugin Other WP Firewall <= 1.1 - IP Address Spoofing to Protection Mechanism Bypass No login needed ≤ 1.1 CVE-2022-4536 Wordfence
6.4 Medium Share This Image Plugin share-this-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via alignment Parameter ≤ 2.01 CVE-2024-8108 Wordfence
5.3 Medium WP Cerber Security Plugin wp-cerber Other IP Protection Bypass No login needed ≤ 9.4 CVE-2022-4100 Wordfence
6.4 Medium WPZOOM Portfolio Lite – Filterable Portfolio Plugin wpzoom-portfolio Cross-Site Scripting Filterable Portfolio Plugin <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute ≤ 1.4.4 CVE-2024-8276 Wordfence
6.1 Medium tagDiv Composer Plugin Cross-Site Scripting Reflected Cross-Site Scripting via envato_code[] No login needed ≤ 5.0 CVE-2024-5212 Wordfence
6.1 Medium tagDiv Composer Plugin Cross-Site Scripting Reflected Cross-Site Scripting via envato_code[] No login needed ≤ 5.0 CVE-2024-3886 Wordfence
8.8 High Attire Theme attire PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.0.6 CVE-2024-7435 Wordfence
8.8 High Clean Login Plugin clean-login Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.14.5 CVE-2024-8252 Wordfence
6.3 Medium Media Library Folders Plugin media-library-plus Broken Access Control Missing Authorization on Various Functions ≤ 8.2.3 CVE-2024-7858 Wordfence
6.1 Medium WP Booking Calendar Plugin booking Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 10.5 CVE-2024-8274 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.13.6 CVE-2024-7122 Wordfence
4.3 Medium Tourfic Plugin tourfic Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 2.11.20 CVE-2024-8319 Wordfence
9.1 Critical The Events Calendar Pro Plugin PHP Object Injection Authenticated (Administrator+) PHP Object Injection to Remote Code Execution ≤ 7.0.2 CVE-2024-8016 Wordfence
9.1 Critical Web Directory Free Plugin web-directory-free Local File Inclusion Unauthenticated LFI No login needed < 1.7.3 Fixed in 1.7.3 CVE-2024-3673 WPScan
6.4 Medium HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics Plugin leadin Cross-Site Scripting CRM, Email Marketing, Live Chat, Forms & Analytics <= 11.1.22 - Authenticated (Contributor+) Stored Cross-Site Scripting via HubSpot Meeting Widget ≤ 11.1.22 CVE-2024-5879 Wordfence
8.8 High Betheme Theme PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 27.5.6 CVE-2024-2694 Wordfence
6.4 Medium Betheme | Responsive Multipurpose WordPress & WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 27.5.6 CVE-2024-3998 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only