WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,251–24,300 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 486 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WordPress File Upload Plugin Arbitrary File Upload Reflected XSS No login needed < 4.24.8 Fixed in 4.24.8 CVE-2024-6651 WPScan
8.8 High WPBakery Plugin Local File Inclusion Authenticated (Author+) Local File Inclusion ≤ 7.7 CVE-2024-5709 Wordfence
6.4 Medium WPBakery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 7.7 CVE-2024-5708 Wordfence
7.2 High Traffic Manager Plugin traffic-manager Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.4.5 CVE-2024-7485 Wordfence
8.8 High Horizontal scrolling announcements Plugin horizontal-scrolling-announcements SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 2.4 CVE-2023-5000 Wordfence
8.8 High Blox Page Builder Plugin blox-page-builder Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.65 CVE-2024-6315 Wordfence
7.2 High CRM Perks Forms Plugin crm-perks-forms Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 1.1.3 CVE-2024-7484 Wordfence
5.4 Medium Cooked Plugin cooked Cross-Site Scripting WordPress Cooked Plugin Persistent Cross-Site Scripting via Shortcode < 1.8.1 CVE-2024-41816 GitHub_M
5.4 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting Author+ Stored XSS < 3.1.45 Fixed in 3.1.45 CVE-2024-6710 WPScan
4.8 Medium CollectChat Plugin Cross-Site Scripting Admin+ XSS < 2.4.4 Fixed in 2.4.4 CVE-2024-6498 WPScan
4.8 Medium Community Events Plugin Cross-Site Scripting Admin+ Stored XSS < 1.5.1 Fixed in 1.5.1 CVE-2024-6270 WPScan
6.1 Medium WP eMember Plugin Cross-Site Scripting Stored XSS via CSRF No login needed < v10.7.0 CVE-2024-5081 WPScan
5.4 Medium Pinpoint Booking System Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.9.9.4.8 Fixed in 2.9.9.4.8 CVE-2024-3636 WPScan
4.3 Medium TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder Plugin templatespare Broken Access Control TemplateSpare <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Theme Update ≤ 2.4.2 CVE-2024-6872 Wordfence
4.3 Medium Sync Post With Other Site Plugin sync-post-with-other-site Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Creation and Update ≤ 1.6 CVE-2024-6709 Wordfence
6.4 Medium Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via filename Parameter ≤ 3.3.100 CVE-2024-7356 Wordfence
9.8 Critical YayExtra – WooCommerce Extra Product Options Plugin yayextra Arbitrary File Upload WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via handle_upload_file Function No login needed ≤ 1.3.7 CVE-2024-7257 Wordfence
7.5 High File Manager Pro – Filester Plugin filester Broken Access Control Filester <= 1.8.2 - Authenticated Plugin Settings Update ≤ 1.8.2 CVE-2024-7031 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Privilege Escalation Authenticated (Administrator+) Privilege Escalation ≤ 3.3.4.1 CVE-2024-7291 Wordfence
7.5 High UsersWP Plugin userswp Information Disclosure Users Information Disclosure No login needed < 1.2.12 Fixed in 1.2.12 CVE-2024-6477 WPScan
5.9 Medium Quiz and Survey Master (QSM) Plugin quiz-master-next Cross-Site Scripting Contributor+ Stored XSS < 9.1.0 Fixed in 9.1.0 CVE-2024-6390 WPScan
5.3 Medium Comments – wpDiscuz Plugin wpdiscuz Content Injection wpDiscuz <= 7.6.21 - Unauthenticated HTML Injection No login needed ≤ 7.6.21 CVE-2024-6704 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.11 CVE-2024-4643 Wordfence
7.1 High WP GoToWebinar Plugin wp-gotowebinar Cross-Site Request Forgery CSRF to XSS No login needed ≤ 15.7 Fixed in 15.8 CVE-2024-38776 Patchstack
8.8 High WordPress Menu Plugin — Superfly Responsive Menu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Deletion No login needed ≤ 5.0.29 CVE-2024-3238 Wordfence
5.4 Medium Essential Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 4.7.0 Fixed in 4.7.0 CVE-2024-5595 WPScan
6.4 Medium Spectra Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block IDs ≤ 1.1.4 CVE-2024-3827 Wordfence
7.5 High Forminator Plugin forminator Information Disclosure HubSpot Developer API Key Sensitive Information Exposure No login needed ≤ 1.29.1 CVE-2024-7389 Wordfence
5.3 Medium Ebook Store Plugin ebook-store Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 5.8001 CVE-2024-6567 Wordfence
5.9 Medium Pretty Simple Popup Builder Plugin pretty-simple-popup-builder Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2024-39626 Patchstack
5.9 Medium NextGEN Gallery Plugin nextgen-gallery Cross-Site Scripting NextGEN Gallery plugin <= 3.59.3 - Cross Site Scripting (XSS) ≤ 3.59.3 Fixed in 3.59.4 CVE-2024-39627 Patchstack
5.9 Medium Himalayas Theme himalayas Cross-Site Scripting ≤ 1.3.2 CVE-2024-39629 Patchstack
7.1 High Contest Gallery Plugin contest-gallery Cross-Site Scripting No login needed ≤ 23.1.2 Fixed in 23.1.3 CVE-2024-39631 Patchstack
5.8 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 6.0.0.1 Fixed in 6.0.0.2 CVE-2024-39643 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-39644 Patchstack
7.1 High Custom 404 Pro Plugin custom-404-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2024-39646 Patchstack
7.1 High Message Filter for Contact Form 7 Plugin cf7-message-filter Cross-Site Scripting No login needed ≤ 1.6.1.1 Fixed in 1.6.2 CVE-2024-39647 Patchstack
5.9 Medium Eventin Plugin wp-event-solution Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-39648 Patchstack
6.5 Medium Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting ≤ 5.9.26 Fixed in 5.9.27 CVE-2024-39649 Patchstack
7.1 High WooCommerce PDF Vouchers Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 4.9.5 Fixed in 4.9.5 CVE-2024-39652 Patchstack
6.5 Medium LiquidPoll – Advanced Polls for Creators and Brands Plugin wp-poll Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.3.77 Fixed in 3.3.78 CVE-2024-39655 Patchstack
7.1 High Tin Canny Reporting for LearnDash Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.3.0.7 Fixed in 4.3.0.8 CVE-2024-39656 Patchstack
6.5 Medium WP-PostRatings Plugin wp-postratings Cross-Site Scripting ≤ 1.91.1 Fixed in 1.91.2 CVE-2024-39659 Patchstack
5.9 Medium Photo Engine Plugin wplr-sync Cross-Site Scripting ≤ 6.3.1 Fixed in 6.3.2 CVE-2024-39660 Patchstack
6.5 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Authenticated Cross Site Scripting (XSS) ≤ 2.2.4 Fixed in 2.2.5 CVE-2024-39661 Patchstack
6.5 Medium Black Widgets For Elementor Plugin black-widgets Cross-Site Scripting ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-39662 Patchstack
7.1 High WP Fast Total Search Plugin fulltext-search Cross-Site Scripting No login needed ≤ 1.68.232 Fixed in 1.69.234 CVE-2024-39663 Patchstack
6.5 Medium Filter & Grids Plugin ymc-smart-filter Cross-Site Scripting ≤ 2.9.2 Fixed in 2.9.3 CVE-2024-39665 Patchstack
6.5 Medium Element Pack Elementor Addons Plugin bdthemes-element-pack-lite Cross-Site Scripting ≤ 5.6.11 Fixed in 5.6.12 CVE-2024-39667 Patchstack
6.5 Medium Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting ≤ 2.0.31 Fixed in 2.0.32 CVE-2024-39668 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only