WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,401–24,450 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 489 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update ≤ 3.4.6 CVE-2024-6836 Wordfence
6.1 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.2.0.1 CVE-2024-3246 Wordfence
5.3 Medium WP Easy Pay (Free) Plugin wp-easy-pay Broken Access Control Missing Authorization to Unauthenticated Service Disconnection No login needed ≤ 4.2.3 CVE-2024-5861 Wordfence
7.3 High WooCommerce - PDF Vouchers Plugin Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed ≤ 4.9.3 CVE-2024-7027 Wordfence
6.5 Medium Social Auto Poster Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 5.3.14 CVE-2024-6755 Wordfence
6.3 Medium Social Auto Poster Plugin Cross-Site Request Forgery Cross-Site Request Forgery via Multiple Functions No login needed ≤ 5.3.14 CVE-2024-6751 Wordfence
5.4 Medium Social Auto Poster Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update via wpw_auto_poster_update_tweet_template ≤ 5.3.14 CVE-2024-6754 Wordfence
7.2 High Social Auto Poster Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.3.14 CVE-2024-6753 Wordfence
6.4 Medium Social Auto Poster Plugin Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 5.3.14 CVE-2024-6752 Wordfence
7.3 High Social Auto Poster Plugin Broken Access Control Missing Authorization via Multiple Functions No login needed ≤ 5.3.14 CVE-2024-6750 Wordfence
8.8 High Social Auto Poster Plugin Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 5.3.14 CVE-2024-6756 Wordfence
8.6 High Hide My WP Ghost Plugin hide-my-wp Information Disclosure Hidden Login Page Disclosure No login needed < 5.2.02 Fixed in 5.2.02 CVE-2024-6420 WPScan
5.9 Medium Request a Quote Plugin get-a-quote-button-for-woocommerce Cross-Site Scripting Admin+ Stored XSS < 2.4.1 Fixed in 2.4.1 CVE-2024-6231 WPScan
6.5 Medium CoBlocks Plugin Server-Side Request Forgery Contributor+ SSRF < 3.1.12 Fixed in 3.1.12 CVE-2024-4260 WPScan
8.1 High MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles Plugin maxi-blocks Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 1.9.2 CVE-2024-6885 Wordfence
7.2 High Redux Framework Plugin redux-framework Arbitrary File Upload Unauthenticated JSON File Upload to Stored Cross-Site Scripting No login needed 4.4.12 – 4.4.17 CVE-2024-6828 Wordfence
5.4 Medium Search & Replace Plugin search-and-replace PHP Object Injection Deserialization of untrusted data No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2024-38759 Patchstack
7.2 High BerqWP Plugin searchpro Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed ≤ 1.7.5 Fixed in 1.7.6 CVE-2024-37942 Patchstack
6.4 Medium JSON Content Importer Plugin json-content-importer Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) ≤ 1.5.6 Fixed in 1.6.0 CVE-2024-38723 Patchstack
7.1 High Seraphinite Post .DOCX Source Plugin seraphinite-post-docx-source Server-Side Request Forgery No login needed ≤ 2.16.9 Fixed in 2.16.10 CVE-2024-38728 Patchstack
4.9 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Server-Side Request Forgery ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38730 Patchstack
4.3 Medium Academy LMS Plugin academy Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2024-38701 Patchstack
7.6 High Spiffy Calendar Plugin spiffy-calendar SQL Injection ≤ 4.9.11 Fixed in 4.9.12 CVE-2024-38692 Patchstack
8.5 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders SQL Injection ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-38708 Patchstack
8.5 High DirectoryPress Plugin directorypress SQL Injection ≤ 3.6.10 CVE-2024-38755 Patchstack
9.3 Critical FormLift for Infusionsoft Web Forms Plugin formlift SQL Injection Unauthenticated Blind SQL Injection No login needed ≤ 7.5.17 Fixed in 7.5.18 CVE-2024-38773 Patchstack
7.6 High UiPress lite Plugin uipress-lite SQL Injection ≤ 3.4.06 Fixed in 3.4.07 CVE-2024-38788 Patchstack
6.5 Medium Elementor – Header, Footer & Blocks Template Plugin header-footer-elementor Cross-Site Scripting Contributor+ DOM-Based Cross Site Scripting (XSS) ≤ 1.6.35 Fixed in 1.6.36 CVE-2024-33933 Patchstack
7.1 High Shortcodes by United Themes Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 5.0.5 Fixed in 5.0.5 CVE-2024-37097 Patchstack
6.5 Medium Elegant Themes Icons Plugin elegant-themes-icons Cross-Site Scripting ≤ 1.3 CVE-2024-37100 Patchstack
6.5 Medium WP Post Author Plugin wp-post-author Cross-Site Scripting ≤ 3.6.7 Fixed in 3.6.8 CVE-2024-37101 Patchstack
6.5 Medium My Favorites Plugin my-favorites Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-37114 Patchstack
6.5 Medium Sinatra Theme sinatra Cross-Site Scripting ≤ 1.3 CVE-2024-37116 Patchstack
7.1 High Uncanny Automator Pro Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3 Fixed in 5.3.0.1 CVE-2024-37117 Patchstack
5.9 Medium Tabs Plugin vc-tabs Cross-Site Scripting ≤ 4.0.6 CVE-2024-37120 Patchstack
5.9 Medium Shortcode Addons Plugin shortcode-addons Cross-Site Scripting ≤ 3.2.5 CVE-2024-37121 Patchstack
5.9 Medium Accordions Plugin accordions-or-faqs Cross-Site Scripting ≤ 2.3.5 CVE-2024-37122 Patchstack
7.1 High Enfold Theme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.6.9 Fixed in 5.6.10 CVE-2024-37199 Patchstack
7.1 High Demo Awesome Plugin demo-awesome Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2024-37206 Patchstack
7.1 High Ali2Woo Lite Plugin ali2woo-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.3.5 Fixed in 3.3.7 CVE-2024-37211 Patchstack
5.9 Medium Transition Slider – Responsive Image Slider and Gallery Plugin transition-slider-lite Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) ≤ 2.20.3 CVE-2024-37215 Patchstack
6.5 Medium Sketchfab Embed Plugin sketchfab-oembed Cross-Site Scripting ≤ 1.5 CVE-2024-37216 Patchstack
6.5 Medium Empty Cart Button for WooCommerce Plugin empty-cart-button-for-woocommerce Cross-Site Scripting ≤ 1.3.8 CVE-2024-37217 Patchstack
6.5 Medium Page Builder Sandwich – Front-End Page Builder Plugin page-builder-sandwich Cross-Site Scripting ≤ 5.1.0 CVE-2024-37219 Patchstack
6.5 Medium Kimili Flash Embed Plugin kimili-flash-embed Cross-Site Scripting ≤ 2.5.3 CVE-2024-37221 Patchstack
6.5 Medium Restaurant Reservations Plugin nd-restaurant-reservations Cross-Site Scripting ≤ 2.0 CVE-2024-37223 Patchstack
6.5 Medium Blogmentor – Blog Layouts for Elementor Plugin blogmentor Cross-Site Scripting Blog Layouts for Elementor plugin <= 1.5 - Cross Site Scripting (XSS) ≤ 1.5 CVE-2024-37229 Patchstack
5.9 Medium Branda Plugin branda-white-labeling Cross-Site Scripting ≤ 3.4.17 Fixed in 3.4.18 CVE-2024-37239 Patchstack
6.5 Medium Ninja Beaver Add-ons for Beaver Builder Plugin ninja-beaver-lite-addons-for-beaver-builder Cross-Site Scripting ≤ 2.4.5 CVE-2024-37244 Patchstack
7.1 High All In One Redirection Plugin all-in-one-redirection Cross-Site Scripting No login needed ≤ 2.2.0 CVE-2024-37245 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only