WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 24,401–24,450 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Broken Access Control Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.4.6 - Missing Authorization to Authenticated (Contributor+) Settings Update |
≤ 3.4.6 |
CVE-2024-6836 |
Wordfence | |
| 6.1 Medium | LiteSpeed Cache | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 6.2.0.1 |
CVE-2024-3246 |
Wordfence | |
| 5.3 Medium | WP Easy Pay (Free) | Broken Access Control Missing Authorization to Unauthenticated Service Disconnection No login needed |
≤ 4.2.3 |
CVE-2024-5861 |
Wordfence | |
| 7.3 High | WooCommerce - PDF Vouchers | Authentication Bypass PDF Vouchers <= 4.9.3 - Authentication Bypass to Voucher Vendor No login needed |
≤ 4.9.3 |
CVE-2024-7027 |
Wordfence | |
| 6.5 Medium | Social Auto Poster | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed |
≤ 5.3.14 |
CVE-2024-6755 |
Wordfence | |
| 6.3 Medium | Social Auto Poster | Cross-Site Request Forgery Cross-Site Request Forgery via Multiple Functions No login needed |
≤ 5.3.14 |
CVE-2024-6751 |
Wordfence | |
| 5.4 Medium | Social Auto Poster | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update via wpw_auto_poster_update_tweet_template |
≤ 5.3.14 |
CVE-2024-6754 |
Wordfence | |
| 7.2 High | Social Auto Poster | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 5.3.14 |
CVE-2024-6753 |
Wordfence | |
| 6.4 Medium | Social Auto Poster | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 5.3.14 |
CVE-2024-6752 |
Wordfence | |
| 7.3 High | Social Auto Poster | Broken Access Control Missing Authorization via Multiple Functions No login needed |
≤ 5.3.14 |
CVE-2024-6750 |
Wordfence | |
| 8.8 High | Social Auto Poster | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 5.3.14 |
CVE-2024-6756 |
Wordfence | |
| 8.6 High | Hide My WP Ghost | Information Disclosure Hidden Login Page Disclosure No login needed |
< 5.2.02 Fixed in 5.2.02 |
CVE-2024-6420 |
WPScan | |
| 5.9 Medium | Request a Quote | Cross-Site Scripting Admin+ Stored XSS |
< 2.4.1 Fixed in 2.4.1 |
CVE-2024-6231 |
WPScan | |
| 6.5 Medium | CoBlocks | Server-Side Request Forgery Contributor+ SSRF |
< 3.1.12 Fixed in 3.1.12 |
CVE-2024-4260 |
WPScan | |
| 8.1 High | MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles | Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion |
≤ 1.9.2 |
CVE-2024-6885 |
Wordfence | |
| 7.2 High | Redux Framework | Arbitrary File Upload Unauthenticated JSON File Upload to Stored Cross-Site Scripting No login needed |
4.4.12 – 4.4.17 |
CVE-2024-6828 |
Wordfence | |
| 5.4 Medium | Search & Replace | PHP Object Injection Deserialization of untrusted data No login needed |
≤ 3.2.2 Fixed in 3.2.3 |
CVE-2024-38759 |
Patchstack | |
| 7.2 High | BerqWP | Server-Side Request Forgery Unauthenticated Non-Blind Server Side Request Forgery (SSRF) No login needed |
≤ 1.7.5 Fixed in 1.7.6 |
CVE-2024-37942 |
Patchstack | |
| 6.4 Medium | JSON Content Importer | Server-Side Request Forgery JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) |
≤ 1.5.6 Fixed in 1.6.0 |
CVE-2024-38723 |
Patchstack | |
| 7.1 High | Seraphinite Post .DOCX Source | Server-Side Request Forgery No login needed |
≤ 2.16.9 Fixed in 2.16.10 |
CVE-2024-38728 |
Patchstack | |
| 4.9 Medium | Magical Addons For Elementor | Server-Side Request Forgery |
≤ 1.1.41 Fixed in 1.1.42 |
CVE-2024-38730 |
Patchstack | |
| 4.3 Medium | Academy LMS | Broken Access Control |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2024-38701 |
Patchstack | |
| 7.6 High | Spiffy Calendar | SQL Injection |
≤ 4.9.11 Fixed in 4.9.12 |
CVE-2024-38692 |
Patchstack | |
| 8.5 High | Barcode Scanner with Inventory & Order Manager | SQL Injection |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-38708 |
Patchstack | |
| 8.5 High | DirectoryPress | SQL Injection |
≤ 3.6.10 |
CVE-2024-38755 |
Patchstack | |
| 9.3 Critical | FormLift for Infusionsoft Web Forms | SQL Injection Unauthenticated Blind SQL Injection No login needed |
≤ 7.5.17 Fixed in 7.5.18 |
CVE-2024-38773 |
Patchstack | |
| 7.6 High | UiPress lite | SQL Injection |
≤ 3.4.06 Fixed in 3.4.07 |
CVE-2024-38788 |
Patchstack | |
| 6.5 Medium | Elementor – Header, Footer & Blocks Template | Cross-Site Scripting Contributor+ DOM-Based Cross Site Scripting (XSS) |
≤ 1.6.35 Fixed in 1.6.36 |
CVE-2024-33933 |
Patchstack | |
| 7.1 High | Shortcodes by United Themes | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 5.0.5 Fixed in 5.0.5 |
CVE-2024-37097 |
Patchstack | |
| 6.5 Medium | Elegant Themes Icons | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-37100 |
Patchstack | |
| 6.5 Medium | WP Post Author | Cross-Site Scripting |
≤ 3.6.7 Fixed in 3.6.8 |
CVE-2024-37101 |
Patchstack | |
| 6.5 Medium | My Favorites | Cross-Site Scripting |
≤ 1.4.3 Fixed in 1.4.4 |
CVE-2024-37114 |
Patchstack | |
| 6.5 Medium | Sinatra | Cross-Site Scripting |
≤ 1.3 |
CVE-2024-37116 |
Patchstack | |
| 7.1 High | Uncanny Automator Pro | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.3 Fixed in 5.3.0.1 |
CVE-2024-37117 |
Patchstack | |
| 5.9 Medium | Tabs | Cross-Site Scripting |
≤ 4.0.6 |
CVE-2024-37120 |
Patchstack | |
| 5.9 Medium | Shortcode Addons | Cross-Site Scripting |
≤ 3.2.5 |
CVE-2024-37121 |
Patchstack | |
| 5.9 Medium | Accordions | Cross-Site Scripting |
≤ 2.3.5 |
CVE-2024-37122 |
Patchstack | |
| 7.1 High | Enfold | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.6.9 Fixed in 5.6.10 |
CVE-2024-37199 |
Patchstack | |
| 7.1 High | Demo Awesome | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 Fixed in 1.0.2 |
CVE-2024-37206 |
Patchstack | |
| 7.1 High | Ali2Woo Lite | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.3.5 Fixed in 3.3.7 |
CVE-2024-37211 |
Patchstack | |
| 5.9 Medium | Transition Slider – Responsive Image Slider and Gallery | Cross-Site Scripting Responsive Image Slider and Gallery plugin <= 2.20.3 - Cross Site Scripting (XSS) |
≤ 2.20.3 |
CVE-2024-37215 |
Patchstack | |
| 6.5 Medium | Sketchfab Embed | Cross-Site Scripting |
≤ 1.5 |
CVE-2024-37216 |
Patchstack | |
| 6.5 Medium | Empty Cart Button for WooCommerce | Cross-Site Scripting |
≤ 1.3.8 |
CVE-2024-37217 |
Patchstack | |
| 6.5 Medium | Page Builder Sandwich – Front-End Page Builder | Cross-Site Scripting |
≤ 5.1.0 |
CVE-2024-37219 |
Patchstack | |
| 6.5 Medium | Kimili Flash Embed | Cross-Site Scripting |
≤ 2.5.3 |
CVE-2024-37221 |
Patchstack | |
| 6.5 Medium | Restaurant Reservations | Cross-Site Scripting |
≤ 2.0 |
CVE-2024-37223 |
Patchstack | |
| 6.5 Medium | Blogmentor – Blog Layouts for Elementor | Cross-Site Scripting Blog Layouts for Elementor plugin <= 1.5 - Cross Site Scripting (XSS) |
≤ 1.5 |
CVE-2024-37229 |
Patchstack | |
| 5.9 Medium | Branda | Cross-Site Scripting |
≤ 3.4.17 Fixed in 3.4.18 |
CVE-2024-37239 |
Patchstack | |
| 6.5 Medium | Ninja Beaver Add-ons for Beaver Builder | Cross-Site Scripting |
≤ 2.4.5 |
CVE-2024-37244 |
Patchstack | |
| 7.1 High | All In One Redirection | Cross-Site Scripting No login needed |
≤ 2.2.0 |
CVE-2024-37245 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.