WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,551–24,600 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 492 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium CodePen Embedded Pens Shortcode Plugin codepen-embedded-pen-shortcode Cross-Site Scripting ≤ 1.0.0 Fixed in 1.0.1 CVE-2024-37960 Patchstack
7.1 High codoc Plugin codoc Cross-Site Scripting No login needed ≤ 0.9.51.12 Fixed in 0.9.52 CVE-2024-37961 Patchstack
7.1 High WooCommerce Predictive Search Plugin woocommerce-predictive-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.1 CVE-2024-38669 Patchstack
6.5 Medium Team Members Plugin team-members Cross-Site Scripting ≤ 5.3.3 Fixed in 5.3.4 CVE-2024-38670 Patchstack
6.5 Medium WP GoToWebinar Plugin wp-gotowebinar Cross-Site Scripting ≤ 15.7 CVE-2024-38671 Patchstack
7.1 High AdPush Plugin adsense-plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.50 CVE-2024-38672 Patchstack
7.1 High Multisite Content Copier/Updater Plugin wp-multisite-content-copier Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.0 CVE-2024-38673 Patchstack
6.5 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting ≤ 3.0 CVE-2024-38674 Patchstack
6.5 Medium Arkhe Blocks Plugin arkhe-blocks Cross-Site Scripting ≤ 2.22.1 CVE-2024-38675 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.13 CVE-2024-38676 Patchstack
6.5 Medium REVIEWS.io Plugin reviewscouk-for-woocommerce Cross-Site Scripting ≤ 1.2.7 CVE-2024-38677 Patchstack
6.5 Medium Calendar.online / Kalender.digital Plugin kalender-digital Cross-Site Scripting Plugin plugin <= 1.0.8 - Cross Site Scripting (XSS) ≤ 1.0.8 Fixed in 1.0.9 CVE-2024-38678 Patchstack
6.5 Medium Animated Typed JS Shortcode Plugin animated-typed-js-shortcode Cross-Site Scripting ≤ 2.0 CVE-2024-38679 Patchstack
7.1 High Appmaker – Convert WooCommerce to Android & iOS Native Mobile Apps Plugin appmaker-woocommerce-mobile-app-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.36.12 CVE-2024-38680 Patchstack
6.5 Medium Magical Addons For Elementor Plugin magical-addons-for-elementor Cross-Site Scripting ≤ 1.1.41 Fixed in 1.1.42 CVE-2024-38681 Patchstack
6.5 Medium Post Layouts for Gutenberg Plugin post-layouts Cross-Site Scripting ≤ 1.2.7 CVE-2024-38682 Patchstack
7.1 High WooCommerce Report Plugin ithemelandco-woo-report Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.5 CVE-2024-38683 Patchstack
6.5 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting ≤ 1.4.1 Fixed in 1.5.0 CVE-2024-38684 Patchstack
5.9 Medium WP Announcement Plugin sp-announcement Cross-Site Scripting ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-38685 Patchstack
6.5 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Cross-Site Scripting ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-38686 Patchstack
6.5 Medium Sky Addons for Elementor Plugin sky-elementor-addons Cross-Site Scripting ≤ 2.5.5 Fixed in 2.5.8 CVE-2024-38687 Patchstack
9.8 Critical WooCommerce - Social Login Plugin Broken Access Control Social Login <= 2.7.3 - Missing Authorization to Unauthenticated Privilege Escalation No login needed ≤ 2.7.3 CVE-2024-6636 Wordfence
7.3 High WooCommerce - Social Login Plugin Authentication Bypass Social Login <= 2.7.3 - Unauthenticated Authentication Bypass No login needed ≤ 2.7.3 CVE-2024-6635 Wordfence
5.9 Medium Simple Popup Plugin simple-popup-plugin Cross-Site Scripting ≤ 4.4 Fixed in 4.5 CVE-2024-38689 Patchstack
7.3 High WooCommerce - Social Login Plugin Privilege Escalation Social Login <= 2.7.3 - Unauthenticated Privilege Escalation via One-Time Password No login needed ≤ 2.7.3 CVE-2024-6637 Wordfence
7.1 High Moloni Plugin moloni Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.7.4 Fixed in 4.8.0 CVE-2024-38694 Patchstack
7.1 High Zoho CRM Lead Magnet Plugin zoho-crm-forms Cross-Site Scripting No login needed ≤ 1.7.8.8 Fixed in 1.7.8.9 CVE-2024-38696 Patchstack
6.5 Medium Goftino Plugin goftino Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-38697 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.0 Fixed in 2.1 CVE-2024-38698 Patchstack
6.5 Medium WP Event Aggregator Plugin wp-event-aggregator Cross-Site Scripting ≤ 1.7.9 Fixed in 1.8.0 CVE-2024-38703 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-38705 Patchstack
5.9 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor plugin <= 2.0.6.2 - Cross Site Scripting (XSS) ≤ 2.0.6.2 Fixed in 2.0.6.3 CVE-2024-38710 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-38711 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.3 Fixed in 1.3.1 CVE-2024-38712 Patchstack
6.5 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated Stored Cross Site Scripting (XSS) ≤ 8.8.02.002 Fixed in 8.8.02.003 CVE-2024-38713 Patchstack
6.5 Medium Download Button for Elementor Plugin download-button-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2024-38718 Patchstack
6.5 Medium EazyDocs Plugin eazydocs Cross-Site Scripting ≤ 2.5.0 CVE-2024-38720 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.57 CVE-2024-38722 Patchstack
5.9 Medium Admin Dashboard RSS Feed Plugin admin-dashboard-rss-feed Cross-Site Scripting ≤ 3.1 CVE-2024-38725 Patchstack
5.9 Medium Change From Email Plugin wp-from-email Cross-Site Scripting ≤ 1.2.1 CVE-2024-38738 Patchstack
5.1 Medium OnePress Theme onepress Cross-Site Scripting ≤ 2.3.8 CVE-2024-38739 Patchstack
6.5 Medium Amazing Hover Effects Plugin amazing-hover-effects Cross-Site Scripting ≤ 2.4.9 CVE-2024-38741 Patchstack
6.5 Medium Advanced post slider Plugin advanced-post-slider Cross-Site Scripting ≤ 3.0.0 CVE-2024-38750 Patchstack
6.5 Medium Typebot Plugin typebot Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2024-38757 Patchstack
6.5 Medium BSK PDF Manager Plugin bsk-pdf-manager Cross-Site Scripting ≤ 3.6 Fixed in 3.6.1 CVE-2024-38767 Patchstack
4.9 Medium WappPress Plugin wapppress-builds-android-app-for-website Server-Side Request Forgery Blind Server Side Request Forgery (SSRF) ≤ 6.0.4 CVE-2024-38758 Patchstack
5.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.10 - Missing Authorization to Google API key update No login needed ≤ 2.0.10 CVE-2024-6489 Wordfence
4.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.10 - Missing Authentication to MailChimp API key update ≤ 2.0.10 CVE-2024-6491 Wordfence
2.7 Low WP Mail SMTP Plugin wp-mail-smtp Information Disclosure Authenticated (Admin+) SMTP Password Exposure ≤ 4.0.1 CVE-2024-6694 Wordfence
6.5 Medium Mercado Pago payments for WooCommerce Plugin woocommerce-mercadopago Path Traversal Authenticated (Subscriber+) Arbitrary File Download 7.3.0 – 7.6.1 CVE-2024-3934 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only