WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,601–24,650 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 493 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Addonify – Quick View For WooCommerce Plugin addonify-quick-view Information Disclosure Quick View For WooCommerce <= 1.2.16 - Unauthenticated Full Path Dislcosure No login needed ≤ 1.2.16 CVE-2024-6560 Wordfence
6.4 Medium Easy Testimonials Plugin easy-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.5 CVE-2024-2337 Wordfence
4.3 Medium Conditional Fields for Contact Form 7 Plugin cf7-conditional-fields Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Setting Reset No login needed ≤ 2.4.13 CVE-2024-5804 Wordfence
5.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Insecure Direct Object Reference to Authenticated (GiveWP Worker+) Arbitrary Post Actions ≤ 3.13.0 CVE-2024-5977 Wordfence
8.8 High FV Player Plugin fv-wordpress-flowplayer SQL Injection Authenticated (Subscriber+) SQL Injection via exclude Parameter ≤ 7.5.46.7212 CVE-2024-6338 Wordfence
4.3 Medium YITH Essential Kit for WooCommerce #1 Plugin yith-essential-kit-for-woocommerce-1 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Install, Activation, and Deactivation ≤ 2.34.0 CVE-2024-6799 Wordfence
7.6 High PayPlus Payment Gateway Plugin payplus-payment-gateway SQL Injection Unauthenticated SQLi < 6.6.9 Fixed in 6.6.9 CVE-2024-6205 WPScan
5.9 Medium Bug Library Plugin Cross-Site Scripting Admin+ Stored XSS < 2.1.2 Fixed in 2.1.2 CVE-2024-5604 WPScan
7.5 High ArtPlacer Widget Plugin artplacer-widget Cross-Site Scripting Stored XSS via CSRF < 2.21.2 Fixed in 2.21.2 CVE-2023-7269 WPScan
6.5 Medium ArtPlacer Widget Plugin artplacer-widget Broken Access Control Subscriber+ Arbitrary Widget Deletion < 2.21.2 Fixed in 2.21.2 CVE-2023-7268 WPScan
4.3 Medium Duplica Plugin duplica Broken Access Control Authenticated (Subscriber+) Missing Authorization to Users/Posts Duplicates Creation ≤ 0.6 CVE-2024-5997 Wordfence
5.3 Medium ElementsKit Elementor addons Plugin elementskit-lite Information Disclosure Unauthenticated Information Exposure via ekit_widgetarea_content Function No login needed ≤ 3.2.0 CVE-2024-6455 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.5 CVE-2024-5555 Wordfence
6.4 Medium Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.6.11 CVE-2024-5554 Wordfence
8.8 High Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload ≤ 2.4.44 CVE-2024-3242 Wordfence
9.8 Critical Filter & Grids Plugin Local File Inclusion Unauthenticated LFI No login needed < 2.8.33 Fixed in 2.8.33 CVE-2024-6164 WPScan
5.4 Medium SVG Support Plugin svg-support Cross-Site Scripting Authenticated (Author+) Cross-Site Scripting via SVG ≤ 2.5.7 CVE-2023-6708 Wordfence
5.5 Medium RegLevel Plugin reglevel Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.2.1 CVE-2024-6705 Wordfence
4.3 Medium Meks Video Importer Plugin meks-video-importer Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Keys Modification ≤ 1.0.12 CVE-2024-6599 Wordfence
6.4 Medium Zenon Lite Theme zenon-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.9 CVE-2024-5964 Wordfence
8.8 High Timeline Event History Plugin timeline-event-history PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 3.1 CVE-2024-5726 Wordfence
5.4 Medium Booking Ultra Pro Plugin booking-ultra-pro Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Updates ≤ 1.1.13 CVE-2024-6175 Wordfence
6.4 Medium Cooked Plugin cooked Content Injection Authenticated (Contributor+) HTML Injection via Recipe Excerpt < 1.8.0 CVE-2024-39682 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Apply Template to All Recipes No login needed < 1.8.0 CVE-2024-39681 GitHub_M
5.4 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Default Recipe Template Save No login needed < 1.8.0 CVE-2024-39680 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Recipe Template Reset No login needed < 1.8.0 CVE-2024-39679 GitHub_M
4.3 Medium Cooked Plugin cooked Cross-Site Request Forgery Cross-Site Request Forgery to Get Recipe IDs No login needed < 1.8.0 CVE-2024-39678 GitHub_M
9.8 Critical 简数采集器 (Keydatas) Plugin keydatas Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 2.5.2 CVE-2024-6220 Wordfence
6.4 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Attribute ≤ 1.33 CVE-2024-5582 Wordfence
4.3 Medium Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin email-subscribers Broken Access Control Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.26 - Missing Authorization ≤ 5.7.26 CVE-2024-5703 Wordfence
6.4 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.19.20 CVE-2024-5251 Wordfence
5.5 Medium AI ChatBot for WordPress – WPBot Plugin chatbot Cross-Site Scripting WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.5.7 CVE-2024-6669 Wordfence
8.8 High BookingPress Appointment Booking Plugin bookingpress-appointment-booking Path Traversal Authenticated (Subscriber+) Arbitrary File Read to Arbitrary File Creation ≤ 1.1.5 CVE-2024-6467 Wordfence
6.4 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.19.20 CVE-2024-5253 Wordfence
8.8 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Broken Access Control Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update and Arbitrary File Upload ≤ 1.1.5 CVE-2024-6660 Wordfence
6.4 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.19.20 CVE-2024-5252 Wordfence
6.4 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.19.20 CVE-2024-5255 Wordfence
6.4 Medium Ultimate Addons for WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.19.20 CVE-2024-5254 Wordfence
4.3 Medium Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Broken Access Control Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import ≤ 4.0.4 CVE-2024-6033 Wordfence
4.3 Medium WP RSS Aggregator Plugin wp-rss-aggregator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Feed State Update ≤ 4.23.11 CVE-2024-6621 Wordfence
9.8 Critical HUSKY - Products Filter Professional for WooCommerce Plugin woocommerce-products-filter SQL Injection Products Filter Professional for WooCommerce <= 1.3.6 - Unauthenticated Time-Based SQL Injection No login needed ≤ 1.3.6 CVE-2024-6457 Wordfence
4.3 Medium Web and WooCommerce Addons for WPBakery Builder Plugin vc-addons-by-bit14 Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Modification ≤ 1.4.5 CVE-2024-6579 Wordfence
7.1 High Brizy – Page Builder Plugin brizy Broken Access Control Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification ≤ 2.4.44 CVE-2024-1937 Wordfence
5.3 Medium AForms Plugin aforms-form-builder-for-price-calculator-cost-estimation Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 2.2.6 CVE-2024-6565 Wordfence
6.4 Medium Premium Portfolio Features for Phlox Plugin auxin-portfolio Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios' ≤ 2.3.2 CVE-2024-3587 Wordfence
5.3 Medium Glossary Plugin glossary-by-codeat Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 2.2.26 CVE-2024-6570 Wordfence
4.3 Medium WordPress File Upload Plugin Arbitrary File Upload Authenticated (Contributor+) Directory Traversal ≤ 4.24.7 CVE-2024-5852 Wordfence
6.4 Medium WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce Plugin wp-event-manager Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode ≤ 3.1.43 CVE-2024-2691 Wordfence
6.4 Medium Image Hover Effects – Elementor Addon Plugin image-hover-effects-addon-for-elementor Cross-Site Scripting Elementor Addon <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via eihe_link Parameter ≤ 1.4.3 CVE-2024-4780 Wordfence
5.3 Medium XCloner Plugin xcloner-backup-and-restore Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 4.7.3 CVE-2024-6559 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only