WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,701–24,750 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 495 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.8 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Contributor+ Stored XSS < 3.6.0 Fixed in 3.6.0 CVE-2024-3710 WPScan
6.8 Medium Smart Image Gallery Plugin Cross-Site Request Forgery Update/Delete Google API Key via CSRF < 1.0.19 Fixed in 1.0.19 CVE-2024-3632 WPScan
5.4 Medium WordPress Button Plugin MaxButtons Plugin Cross-Site Scripting Editor+ Stored XSS < 9.7.8 Fixed in 9.7.8 CVE-2024-3026 WPScan
6.1 Medium Swift Framework Plugin Cross-Site Scripting Reflected XSS No login needed < 2024.04.30 Fixed in 2024.04.30 CVE-2024-2870 WPScan
5.3 Medium Laposta Plugin laposta Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.12 CVE-2024-6574 Wordfence
7.2 High UserFeedback Lite Plugin userfeedback-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Name Parameter No login needed ≤ 1.0.15 CVE-2024-5902 Wordfence
9.1 Critical Realtyna Organic IDX Plugin real-estate-listing-realtyna-wpl Arbitrary File Upload ≤ 4.14.13 CVE-2024-38736 Patchstack
7.5 High Event post Plugin event-post Local File Inclusion No login needed ≤ 5.9.5 Fixed in 5.9.6 CVE-2024-38735 Patchstack
9.1 Critical Import Spreadsheets from Microsoft Excel Plugin import-spreadsheets-from-microsoft-excel Arbitrary File Upload ≤ 10.1.4 CVE-2024-38734 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Local File Inclusion No login needed ≤ 1.1.13 CVE-2024-38717 Patchstack
6.5 Medium Events Calendar for Google Plugin events-calendar-for-google Local File Inclusion ≤ 2.1.0 CVE-2024-38716 Patchstack
6.5 Medium ExS Widgets Plugin exs-widgets Local File Inclusion ≤ 0.3.1 CVE-2024-38715 Patchstack
5.3 Medium GD Rating System Plugin gd-rating-system Local File Inclusion ≤ 3.6 Fixed in 3.6.1 CVE-2024-38709 Patchstack
6.5 Medium HT Mega Plugin ht-mega-for-elementor Path Traversal JSON Path Traversal ≤ 2.5.7 Fixed in 2.5.8 CVE-2024-38706 Patchstack
6.5 Medium WordPress Team Manager Plugin wp-team-manager Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-38704 Patchstack
6.5 Medium WPCS Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional plugin <= 1.2.0.3 - Arbitrary Shortcode Execution No login needed ≤ 1.2.0.3 CVE-2024-38700 Patchstack
8.6 High Woocommerce OpenPos Plugin Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 6.4.4 CVE-2024-37932 Patchstack
8.6 High Jobmonster Theme Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 4.7.0 CVE-2024-37928 Patchstack
9.8 Critical Jobmonster Theme noo-jobmonster Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 4.7.5 Fixed in 4.7.6 CVE-2024-37927 Patchstack
8.0 High WP User Switch Plugin wp-user-switch Privilege Escalation ≤ 1.1.0 CVE-2024-37560 Patchstack
4.3 Medium SociallyViral Theme sociallyviral Cross-Site Request Forgery No login needed ≤ 1.0.10 CVE-2024-37938 Patchstack
4.3 Medium Patricia Lite Theme patricia-lite Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2024-37939 Patchstack
7.4 High Seraphinite Accelerator (Full, premium) Plugin Cross-Site Request Forgery CSRF Leading to Arbitrary File Deletion No login needed ≤ 2.21.13 Fixed in 2.21.13.1 CVE-2024-37940 Patchstack
4.3 Medium Internal Link Juicer: SEO Auto Linker Plugin internal-links Cross-Site Request Forgery No login needed ≤ 2.24.3 Fixed in 2.24.4 CVE-2024-37941 Patchstack
7.1 High Comment Reply Email Plugin comment-reply-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 Fixed in 1.5 CVE-2024-35773 Patchstack
6.5 Medium Ultimate Custom Add To Cart Button (Ajax) For WooCommerce by Binary Carpenter Plugin custom-add-to-cart-button-for-woocommerce Broken Access Control Broken Access Control to XSS ≤ 1.222.17 CVE-2024-37202 Patchstack
7.1 High AliNext Plugin ali2woo-lite Cross-Site Request Forgery CSRF to XSS No login needed ≤ 3.4.6 Fixed in 3.4.7 CVE-2024-37213 Patchstack
4.3 Medium Get Better Reviews for WooCommerce Plugin more-better-reviews-for-woocommerce Broken Access Control ≤ 4.0.6 CVE-2024-37544 Patchstack
8.5 High PayPlus Payment Gateway Plugin payplus-payment-gateway SQL Injection ≤ 7.0.7 Fixed in 7.0.8 CVE-2024-37564 Patchstack
9.3 Critical Woocommerce OpenPos Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.4.4 CVE-2024-37933 Patchstack
8.8 High Form Vibes Plugin form-vibes SQL Injection Authenticated (Subscriber+) SQL Injection via fv_export_data ≤ 1.4.10 CVE-2024-5325 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Animated Text Widget ≤ 4.10.36 CVE-2024-6495 Wordfence
9.8 Critical MStore API – Create Native Android & iOS Apps On The Cloud Plugin mstore-api Authentication Bypass Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass No login needed ≤ 4.14.7 CVE-2024-6328 Wordfence
8.8 High Wallet for WooCommerce Plugin woo-wallet SQL Injection Authenticated (Subscriber+) SQL Injection via 'search[value]' ≤ 1.5.4 CVE-2024-6353 Wordfence
5.5 Medium WP Total Branding Plugin wp-total-branding Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via title Parameter ≤ 1.2 CVE-2024-6625 Wordfence
6.4 Medium PowerPress Podcasting plugin by Blubrry Plugin powerpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via media_url Parameter ≤ 11.9.10 CVE-2024-6588 Wordfence
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Groups/Emails Deletion via CSRF No login needed ≤ 1.0.3 CVE-2024-6024 WPScan
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Email Adding via CSRF No login needed ≤ 1.0.3 CVE-2024-6023 WPScan
8.8 High ContentLock Plugin contentlock Cross-Site Request Forgery Settings Update via CSRF No login needed ≤ 1.0.3 CVE-2024-6022 WPScan
6.1 Medium Simple Video Directory Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed < 1.4.4 Fixed in 1.4.4 CVE-2024-5811 WPScan
5.9 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting Reflected XSS < 3.7.0 Fixed in 3.7.0 CVE-2024-5626 WPScan
5.9 Medium WP Secure Maintenance Plugin Cross-Site Scripting Admin+ Stored XSS < 1.7 Fixed in 1.7 CVE-2024-4753 WPScan
4.9 Medium Quotes and Tips Plugin quotes-and-tips Arbitrary File Upload Admin+ Arbitrary File Upload < 1.45 Fixed in 1.45 CVE-2024-3112 WPScan
4.8 Medium Swift Framework Plugin Cross-Site Scripting Admin+ Stored XSS via Settings < 2024.04.30 Fixed in 2024.04.30 CVE-2024-2696 WPScan
6.8 Medium Watu Quiz Plugin watu Cross-Site Scripting Author+ Stored XSS < 3.4.1.2 Fixed in 3.4.1.2 CVE-2024-2640 WPScan
6.5 Medium Website Content in Page or Post Plugin Cross-Site Scripting Contributor+ Stored Cross-Site Scripting < 2024.04.09 Fixed in 2024.04.09 CVE-2024-2430 WPScan
4.8 Medium Social Media Widget Plugin Cross-Site Scripting Admin+ Stored XSS < 4.0.9 Fixed in 4.0.9 CVE-2024-0974 WPScan
5.3 Medium WP Popups – WordPress Popup builder Plugin wp-popups-lite Information Disclosure WordPress Popup builder <= 2.2.0.1 - Unauthenticated Full Path Disclosure No login needed ≤ 2.2.0.1 CVE-2024-6555 Wordfence
4.3 Medium Event post Plugin event-post Cross-Site Request Forgery No login needed ≤ 5.9.10 CVE-2024-1375 Wordfence
5.4 Medium Image Optimizer, Resizer and CDN – Sirv Plugin sirv Broken Access Control Sirv <= 7.2.7 - Authenticated(Subscriber+) Missing Authorization to Plugin Settings Update ≤ 7.2.7 CVE-2024-6392 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only