WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,751–24,800 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 496 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.8 High WP ERP Plugin erp SQL Injection Authenticated (Accounting Manager+) SQL Injection via vendor_id ≤ 1.13.0 CVE-2024-6666 Wordfence
9.8 Critical JSON API User Plugin json-api-user Privilege Escalation Unauthenticated Privilege Escalation No login needed ≤ 3.9.3 CVE-2024-6624 Wordfence
6.4 Medium Feeds for YouTube (YouTube video, channel, and gallery plugin) Plugin feeds-for-youtube Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.2.1 CVE-2024-6256 Wordfence
6.5 Medium Secure Copy Content Protection Plugin Cross-Site Scripting Admin+ Stored XSS < 4.0.9 Fixed in 4.0.9 CVE-2024-6138 WPScan
6.1 Medium Slider by 10Web Plugin slider-wd Cross-Site Scripting Editor+ Stored XSS No login needed < 1.2.56 Fixed in 1.2.56 CVE-2024-6026 WPScan
6.5 Medium Quiz and Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.5 Fixed in 9.0.5 CVE-2024-6025 WPScan
5.4 Medium Bible Text Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 0.2 CVE-2024-5444 WPScan
6.3 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Contributor+ Stored XSS No login needed < 3.1.9 Fixed in 3.1.9 CVE-2024-4655 WPScan
8.0 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery < 1.3.2 Fixed in 1.3.2 CVE-2024-1845 WPScan
5.3 Medium Payflex Payment Gateway Plugin payflex-payment-gateway Broken Access Control Missing Authorization to Order Status Update No login needed ≤ 2.5.0 CVE-2024-0619 Wordfence
9.8 Critical InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Authentication Bypass Authentication Bypass to Admin No login needed ≤ 0.1.0.44 CVE-2024-6397 Wordfence
5.3 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Information Disclosure White Label WordPress, Custom Login Page Customizer <= 3.4.18 - Unauthenticated Full Path Disclosure No login needed ≤ 3.4.18 CVE-2024-6554 Wordfence
5.3 Medium Duplicator Plugin duplicator Information Disclosure Full Path Disclosure No login needed ≤ 1.5.9 CVE-2024-6210 Wordfence
7.2 High FULL Plugin full-customer Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via License Plan Parameter No login needed ≤ 3.1.12 CVE-2024-6447 Wordfence
7.5 High WishList Member X Plugin Information Disclosure Unauthenticated Settings & Users Data Dump No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37110 Patchstack
9.8 Critical WishList Member X Plugin Information Disclosure Unauthenticated Database Backup Download No login needed < 3.26.7 Fixed in 3.26.7 CVE-2024-37113 Patchstack
7.5 High Newspack Blocks Plugin Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2024-37115 Patchstack
5.3 Medium affiliate-toolkit Plugin affiliate-toolkit-starter Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 3.4.4 Fixed in 3.4.5 CVE-2024-37205 Patchstack
5.3 Medium TrustedLogin Vendor Plugin Information Disclosure Sensitive Data Exposure No login needed < 1.1.1 Fixed in 1.1.1 CVE-2024-37270 Patchstack
5.3 Medium Table & Contact Form 7 Database – Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure via API No login needed ≤ 1.0.33 Fixed in 1.0.34 CVE-2024-37498 Patchstack
5.3 Medium FileBird Document Library Plugin filebird-document-library Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0.6 Fixed in 2.0.8.1 CVE-2024-37504 Patchstack
5.3 Medium SmartCrawl WordPress SEO checker, SEO analyzer, SEO optimizer Plugin Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 3.10.8 CVE-2024-6556 Wordfence
6.4 Medium MP3 Audio Player for Music, Radio & Podcast by Sonaar Plugin mp3-music-player-by-sonaar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sonaar_audioplayer Shortcode ≤ 5.5 CVE-2024-5664 Wordfence
6.1 Medium Login by Auth0 Plugin auth0 Cross-Site Scripting Reflected Cross-Site Scripting via wle No login needed ≤ 4.6.0 CVE-2023-6813 Wordfence
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation ≤ 5.8.9 CVE-2024-6411 Wordfence
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference ≤ 5.8.9 CVE-2024-6410 Wordfence
5.3 Medium Gravity Forms: Multiple Form Instances Plugin gravity-forms-multiple-form-instances Information Disclosure Unauthenticated Full Path Disclosure No login needed ≤ 1.1.1 CVE-2024-6550 Wordfence
8.8 High Houzez CRM Plugin SQL Injection Authenticated (Seller+) SQL Injection ≤ 1.4.2 CVE-2024-5792 Wordfence
8.8 High Advanced File Manager Shortcodes Plugin Path Traversal Authenticated (Contributor+) Directory Traversal ≤ 2.4 CVE-2023-7062 Wordfence
4.3 Medium Featured Image Generator Plugin featured-image-generator Broken Access Control Missing Authorization to Authenticated (Subscriber+) Images Upload ≤ 1.3.1 CVE-2024-5677 Wordfence
6.4 Medium UltraAddons for Elementor Plugin ultraaddons-elementor-lite Cross-Site Scripting Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.1.6 CVE-2024-4866 Wordfence
8.8 High Advanced File Manager Shortcode Plugin Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 2.5.3 CVE-2023-7061 Wordfence
8.8 High BookYourTravel Theme Privilege Escalation Subscriber+ Privilege Escalation ≤ 8.18.17 Fixed in 8.18.19 CVE-2024-37952 Patchstack
5.4 Medium Ninja Forms Plugin ninja-forms Arbitrary Shortcode Execution Subscriber+ Arbitrary Shortcode Execution ≤ 3.8.4 Fixed in 3.8.5 CVE-2024-37934 Patchstack
6.5 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Local File Inclusion Elementor WooCommerce Builder Addons plugin <= 2.1.12 - Local File Inclusion ≤ 2.1.12 Fixed in 2.1.13 CVE-2024-37520 Patchstack
8.5 High WPCafe Plugin wp-cafe Local File Inclusion ≤ 2.2.27 Fixed in 2.2.28 CVE-2024-37513 Patchstack
8.5 High Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Local File Inclusion ≤ 3.1.3 Fixed in 3.2.1 CVE-2024-37501 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Local File Inclusion ≤ 4.4.2 Fixed in 4.4.3 CVE-2024-37499 Patchstack
7.7 High JetThemeCore Plugin jet-theme-core Arbitrary File Deletion Subscriber+ Arbitrary File Deletion ≤ 2.2.1 Fixed in 2.2.1 CVE-2024-37497 Patchstack
8.8 High Zephyr Project Manager Plugin zephyr-project-manager Privilege Escalation ≤ 3.3.97 Fixed in 3.3.99 CVE-2024-37484 Patchstack
4.9 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Local File Inclusion ≤ 1.3.5 Fixed in 1.3.6 CVE-2024-37464 Patchstack
6.4 Medium oik Plugin oik Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bw_button Shortcode ≤ 4.10.3 CVE-2024-6391 Wordfence
6.4 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5 CVE-2024-4862 Wordfence
6.4 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via tab Shortcode ≤ 0.4.8 CVE-2024-5946 Wordfence
8.5 High Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Local File Inclusion ≤ 1.4.2 Fixed in 1.4.3 CVE-2024-37462 Patchstack
8.8 High Ultimate Addons for Elementor Plugin header-footer-elementor Privilege Escalation ≤ 1.36.31 Fixed in 1.36.32 CVE-2024-37455 Patchstack
6.5 Medium AWSM Team Plugin awsm-team Local File Inclusion Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion ≤ 1.3.1 Fixed in 1.3.2 CVE-2024-37454 Patchstack
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
5.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting Arbitrary SVG File Download ≤ 3.22.1 Fixed in 3.22.2 CVE-2024-37437 Patchstack
5.3 Medium Patreon Plugin patreon-connect Authentication Bypass Image Protection Bypass No login needed ≤ 1.9.0 Fixed in 1.9.1 CVE-2024-37430 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only