WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 24,901–24,950 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 499 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.3 Medium Himer - Social Questions and Answers Theme Cross-Site Request Forgery Social Questions and Answers < 2.1.1 - Arbitrary Group Joining via CSRF No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-2040 WPScan
4.3 Medium Snippet Shortcodes Plugin shortcode-variables Cross-Site Request Forgery No login needed ≤ 4.1.4 CVE-2024-4543 Wordfence
6.4 Medium Post Meta Data Manager Plugin post-meta-data-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-6264 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Other WordPress LMS Plugin <= 4.2.6.8.1 - Unauthenticated Bypass to User Registration No login needed ≤ 4.2.6.8.1 CVE-2024-6099 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.6.8.1 - Missing Authorization to Unauthenticated User Registration Bypass No login needed ≤ 4.2.6.8.1 CVE-2024-6088 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin ultimate-blocks Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Multiple Blocks ≤ 3.1.9 CVE-2024-4268 Wordfence
4.3 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Content Creation ≤ 3.2.12 CVE-2024-6012 Wordfence
4.4 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.2.12 CVE-2024-6011 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via read_more_text Parameter ≤ 3.5.5 CVE-2024-5260 Wordfence
8.5 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Contributor+ Local File Inclusion ≤ 1.3.8.1 Fixed in 1.3.9 CVE-2024-37479 Patchstack
6.1 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 3.17 CVE-2024-5544 Wordfence
5.3 Medium Motors – Car Dealer, Classifieds & Listing Plugin Broken Access Control Car Dealer, Classifieds & Listing <= 1.4.9 - Missing Authorization No login needed ≤ 1.4.9 CVE-2024-5545 Wordfence
6.4 Medium Rife Elementor Extensions & Templates Plugin rife-elementor-extensions Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Writing Effect Headline Widget ≤ 1.2.1 CVE-2024-5504 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via title tag attribute ≤ 3.1.9 CVE-2024-3513 Wordfence
6.4 Medium Easy Google Maps Plugin google-maps-easy Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.11.15 CVE-2024-5219 Wordfence
9.8 Critical Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce Plugin email-subscribers SQL Injection Email Marketing, Newsletters, Automation for WordPress & WooCommerce <= 5.7.25 - Unauthenticated SQL Injection via unsubscribe No login needed ≤ 5.7.25 CVE-2024-6172 Wordfence
8.8 High Sitetweet Plugin sitetweet-tweets-user-behaviors-on-your-site-on-twitter Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 0.2 CVE-2024-5767 WPScan
8.8 High Quiz And Survey Master Plugin SQL Injection Contributor+ SQLi < 9.0.2 Fixed in 9.0.2 CVE-2024-5606 WPScan
5.5 Medium Rank Math SEO Plugin seo-by-rank-math Cross-Site Scripting Authenticated Stored XSS < 1.0.219 Fixed in 1.0.219 CVE-2024-4627 WPScan
4.8 Medium EazyDocs Plugin eazydocs Cross-Site Scripting Admin+ Stored XSS < 2.5.0 Fixed in 2.5.0 CVE-2024-3999 WPScan
6.4 Medium The Post Grid Plugin the-post-grid Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag ≤ 7.7.1 CVE-2024-1427 Wordfence
8.8 High LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.3.8.1 CVE-2024-5349 Wordfence
6.4 Medium Void Contact Form 7 Widget For Elementor Page Builder Plugin cf7-widget-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cf7_redirect_page Attribute ≤ 2.4 CVE-2024-5419 Wordfence
6.4 Medium Boot Store Theme boot-store Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.6.4 CVE-2024-5938 Wordfence
5.4 Medium Basil Theme Cross-Site Scripting WordPress Basil Theme Authenticated (Contributor+) Persistent Cross-Site Scripting < 2.0.5 CVE-2024-39310 GitHub_M
4.8 Medium Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.26 Fixed in 1.15.26 CVE-2024-6130 WPScan
5.5 Medium Quiz And Survey Master Plugin Cross-Site Scripting Contributor+ Stored XSS < 9.0.2 Fixed in 9.0.2 CVE-2024-4934 WPScan
8.8 High WordPress Plugin for Google Maps – WP MAPS Plugin wp-google-map-plugin SQL Injection WP MAPS <= 4.6.1 - Authenticated (Contributor+) SQL Injection ≤ 4.6.1 CVE-2024-2386 Wordfence
6.1 Medium Goya Theme Cross-Site Scripting Unauthenticated Reflected Cross-Site Scripting via Multiple Parameters No login needed ≤ 1.0.8.7 CVE-2023-4017 Wordfence
6.4 Medium Gutenberg Blocks with AI by Kadence WP – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.45 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via HTML Data Attributes ≤ 3.2.45 CVE-2024-5819 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Gradient Heading Widget ≤ 3.11.1 CVE-2024-5790 Wordfence
6.4 Medium Extensions for Elementor Plugin extensions-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter ≤ 2.0.30 CVE-2024-5666 Wordfence
6.4 Medium Stock Ticker Plugin stock-ticker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stock_ticker Shortcode ≤ 3.24.4 CVE-2024-6363 Wordfence
7.5 High Advanced File Manager Plugin file-manager-advanced Information Disclosure Sensitive Information Exposure via Directory Listing No login needed ≤ 5.2.4 CVE-2024-5598 Wordfence
9.8 Critical UsersWP – Front-end login form, User Registration, User Profile & Members Directory Plugin userswp SQL Injection Front-end login form, User Registration, User Profile & Members Directory plugin for WordPress <= 1.2.10 - Unauthenticated SQL Injection via 'uwp_sort_by' No login needed ≤ 1.2.10 CVE-2024-6265 Wordfence
6.1 Medium Events Manager Plugin events-manager Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 6.4.8 CVE-2024-5889 Wordfence
4.3 Medium Page and Post Clone Plugin page-or-post-clone Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Sensitive Information Exposure ≤ 6.0 CVE-2024-5942 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells <= 3.3.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.3.1 CVE-2024-5192 Wordfence
6.1 Medium Floating Social Buttons Plugin floating-social-buttons Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2024-6405 Wordfence
6.4 Medium Scylla lite Theme scylla-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.8.3 CVE-2024-5922 Wordfence
6.4 Medium Ultimate Post Kit Addons for Elementor Plugin ultimate-post-kit Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget ≤ 3.11.7 CVE-2024-5662 Wordfence
6.4 Medium Theron Lite Theme theron-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 2.0 CVE-2024-5925 Wordfence
6.4 Medium Mixed Media Gallery Blocks Plugin simply-gallery-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters ≤ 3.2.1 CVE-2024-5424 Wordfence
4.7 Medium Conversios.io - All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce Plugin enhanced-e-commerce-for-woocommerce-store Cross-Site Scripting All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce <= 7.1.0 - Reflected Cross-Site Scripting No login needed ≤ 7.1.0 CVE-2024-6288 Wordfence
6.4 Medium Infinite Theme infinite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via project_url Parameter ≤ 1.1.2 CVE-2024-5796 Wordfence
5.3 Medium SEO SIMPLE PACK Plugin seo-simple-pack Information Disclosure Information Exposure No login needed ≤ 3.2.1 CVE-2024-2795 Wordfence
6.4 Medium Silesia Theme silesia Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.0.6 CVE-2024-5788 Wordfence
6.1 Medium Pagerank Tools Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.1.5 CVE-2024-5730 WPScan
6.1 Medium Simple AL Slider Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2.10 CVE-2024-5729 WPScan
5.4 Medium Animated AL List Plugin animated-al-list Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.6 CVE-2024-5728 WPScan

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only