WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 201–250 of 269 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership | Broken Access Control BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Missing Authorization to Arbitrary (Subscriber+) Attachment Deletion |
≤ 1.3.0 |
CVE-2024-9067 |
Wordfence | |
| 6.4 Medium | Curator.io: Show all your social media posts in a beautiful feed. | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via feed_id Attribute |
≤ 1.9.1 |
CVE-2024-9057 |
Wordfence | |
| 6.4 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership | Cross-Site Scripting BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via youzify_media Shortcode |
≤ 1.3.0 |
CVE-2024-8987 |
Wordfence | |
| 6.4 Medium | Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg | Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 1.2.4 |
CVE-2024-8288 |
Wordfence | |
| 5.3 Medium | WP Hardening – Fix Your WordPress Security | Other Fix Your WordPress Security <= 1.2.6 - Unauthenticated Security Feature Bypass to Username Enumeration No login needed |
≤ 1.2.6 |
CVE-2024-6641 |
Wordfence | |
| 6.5 Medium | PixelYourSite – Your smart PIXEL (TAG) & API Manager | Information Disclosure Your smart PIXEL (TAG) & API Manager <= 9.7.1 and PixelYourSite PRO <= 10.4.2 - Unauthenticated Information Exposure and Log Deletion No login needed |
≤ 9.7.1, ≤ 10.4.2 |
CVE-2024-7870 |
Wordfence | |
| 4.3 Medium | Masteriyo - LMS | Broken Access Control Insecure Direct Object Reference (IDOR) |
≤ 1.11.4 Fixed in 1.11.5 |
CVE-2024-43239 |
Patchstack | |
| 6.5 Medium | Custom Layouts – Post + Product grids made easy | Cross-Site Scripting Post + Product grids made easy plugin <= 1.4.11 - Cross Site Scripting (XSS) |
≤ 1.4.11 Fixed in 1.4.12 |
CVE-2024-43305 |
Patchstack | |
| 4.3 Medium | TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder | Broken Access Control TemplateSpare <= 2.4.2 - Missing Authorization to Authenticated (Subscriber+) Theme Update |
≤ 2.4.2 |
CVE-2024-6872 |
Wordfence | |
| 6.5 Medium | Blogmentor – Blog Layouts for Elementor | Cross-Site Scripting Blog Layouts for Elementor plugin <= 1.5 - Cross Site Scripting (XSS) |
≤ 1.5 |
CVE-2024-37229 |
Patchstack | |
| 5.9 Medium | PixelYourSite – Your smart PIXEL (TAG) Manager | Cross-Site Scripting |
≤ 9.6.1.1 Fixed in 9.6.2 |
CVE-2024-37447 |
Patchstack | |
| 6.5 Medium | Caxton – Create Pro page layouts in Gutenberg | Cross-Site Scripting Create Pro page layouts in Gutenberg plugin <= 1.30.1 - Cross Site Scripting (XSS) |
≤ 1.30.1 |
CVE-2024-37948 |
Patchstack | |
| 6.5 Medium | Post Layouts for Gutenberg | Cross-Site Scripting |
≤ 1.2.7 |
CVE-2024-38682 |
Patchstack | |
| 6.5 Medium | FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross-Site Scripting |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-38686 |
Patchstack | |
| 6.4 Medium | Feeds for YouTube (YouTube video, channel, and gallery plugin) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.2.1 |
CVE-2024-6256 |
Wordfence | |
| 6.4 Medium | Mixed Media Gallery Blocks | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters |
≤ 3.2.1 |
CVE-2024-5424 |
Wordfence | |
| 6.5 Medium | Serious Slider | Cross-Site Scripting |
≤ 1.2.4 Fixed in 1.2.5 |
CVE-2024-35762 |
Patchstack | |
| 6.4 Medium | JetWidgets For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters |
≤ 1.0.17 |
CVE-2024-4626 |
Wordfence | |
| 6.5 Medium | Youzify – BuddyPress Community, User Profile, Social Network & Membership | SQL Injection BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection |
≤ 1.2.5 |
CVE-2024-4742 |
Wordfence | |
| 6.4 Medium | Blogmentor – Blog Layouts for Elementor | Cross-Site Scripting Blog Layouts for Elementor <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagination_style Parameter |
≤ 1.5 |
CVE-2024-4623 |
Wordfence | |
| 6.4 Medium | Video Gallery – YouTube Playlist, Channel Gallery by YotuWP | Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Authenticated (Contributor+) Arbitrary File Inclusion via Shortcode |
≤ 1.3.13 |
CVE-2024-4551 |
Wordfence | |
| 5.3 Medium | Yoast SEO Premium | Broken Access Control Unauthenticated Zapier API Key Reset No login needed |
≤ 20.4 Fixed in 20.5 |
CVE-2023-28775 |
Patchstack | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 4.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget |
≤ 4.0.1 |
CVE-2024-5571 |
Wordfence | |
| 4.3 Medium | Gutenberg Blocks and Page Layouts – Attire Blocks | Broken Access Control Attire Blocks <= 1.9.2 - Missing Authorization |
≤ 1.9.2 |
CVE-2024-4088 |
Wordfence | |
| 6.4 Medium | SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! | Cross-Site Scripting Connect All Your Plugins, Apps, Tools & Automate Everything! <= 1.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trigger Link Shortcode |
≤ 1.0.47 |
CVE-2024-5485 |
Wordfence | |
| 4.8 Medium | Playlist for Youtube | Cross-Site Scripting Editor+ Stored XSS |
≤ 1.32 |
CVE-2024-3937 |
WPScan | |
| 6.4 Medium | Custom Fonts – Host Your Fonts Locally | Cross-Site Scripting Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 2.1.4 |
CVE-2024-1332 |
Wordfence | |
| 4.3 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Broken Access Control Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual |
≤ 3.9.12 |
CVE-2024-1803 |
Wordfence | |
| 4.3 Medium | ApplyOnline – Application Form Builder and Manager | Broken Access Control Application Form Builder and Manager <= 2.6.2 - Missing Authorization to Sensitive Information Exposure |
≤ 2.6.2 |
CVE-2024-2036 |
Wordfence | |
| 5.3 Medium | YouTube Video Gallery by YouTube Showcase – Video Gallery | Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed |
≤ 3.3.6 |
CVE-2024-3268 |
Wordfence | |
| 6.4 Medium | Yoast SEO | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 22.6 |
CVE-2024-4984 |
Wordfence | |
| 4.3 Medium | Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease | Broken Access Control Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure |
≤ 2.6.6 |
CVE-2024-0437 |
Wordfence | |
| 6.4 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter |
≤ 4.2.6.5 |
CVE-2024-4277 |
Wordfence | |
| 6.1 Medium | Yoast SEO | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 22.5 |
CVE-2024-4041 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 3.9.16 |
CVE-2024-4316 |
Wordfence | |
| 4.3 Medium | Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery | Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-34377 |
Patchstack | |
| 5.5 Medium | Where Did You Hear About Us Checkout Field for WooCommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-2752 |
Wordfence | |
| 5.3 Medium | Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page | Broken Access Control Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure No login needed |
≤ 1.13.4 |
CVE-2024-0908 |
Wordfence | |
| 4.3 Medium | Serious Slider | Cross-Site Request Forgery No login needed |
≤ 1.2.4 |
CVE-2024-33650 |
Patchstack | |
| 4.3 Medium | EleSpare – News, Magazine and Blog Addons for Elementor | Broken Access Control Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation |
≤ 2.1.2 |
CVE-2024-0900 |
Wordfence | |
| 6.5 Medium | DSGVO Youtube | Cross-Site Scripting |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2024-32596 |
Patchstack | |
| 6.4 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) |
≤ 4.4.7 |
CVE-2023-6805 |
Wordfence | |
| 6.5 Medium | Yoga Schedule Momoyoga | Cross-Site Scripting |
≤ 2.7.0 |
CVE-2024-32529 |
Patchstack | |
| 4.3 Medium | Custom Thank You Page Customize For WooCommerce by Binary Carpenter | Broken Access Control |
≤ 1.4.12 Fixed in 1.4.14 |
CVE-2024-32517 |
Patchstack | |
| 4.3 Medium | NextMove Lite | Cross-Site Request Forgery No login needed |
≤ 2.18.1 Fixed in 2.18.2 |
CVE-2024-32104 |
Patchstack | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.9.14 |
CVE-2024-3244 |
Wordfence | |
| 6.5 Medium | MailMunch – Grow your Email List | Cross-Site Scripting Grow your Email List plugin <= 3.1.6 - Cross Site Scripting (XSS) |
≤ 3.1.6 Fixed in 3.1.7 |
CVE-2024-31349 |
Patchstack | |
| 6.4 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message |
≤ 4.3.3 |
CVE-2023-6877 |
Wordfence | |
| 6.4 Medium | Powerkit – Supercharge your WordPress Site | Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.9.1 |
CVE-2024-2458 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block |
≤ 3.9.14 |
CVE-2024-3245 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.