WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 201–250 of 308 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.3 High | Avada Builder | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed |
≤ 3.11.13 |
CVE-2024-13345 |
Wordfence | |
| 7.1 High | Forge – Front-End Page Builder | Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed |
≤ 1.4.6 |
CVE-2025-22703 |
Patchstack | |
| 7.5 High | PDF Generator Addon for Elementor Page Builder | Path Traversal Arbitrary File Read No login needed |
≤ 1.7.5 Fixed in 2.0.1 |
CVE-2025-24569 |
Patchstack | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 6.0.3.3 Fixed in 6.0.3.4 |
CVE-2025-24686 |
Patchstack | |
| 7.1 High | Internal Link Builder | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2025-23989 |
Patchstack | |
| 8.5 High | Form Builder CP | SQL Injection |
≤ 1.2.41 Fixed in 1.2.42 |
CVE-2025-24672 |
Patchstack | |
| 8.5 High | Taskbuilder | SQL Injection |
≤ 3.0.6 Fixed in 3.0.7 |
CVE-2025-22716 |
Patchstack | |
| 7.1 High | WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto | Cross-Site Scripting No login needed |
≤ 8.0.6 Fixed in 8.0.7 |
CVE-2025-22295 |
Patchstack | |
| 8.8 High | SKT Page Builder | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 4.7 |
CVE-2024-12848 |
Wordfence | |
| 7.5 High | Cost Calculator Builder PRO | SQL Injection Unauthenticated SQL Injection via data No login needed |
≤ 3.2.15 |
CVE-2024-11939 |
Wordfence | |
| 7.5 High | Classic Addons – WPBakery Page Builder | Local File Inclusion WPBakery Page Builder plugin <= 3.0 - Local File Inclusion |
≤ 3.0 Fixed in 3.1 |
CVE-2024-56286 |
Patchstack | |
| 7.5 High | WP Data Access – App, Table, Form and Chart Builder | SQL Injection App, Table, Form and Chart Builder plugin <= 5.5.22 - Unauthenticated SQL Injection No login needed |
≤ 5.5.22 |
CVE-2024-12428 |
Wordfence | |
| 8.5 High | PowerFormBuilder | SQL Injection |
≤ 1.0.6 |
CVE-2024-55983 |
Patchstack | |
| 7.2 High | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed |
≤ 5.2.6 |
CVE-2024-10646 |
Wordfence | |
| 7.2 High | Ninja Forms – The Contact Form Builder That Grows With You | Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed |
≤ 3.8.19 |
CVE-2024-11052 |
Wordfence | |
| 7.5 High | WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses | Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed |
≤ 3.2.21 |
CVE-2024-12172 |
Wordfence | |
| 7.5 High | RegistrationMagic | Broken Access Control No login needed |
≤ 5.2.3.0 Fixed in 5.2.3.1 |
CVE-2023-49831 |
Patchstack | |
| 8.5 High | NEX-Forms | SQL Injection |
≤ 8.7.8 Fixed in 8.7.9 |
CVE-2024-53808 |
Patchstack | |
| 7.5 High | Classic Addons – WPBakery Page Builder | Local File Inclusion WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion |
≤ 3.0 |
CVE-2024-11952 |
Wordfence | |
| 7.5 High | PDF Generator Addon for Elementor Page Builder | Path Traversal Unauthenticated Arbitrary File Download No login needed |
≤ 2.0.0 |
CVE-2024-9935 |
Wordfence | |
| 8.0 High | Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders | Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation |
≤ 6.0.9 |
CVE-2024-8979 |
Wordfence | |
| 7.1 High | Team Showcase and Slider – Team Members Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.3 |
CVE-2024-51763 |
Patchstack | |
| 8.5 High | Lodgix.com Vacation Rental Website Builder | SQL Injection |
≤ 3.9.73 |
CVE-2024-50539 |
Patchstack | |
| 7.5 High | Stacks Mobile App Builder | Information Disclosure Sensitive Data Exposure No login needed |
≤ 5.2.3 |
CVE-2024-50528 |
Patchstack | |
| 8.8 High | Masteriyo LMS – eLearning and Online Course Builder | Broken Access Control eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation |
≤ 1.13.3 |
CVE-2024-10008 |
Wordfence | |
| 7.5 High | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation |
≤ 1.35.1 |
CVE-2024-10402 |
Wordfence | |
| 8.1 High | App Builder – Create Native Android & iOS Apps On The Flight | Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP No login needed |
≤ 5.3.7 |
CVE-2024-9302 |
Wordfence | |
| 7.3 High | WP Popup Builder – Popup Forms and Marketing Lead Generation | Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed |
≤ 1.3.5 |
CVE-2024-9061 |
Wordfence | |
| 8.3 High | WP Lead Plus X | Cross-Site Request Forgery No login needed |
≤ 0.99 |
CVE-2020-36839 |
Wordfence | |
| 8.3 High | Formidable Form Builder | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
< 2.05.03 Fixed in 2.05.03 |
CVE-2017-20192 |
Wordfence | |
| 7.1 High | Chartify | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.7.6 Fixed in 2.7.7 |
CVE-2024-47347 |
Patchstack | |
| 7.1 High | NEX-Forms | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 8.7.3 Fixed in 8.7.4 |
CVE-2024-47389 |
Patchstack | |
| 7.2 High | Cost Calculator Builder | SQL Injection Admin+ SQL Injection |
< 3.2.29 Fixed in 3.2.29 |
CVE-2024-8379 |
WPScan | |
| 7.1 High | Beaver Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.8.3.2 Fixed in 2.8.3.4 |
CVE-2024-43926 |
Patchstack | |
| 8.7 High | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | Arbitrary File Deletion Authenticater (Administrator+) Arbitrary File Deletion |
2.0 – 2.13.4 |
CVE-2024-7782 |
Wordfence | |
| 7.2 High | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | SQL Injection Authenticated (Administrator+) SQL Injection |
2.0 – 2.13.9 |
CVE-2024-7780 |
Wordfence | |
| 7.2 High | Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | SQL Injection Authenticated (Administrator+) SQL Injection via getLogHistory Function |
2.0 – 2.13.9 |
CVE-2024-7702 |
Wordfence | |
| 7.5 High | Landing Page Builder | Local File Inclusion |
≤ 1.5.2.0 Fixed in 1.5.2.1 |
CVE-2024-43345 |
Patchstack | |
| 8.5 High | JetGridBuilder | Local File Inclusion |
≤ 1.1.2 Fixed in 1.1.3 |
CVE-2024-43221 |
Patchstack | |
| 7.1 High | PowerPack for Beaver Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 2.37.4 Fixed in 2.37.4 |
CVE-2024-43330 |
Patchstack | |
| 8.1 High | Metform Elementor Contact Form Builder | Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed |
≤ 3.2.4 |
CVE-2023-0714 |
Wordfence | |
| 8.8 High | Depicter — Popup & Slider Builder | Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 3.1.1 |
CVE-2024-4389 |
Wordfence | |
| 8.8 High | Blox Page Builder | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 1.0.65 |
CVE-2024-6315 |
Wordfence | |
| 7.2 High | JetFormBuilder | Privilege Escalation Authenticated (Administrator+) Privilege Escalation |
≤ 3.3.4.1 |
CVE-2024-7291 |
Wordfence | |
| 8.8 High | PowerPack for Beaver Builder | Privilege Escalation Contributor+ Privilege Escalation |
≤ 2.33.0 Fixed in 2.33.1 |
CVE-2024-39633 |
Patchstack | |
| 7.2 High | Lifetime free Drag & Drop Contact Form Builder for WordPress VForm | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.1.5 |
CVE-2024-6770 |
Wordfence | |
| 8.8 High | Flipbox Builder | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.5 |
CVE-2024-6152 |
Wordfence | |
| 7.1 High | ARForms Form Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.6.7 Fixed in 1.6.8 |
CVE-2024-37920 |
Patchstack | |
| 8.8 High | Brizy – Page Builder | Arbitrary File Upload Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 2.4.44 |
CVE-2024-3242 |
Wordfence | |
| 7.1 High | Brizy – Page Builder | Broken Access Control Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification |
≤ 2.4.44 |
CVE-2024-1937 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.