WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 201–250 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 5 of 7
Severity Component Vulnerability Affected versions Published CVE Source
7.3 High Avada Builder Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.11.13 CVE-2024-13345 Wordfence
7.1 High Forge – Front-End Page Builder Plugin forge Cross-Site Request Forgery Front-End Page Builder plugin <= 1.4.6 - CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.4.6 CVE-2025-22703 Patchstack
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Arbitrary File Read No login needed ≤ 1.7.5 Fixed in 2.0.1 CVE-2025-24569 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.3.3 Fixed in 6.0.3.4 CVE-2025-24686 Patchstack
7.1 High Internal Link Builder Plugin internal-link-builder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23989 Patchstack
8.5 High Form Builder CP Plugin cp-easy-form-builder SQL Injection ≤ 1.2.41 Fixed in 1.2.42 CVE-2025-24672 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-22716 Patchstack
7.1 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting No login needed ≤ 8.0.6 Fixed in 8.0.7 CVE-2025-22295 Patchstack
8.8 High SKT Page Builder Plugin skt-builder Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 4.7 CVE-2024-12848 Wordfence
7.5 High Cost Calculator Builder PRO Plugin SQL Injection Unauthenticated SQL Injection via data No login needed ≤ 3.2.15 CVE-2024-11939 Wordfence
7.5 High Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Local File Inclusion WPBakery Page Builder plugin <= 3.0 - Local File Inclusion ≤ 3.0 Fixed in 3.1 CVE-2024-56286 Patchstack
7.5 High WP Data Access – App, Table, Form and Chart Builder Plugin wp-data-access SQL Injection App, Table, Form and Chart Builder plugin <= 5.5.22 - Unauthenticated SQL Injection No login needed ≤ 5.5.22 CVE-2024-12428 Wordfence
8.5 High PowerFormBuilder Plugin power-forms-builder SQL Injection ≤ 1.0.6 CVE-2024-55983 Patchstack
7.2 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Form Subject No login needed ≤ 5.2.6 CVE-2024-10646 Wordfence
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed ≤ 3.8.19 CVE-2024-11052 Wordfence
7.5 High WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses Plugin wp-courses Broken Access Control Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Meta Update No login needed ≤ 3.2.21 CVE-2024-12172 Wordfence
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Broken Access Control No login needed ≤ 5.2.3.0 Fixed in 5.2.3.1 CVE-2023-49831 Patchstack
8.5 High NEX-Forms Plugin nex-forms-express-wp-form-builder SQL Injection ≤ 8.7.8 Fixed in 8.7.9 CVE-2024-53808 Patchstack
7.5 High Classic Addons – WPBakery Page Builder Plugin classic-addons-wpbakery-page-builder-addons Local File Inclusion WPBakery Page Builder <= 3.0 - Authenticated (Contributor+) Limited Local PHP File Inclusion ≤ 3.0 CVE-2024-11952 Wordfence
7.5 High PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 2.0.0 CVE-2024-9935 Wordfence
8.0 High Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation ≤ 6.0.9 CVE-2024-8979 Wordfence
7.1 High Team Showcase and Slider – Team Members Builder Plugin team-showcase-ultimate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2024-51763 Patchstack
8.5 High Lodgix.com Vacation Rental Website Builder Plugin lodgixcom-vacation-rental-listing-management-booking-plugin SQL Injection ≤ 3.9.73 CVE-2024-50539 Patchstack
7.5 High Stacks Mobile App Builder Plugin stacks-mobile-app-builder Information Disclosure Sensitive Data Exposure No login needed ≤ 5.2.3 CVE-2024-50528 Patchstack
8.8 High Masteriyo LMS – eLearning and Online Course Builder Plugin learning-management-system Broken Access Control eLearning and Online Course Builder for WordPress <= 1.13.3 - Authenticated (Student+) Missing Authorization to Privilege Escalation ≤ 1.13.3 CVE-2024-10008 Wordfence
7.5 High Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator Broken Access Control Contact Form, Payment Form & Custom Form Builder <= 1.35.1 - Missing Authorization to Authenticated (Contributor+) Form Update and Creation ≤ 1.35.1 CVE-2024-10402 Wordfence
8.1 High App Builder – Create Native Android & iOS Apps On The Flight Plugin app-builder Privilege Escalation Create Native Android & iOS Apps On The Flight <= 5.3.7 - Privilege Escalation and Account Takeover via Weak OTP No login needed ≤ 5.3.7 CVE-2024-9302 Wordfence
7.3 High WP Popup Builder – Popup Forms and Marketing Lead Generation Plugin wp-popup-builder Arbitrary Shortcode Execution Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add No login needed ≤ 1.3.5 CVE-2024-9061 Wordfence
8.3 High WP Lead Plus X Plugin free-sales-funnel-squeeze-pages-landing-page-builder-templates-make Cross-Site Request Forgery No login needed ≤ 0.99 CVE-2020-36839 Wordfence
8.3 High Formidable Form Builder Plugin formidable Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed < 2.05.03 Fixed in 2.05.03 CVE-2017-20192 Wordfence
7.1 High Chartify Plugin chart-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.7.6 Fixed in 2.7.7 CVE-2024-47347 Patchstack
7.1 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.7.3 Fixed in 8.7.4 CVE-2024-47389 Patchstack
7.2 High Cost Calculator Builder Plugin cost-calculator-builder SQL Injection Admin+ SQL Injection < 3.2.29 Fixed in 3.2.29 CVE-2024-8379 WPScan
7.1 High Beaver Builder Plugin beaver-builder-lite-version Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.3.2 Fixed in 2.8.3.4 CVE-2024-43926 Patchstack
8.7 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form Arbitrary File Deletion Authenticater (Administrator+) Arbitrary File Deletion 2.0 – 2.13.4 CVE-2024-7782 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection 2.0 – 2.13.9 CVE-2024-7780 Wordfence
7.2 High Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder Plugin bit-form SQL Injection Authenticated (Administrator+) SQL Injection via getLogHistory Function 2.0 – 2.13.9 CVE-2024-7702 Wordfence
7.5 High Landing Page Builder Plugin page-builder-add Local File Inclusion ≤ 1.5.2.0 Fixed in 1.5.2.1 CVE-2024-43345 Patchstack
8.5 High JetGridBuilder Plugin jetgridbuilder Local File Inclusion ≤ 1.1.2 Fixed in 1.1.3 CVE-2024-43221 Patchstack
7.1 High PowerPack for Beaver Builder Plugin bbpowerpack Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.37.4 Fixed in 2.37.4 CVE-2024-43330 Patchstack
8.1 High Metform Elementor Contact Form Builder Plugin metform Arbitrary File Upload Unauthenticated Double-Extension Arbitrary File Upload No login needed ≤ 3.2.4 CVE-2023-0714 Wordfence
8.8 High Depicter — Popup & Slider Builder Plugin depicter Arbitrary File Upload Add Image Slider, Carousel Slider, Exit Intent Popup, Popup Modal, Coupon Popup, Post Slider Carousel <= 3.1.1 - Authenticated (Contributor+) Arbitrary File Upload ≤ 3.1.1 CVE-2024-4389 Wordfence
8.8 High Blox Page Builder Plugin blox-page-builder Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 1.0.65 CVE-2024-6315 Wordfence
7.2 High JetFormBuilder Plugin jetformbuilder Privilege Escalation Authenticated (Administrator+) Privilege Escalation ≤ 3.3.4.1 CVE-2024-7291 Wordfence
8.8 High PowerPack for Beaver Builder Plugin Privilege Escalation Contributor+ Privilege Escalation ≤ 2.33.0 Fixed in 2.33.1 CVE-2024-39633 Patchstack
7.2 High Lifetime free Drag & Drop Contact Form Builder for WordPress VForm Plugin v-form Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.1.5 CVE-2024-6770 Wordfence
8.8 High Flipbox Builder Plugin flipbox-builder PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.5 CVE-2024-6152 Wordfence
7.1 High ARForms Form Builder Plugin arforms-form-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.7 Fixed in 1.6.8 CVE-2024-37920 Patchstack
8.8 High Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.4.44 - Authenticated (Contributor+) Arbitrary File Upload ≤ 2.4.44 CVE-2024-3242 Wordfence
7.1 High Brizy – Page Builder Plugin brizy Broken Access Control Page Builder <= 2.4.44 - Missing Authorization to Authenticated (Contributor+) Post Modification ≤ 2.4.44 CVE-2024-1937 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only