WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 201–250 of 316 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | ProfileGrid | Broken Access Control User Profiles, Groups and Communities plugin <= 5.8.7 - Broken Access Control |
≤ 5.8.7 Fixed in 5.8.8 |
CVE-2024-37453 |
Patchstack | |
| 6.5 Medium | The Post Grid | Broken Access Control No login needed |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37481 |
Patchstack | |
| 4.3 Medium | The Post Grid | Broken Access Control |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37482 |
Patchstack | |
| 5.4 Medium | The Post Grid | Broken Access Control |
≤ 7.7.4 Fixed in 7.7.5 |
CVE-2024-37483 |
Patchstack | |
| 7.3 High | Filter & Grids | Authentication Bypass Broken Authentication No login needed |
≤ 2.8.33 Fixed in 2.8.34 |
CVE-2024-39664 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.2.93 Fixed in 2.2.94 |
CVE-2024-50432 |
Patchstack | |
| 7.2 High | WordPress Post Grid Layouts with Pagination – Sogrid | Local File Inclusion Sogrid <= 1.5.6 - Authenticated (Admin+) Local File Inclusion |
≤ 1.5.6 |
CVE-2024-8392 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Cross-Site Request Forgery No login needed |
≤ 5.9.3 Fixed in 5.9.3.1 |
CVE-2024-49273 |
Patchstack | |
| 4.3 Medium | SendGrid | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Deletion |
≤ 1.4 |
CVE-2024-9364 |
Wordfence | |
| 6.5 Medium | WordPress Portfolio Builder – Portfolio Gallery | Cross-Site Scripting Portfolio Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) |
≤ 1.1.7 |
CVE-2024-49302 |
Patchstack | |
| 6.1 Medium | Video Grid | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.21 |
CVE-2023-7295 |
Wordfence | |
| 8.8 High | Post Grid | SQL Injection Contributor+ SQL Injection |
< 2.1.13 Fixed in 2.1.13 |
CVE-2021-4450 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-grid-with-filters Shortcode |
≤ 3.9.3 |
CVE-2024-9051 |
Wordfence | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Cross-Site Scripting |
≤ 2.2.89 Fixed in 2.2.90 |
CVE-2024-47340 |
Patchstack | |
| 6.1 Medium | Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid | Cross-Site Scripting Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid <= 1.3.14 - Reflected Cross-Site Scripting No login needed |
≤ 1.3.14 |
CVE-2024-9218 |
Wordfence | |
| 6.4 Medium | Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg | Cross-Site Scripting An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via align Attribute |
≤ 1.2.4 |
CVE-2024-8288 |
Wordfence | |
| 6.4 Medium | Stars Testimonials | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stars_testimonials Shortcode |
≤ 3.3.1 |
CVE-2024-8989 |
Wordfence | |
| 4.8 Medium | The Post Grid | Cross-Site Scripting Editor+ Stored XSS via Grid Creation |
< 7.5.0 Fixed in 7.5.0 |
CVE-2024-3635 |
WPScan | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Media Grid Widget |
≤ 4.10.52 |
CVE-2024-8681 |
Wordfence | |
| 6.4 Medium | ProfileGrid – User Profiles, Groups and Communities | Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.9.3.2 |
CVE-2024-8861 |
Wordfence | |
| 6.5 Medium | Product Carousel Slider & Grid Ultimate for WooCommerce | Local File Inclusion Authenticated Local File Inclusion |
≤ 1.9.10 Fixed in 1.10.0 |
CVE-2024-44048 |
Patchstack | |
| 7.5 High | Justified Image Grid | Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed |
≤ 4.6.1 Fixed in 4.7 |
CVE-2024-43989 |
Patchstack | |
| 8.8 High | Post Grid and Gutenberg Blocks | Privilege Escalation Authenticated (Subscriber+) Privilege Escalation |
2.2.87 – 2.2.90 |
CVE-2024-8253 |
Wordfence | |
| 8.2 High | SendGrid | SQL Injection No login needed |
≤ 1.4 |
CVE-2024-43965 |
Patchstack | |
| 4.3 Medium | The Post Grid | Information Disclosure Authenticated (Contributor+) Information Disclosure |
≤ 7.7.11 |
CVE-2024-7418 |
Wordfence | |
| 9.8 Critical | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 2.0.3 |
CVE-2024-8030 |
Wordfence | |
| 6.4 Medium | 140+ Widgets | Xpro Addons For Elementor – FREE | Cross-Site Scripting FREE <= 1.4.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Grid Widget |
≤ 1.4.4.3 |
CVE-2024-7791 |
Wordfence | |
| 6.4 Medium | Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | Cross-Site Scripting Logo Carousel, Logo Slider & Logo Grid <= 1.4.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload |
≤ 1.4.1 |
CVE-2024-8046 |
Wordfence | |
| 9.8 Critical | Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | PHP Object Injection Unauthenticated PHP Object Injection No login needed |
≤ 1.6.4 |
CVE-2024-5335 |
Wordfence | |
| 5.3 Medium | Void Elementor Post Grid Addon for Elementor Page builder | Local File Inclusion |
≤ 2.3 Fixed in 2.4 |
CVE-2024-43281 |
Patchstack | |
| 8.5 High | JetGridBuilder | Local File Inclusion |
≤ 1.1.2 Fixed in 1.1.3 |
CVE-2024-43221 |
Patchstack | |
| 6.5 Medium | Custom Layouts – Post + Product grids made easy | Cross-Site Scripting Post + Product grids made easy plugin <= 1.4.11 - Cross Site Scripting (XSS) |
≤ 1.4.11 Fixed in 1.4.12 |
CVE-2024-43305 |
Patchstack | |
| 6.5 Medium | Ultimate Store Kit Elementor Addons | Cross-Site Scripting |
≤ 1.6.4 Fixed in 2.0.0 |
CVE-2024-43342 |
Patchstack | |
| 6.4 Medium | Gutenberg Blocks, Page Builder – ComboBlocks | Cross-Site Scripting ComboBlocks <= 2.2.87 - Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Block |
≤ 2.2.84 |
CVE-2024-7588 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Gallery and Countdown Widgets |
≤ 5.7.2 |
CVE-2024-7247 |
Wordfence | |
| 6.5 Medium | ComboBlocks | Cross-Site Scripting |
≤ 2.2.86 Fixed in 2.2.87 |
CVE-2024-43155 |
Patchstack | |
| 7.1 High | Post Grid Master | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.4.10 Fixed in 3.4.11 |
CVE-2024-43156 |
Patchstack | |
| 6.5 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Path Traversal Authenticated (Contributor+) Arbitrary File Read |
≤ 5.7.2 |
CVE-2024-4359 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title_tag |
≤ 5.7.6 |
CVE-2024-4360 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-4643 |
Wordfence | |
| 6.5 Medium | Filter & Grids | Cross-Site Scripting |
≤ 2.9.2 Fixed in 2.9.3 |
CVE-2024-39665 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.85 - Authenticated (Contributor+) Stored Cross-Site Scripting via redirectURL Parameter of Date Countdown Widget |
≤ 2.2.85 |
CVE-2024-6346 |
Wordfence | |
| 6.4 Medium | SiteOrigin Widgets Bundle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Image Grid widget |
≤ 1.62.2 |
CVE-2024-5901 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Magazine Grid/Slider Widget |
≤ 1.3.980 |
CVE-2024-5818 |
Wordfence | |
| 6.4 Medium | Post and Page Builder by BoldGrid – Visual Drag and Drop Editor | Cross-Site Scripting Visual Drag and Drop Editor <= 1.26.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via File Upload |
≤ 1.26.6 |
CVE-2024-6848 |
Wordfence | |
| 6.5 Medium | FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor | Cross-Site Scripting |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2024-38686 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.5 |
CVE-2024-5555 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.6.11 |
CVE-2024-5554 |
Wordfence | |
| 9.8 Critical | Filter & Grids | Local File Inclusion Unauthenticated LFI No login needed |
< 2.8.33 Fixed in 2.8.33 |
CVE-2024-6164 |
WPScan | |
| 6.4 Medium | Premium Portfolio Features for Phlox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ' Grid Portfolios' |
≤ 2.3.2 |
CVE-2024-3587 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.