WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,001–25,050 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 501 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.5 High Consulting Elementor Widgets Plugin Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37092 Patchstack
9.9 Critical Consulting Elementor Widgets Plugin Remote Code Execution ≤ 1.3.0, ≤ 1.2.2 Fixed in 1.3.1 CVE-2024-37091 Patchstack
9.0 Critical Consulting Elementor Widgets Plugin Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-37089 Patchstack
6.1 Medium SEOPress Plugin wp-seopress Open Redirect Contributor+ Open Redirect No login needed < 7.8 Fixed in 7.8 CVE-2024-4900 WPScan
5.0 Medium SEOPress Plugin wp-seopress Cross-Site Scripting Contributor+ Stored XSS No login needed < 7.8 Fixed in 7.8 CVE-2024-4899 WPScan
7.2 High UberMenu Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 3.8.3 CVE-2024-3593 Wordfence
6.3 Medium ARMember Premium Plugin Cross-Site Request Forgery Cross-Site Request Forgery via multiple functions No login needed ≤ 6.7 CVE-2024-5596 Wordfence
4.3 Medium Bricks Builder Plugin Broken Access Control Insecure Direct Object Reference ≤ 1.9.8 CVE-2024-4874 Wordfence
6.4 Medium Mosaic Theme mosaic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Shortcode ≤ 1.7.1 CVE-2024-5965 Wordfence
6.4 Medium Grey Opaque Theme grey-opaque Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Download-Button Shortcode ≤ 2.0.1 CVE-2024-5966 Wordfence
6.4 Medium Table Addons for Elementor Plugin table-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via _id Parameter ≤ 2.1.2 CVE-2024-4313 Wordfence
7.2 High Appointment Booking and Online Scheduling Plugin meeting-scheduler-by-vcita Broken Access Control Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5791 Wordfence
6.4 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets ≤ 2.10.34 CVE-2024-2484 Wordfence
6.4 Medium Flatsome | Multi-Purpose Responsive WooCommerce Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.18.7 CVE-2024-5346 Wordfence
6.5 Medium Sparkle Demo Importer Plugin sparkle-demo-importer Broken Access Control Missing Authorization to Authorized(Subscriber+) Post/Pages/Attachements Deletion and Demo Data Import ≤ 1.4.7 CVE-2024-6120 Wordfence
6.5 Medium Word Balloon Plugin word-balloon Local File Inclusion ≤ 4.21.1 Fixed in 4.22.0 CVE-2024-35781 Patchstack
6.5 Medium Slideshow SE Plugin slideshow-se Local File Inclusion Auth. Limited Local File Inclusion ≤ 2.5.17 Fixed in 2.5.18 CVE-2024-35778 Patchstack
9.1 Critical Squeeze Plugin squeeze Arbitrary File Upload ≤ 1.4 Fixed in 1.4.1 CVE-2024-35767 Patchstack
9.8 Critical JupiterX Core Plugin Privilege Escalation Unauthenticated Account Takeover No login needed ≤ 3.3.8 Fixed in 3.4.3 CVE-2023-38389 Patchstack
3.7 Low Solid Security Plugin better-wp-security Denial of Service IP Spoofing Leading to Denial of Service No login needed ≤ 9.3.1 Fixed in 9.3.2 CVE-2022-44593 Patchstack
5.3 Medium WP 2FA Plugin wp-2fa Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.6.3 Fixed in 2.6.4 CVE-2022-44587 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Content Injection Auth. HTML Injection ≤ 2.0.9 Fixed in 2.1.0 CVE-2022-38055 Patchstack
5.4 Medium Uncanny Automator Pro Plugin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) Leading to License Settings Reset No login needed ≤ 5.3 CVE-2024-37118 Patchstack
4.3 Medium Digital Newspaper Theme digital-newspaper Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-37198 Patchstack
8.3 High Ali2Woo Lite Plugin ali2woo-lite Cross-Site Request Forgery CSRF to PHP Object Injection No login needed ≤ 3.3.5 CVE-2024-37212 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.9.7 Fixed in 4.9.8 CVE-2024-37227 Patchstack
4.3 Medium Book Landing Page Theme book-landing-page Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2024-37230 Patchstack
4.3 Medium EmbedPress Plugin embedpress Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2023-51375 Patchstack
6.5 Medium WordPress Form Builder Plugin – Gutenberg Forms Plugin forms-gutenberg Broken Access Control Auth. Broken Access Control ≤ 2.2.8.3 Fixed in 2.2.9 CVE-2022-45803 Patchstack
8.8 High WP Tools Plugin wptools Broken Access Control Auth. Broken Access Control ≤ 3.41 Fixed in 3.43 CVE-2022-43453 Patchstack
4.3 Medium Vimeography: Vimeo Video Gallery Plugin vimeography Cross-Site Request Forgery No login needed ≤ 2.4.1 Fixed in 2.4.2 CVE-2024-35770 Patchstack
4.3 Medium Customizr Theme customizr Cross-Site Request Forgery No login needed ≤ 4.4.21 Fixed in 4.4.22 CVE-2024-35771 Patchstack
4.3 Medium Hueman Theme hueman Cross-Site Request Forgery No login needed ≤ 3.7.24 Fixed in 3.7.25 CVE-2024-35772 Patchstack
5.3 Medium phpinfo() WP Plugin phpinfo-wp Information Disclosure Unauthenticated Data Exposure No login needed ≤ 5.0 CVE-2024-35776 Patchstack
5.3 Medium Event Management Tickets Booking Plugin event-monster Information Disclosure Sensitive Data Exposure No login needed ≤ 1.4.0 CVE-2024-5059 Patchstack
5.9 Medium Easy Age Verify Plugin easy-age-verify Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-35757 Patchstack
6.5 Medium Interface Theme interface Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2024-35758 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35759 Patchstack
5.9 Medium WP Job Portal Plugin wp-job-portal Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-35760 Patchstack
6.5 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-35761 Patchstack
6.5 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting ≤ 1.2.4 Fixed in 1.2.5 CVE-2024-35762 Patchstack
6.5 Medium Excellent Theme excellent Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-35763 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.4.4 Fixed in 4.4.5 CVE-2024-35764 Patchstack
7.1 High WPPizza Plugin wppizza Cross-Site Scripting A Restaurant Plugin plugin <= 3.18.13 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.18.13 Fixed in 3.18.14 CVE-2024-35766 Patchstack
5.9 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting ≤ 2.1.22 CVE-2024-35768 Patchstack
5.9 Medium Slideshow SE Plugin slideshow-se Cross-Site Scripting ≤ 2.5.17 CVE-2024-35769 Patchstack
6.5 Medium DImage 360 Plugin dimage-360 Cross-Site Scripting ≤ 2.0 CVE-2024-35774 Patchstack
6.5 Medium Page Builder: Live Composer Plugin live-composer-page-builder Cross-Site Scripting Contributor+ Shortcode Cross Site Scripting (XSS) ≤ 1.5.42 CVE-2024-35779 Patchstack
6.5 Medium Typing Text Plugin typing-text Cross-Site Scripting ≤ 1.2.5 Fixed in 1.2.6 CVE-2024-5058 Patchstack
9.8 Critical Themify - WooCommerce Product Filter Plugin themify-wc-product-filter SQL Injection WooCommerce Product Filter <= 1.4.9 - Unauthenticated SQL Injection via conditions Parameter No login needed ≤ 1.4.9 CVE-2024-6027 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only