WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,051–25,100 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 502 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Appointment Booking and Online Scheduling Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.4.2 CVE-2024-5859 Wordfence
6.4 Medium WP SVG Images Plugin wp-svg-images Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 4.3 CVE-2024-5945 Wordfence
4.4 Medium Amelia Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1.5, ≤ 7.5.1 CVE-2024-6225 Wordfence
6.4 Medium Branda – White Label WordPress, Custom Login Page Customizer Plugin branda-white-labeling Cross-Site Scripting White Label WordPress, Custom Login Page Customizer <= 3.4.17 - Authenticated (Author+) Stored Cross-Site Scripting via SVG Upload ≤ 3.4.17 CVE-2024-5191 Wordfence
4.3 Medium User Profile Picture Plugin metronet-profile-picture Broken Access Control Authenticated (Author+) Insecure Direct Object Reference to Profile Picture Update ≤ 2.6.1 CVE-2024-5639 Wordfence
6.1 Medium PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Plugin Cross-Site Scripting Contributor+ Stored XSS No login needed ≤ 1.7 CVE-2024-5448 WPScan
5.4 Medium PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.7 CVE-2024-5447 WPScan
6.1 Medium Widget Bundle Plugin Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 2.0.0 CVE-2024-4970 WPScan
4.3 Medium Widget Bundle Plugin Cross-Site Request Forgery Widget Disable/Enable via CSRF No login needed ≤ 2.0.0 CVE-2024-4969 WPScan
4.0 Medium Google CSE Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.7 CVE-2024-4755 WPScan
6.1 Medium Widget Bundle Plugin Cross-Site Scripting Unauthencated Reflected XSS No login needed ≤ 2.0.0 CVE-2024-4616 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Scripting Unauthenticated Stored XSS ≤ 1.0.1 CVE-2024-4477 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Request Forgery Log Clearing via CSRF ≤ 1.0.1 CVE-2024-4475 WPScan
4.3 Medium WP Logs Book Plugin Cross-Site Request Forgery Disable Logging via CSRF ≤ 1.0.1 CVE-2024-4474 WPScan
6.1 Medium CSSable Countdown Plugin Cross-Site Scripting Admin+ Stored XSS No login needed ≤ 1.5 CVE-2024-4384 WPScan
4.3 Medium CB (legacy) Plugin Cross-Site Request Forgery Code/Timeframe/Booking Deletion via CSRF No login needed ≤ 0.9.4.18 CVE-2024-4382 WPScan
4.8 Medium CB (legacy) Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 0.9.4.18 CVE-2024-4381 WPScan
6.1 Medium DOP Shortcodes Plugin Cross-Site Scripting Contributor+ Stored XSS via Shortcode No login needed ≤ 1.2 CVE-2024-4377 WPScan
9.8 Critical Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin email-subscribers SQL Injection Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin No login needed ≤ 5.7.23 CVE-2024-5756 Wordfence
5.3 Medium ConvertKit Plugin Broken Access Control Missing Authorization No login needed ≤ 2.4.9 CVE-2024-3961 Wordfence
8.8 High The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin Local File Inclusion Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.6 - Authenticated (Contributor+) Local File Inclusion ≤ 5.5.6 CVE-2024-5455 Wordfence
4.3 Medium Hide Dashboard Notifications Plugin wp-hide-backed-notices Broken Access Control Missing Authorization to Authenticated(Contributor+) Plugin Settings Modification ≤ 1.3 CVE-2024-1955 Wordfence
4.3 Medium Smush – Lazy Load Images, Optimize & Compress Images Plugin wp-smushit Broken Access Control Lazy Load Images, Optimize & Compress Images <= 3.16.4 - Missing Authorization to Resmush List Deletion ≤ 3.16.4 CVE-2023-3352 Wordfence
5.3 Medium WP Child Theme Generator Plugin wp-child-theme-generator Broken Access Control Missing Authorization to Unauthenticated Child Theme Creation/Activation No login needed ≤ 1.1.1 CVE-2024-3610 Wordfence
6.5 Medium License Manager for WooCommerce Plugin license-manager-for-woocommerce Information Disclosure Improper Authorization to Authenticated(Contributor+) Sensitive Information Exposure ≤ 3.0.6 CVE-2024-1639 Wordfence
8.8 High WP Blog Post Layouts Plugin wp-blog-post-layouts Local File Inclusion Authenticated (Contributor+) Local File Inlcusion ≤ 1.1.3 CVE-2024-5503 Wordfence
6.1 Medium The Plus Addons for Elementor Page Builder Plugin Cross-Site Scripting Reflected Cross-Site Scripting via WP Login and Register Widget No login needed ≤ 5.5.6 CVE-2024-5344 Wordfence
7.1 High Master Slider Plugin master-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.10.0 Fixed in 3.10.5 CVE-2024-37222 Patchstack
6.4 Medium Flatsome Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.18.7 CVE-2024-5156 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.5.4 CVE-2024-5036 Wordfence
9.8 Critical Shariff Wrapper Plugin shariff Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 4.6.13 CVE-2024-4098 Wordfence
6.5 Medium HTML5 Video Player Plugin html5-video-player SQL Injection Unauthenticated SQLi No login needed < 2.5.27 Fixed in 2.5.27 CVE-2024-5522 WPScan
5.4 Medium Responsive video embed Plugin responsive-video-embed Cross-Site Scripting Contributor+ Stored XSS No login needed < 0.5.1 Fixed in 0.5.1 CVE-2024-5475 WPScan
7.5 High Advanced Custom Fields Plugin Broken Access Control Contributor+ Custom Field Access No login needed < 6.3 Fixed in 6.3 CVE-2024-4565 WPScan
6.4 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget ≤ 1.1.38 CVE-2024-5686 Wordfence
6.5 Medium Depicter Plugin depicter Broken Access Control Authenticated (Contributor+) Arbitrary Nonce Generation ≤ 3.0.2 CVE-2024-4390 Wordfence
8.8 High Media Library Assistant Plugin media-library-assistant SQL Injection Authenticated (Contributor+) SQL Injection via order Parameter ≤ 3.16 CVE-2024-5605 Wordfence
8.8 High Custom Field Suite Plugin Remote Code Execution Authenticated (Contributor+) PHP Code Injection via Loop Custom Field ≤ 2.6.7 CVE-2024-3562 Wordfence
8.8 High Custom Field Suite Plugin custom-field-suite SQL Injection Authenticated (Contributor+) SQL Injection via Term Custom Field ≤ 2.6.7 CVE-2024-3561 Wordfence
6.4 Medium SEOPress – On-site SEO Plugin wp-seopress Cross-Site Scripting On-site SEO <= 7.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Social Image URL ≤ 7.9 CVE-2024-1168 Wordfence
6.5 Medium Materialis Theme materialis Broken Access Control Missing Authorization to Limited Arbitrary Options Update ≤ 1.1.24 CVE-2023-3204 Wordfence
6.4 Medium Custom Field Suite Plugin custom-field-suite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cfs[post_title] ≤ 2.6.7 CVE-2024-3558 Wordfence
7.1 High Export WP Page to Static HTML/CSS Plugin export-wp-page-to-static-html Open Redirect No login needed ≤ 2.2.2 CVE-2024-3597 Wordfence
10.0 Critical WP Hotel Booking Plugin wp-hotel-booking SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.1.0 CVE-2024-3605 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via layout_type and id Parameters ≤ 1.0.17 CVE-2024-4626 Wordfence
9.8 Critical Lifeline Donation Plugin lifeline-donation Authentication Bypass No login needed ≤ 1.2.6 CVE-2024-5432 Wordfence
6.5 Medium Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin youzify SQL Injection BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1.2.5 - Authenticated (Contributor+) SQL Injection ≤ 1.2.5 CVE-2024-4742 Wordfence
5.4 Medium Wheel of Life: Coaching and Assessment Tool for Life Coach Plugin wheel-of-life Broken Access Control Missing Authorization on Several AJAX Endpoints ≤ 1.1.7 CVE-2024-3627 Wordfence
4.3 Medium Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer Plugin promolayer-popup-builder Broken Access Control Promolayer <= 1.1.0 - Missing Authorization ≤ 1.1.0 CVE-2024-3602 Wordfence
7.1 High Slider Revolution Plugin Broken Access Control Unauthenticated Broken Access Control No login needed < 6.7.0 Fixed in 6.7.0 CVE-2024-34444 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only