WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,151–25,200 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 504 of 1
Severity Component Vulnerability Affected versions Published CVE Source
9.9 Critical Image Optimizer, Resizer and CDN – Sirv Plugin sirv Arbitrary File Upload Sirv <= 7.2.6 - Authenticated (Contributor+) Arbitrary File Upload ≤ 7.2.6 CVE-2024-5853 Wordfence
7.5 High WP Magazine Modules Lite Plugin wp-magazine-modules-lite Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.1.2 CVE-2024-5574 Wordfence
6.4 Medium Ultimate Blocks – WordPress Blocks Plugin Cross-Site Scripting WordPress Blocks Plugin <= 3.0.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via metabox ≤ 3.1.0 CVE-2023-6692 Wordfence
8.8 High Photo Gallery, Images, Slider in Rbs Image Gallery Plugin robo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Post Creation and Limited Data Loss No login needed ≤ 3.2.19 CVE-2024-5343 Wordfence
9.8 Critical Salon Booking System Plugin salon-booking-system Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 10.2 CVE-2024-3229 Wordfence
6.4 Medium MIMO Woocommerce Order Tracking Plugin mimo-woocommerce-order-tracking Broken Access Control Missing Authorization to Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2024-5768 Wordfence
6.4 Medium Blogmentor – Blog Layouts for Elementor Plugin blogmentor Cross-Site Scripting Blog Layouts for Elementor <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagination_style Parameter ≤ 1.5 CVE-2024-4623 Wordfence
8.8 High AliExpress Dropshipping with AliNext Lite Plugin ali2woo-lite Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 3.3.5 CVE-2024-2381 Wordfence
8.8 High Photo Video Gallery Master Plugin photo-video-gallery-master PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.5.3 CVE-2024-5724 Wordfence
5.4 Medium Universal Slider Plugin fusion-slider PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.6.5 CVE-2024-5649 Wordfence
4.3 Medium Replace Image Plugin replace-image Broken Access Control Insecure Direct Object Reference ≤ 1.1.10 CVE-2024-4873 Wordfence
6.4 Medium EmbedSocial – Social Media Feeds, Reviews and Galleries Plugin embedalbum-pro Cross-Site Scripting Social Media Feeds, Reviews and Galleries <= 1.1.29 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.29 CVE-2024-3984 Wordfence
6.4 Medium OSM Map Widget for Elementor Plugin osm-map-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.2.2 CVE-2024-4663 Wordfence
4.3 Medium Custom Product List Table Plugin custom-product-list-table Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2024-4541 Wordfence
9.3 Critical WordPress Picture / Portfolio / Media Gallery Plugin nimble-portfolio Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 3.0.1 CVE-2024-5021 Wordfence
6.3 Medium AliExpress Dropshipping with AliNext Lite Plugin ali2woo-lite Broken Access Control Missing Authorization via Several Functions ≤ 3.3.6 CVE-2024-4450 Wordfence
8.1 High Login with phone number Plugin login-with-phone-number Broken Access Control Insecure Password Reset Mechanism No login needed ≤ 1.7.34 CVE-2024-6125 Wordfence
6.4 Medium MaxGalleria Plugin maxgalleria Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via maxgallery_thumb Shortcode ≤ 6.4.4 CVE-2024-5970 Wordfence
6.4 Medium Divi Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.25.1 CVE-2024-5533 Wordfence
4.8 Medium Expert Invoice Plugin Cross-Site Scripting Expert Invoice <= 1.0.2 -Admin+ Stored XSS ≤ 1.0.2 CVE-2024-5172 WPScan
5.4 Medium Simple Share Buttons Adder Plugin simple-share-buttons-adder Cross-Site Scripting Admin+ Stored XSS < 8.5.1 Fixed in 8.5.1 CVE-2024-4094 WPScan
6.1 Medium FooBox (Free and Premium) Plugin Cross-Site Scripting Admin+ Stored XSS No login needed < 2.7.28 Fixed in 2.7.28 CVE-2024-3276 WPScan
7.4 High Business Directory Plugin business-directory-plugin Content Injection Authenticated (Author+) CSV Injection ≤ 6.4.3 CVE-2023-5527 Wordfence
4.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion ≤ 3.5.2.8 CVE-2024-5860 Wordfence
5.3 Medium Ibtana - WordPress Website Builder Plugin ibtana-visual-editor Broken Access Control WordPress Website Builder <= 1.2.3.3 - Unauthenticated reCAPTCHA Settings Update No login needed ≤ 1.2.3.3 CVE-2024-5541 Wordfence
6.5 Medium Scheduling Plugin – Online Booking Plugin calendar-booking Broken Access Control Online Booking for WordPress <= 3.5.10 - Missing Authorization to Unauthenticated Service Disconnection No login needed ≤ 3.5.10 CVE-2024-1634 Wordfence
6.4 Medium PDF Viewer for Elementor Plugin pdf-viewer-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via render ≤ 2.9.3 CVE-2024-0845 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.9.10 CVE-2024-4375 Wordfence
6.8 Medium PostX Plugin Cross-Site Scripting Contributor+ Stored XSS < 4.1.0 Fixed in 4.1.0 CVE-2024-4305 WPScan
5.4 Medium Easy Notify Lite Plugin easy-notify-lite Cross-Site Scripting Contributor+ Stored XSS < 1.1.33 Fixed in 1.1.33 CVE-2024-3236 WPScan
6.4 Medium Stratum – Elementor Widgets Plugin stratum Cross-Site Scripting Elementor Widgets <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.4.1 CVE-2024-5611 Wordfence
6.4 Medium Collapse-O-Matic Plugin jquery-collapse-o-matic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.8.5.8 CVE-2024-4095 Wordfence
6.4 Medium Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Authenticated (Contributor+) Arbitrary File Inclusion via Shortcode ≤ 1.3.13 CVE-2024-4551 Wordfence
9.8 Critical Video Gallery – YouTube Playlist, Channel Gallery by YotuWP Plugin yotuwp-easy-youtube-embed Local File Inclusion YouTube Playlist, Channel Gallery by YotuWP <= 1.3.13 - Unauthenticated Local File Inclusion No login needed ≤ 1.3.13 CVE-2024-4258 Wordfence
6.4 Medium Shariff Wrapper Plugin shariff Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.6.13 CVE-2024-2695 Wordfence
4.3 Medium Infographic Maker iList Plugin infographic-and-list-builder-ilist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Title Update ≤ 4.7.4 CVE-2024-5858 Wordfence
9.9 Critical Woody code snippets – Insert Header Footer Code, AdSense Ads Plugin insert-php Remote Code Execution Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code Execution ≤ 2.5.0 CVE-2024-3105 Wordfence
6.4 Medium Restaurant Menu and Food Ordering Plugin mp-restaurant-menu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.4.0 CVE-2024-1399 Wordfence
9.8 Critical WooCommerce - Social Login Plugin PHP Object Injection Social Login <= 2.6.2 - Unauthenticated PHP Object Injection No login needed ≤ 2.6.2 CVE-2024-5871 Wordfence
6.5 Medium WooCommerce - Social Login Plugin Other Social Login <= 2.6.2 - Email Verification due to Insufficient Randomness No login needed ≤ 2.6.2 CVE-2024-5868 Wordfence
7.1 High FooEvents for WooCommerce Plugin Arbitrary File Upload Improper Authorization to (Contributor+) Arbitrary File Upload ≤ 1.19.20 CVE-2024-6000 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via JKit - Tabs and JKit - Accordion Widgets ≤ 2.6.5 CVE-2024-4479 Wordfence
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
5.5 Medium Newspaper Theme Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta ≤ 12.6.5 CVE-2024-3815 Wordfence
8.8 High tagDiv Composer Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode ≤ 4.8 CVE-2024-3813 Wordfence
6.4 Medium ElementsKit Elementor addons and Templates Library Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Motion Text and Table Widgets ≤ 3.6.2 CVE-2024-5263 Wordfence
5.5 Medium tagDiv Composer Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Attachment Meta ≤ 4.8 CVE-2024-3814 Wordfence
7.4 High Popup Builder Plugin popup-builder Broken Access Control Missing Authorization in Multiple AJAX Actions ≤ 4.3.0 CVE-2024-2544 Wordfence
8.8 High Folders Pro Plugin folders Arbitrary File Upload Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload ≤ 3.0.2 CVE-2024-2024 Wordfence
4.3 Medium Folders Plugin folders Path Traversal Directory Traversal via handle_folders_file_upload ≤ 3.0, ≤ 3.0.2 CVE-2024-2023 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only