WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,551–25,600 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 512 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Formula Theme formula Cross-Site Scripting Reflected Cross-Site Scripting via quality_customizer_notify_dismiss_action No login needed ≤ 0.5.1 CVE-2024-5613 Wordfence
6.1 Medium Formula Theme formula Cross-Site Scripting Reflected Cross-Site Scripting via ti_customizer_notify_dismiss_recommended_plugins No login needed ≤ 0.5.1 CVE-2024-5638 Wordfence
6.3 Medium Minimal Coming Soon – Coming Soon Page Plugin minimal-coming-soon-maintenance-mode Broken Access Control Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change ≤ 2.38 CVE-2024-5087 Wordfence
4.3 Medium WP Reset Plugin wp-reset Broken Access Control Missing Authorization to License Key Modification ≤ 2.01 CVE-2024-4661 Wordfence
4.2 Medium WP Force SSL & HTTPS SSL Redirect Plugin wp-force-ssl Broken Access Control Missing Authorization to Settings Update ≤ 1.66 CVE-2024-5770 Wordfence
8.8 High PowerPack Pro for Elementor Plugin Privilege Escalation Authenticated (Contributor+) Privilege Escalation ≤ 2.10.17 CVE-2024-3668 Wordfence
6.4 Medium Cards for Beaver Builder Plugin bb-bootstrap-cards Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Cards Widget ≤ 1.1.3 CVE-2024-5663 Wordfence
6.5 Medium Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification No login needed ≤ 2.0.6.1 CVE-2024-5382 Wordfence
7.5 High FileOrganizer Plugin fileorganizer Information Disclosure Sensitive Information Exposure via Directory Listing No login needed ≤ 1.0.7 CVE-2024-5599 Wordfence
7.2 High Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Plugin master-addons Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed ≤ 2.0.6.1 CVE-2024-5542 Wordfence
4.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion ≤ 2.7.1 CVE-2024-5438 Wordfence
7.5 High Market Exporter Plugin market-exporter Broken Access Control Missing Authorization to Arbitrary File Deletion No login needed ≤ 2.0.19 CVE-2024-5637 Wordfence
6.4 Medium Envo Extra Plugin envo-extra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 1.8.23 CVE-2024-5645 Wordfence
6.8 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Path Traversal Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function ≤ 1.8.23 CVE-2024-5481 Wordfence
6.4 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG ≤ 1.8.23 CVE-2024-5426 Wordfence
4.7 Medium WS Form LITE Plugin ws-form Content Injection Unauthenticated CSV Injection No login needed ≤ 1.9.217 CVE-2023-5424 Wordfence
6.4 Medium One Page Express Companion Plugin one-page-express-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via one_page_express_contact_form Shortcode ≤ 1.6.37 CVE-2024-4703 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.976 CVE-2024-4488 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads ≤ 1.3.976 CVE-2024-4489 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode ≤ 1.0.276 CVE-2024-4451 Wordfence
5.4 Medium WP Stacker Plugin wp-stacker Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.8.5 CVE-2024-5003 WPScan
5.4 Medium WP Backpack Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 2.1 CVE-2024-4756 WPScan
4.8 Medium ArForms Plugin Cross-Site Scripting Admin+ Stored XSS < 6.6 Fixed in 6.6 CVE-2024-4621 WPScan
9.8 Critical ArForms Plugin Remote Code Execution Unauthenticated RCE No login needed < 6.6 Fixed in 6.6 CVE-2024-4620 WPScan
5.4 Medium Logo Slider Plugin gs-logo-slider Cross-Site Scripting Contributor+ Stored XSS < 4.0.0 Fixed in 4.0.0 CVE-2024-3288 WPScan
9.9 Critical Quiz And Survey Master – Best Quiz, Exam and Survey Plugin quiz-master-next SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection ≤ 9.0.1 CVE-2024-3592 Wordfence
4.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control Authenticated(Contributor+) Improper Authorization to Views Modification ≤ 3.1.12 CVE-2023-6491 Wordfence
6.4 Medium TablePress – Tables in WordPress made easy Plugin tablepress Server-Side Request Forgery Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind ≤ 2.3.1 CVE-2024-4354 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute ≤ 2.2.80 CVE-2024-4042 Wordfence
7.2 High Tutor LMS – eLearning and online course solution Plugin tutor SQL Injection eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection ≤ 2.7.1 CVE-2024-4902 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pacific Widget ≤ 3.14.7 CVE-2024-5640 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget ≤ 5.8.15 CVE-2024-5612 Wordfence
6.5 Medium Music Store - WordPress eCommerce Plugin music-store SQL Injection WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitr… prior to 1.1.14 CVE-2024-36082 jpcert
6.4 Medium WP jQuery Lightbox Plugin wp-jquery-lightbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Attribute ≤ 1.5.4 CVE-2024-5425 Wordfence
6.4 Medium Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks Plugin post-grid Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.80 CVE-2024-1988 Wordfence
7.5 High Qi Addons For Elementor Plugin qi-addons-for-elementor Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.7.2 CVE-2024-4887 Wordfence
5.4 Medium GDPR CCPA Compliance & Cookie Consent Banner Plugin ninja-gdpr-compliance Broken Access Control Missing Authorization to Settings Update and Stored Cross-Site Scripting ≤ 2.7.0 CVE-2024-5607 Wordfence
5.4 Medium WP Mobile Menu – The Mobile-Friendly Responsive Menu Plugin mobile-menu Cross-Site Scripting The Mobile-Friendly Responsive Menu <= 2.8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Alt ≤ 2.8.4.2 CVE-2024-3987 Wordfence
6.4 Medium Clever Fox Plugin clever-fox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 25.2.0 CVE-2024-1768 Wordfence
5.4 Medium Clever Fox – One Click Website Importer by Nayra Themes Plugin clever-fox Broken Access Control One Click Website Importer by Nayra Themes <= 25.2.0 - Missing Authorization to arbitrary theme activation via clever-fox-activate-theme ≤ 25.2.0 CVE-2023-6876 Wordfence
4.3 Medium WooCommerce Tools Plugin woo-tools Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Module Deactivation ≤ 1.2.9 CVE-2024-1689 Wordfence
4.3 Medium Wbcom Designs - Custom Font Uploader Plugin custom-font-uploader Broken Access Control Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion ≤ 2.3.4 CVE-2024-5489 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.22 CVE-2024-5188 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.276 CVE-2024-5038 Wordfence
8.8 High Unlimited Elements For Elementor (Free Widgets, Addons, Templates) Plugin unlimited-elements-for-elementor SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter ≤ 1.5.109 CVE-2024-5329 Wordfence
6.4 Medium MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution Plugin dc-woocommerce-multi-vendor Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter ≤ 4.1.11 CVE-2024-5259 Wordfence
6.4 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.2.9 CVE-2024-5221 Wordfence
4.3 Medium Login/Signup Popup ( Inline Form + Woocommerce ) Plugin easy-login-woocommerce Broken Access Control Missing Authorization to Arbitrary Options Exposure 2.7.1 – 2.7.2 CVE-2024-5665 Wordfence
6.4 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.0 CVE-2024-5152 Wordfence
5.3 Medium BuddyPress Members Only Plugin buddypress-members-only Broken Access Control Improper Access Control to Sensitive Information Exposure via REST API No login needed ≤ 3.4.8 CVE-2024-0972 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only