WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 25,551–25,600 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | Formula | Cross-Site Scripting Reflected Cross-Site Scripting via quality_customizer_notify_dismiss_action No login needed |
≤ 0.5.1 |
CVE-2024-5613 |
Wordfence | |
| 6.1 Medium | Formula | Cross-Site Scripting Reflected Cross-Site Scripting via ti_customizer_notify_dismiss_recommended_plugins No login needed |
≤ 0.5.1 |
CVE-2024-5638 |
Wordfence | |
| 6.3 Medium | Minimal Coming Soon – Coming Soon Page | Broken Access Control Coming Soon Page <= 2.38 - Missing Authorization to Limited Settings Change |
≤ 2.38 |
CVE-2024-5087 |
Wordfence | |
| 4.3 Medium | WP Reset | Broken Access Control Missing Authorization to License Key Modification |
≤ 2.01 |
CVE-2024-4661 |
Wordfence | |
| 4.2 Medium | WP Force SSL & HTTPS SSL Redirect | Broken Access Control Missing Authorization to Settings Update |
≤ 1.66 |
CVE-2024-5770 |
Wordfence | |
| 8.8 High | PowerPack Pro for Elementor | Privilege Escalation Authenticated (Contributor+) Privilege Escalation |
≤ 2.10.17 |
CVE-2024-3668 |
Wordfence | |
| 6.4 Medium | Cards for Beaver Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Cards Widget |
≤ 1.1.3 |
CVE-2024-5663 |
Wordfence | |
| 6.5 Medium | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to MA Template Creation or Modification No login needed |
≤ 2.0.6.1 |
CVE-2024-5382 |
Wordfence | |
| 7.5 High | FileOrganizer | Information Disclosure Sensitive Information Exposure via Directory Listing No login needed |
≤ 1.0.7 |
CVE-2024-5599 |
Wordfence | |
| 7.2 High | Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor | Broken Access Control Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor <= 2.0.6.1 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting via Navigation Menu Widget No login needed |
≤ 2.0.6.1 |
CVE-2024-5542 |
Wordfence | |
| 4.3 Medium | Tutor LMS – eLearning and online course solution | Broken Access Control eLearning and online course solution <= 2.7.1 - Authenticated (Instructor+) Insecure Direct Object Reference to Arbitrary Quiz Attempt Deletion |
≤ 2.7.1 |
CVE-2024-5438 |
Wordfence | |
| 7.5 High | Market Exporter | Broken Access Control Missing Authorization to Arbitrary File Deletion No login needed |
≤ 2.0.19 |
CVE-2024-5637 |
Wordfence | |
| 6.4 Medium | Envo Extra | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget |
≤ 1.8.23 |
CVE-2024-5645 |
Wordfence | |
| 6.8 Medium | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | Path Traversal Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Path Traversal via esc_dir Function |
≤ 1.8.23 |
CVE-2024-5481 |
Wordfence | |
| 6.4 Medium | Photo Gallery by 10Web – Mobile-Friendly Image Gallery | Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.23 - Authenticated (Contributor+) Stored Cross-Site Scripting via Zipped SVG |
≤ 1.8.23 |
CVE-2024-5426 |
Wordfence | |
| 4.7 Medium | WS Form LITE | Content Injection Unauthenticated CSV Injection No login needed |
≤ 1.9.217 |
CVE-2023-5424 |
Wordfence | |
| 6.4 Medium | One Page Express Companion | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via one_page_express_contact_form Shortcode |
≤ 1.6.37 |
CVE-2024-4703 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.976 |
CVE-2024-4488 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG Uploads |
≤ 1.3.976 |
CVE-2024-4489 |
Wordfence | |
| 6.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_video_player Shortcode |
≤ 1.0.276 |
CVE-2024-4451 |
Wordfence | |
| 5.4 Medium | WP Stacker | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 1.8.5 |
CVE-2024-5003 |
WPScan | |
| 5.4 Medium | WP Backpack | Cross-Site Scripting Admin+ Stored XSS |
≤ 2.1 |
CVE-2024-4756 |
WPScan | |
| 4.8 Medium | ArForms | Cross-Site Scripting Admin+ Stored XSS |
< 6.6 Fixed in 6.6 |
CVE-2024-4621 |
WPScan | |
| 9.8 Critical | ArForms | Remote Code Execution Unauthenticated RCE No login needed |
< 6.6 Fixed in 6.6 |
CVE-2024-4620 |
WPScan | |
| 5.4 Medium | Logo Slider | Cross-Site Scripting Contributor+ Stored XSS |
< 4.0.0 Fixed in 4.0.0 |
CVE-2024-3288 |
WPScan | |
| 9.9 Critical | Quiz And Survey Master – Best Quiz, Exam and Survey | SQL Injection Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (Contributor+) SQL Injection |
≤ 9.0.1 |
CVE-2024-3592 |
Wordfence | |
| 4.3 Medium | Strong Testimonials | Broken Access Control Authenticated(Contributor+) Improper Authorization to Views Modification |
≤ 3.1.12 |
CVE-2023-6491 |
Wordfence | |
| 6.4 Medium | TablePress – Tables in WordPress made easy | Server-Side Request Forgery Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request Forgery via DNS Rebind |
≤ 2.3.1 |
CVE-2024-4354 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute |
≤ 2.2.80 |
CVE-2024-4042 |
Wordfence | |
| 7.2 High | Tutor LMS – eLearning and online course solution | SQL Injection eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injection |
≤ 2.7.1 |
CVE-2024-4902 |
Wordfence | |
| 6.4 Medium | Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) | Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Pacific Widget |
≤ 3.14.7 |
CVE-2024-5640 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.8.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Lightbox and Modal Widget |
≤ 5.8.15 |
CVE-2024-5612 |
Wordfence | |
| 6.5 Medium | Music Store - WordPress eCommerce | SQL Injection WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitr… |
prior to 1.1.14 |
CVE-2024-36082 |
jpcert | |
| 6.4 Medium | WP jQuery Lightbox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Attribute |
≤ 1.5.4 |
CVE-2024-5425 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-1988 |
Wordfence | |
| 7.5 High | Qi Addons For Elementor | Local File Inclusion Authenticated (Contributor+) Local File Inclusion |
≤ 1.7.2 |
CVE-2024-4887 |
Wordfence | |
| 5.4 Medium | GDPR CCPA Compliance & Cookie Consent Banner | Broken Access Control Missing Authorization to Settings Update and Stored Cross-Site Scripting |
≤ 2.7.0 |
CVE-2024-5607 |
Wordfence | |
| 5.4 Medium | WP Mobile Menu – The Mobile-Friendly Responsive Menu | Cross-Site Scripting The Mobile-Friendly Responsive Menu <= 2.8.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Alt |
≤ 2.8.4.2 |
CVE-2024-3987 |
Wordfence | |
| 6.4 Medium | Clever Fox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 25.2.0 |
CVE-2024-1768 |
Wordfence | |
| 5.4 Medium | Clever Fox – One Click Website Importer by Nayra Themes | Broken Access Control One Click Website Importer by Nayra Themes <= 25.2.0 - Missing Authorization to arbitrary theme activation via clever-fox-activate-theme |
≤ 25.2.0 |
CVE-2023-6876 |
Wordfence | |
| 4.3 Medium | WooCommerce Tools | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Module Deactivation |
≤ 1.2.9 |
CVE-2024-1689 |
Wordfence | |
| 4.3 Medium | Wbcom Designs - Custom Font Uploader | Broken Access Control Custom Font Uploader <= 2.3.4 - Missing Authorization to Font Deletion |
≤ 2.3.4 |
CVE-2024-5489 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.22 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.9.22 |
CVE-2024-5188 |
Wordfence | |
| 6.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.276 |
CVE-2024-5038 |
Wordfence | |
| 8.8 High | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | SQL Injection Authenticated (Contributor+) Blind SQL Injection via data[addonID] Parameter |
≤ 1.5.109 |
CVE-2024-5329 |
Wordfence | |
| 6.4 Medium | MultiVendorX Marketplace – WooCommerce MultiVendor Marketplace Solution | Cross-Site Scripting WooCommerce MultiVendor Marketplace Solution <= 4.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via hover_animation Parameter |
≤ 4.1.11 |
CVE-2024-5259 |
Wordfence | |
| 6.4 Medium | Qi Blocks | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 1.2.9 |
CVE-2024-5221 |
Wordfence | |
| 4.3 Medium | Login/Signup Popup ( Inline Form + Woocommerce ) | Broken Access Control Missing Authorization to Arbitrary Options Exposure |
2.7.1 – 2.7.2 |
CVE-2024-5665 |
Wordfence | |
| 6.4 Medium | ElementsReady Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.1.0 |
CVE-2024-5152 |
Wordfence | |
| 5.3 Medium | BuddyPress Members Only | Broken Access Control Improper Access Control to Sensitive Information Exposure via REST API No login needed |
≤ 3.4.8 |
CVE-2024-0972 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.