WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 25,751–25,800 of 29,211 vulnerabilities

Known WordPress vulnerabilities, page 516 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Admin Notices Manager Plugin admin-notices-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) User Email Retrieval ≤ 1.4.0 CVE-2024-1717 Wordfence
6.4 Medium tagDiv Composer Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via button Shortcode ≤ 4.8 CVE-2024-3888 Wordfence
9.8 Critical Social Login Lite For WooCommerce Plugin social-login-lite-for-woocommerce Authentication Bypass No login needed ≤ 1.6.0 CVE-2024-4552 Wordfence
7.2 High Frontend Registration – Contact Form 7 Plugin frontend-registration-contact-form-7 Privilege Escalation Contact Form 7 <= 5.1 - Authenticated (Editor+) Privilege Escalation ≤ 5.1 CVE-2024-4870 Wordfence
4.3 Medium CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.4.10 Fixed in 1.4.11 CVE-2023-28492 Patchstack
4.3 Medium CP Contact Form with Paypal Plugin cp-contact-form-with-paypal Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.3.34 Fixed in 1.3.35 CVE-2023-27460 Patchstack
3.7 Low Event Espresso 4 Decaf Plugin event-espresso-decaf Broken Access Control Bypass No login needed ≤ 4.10.44.decaf Fixed in 4.10.45.decaf CVE-2023-27437 Patchstack
4.3 Medium Calculated Fields Form Plugin calculated-fields-form Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.1.120 Fixed in 1.1.121 CVE-2023-26523 Patchstack
4.3 Medium Search in Place Plugin search-in-place Broken Access Control Missing Authorization Leading To Feedback Submission ≤ 1.0.104 Fixed in 1.0.105 CVE-2023-26521 Patchstack
3.7 Low Booking calendar, Appointment Booking System Plugin booking-calendar Other Bypass No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2023-24373 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email Spoofing No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23738 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Content Injection WordPress Gutenberg Blocks plugin <= 2.3.0 - Unauthenticated Email HTML Injection No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23735 Patchstack
5.3 Medium Spectra Plugin ultimate-addons-for-gutenberg Authentication Bypass WordPress Gutenberg Blocks plugin <= 2.3.0 - Captcha Bypass No login needed ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23730 Patchstack
4.3 Medium Integration for Contact Form 7 and Constant Contact Plugin cf7-constant-contact Cross-Site Request Forgery No login needed ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-35632 Patchstack
5.9 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Cross-Site Scripting ≤ 3.32.0 Fixed in 3.33.0 CVE-2024-34385 Patchstack
6.5 Medium ChaosTheory Theme chaostheory Cross-Site Scripting ≤ 1.3 Fixed in 1.3.2 CVE-2024-34766 Patchstack
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 2.8.7 Fixed in 2.8.8 CVE-2024-34767 Patchstack
6.5 Medium Elegant Blocks Plugin elegant-blocks Cross-Site Scripting Amazing Gutenberg Blocks plugin <= 1.7 - Cross Site Scripting (XSS) ≤ 1.7 CVE-2024-34769 Patchstack
6.5 Medium Popup Maker WP Plugin popup-maker-wp Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-34770 Patchstack
6.5 Medium Post Grid Elementor Addon Plugin post-grid-elementor-addon Cross-Site Scripting ≤ 2.0.16 Fixed in 2.0.17 CVE-2024-34789 Patchstack
5.9 Medium ImageMagick Sharpen Resized Images Theme imagemagick-sharpen-resized-images Cross-Site Scripting ≤ 1.1.7 CVE-2024-34790 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.0.9 Fixed in 1.2 CVE-2024-34791 Patchstack
5.9 Medium WP Next Post Navi Plugin wp-next-post-navi Cross-Site Scripting ≤ 1.8.3 CVE-2024-34793 Patchstack
7.1 High Tainacan Plugin tainacan Cross-Site Scripting No login needed ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34794 Patchstack
6.5 Medium Tainacan Plugin tainacan Cross-Site Scripting ≤ 0.21.3 Fixed in 0.21.4 CVE-2024-34795 Patchstack
5.9 Medium PopupAlly Plugin popupally Cross-Site Scripting ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-34796 Patchstack
5.9 Medium Simple Popup Manager Plugin simple-popup-manager Cross-Site Scripting ≤ 1.3.5 CVE-2024-34797 Patchstack
6.5 Medium Praison SEO Plugin seo-wordpress Cross-Site Scripting ≤ 4.0.15 Fixed in 4.0.16 CVE-2024-34801 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting No login needed ≤ 7.5.45.7212 Fixed in 7.5.46.7212 CVE-2024-35631 Patchstack
7.6 High WP TripAdvisor Review Slider Plugin wp-tripadvisor-review-slider SQL Injection ≤ 12.6 Fixed in 12.7 CVE-2024-35630 Patchstack
5.3 Medium Contact Form Widget Plugin new-contact-form-widget Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2024-34754 Patchstack
5.3 Medium Debug Log – Manger Tool Plugin debug-log-config-tool Information Disclosure Manger Tool plugin <= 1.4.5 - Sensitive Data Exposure No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2024-34798 Patchstack
4.3 Medium Fastly Plugin fastly Broken Access Control ≤ 1.2.25 Fixed in 1.2.26 CVE-2024-34803 Patchstack
4.4 Medium Blocksy Companion Plugin blocksy-companion Server-Side Request Forgery ≤ 2.0.42 Fixed in 2.0.43 CVE-2024-35633 Patchstack
4.4 Medium Ninja Tables Plugin ninja-tables Server-Side Request Forgery ≤ 5.0.9 Fixed in 5.0.10 CVE-2024-35635 Patchstack
4.4 Medium Church Admin Plugin church-admin Server-Side Request Forgery ≤ 4.3.6 Fixed in 4.4.0 CVE-2024-35637 Patchstack
4.3 Medium ActiveDEMAND Plugin activedemand Cross-Site Request Forgery No login needed ≤ 0.2.43 CVE-2024-35638 Patchstack
5.9 Medium Simple Spoiler Plugin simple-spoiler Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2024-35639 Patchstack
5.9 Medium Safety Exit Plugin safety-exit Cross-Site Scripting ≤ 1.7.0 Fixed in 1.7.1 CVE-2024-35640 Patchstack
5.9 Medium Just Writing Statistics Plugin just-writing-statistics Cross-Site Scripting ≤ 4.5 Fixed in 4.6 CVE-2024-35641 Patchstack
5.9 Medium Site Favicon Plugin site-favicon Cross-Site Scripting ≤ 0.2 Fixed in 0.3 CVE-2024-35642 Patchstack
5.9 Medium WP Back Button Plugin wp-back-button Cross-Site Scripting ≤ 1.1.3 CVE-2024-35643 Patchstack
4.3 Medium Shield Security – Smart Bot Blocking & Intrusion Prevention Security Plugin wp-simple-firewall Cross-Site Request Forgery Smart Bot Blocking & Intrusion Prevention Security <= 19.1.13 - Cross-Site Request Forgery No login needed ≤ 19.1.10 CVE-2024-4344 Wordfence
5.9 Medium Random Banner Plugin random-banner Cross-Site Scripting ≤ 4.2.12 CVE-2024-35645 Patchstack
5.9 Medium Smartarget Message Bar Plugin smartarget-message-bar Cross-Site Scripting ≤ 1.5 CVE-2024-35646 Patchstack
5.9 Medium Global Notification Bar Plugin global-notification-bar Cross-Site Scripting ≤ 1.0.1 CVE-2024-35647 Patchstack
4.3 Medium Uploadcare File Uploader and Adaptive Delivery (beta) Plugin uploadcare Arbitrary File Upload Cross Site Request Forgery (CSRF) No login needed ≤ 3.0.11 CVE-2024-35636 Patchstack
10.0 Critical wpDataTables - Tables & Table Charts (Premium) Plugin SQL Injection Tables & Table Charts (Premium) <= 6.3.1 - Unauthenticated SQL Injection No login needed ≤ 6.3.1 CVE-2024-3820 Wordfence
9.9 Critical wpForo Forum Plugin wpforo SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3.3 CVE-2024-3200 Wordfence
8.8 High Elements For Elementor Plugin nd-elements Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Multiple Widget Attributes ≤ 2.1 CVE-2024-5348 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only