WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 25,801–25,850 of 29,211 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.3 High | wpDataTables - Tables & Table Charts (Premium) | Broken Access Control Tables & Table Charts (Premium) <= 6.3.2 - Missing Authorization to DataTable Access & Modification No login needed |
≤ 6.3.2 |
CVE-2024-3821 |
Wordfence | |
| 7.1 High | User Registration – Custom Registration Form, Login Form, and User Profile | Broken Access Control Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation |
≤ 3.2.0.1 |
CVE-2024-4958 |
Wordfence | |
| 6.4 Medium | Contact Form Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6 |
CVE-2024-2295 |
Wordfence | |
| 5.3 Medium | QQWorld Auto Save Images | Broken Access Control Missing Authorization to Arbitrary Post Content Retrieval No login needed |
≤ 1.9.8 |
CVE-2024-1324 |
Wordfence | |
| 6.4 Medium | Popup Builder | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS |
≤ 4.2.7 |
CVE-2024-2506 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Back to Top Widget |
≤ 1.3.975 |
CVE-2024-4087 |
Wordfence | |
| 6.4 Medium | Supreme Modules Lite – Divi Theme, Extra Theme and Divi Builder | Cross-Site Scripting Divi Theme, Extra Theme and Divi Builder <= 2.5.51 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.5.51 |
CVE-2024-5501 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.975 |
CVE-2024-4342 |
Wordfence | |
| 6.4 Medium | Master Slider - Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.9.9 |
CVE-2023-6382 |
Wordfence | |
| 8.8 High | Content Blocks (Custom Post Widget) | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Shortcode |
≤ 3.3.0 |
CVE-2024-3564 |
Wordfence | |
| 6.4 Medium | Content Blocks (Custom Post Widget) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via content_block Shortcode |
≤ 3.3.0 |
CVE-2024-3565 |
Wordfence | |
| 6.4 Medium | WordPress Infinite Scroll – Ajax Load More | Cross-Site Scripting Ajax Load More <= 7.1.1 - Authenticated (Contributor+) Cross-Site Scripting |
≤ 7.1.1 |
CVE-2024-4711 |
Wordfence | |
| 6.4 Medium | Page Builder Gutenberg Blocks – CoBlocks | Cross-Site Scripting CoBlocks <= 3.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Profiles |
≤ 3.1.9 |
CVE-2024-2933 |
Wordfence | |
| 6.4 Medium | Auto Featured Image (Auto Post Thumbnail) | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery |
≤ 4.1.7 |
CVE-2023-7073 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Accordion |
≤ 3.10.9 |
CVE-2024-5041 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation Widget |
≤ 3.10.9 |
CVE-2024-5347 |
Wordfence | |
| 6.4 Medium | Download Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpdm-all-packages Shortcode |
≤ 3.2.90 |
CVE-2024-4160 |
Wordfence | |
| 6.4 Medium | WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce | Cross-Site Scripting Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode |
≤ 2.2.24 |
CVE-2024-5427 |
Wordfence | |
| 7.5 High | Migration Backup Restore | Server-Side Request Forgery Admin+ SSRF No login needed |
< 3.5.0 Fixed in 3.5.0 |
CVE-2024-4469 |
WPScan | |
| 5.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Global Tooltip |
≤ 4.10.31 |
CVE-2024-4379 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Fancy Text Widget |
≤ 4.10.31 |
CVE-2024-4376 |
Wordfence | |
| 4.3 Medium | Premium Addons for Elementor | Broken Access Control Missing Authorization to Information Disclosure |
≤ 4.10.31 |
CVE-2024-4205 |
Wordfence | |
| 7.2 High | Visual Website Collaboration, Feedback & Project Management – Atarim | Cross-Site Scripting Atarim <= 3.30 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 3.30 |
CVE-2024-2793 |
Wordfence | |
| 6.4 Medium | DethemeKit For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slitems Attribute |
≤ 2.1.4 |
CVE-2024-5418 |
Wordfence | |
| 8.8 High | Responsive Owl Carousel for Elementor | Local File Inclusion |
≤ 1.2.0 |
CVE-2024-5345 |
Wordfence | |
| 8.8 High | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | Broken Access Control PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update |
≤ 4.1.2 |
CVE-2024-5326 |
Wordfence | |
| 6.4 Medium | Simple Like Page | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.5.2 |
CVE-2024-3583 |
Wordfence | |
| 6.4 Medium | Gum Elementor Addon | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price Table and Post Slider Widgets |
≤ 1.3.4 |
CVE-2024-4668 |
Wordfence | |
| 4.3 Medium | Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection | Broken Access Control Missing Authorization to Information Expsoure |
≤ 10.23 |
CVE-2024-4355 |
Wordfence | |
| 4.3 Medium | Comparison Slider | Broken Access Control Missing Authorization |
≤ 1.0.5 |
CVE-2024-4427 |
Wordfence | |
| 4.3 Medium | Comparison Slider | Cross-Site Request Forgery No login needed |
≤ 1.0.5 |
CVE-2024-4426 |
Wordfence | |
| 4.4 Medium | Font Farsi | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.6.6 |
CVE-2024-2657 |
Wordfence | |
| 5.4 Medium | Remote Content Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5 |
CVE-2024-2089 |
Wordfence | |
| 6.4 Medium | Comparison Slider | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 1.0.5 |
CVE-2024-4422 |
Wordfence | |
| 6.4 Medium | PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.7.19 |
CVE-2024-5327 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Feed |
≤ 5.9.21 |
CVE-2024-5073 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce | Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 5.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Title Widget |
≤ 5.5.4 |
CVE-2024-5341 |
Wordfence | |
| 7.2 High | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP | SQL Injection Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.9.3 - Authenticated (Administrator+) SQL Injection |
≤ 2.9.3 |
CVE-2024-5207 |
Wordfence | |
| 4.4 Medium | WP To Do | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Settings |
≤ 1.3.0 |
CVE-2024-3946 |
Wordfence | |
| 5.0 Medium | Yumpu ePaper publishing | Broken Access Control Missing Authorization to PDF Upload, Publishing, and API Key Modification |
≤ 2.0.24 |
CVE-2024-3277 |
Wordfence | |
| 6.4 Medium | List categories | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 0.4 |
CVE-2024-4356 |
Wordfence | |
| 4.3 Medium | WP To Do | Cross-Site Request Forgery Cross-Site Request Forgery via wptodo_settings No login needed |
≤ 1.3.0 |
CVE-2024-3947 |
Wordfence | |
| 4.3 Medium | WP To Do | Cross-Site Request Forgery Cross-Site Request Forgery via wptodo_manage() No login needed |
≤ 1.3.0 |
CVE-2024-3945 |
Wordfence | |
| 4.3 Medium | WP To Do | Cross-Site Request Forgery Cross-Site Request Forgery via wptodo_addcomment No login needed |
≤ 1.3.0 |
CVE-2024-3943 |
Wordfence | |
| 6.5 Medium | AffiEasy | Cross-Site Request Forgery Cross-Site Request Forgery to Various Actions No login needed |
≤ 1.1.6 |
CVE-2024-4218 |
Wordfence | |
| 5.4 Medium | Download Monitor | Broken Access Control Missing Authorization |
≤ 4.9.13 |
CVE-2024-3269 |
Wordfence | |
| 6.4 Medium | Testimonial Carousel For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 10.2.2 |
CVE-2024-2253 |
Wordfence | |
| 5.4 Medium | Unlimited Elements For Elementor (Free Widgets, Addons, Templates) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Text Field |
≤ 1.5.107 |
CVE-2024-3190 |
Wordfence | |
| 6.4 Medium | WPB Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.9 |
CVE-2024-3063 |
Wordfence | |
| 6.4 Medium | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | Cross-Site Scripting PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 4.1.1 |
CVE-2024-5223 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.