WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,051–26,100 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 522 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Contributor+ Stored XSS No login needed < 7.1.2 Fixed in 7.1.2 CVE-2024-3548 WPScan
5.3 Medium WP Prayer Plugin Cross-Site Request Forgery Arbitrary Prayer Deletion via CSRF ≤ 2.0.9 CVE-2024-3407 WPScan
8.8 High WP Prayer Plugin Cross-Site Request Forgery Email Settings Update via CSRF No login needed ≤ 2.0.9 CVE-2024-3406 WPScan
7.6 High WP Prayer Plugin Cross-Site Request Forgery Settings Update via CSRF ≤ 2.0.9 CVE-2024-3405 WPScan
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Cross-Site Scripting Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting via Typer Effect ≤ 3.2.37 CVE-2024-4208 Wordfence
5.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.37 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.37 CVE-2024-3189 Wordfence
4.4 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.26.6.1 CVE-2024-4656 Wordfence
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-site Scriping via 'Sina Particle Layer' ≤ 3.5.3 CVE-2024-4373 Wordfence
8.8 High Alt Text AI – Automatically generate image alt text for SEO and accessibility Plugin alttext-ai SQL Injection Automatically generate image alt text for SEO and accessibility <= 1.4.9 - Authenticated (Subscriber+) SQL Injection ≤ 1.4.9 CVE-2024-4847 Wordfence
4.3 Medium Bulk Posts Editing Plugin Broken Access Control Authenticated (Subscriber+) Missing Authorization ≤ 4.2.3 CVE-2024-4199 Wordfence
4.4 Medium Import and export users and customers Plugin import-users-from-csv-with-meta Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.26.6.1 CVE-2024-4734 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Member Widget ≤ 2.6.9.6 CVE-2024-4618 Wordfence
6.4 Medium WPZOOM Addons for Elementor (Templates, Widgets) Plugin wpzoom-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget ≤ 1.1.36 CVE-2024-4370 Wordfence
4.3 Medium Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease Plugin Broken Access Control Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure ≤ 2.6.6 CVE-2024-0437 Wordfence
6.4 Medium Visual Portfolio, Photo Gallery & Post Grid Plugin visual-portfolio Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter ≤ 3.3.2 CVE-2024-4363 Wordfence
6.4 Medium Borderless - Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg Plugin borderless Cross-Site Scripting Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.3 CVE-2024-4666 Wordfence
8.8 High Leyka Plugin leyka Privilege Escalation ≤ 3.30.2 Fixed in 3.30.3 CVE-2023-33327 Patchstack
6.4 Medium Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting Authenticated (Contributor+) DOM-Based Cross-Site Scripting ≤ 3.5.3 CVE-2024-4333 Wordfence
6.4 Medium Sydney Toolbox Plugin sydney-toolbox Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aThemes: Portfolio Widget ≤ 1.31 CVE-2024-4473 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.20 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.20 CVE-2024-4624 Wordfence
6.4 Medium 140+ Widgets | Best Addons For Elementor – FREE Plugin xpro-elementor-addons Cross-Site Scripting FREE <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.4.3 CVE-2024-4440 Wordfence
5.4 Medium WordPress RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting The 'WordPress RSS Aggregator' WordPress Plugin, versions < 4.23.9 are affected by a Cross-Site Scripting (XSS) vulnerability due to the lack of sanitization of the 'notice_id' GE… No login needed < 4.23.9 Fixed in 4.23.9 CVE-2024-4860 tenable
6.4 Medium Jetpack – WP Security, Backup, Speed, & Growth Plugin jetpack Cross-Site Scripting WP Security, Backup, Speed, & Growth <= 13.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpvideo Shortcode ≤ 13.3.1 CVE-2024-4392 Wordfence
5.4 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting Contributor+ Stored XSS < 3.1.7 Fixed in 3.1.7 CVE-2024-3241 WPScan
6.5 Medium Simple Basic Contact Form Plugin simple-basic-contact-form Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 20240502 CVE-2024-4144 Wordfence
6.5 Medium WP Compress – Image Optimizer [All-In-One] Plugin wp-compress-image-optimizer Broken Access Control Image Optimizer [All-In-One] <= 6.20.01 - Missing Authorization ≤ 6.20.01 CVE-2024-4445 Wordfence
5.3 Medium YITH WooCommerce Gift Cards Plugin yith-woocommerce-gift-cards Broken Access Control Missing Authorization to Unauthenticated WooCommerce Settings Update No login needed ≤ 4.12.0 CVE-2024-0870 Wordfence
4.3 Medium WP Compress – Image Optimizer [All-In-One] Plugin wp-compress-image-optimizer Open Redirect Image Optimizer [All-In-One] <= 6.20.01 - Open Redirect via css No login needed ≤ 6.20.01 CVE-2023-6812 Wordfence
6.5 Medium Envo's Elementor Templates & Widgets for WooCommerce Plugin envo-elementor-for-woocommerce Cross-Site Scripting ≤ 1.4.8 Fixed in 1.4.9 CVE-2024-35167 Patchstack
5.9 Medium All Bootstrap Blocks Plugin all-bootstrap-blocks Cross-Site Scripting ≤ 1.3.15 Fixed in 1.3.16 CVE-2024-35169 Patchstack
5.9 Medium Sticky banner Plugin sticky-banner Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-35170 Patchstack
7.1 High Propovoice CRM Plugin propovoice Cross-Site Scripting No login needed ≤ 1.7.6.2 CVE-2024-4747 Patchstack
5.3 Medium Easy Digital Downloads Plugin easy-digital-downloads Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.11 Fixed in 3.2.12 CVE-2024-32100 Patchstack
5.3 Medium ShopBuilder – Elementor WooCommerce Builder Addons Plugin shopbuilder Information Disclosure Sensitive Data Exposure No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2024-34812 Patchstack
5.3 Medium Gutenify Plugin gutenify Information Disclosure Sensitive Data Exposure via API No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2024-35165 Patchstack
5.3 Medium Filebird Plugin filebird Information Disclosure WordPress Media Library Folders & File Manager plugin <= 5.6.3 - Sensitive Data Exposure No login needed ≤ 5.6.3 Fixed in 5.6.4 CVE-2024-35166 Patchstack
5.3 Medium Academy LMS Plugin academy Information Disclosure Sensitive Data Exposure No login needed ≤ 1.9.25 Fixed in 1.9.26 CVE-2024-35171 Patchstack
10.0 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload Unauth. Arbitrary File Upload No login needed ≤ 8.7.01.001 Fixed in 8.7.01.002 CVE-2024-31377 Patchstack
9.9 Critical canvasio3D Light Plugin canvasio3d-light Arbitrary File Upload ≤ 2.5.0 CVE-2024-34411 Patchstack
9.1 Critical Pk Favicon Manager Plugin phpsword-favicon-manager Arbitrary File Upload ≤ 2.1 CVE-2024-34416 Patchstack
9.1 Critical AI Engine: ChatGPT Chatbot Plugin ai-engine Arbitrary File Upload Auth. Arbitrary File Upload ≤ 2.2.63 Fixed in 2.2.70 CVE-2024-34440 Patchstack
9.1 Critical Z-Downloads Plugin z-downloads Arbitrary File Upload Auth. Arbitrary File Upload No login needed ≤ 1.11.3 Fixed in 1.11.4 CVE-2024-34555 Patchstack
4.4 Medium ShortPixel Adaptive Images Plugin shortpixel-adaptive-images Server-Side Request Forgery ≤ 3.8.3 Fixed in 3.8.4 CVE-2024-35172 Patchstack
5.9 Medium WP SMS Plugin wp-sms Cross-Site Scripting ≤ 6.5.1 Fixed in 6.5.2 CVE-2024-34811 Patchstack
10.0 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2024-32700 Patchstack
5.4 Medium PostX Plugin Cross-Site Scripting Contributor+ Stored XSS < 4.0.2 Fixed in 4.0.2 CVE-2024-3239 WPScan
6.4 Medium Blocksy Companion Plugin blocksy-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via SVG Uploads ≤ 2.0.45 CVE-2024-4487 Wordfence
6.4 Medium Thim Elementor Kit Plugin thim-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.1.9 CVE-2024-4329 Wordfence
9.8 Critical Kognetiks Chatbot Plugin chatbot-chatgpt Arbitrary File Upload Unauthenticated Arbitrary File Upload via chatbot_chatgpt_upload_file_to_assistant Function No login needed ≤ 1.9.9 CVE-2024-4560 Wordfence
6.4 Medium Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2.1 CVE-2024-4630 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only