WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,151–26,200 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 524 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Visual Footer Credit Remover Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.2 CVE-2024-2846 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.4.2 CVE-2024-0445 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tooltip & Popover Widget ≤ 2.5.0 CVE-2024-3990 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1.1 CVE-2024-3923 Wordfence
9.8 Critical Porto Theme Local File Inclusion Unauthenticated Local File Inclusion via porto_ajax_posts No login needed ≤ 7.1.0 CVE-2024-3806 Wordfence
4.3 Medium SimpleShop Plugin simpleshop-cz Cross-Site Request Forgery No login needed ≤ 2.10.0 CVE-2024-1230 Wordfence
6.4 Medium Rank Math SEO with AI Best SEO Tools Plugin seo-by-rank-math Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.217 CVE-2024-4335 Wordfence
4.3 Medium ADFO – Custom data in admin dashboard Plugin admin-form Cross-Site Request Forgery Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery No login needed ≤ 1.9.0 CVE-2024-4103 Wordfence
8.1 High XML Sitemap & Google News Plugin xml-sitemap-feed Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.4.8 CVE-2024-4441 Wordfence
5.3 Medium Swift Framework Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Content Update No login needed ≤ 2.7.31 CVE-2024-3915 Wordfence
6.4 Medium Mihdan: Yandex Turbo Feed Plugin mihdan-yandex-turbo-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.6.5.1 CVE-2024-4411 Wordfence
6.4 Medium Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Text Effect Widget ≤ 1.1.37 CVE-2024-2923 Wordfence
6.4 Medium Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.3 CVE-2024-4339 Wordfence
4.3 Medium hostel Plugin hostel Cross-Site Request Forgery No login needed ≤ 1.1.5.3 CVE-2024-4314 Wordfence
6.4 Medium Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) Plugin content-views-query-and-display-post-page Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter ≤ 3.7.1 CVE-2024-4446 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Heading widget ≤ 2.1.5 CVE-2024-3831 Wordfence
5.4 Medium Swift Performance Lite Plugin swift-performance-lite Broken Access Control Incorrect Authorization to Authenticated (Subscriber+) Settings Modification ≤ 2.3.6.18 CVE-2024-3722 Wordfence
6.4 Medium Pure Chat – Live Chat Plugin & More! Plugin pure-chat Cross-Site Scripting Live Chat Plugin & More! <= 2.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.22 CVE-2024-3595 Wordfence
4.3 Medium Soccer Engine – Soccer Plugin Cross-Site Request Forgery Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery No login needed ≤ 1.12 CVE-2024-4312 Wordfence
6.4 Medium Swift Framework Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes ≤ 2.7.31 CVE-2024-3916 Wordfence
6.4 Medium Simple Membership Plugin simple-membership Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.5 CVE-2024-4383 Wordfence
6.4 Medium Advanced Ads – Ad Manager & AdSense Plugin advanced-ads Cross-Site Scripting Ad Manager & AdSense <= 1.52.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Ad Widget ≤ 1.52.1 CVE-2024-3952 Wordfence
6.1 Medium Yoast SEO Plugin wordpress-seo Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 22.5 CVE-2024-4041 Wordfence
5.3 Medium SimpleShop Plugin simpleshop-cz Broken Access Control Missing Authorization No login needed ≤ 2.10.2 CVE-2024-1229 Wordfence
8.8 High Porto Theme Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Meta ≤ 7.1.0 CVE-2024-3807 Wordfence
6.4 Medium Image Hover Effects - Elementor Addon Plugin Cross-Site Scripting Elementor Addon <= 1.4.1 - Authenticated(Contributor+) DOM-based Stored Cross-Site Scripting via Image Hover Effects Widget ≤ 1.4.1 CVE-2024-1166 Wordfence
6.4 Medium Gallery Block (Meow Gallery) Plugin meow-gallery Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.1.3 CVE-2024-4386 Wordfence
6.4 Medium BuddyPress Plugin buddypress Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 12.4.0 CVE-2024-3974 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 3.9.16 CVE-2024-4316 Wordfence
6.4 Medium Enter Addons – Ultimate Template Builder for Elementor Plugin enteraddons Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Animation Title widget img tag ≤ 2.1.5 CVE-2024-3680 Wordfence
6.4 Medium Blocksy Theme blocksy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.42 CVE-2024-4158 Wordfence
5.3 Medium ShopLentor (formerly WooLentor) Plugin woolentor-addons Broken Access Control Missing Authorization via purchased_new_products No login needed ≤ 2.8.7 CVE-2023-6327 Wordfence
6.1 Medium Simple Basic Contact Form Plugin simple-basic-contact-form Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 20221201 CVE-2024-4150 Wordfence
4.3 Medium SP Project & Document Manager Plugin sp-client-document-manager Broken Access Control Authenticated (Subscriber+) Arbitrary Folder Name Update ≤ 4.70 CVE-2024-1693 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 3.21.0 CVE-2024-4107 Wordfence
8.8 High Ditty – Responsive News Tickers, Sliders, and Lists Plugin ditty-news-ticker PHP Object Injection Responsive News Tickers, Sliders, and Lists <= 3.1.38 - Authenticated (Contributor+) PHP Object Injection ≤ 3.1.38 CVE-2024-3954 Wordfence
8.8 High Breakdance Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 1.7.1 CVE-2024-4605 Wordfence
4.4 Medium Custom Field Suite Plugin custom-field-suite Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.6.5 CVE-2024-3068 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gallery Justify ≤ 2.5.0 CVE-2024-3989 Wordfence
7.5 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control No login needed ≤ 4.0.14 Fixed in 4.0.15 CVE-2024-32712 Patchstack
6.5 Medium SchedulePress Plugin wp-scheduled-posts Broken Access Control ≤ 5.0.8 Fixed in 5.0.9 CVE-2024-32717 Patchstack
5.3 Medium WP Club Manager Plugin wp-club-manager Broken Access Control No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-32719 Patchstack
7.5 High Sharkdropship dropshipping for Aliexpress, eBay, Amazon, etsy Plugin woo-aliexpress-dropshipping Broken Access Control Arbitrary Content Deletion No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2024-32724 Patchstack
5.3 Medium WP Job Manager Plugin wp-job-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.2 Fixed in 2.3.0 CVE-2024-34549 Patchstack
5.3 Medium Dynamics 365 Integration Plugin integration-dynamics Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.17 Fixed in 1.3.18 CVE-2024-34550 Patchstack
5.3 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Information Disclosure Sensitive Data Exposure via Exported File No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-34556 Patchstack
7.5 High Ghost Plugin ghost Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 1.4.0 Fixed in 1.5.0 CVE-2024-34559 Patchstack
4.4 Medium One Click Demo Import Plugin one-click-demo-import PHP Object Injection ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-34433 Patchstack
5.4 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit PHP Object Injection No login needed ≤ 2.0.3 Fixed in 2.0.4 CVE-2024-4606 Patchstack
4.3 Medium DS Site Message Plugin ds-site-message Cross-Site Request Forgery No login needed ≤ 1.14.4 CVE-2024-34439 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only