WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,251–26,300 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 526 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.3 CVE-2024-34570 Patchstack
6.5 Medium Himalayas Theme himalayas Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2024-34571 Patchstack
5.4 Medium WP Latest Posts Plugin wp-latest-posts Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 5.0.7 CVE-2024-4135 Wordfence
6.4 Medium Link Library Plugin link-library Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via link-library Shortcode ≤ 7.6.11 CVE-2024-4281 Wordfence
6.5 Medium Fancy Elementor Flipbox Plugin fancy-elementor-flipbox Cross-Site Scripting ≤ 2.4.2 CVE-2024-34572 Patchstack
6.5 Medium Pootle Pagebuilder – WordPress Page builder Plugin pootle-page-builder Cross-Site Scripting ≤ 5.7.1 CVE-2024-34573 Patchstack
5.9 Medium Table Maker Plugin table-maker Cross-Site Scripting ≤ 1.9.1 CVE-2024-34574 Patchstack
6.5 Medium Multi-column Tag Map Plugin multi-column-tag-map Broken Access Control No login needed ≤ 17.0.26 Fixed in 17.0.27 CVE-2023-41651 Patchstack
6.5 Medium SSL Zen Plugin Other Unauthenticated Private Keys Access No login needed < 4.6.0 Fixed in 4.6.0 CVE-2024-1076 WPScan
6.4 Medium Mesmerize Companion Plugin mesmerize-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mesmerize_contact_form Shortcode ≤ 1.6.148 CVE-2024-3494 Wordfence
5.4 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Scripting Heateor Social Login WordPress prior to 1.1.32 contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web br… prior to 1.1.32 CVE-2024-32674 jpcert
9.8 Critical Social Connect Plugin social-connect Authentication Bypass No login needed ≤ 1.2 CVE-2024-4393 Wordfence
6.3 Medium Tilda Publishing Plugin tilda-publishing Broken Access Control ≤ 0.3.23 Fixed in 0.3.24 CVE-2023-31234 Patchstack
4.3 Medium ClickCease Click Fraud Protection Plugin clickcease-click-fraud-protection Information Disclosure Improper Authorization to sensitive information exposure via get_settings ≤ 3.2.4 CVE-2023-6810 Wordfence
9.1 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Arbitrary File Deletion Unauthenticated Arbitrary File Deletion No login needed ≤ 1.7.13 CVE-2024-4346 Wordfence
9.8 Critical Startklar Elementor Addons Plugin startklar-elmentor-forms-extwidgets Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 1.7.13 CVE-2024-4345 Wordfence
3.8 Low EasyEvent Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.0 CVE-2024-3628 WPScan
9.8 Critical Edwiser Bridge Plugin edwiser-bridge Authentication Bypass Authentication Bypass due to Missing Empty Value Check No login needed ≤ 3.0.5 CVE-2024-4186 Wordfence
5.9 Medium SliceWP Plugin slicewp Cross-Site Scripting ≤ 1.1.10 Fixed in 1.1.11 CVE-2024-34413 Patchstack
4.3 Medium Metform Plugin metform Broken Access Control ≤ 3.8.3 Fixed in 3.8.4 CVE-2024-33570 Patchstack
6.5 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.18.10 Fixed in 3.18.11 CVE-2024-33576 Patchstack
5.3 Medium Print My Blog Plugin print-my-blog Broken Access Control No login needed ≤ 3.26.2 Fixed in 3.26.3 CVE-2024-33907 Patchstack
5.3 Medium WidgetKit Plugin widgetkit-for-elementor Broken Access Control No login needed ≤ 2.5.0 CVE-2024-33908 Patchstack
5.3 Medium Digital Publications by Supsystic Plugin digital-publications-by-supsystic Broken Access Control No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2024-33910 Patchstack
7.1 High Academy LMS Plugin academy Broken Access Control Broken Access Control on Paid Courses ≤ 1.9.16 Fixed in 1.9.17 CVE-2024-33912 Patchstack
4.3 Medium Login with phone number Plugin login-with-phone-number Broken Access Control No login needed ≤ 1.7.18 Fixed in 1.7.20 CVE-2024-34371 Patchstack
5.3 Medium Post Grid Master Plugin ajax-filter-posts Broken Access Control No login needed ≤ 3.4.7 Fixed in 3.4.8 CVE-2024-34372 Patchstack
4.3 Medium Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery Plugin new-video-gallery Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-34377 Patchstack
8.6 High LeadConnector Plugin leadconnector Broken Access Control No login needed ≤ 1.7 Fixed in 1.8 CVE-2024-34378 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control Rating Value Manipulation ≤ 3.6.4 CVE-2024-34387 Patchstack
4.3 Medium WP Post Author Plugin wp-post-author Broken Access Control ≤ 3.6.4 CVE-2024-34389 Patchstack
5.9 Medium Download Alt Text AI Plugin alttext-ai Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-34366 Patchstack
7.1 High Webpushr Plugin webpushr-web-push-notifications Cross-Site Scripting Webpushr plugin <= 4.35.0 - Cross Site Scripting (XSS) No login needed ≤ 4.35.0 Fixed in 4.36.0 CVE-2024-34369 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 5.4.2 Fixed in 5.5.0 CVE-2024-34373 Patchstack
6.5 Medium ElementsReady Addons for Elementor Plugin element-ready-lite Cross-Site Scripting ≤ 5.8.0 Fixed in 5.9.0 CVE-2024-34374 Patchstack
5.9 Medium Sheets To WP Table Live Sync Plugin sheets-to-wp-table-live-sync Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1 CVE-2024-34375 Patchstack
6.5 Medium Edge Theme edge Cross-Site Scripting ≤ 2.0.9 Fixed in 2.1.0 CVE-2024-34376 Patchstack
5.9 Medium Conversational Forms for ChatBot Plugin conversational-forms Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2024-34380 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2024-34381 Patchstack
6.5 Medium Post Grid Master Plugin ajax-filter-posts Cross-Site Scripting Auth. Cross Site Scripting (XSS) ≤ 3.4.8 CVE-2024-34390 Patchstack
4.3 Medium Restaurant and Cafe Theme restaurant-and-cafe Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2024-34379 Patchstack
7.1 High Popup box Plugin ays-popup-box Cross-Site Request Forgery CSRF to XSS No login needed ≤ 4.1.2 Fixed in 4.1.3 CVE-2024-34367 Patchstack
7.6 High Auto Affiliate Links Plugin wp-auto-affiliate-links SQL Injection ≤ 6.4.3.1 Fixed in 6.4.4 CVE-2024-34386 Patchstack
8.5 High ParcelPanel Plugin parcelpanel SQL Injection Auth. SQL Injection ≤ 3.8.1 Fixed in 3.9.0 CVE-2024-34412 Patchstack
5.3 Medium Mooberry Book Manager Plugin mooberry-book-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 4.15.12 Fixed in 4.15.13 CVE-2024-34368 Patchstack
5.3 Medium Robo Gallery Plugin robo-gallery Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.18 Fixed in 3.2.19 CVE-2024-34382 Patchstack
5.3 Medium SEOPress Plugin wp-seopress Information Disclosure Sensitive Data Exposure No login needed ≤ 7.7.1 Fixed in 7.7.2 CVE-2024-34383 Patchstack
7.5 High GDPR Compliance Plugin gdpr-compliance Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.5 CVE-2024-34388 Patchstack
8.5 High Sendinblue for WooCommerce Plugin woocommerce-sendinblue-newsletter-subscription Path Traversal Arbitrary File Download and Deletion ≤ 4.0.17 Fixed in 4.0.18 CVE-2024-32807 Patchstack
6.4 Medium Breakdance Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via custom postmeta ≤ 1.7.0 CVE-2023-6854 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only