WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 26,751–26,800 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 536 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium wpDiscuz Plugin wpdiscuz Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Uploaded Image Alternative Text ≤ 7.6.15 CVE-2024-2477 Wordfence
6.4 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via How To and FAQ Blocks ≤ 1.29 CVE-2024-3491 Wordfence
6.4 Medium GeoDirectory – WordPress Business Directory Plugin, or Classified Directory Plugin Cross-Site Scripting WordPress Business Directory Plugin, or Classified Directory <= 2.3.48 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gd_single_tabs' Shortcode ≤ 2.3.48 CVE-2024-3732 Wordfence
6.4 Medium Rank Math SEO with AI SEO Tools Plugin seo-by-rank-math Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'titleWrapper' ≤ 1.0.216 CVE-2024-3665 Wordfence
4.3 Medium EleSpare – News, Magazine and Blog Addons for Elementor Plugin elespare Broken Access Control Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation ≤ 2.1.2 CVE-2024-0900 Wordfence
4.3 Medium Quick Featured Images Plugin quick-featured-images Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Thumbnail Deletion/Setting ≤ 13.7.0 CVE-2024-3664 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Accordion Title Tags ≤ 1.3.971 CVE-2024-3889 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 1.3.971 CVE-2024-2798 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags ≤ 1.3.971 CVE-2024-2799 Wordfence
5.3 Medium Forminator Plugin forminator Arbitrary File Upload Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive in… prior to 1.29.0 CVE-2024-28890 jpcert
7.2 High Forminator Plugin forminator SQL Injection Forminator prior to 1.29.3 contains a SQL injection vulnerability. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege may obtain… prior to 1.29.3 CVE-2024-31077 jpcert
5.4 Medium Forminator Plugin forminator Cross-Site Scripting Forminator prior to 1.15.4 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote attacker may obtain user information etc. and alter the page… No login needed prior to 1.15.4 CVE-2024-31857 jpcert
8.8 High rtMedia for WordPress, BuddyPress and bbPress Plugin buddypress-media SQL Injection Authenticated (Contributor+) SQL Injection via rtmedia_gallery Shortcode ≤ 4.6.18 CVE-2024-3293 Wordfence
6.4 Medium Essential Addons for Elementor Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_html_tag' ≤ 5.8.11 CVE-2024-3645 Wordfence
4.3 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32681 Patchstack
7.1 High Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Broken Access Control ≤ 3.13.2 Fixed in 3.13.3 CVE-2024-32682 Patchstack
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Broken Access Control Broken Access Control on Review No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32684 Patchstack
4.3 Medium WPC Frequently Bought Together for WooCommerce Plugin woo-bought-together Broken Access Control ≤ 7.0.3 Fixed in 7.0.4 CVE-2024-32687 Patchstack
6.5 Medium MyRewards Plugin woorewards Broken Access Control ≤ 5.3.0 Fixed in 5.3.1 CVE-2024-32688 Patchstack
5.3 Medium Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Broken Access Control No login needed ≤ 1.0.6.2 Fixed in 1.0.6.3 CVE-2024-32691 Patchstack
7.6 High Automatic Plugin Cross-Site Request Forgery Multiple Cross Site Request Forgery (CSRF) No login needed < 3.93.0 Fixed in 3.93.0 CVE-2024-32693 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.10.4 Fixed in 3.10.5 CVE-2024-32698 Patchstack
6.5 Medium HelloAsso Plugin helloasso Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2024-32697 Patchstack
6.5 Medium Infographic Maker – iList Plugin infographic-and-list-builder-ilist Cross-Site Scripting ≤ 4.6.6 Fixed in 4.6.8 CVE-2024-32696 Patchstack
7.1 High Language Switcher for Transposh Plugin language-switcher-for-transposh Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.9 Fixed in 1.6.0 CVE-2024-32695 Patchstack
7.1 High 3D FlipBook, PDF Viewer, PDF Embedder – Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.62 Fixed in 3.63 CVE-2024-32694 Patchstack
5.9 Medium RSS Feed Widget Plugin rss-feed-widget Cross-Site Scripting ≤ 2.9.7 Fixed in 2.9.8 CVE-2024-32690 Patchstack
5.3 Medium Tickera Plugin tickera-event-ticketing-system Broken Access Control Ticket leakage through IDOR No login needed < 3.5.2.5 Fixed in 3.5.2.5 CVE-2023-7252 WPScan
6.4 Medium hCaptcha Plugin hcaptcha-for-forms-and-more Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via cf7-hcaptcha Shortcode ≤ 4.0.0 CVE-2024-4014 Wordfence
5.4 Medium Prime Slider – Addons for Elementor Plugin Cross-Site Scripting Addons For Elementor (Revolution of a slider, Hero Slider, Media Slider, Drag Drop Slider, Video Slider, Product Slider, Ecommerce Slider) <= 3.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.14.0 CVE-2024-1730 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +10 Modules – All in One Solution (formerly WooLentor) <= 2.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.1 CVE-2024-1057 Wordfence
5.3 Medium Wp Ultimate Review Plugin wp-ultimate-review Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.2.5 Fixed in 2.3.0 CVE-2024-32683 Patchstack
6.8 Medium Genesis Blocks Plugin genesis-blocks Cross-Site Scripting Contributor+ Stored XSS < 3.1.3 Fixed in 3.1.3 CVE-2024-2761 WPScan
7.2 High Poll Maker – Best WordPress Poll Plugin Broken Access Control Best WordPress Poll Plugin <= 5.1.8 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting No login needed ≤ 5.1.8 CVE-2024-3600 Wordfence
5.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.9 - Authenticated (Contributor+) DOM-Based Cross-Site Scripting via "Social Icons" Block ≤ 4.5.9 CVE-2024-3818 Wordfence
6.1 Medium Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting via 's' No login needed ≤ 5.47.0 CVE-2024-3731 Wordfence
6.1 Medium Media Library Folders Plugin media-library-plus Cross-Site Scripting Reflected Cross-Site Scripting via 's' No login needed ≤ 8.2.0 CVE-2024-3615 Wordfence
6.4 Medium ElementsKit Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'ekit_btn_id' ≤ 3.6.0 CVE-2024-3598 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2.6.4 CVE-2024-3560 Wordfence
6.4 Medium EAN for WooCommerce Plugin ean-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via alg_wc_ean_product_meta Shortcode ≤ 4.9.2 CVE-2023-6892 Wordfence
4.3 Medium EAN for WooCommerce Plugin ean-for-woocommerce Broken Access Control Insecure Direct Object Reference to Sensitve Information Exposure via Shortcode ≤ 4.9.2 CVE-2023-6897 Wordfence
6.8 Medium Store Locator Plugin agile-store-locator Arbitrary File Deletion WordPress Store Locator WordPress Plugin <= 1.4.14 is vulnerable to Arbitrary File Deletion ≤ 1.4.14 CVE-2023-50885 Patchstack
7.6 High CataBlog Plugin catablog Arbitrary File Deletion WordPress CataBlog Plugin <= 1.7.0 is vulnerable to Arbitrary File Deletion ≤ 1.7.0 CVE-2023-47843 Patchstack
4.3 Medium WP Social Comments Plugin gs-facebook-comments Broken Access Control ≤ 1.7.3 Fixed in 1.7.4 CVE-2024-32689 Patchstack
5.3 Medium Backup Migration Plugin backup-backup Information Disclosure Sensitive Data Exposure via Log No login needed ≤ 1.4.3 Fixed in 1.4.4 CVE-2024-32686 Patchstack
5.5 Medium Really Simple SSL Plugin really-simple-ssl Server-Side Request Forgery ≤ 7.2.3 Fixed in 8.0.0 CVE-2024-31229 Patchstack
7.6 High SP Project & Document Manager Plugin sp-client-document-manager SQL Injection Auth. SQL Injection ≤ 4.71 CVE-2024-32551 Patchstack
7.6 High WooCommerce Multilingual & Multicurrency Plugin woocommerce-multilingual SQL Injection ≤ 5.3.3.1 Fixed in 5.3.4 CVE-2024-32602 Patchstack
6.5 Medium WP-FormAssembly Plugin formassembly-web-forms Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2023-49768 Patchstack
5.9 Medium Navigation menu as Dropdown Widget Plugin navigation-menu-as-dropdown-widget Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2024-32126 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only