WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 26,851–26,900 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | PeproDev CF7 Database | Cross-Site Request Forgery No login needed |
≤ 1.8.0 Fixed in 1.9.0 |
CVE-2023-41864 |
Patchstack | |
| 9.9 Critical | Support Genix | Broken Access Control Broken Access Control lead to Arbitrary File Upload |
≤ 1.2.3 Fixed in 1.2.4 |
CVE-2023-49742 |
Patchstack | |
| 5.4 Medium | Ovic Responsive WPBakery | Broken Access Control |
≤ 1.3.0 |
CVE-2024-32142 |
Patchstack | |
| 6.1 Medium | Otter Blocks | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 2.6.6 Fixed in 2.6.6 |
CVE-2024-2729 |
WPScan | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget |
≤ 5.6.0 |
CVE-2024-1429 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget |
≤ 5.6.0 |
CVE-2024-1426 |
Wordfence | |
| 6.4 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) |
≤ 4.4.7 |
CVE-2023-6805 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Store Cross-Site Scripting via Widget URL Attribute |
≤ 5.9.14 |
CVE-2024-3333 |
Wordfence | |
| 7.7 High | JVM rich text icons | Arbitrary File Deletion |
≤ 1.2.6 Fixed in 1.2.7 |
CVE-2023-51418 |
Patchstack | |
| 7.7 High | Uncode Core | Arbitrary File Deletion |
≤ 2.8.8 Fixed in 2.8.9 |
CVE-2023-51500 |
Patchstack | |
| 8.6 High | JS Help Desk – Best Help Desk & Support | SQL Injection Unauth. SQL Injection No login needed |
≤ 2.7.1 Fixed in 2.7.2 |
CVE-2022-47151 |
Patchstack | |
| 6.5 Medium | If Menu | Broken Access Control Visibility control for Menus plugin <= 0.16.3 - Broken Access Control No login needed |
≤ 0.16.3 Fixed in 0.17.0 |
CVE-2022-41698 |
Patchstack | |
| 5.3 Medium | Honeypot for WP Comment | Arbitrary File Deletion No login needed |
≤ 2.2.3 |
CVE-2024-1350 |
Patchstack | |
| 6.5 Medium | Payment Forms for Paystack | Cross-Site Scripting |
≤ 3.4.1 |
CVE-2024-32130 |
Patchstack | |
| 6.5 Medium | Envo Extra | Cross-Site Scripting |
≤ 1.8.11 Fixed in 1.8.12 |
CVE-2024-32456 |
Patchstack | |
| 6.5 Medium | Elements Plus! | Cross-Site Scripting |
≤ 2.16.3 Fixed in 2.16.4 |
CVE-2024-32457 |
Patchstack | |
| 6.5 Medium | ElementsKit Elementor addons Lite | Cross-Site Scripting |
≤ 3.0.6 Fixed in 3.0.7 |
CVE-2024-32505 |
Patchstack | |
| 6.5 Medium | DethemeKit For Elementor | Cross-Site Scripting |
≤ 2.0.2 Fixed in 2.1.0 |
CVE-2024-32508 |
Patchstack | |
| 7.1 High | WP Cost Estimation & Payment Forms Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 10.1.75 Fixed in 10.1.76 |
CVE-2024-32510 |
Patchstack | |
| 6.5 Medium | Easy Textillate | Cross-Site Scripting |
≤ 2.02 |
CVE-2024-32526 |
Patchstack | |
| 6.5 Medium | Jotform Online Forms | Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-32527 |
Patchstack | |
| 7.1 High | WP Dynamic Keywords Injector | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.3.18 Fixed in 2.3.22 |
CVE-2024-32528 |
Patchstack | |
| 6.5 Medium | Yoga Schedule Momoyoga | Cross-Site Scripting |
≤ 2.7.0 |
CVE-2024-32529 |
Patchstack | |
| 6.5 Medium | Simple Testimonials Showcase | Cross-Site Scripting |
≤ 1.1.5 |
CVE-2024-32530 |
Patchstack | |
| 7.1 High | GuCherry Blog | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.1.8 |
CVE-2024-32531 |
Patchstack | |
| 7.5 High | Simple File List | Arbitrary File Deletion WordPress Simple File List Plugin <= 6.1.9 is vulnerable to Arbitrary File Deletion No login needed |
≤ 6.1.9 Fixed in 6.1.10 |
CVE-2023-44227 |
Patchstack | |
| 6.8 Medium | Ninja Forms Contact Form | Arbitrary File Deletion WordPress Ninja Forms Plugin <= 3.6.24 is vulnerable to Arbitrary File Deletion |
≤ 3.6.24 Fixed in 3.6.25 |
CVE-2023-36505 |
Patchstack | |
| 4.3 Medium | Data Tables Generator | Broken Access Control WordPress Data Tables Generator by Supsystic Plugin <= 1.10.25 is vulnerable to Broken Access Control |
≤ 1.10.25 Fixed in 1.10.26 |
CVE-2023-25043 |
Patchstack | |
| 7.1 High | LH Add Media From Url | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.22 Fixed in 1.23 |
CVE-2024-32533 |
Patchstack | |
| 5.9 Medium | Form Maker by 10Web | Cross-Site Scripting |
≤ 1.15.23 Fixed in 1.15.24 |
CVE-2024-32534 |
Patchstack | |
| 7.1 High | Access Category Password | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.5.1 |
CVE-2024-32535 |
Patchstack | |
| 6.5 Medium | WP TradingView | Cross-Site Scripting |
≤ 1.7 |
CVE-2024-32536 |
Patchstack | |
| 6.5 Medium | Easy CountDowner | Cross-Site Request Forgery CSRF to XSS |
≤ 1.0.8 |
CVE-2024-32538 |
Patchstack | |
| 6.5 Medium | WP File Download Light | Cross-Site Scripting |
≤ 1.3.3 |
CVE-2024-32539 |
Patchstack | |
| 5.9 Medium | Fixed HTML Toolbar | Cross-Site Scripting |
≤ 1.0.7 |
CVE-2024-32540 |
Patchstack | |
| 7.1 High | WP-Cufon | Cross-Site Scripting No login needed |
≤ 1.6.10 |
CVE-2024-32541 |
Patchstack | |
| 7.1 High | Bulk Block Converter | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.1 |
CVE-2024-32542 |
Patchstack | |
| 7.1 High | MJ Update History | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0.4 |
CVE-2024-32543 |
Patchstack | |
| 7.1 High | Netgsm | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.8 Fixed in 2.9 |
CVE-2024-32544 |
Patchstack | |
| 7.1 High | Canva – Design beautiful blog graphics | Cross-Site Scripting Design beautiful blog graphics plugin <= 1.2.4 - Cross Site Scripting (XSS) No login needed |
≤ 1.2.4 |
CVE-2024-32545 |
Patchstack | |
| 7.1 High | Tax Rate Upload | Cross-Site Scripting No login needed |
≤ 2.4.5 |
CVE-2024-32546 |
Patchstack | |
| 5.8 Medium | Code Insert Manager (Q2W3 Inc Manager) | Cross-Site Scripting No login needed |
≤ 2.5.3 |
CVE-2024-32547 |
Patchstack | |
| 5.9 Medium | What's New Generator | Cross-Site Scripting |
≤ 2.0.2 |
CVE-2024-32548 |
Patchstack | |
| 7.1 High | BMI Adult & Kid Calculator | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 1.2.1 Fixed in 1.2.2 |
CVE-2024-32550 |
Patchstack | |
| 7.1 High | Related Posts | Cross-Site Request Forgery CSRF to XSS No login needed |
≤ 4.0.3 |
CVE-2024-32549 |
Patchstack | |
| 5.4 Medium | Radio Player | Information Disclosure Sensitive Data Exposure |
≤ 2.0.73 Fixed in 2.0.74 |
CVE-2024-32506 |
Patchstack | |
| 5.3 Medium | Product Feed PRO for WooCommerce | Information Disclosure Sensitive Data Exposure No login needed |
≤ 13.3.1 Fixed in 13.3.2 |
CVE-2024-32513 |
Patchstack | |
| 9.9 Critical | WP Poll Maker | Arbitrary File Upload Authenticated Arbitrary File Upload |
≤ 3.4 |
CVE-2024-32514 |
Patchstack | |
| 6.5 Medium | WP Cost Estimation & Payment Forms Builder | Broken Access Control No login needed |
≤ 10.1.76 Fixed in 10.1.77 |
CVE-2024-32509 |
Patchstack | |
| 5.4 Medium | Mega Addons For Elementor | Broken Access Control |
≤ 1.8 |
CVE-2024-32515 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.