WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 27,151–27,200 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | Cross-Site Scripting ProfilePress <= 4.15.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'reg-single-checkbox' |
≤ 4.15.5 |
CVE-2024-3210 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name |
≤ 8.3.6 |
CVE-2024-2655 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via widget _id attribute |
≤ 8.3.6 |
CVE-2024-2539 |
Wordfence | |
| 4.7 Medium | The Ultimate Video Player | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 2.2.3 Fixed in 2.2.3 |
CVE-2024-2428 |
WPScan | |
| 4.3 Medium | WordPress Ping Optimizer | Cross-Site Request Forgery Log Clearing via CSRF |
≤ 2.35.1.3.0 |
CVE-2023-6385 |
WPScan | |
| 7.2 High | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection |
≤ 2.6.3 |
CVE-2024-3020 |
Wordfence | |
| 6.4 Medium | WP Radio – Worldwide Online Radio Stations Directory | Broken Access Control Worldwide Online Radio Stations Directory for WordPress <= 3.1.9 - Missing Authorization via multiple AJAX actions |
≤ 3.1.9 |
CVE-2024-1042 |
Wordfence | |
| 5.3 Medium | Essential Grid | Information Disclosure Unauthenticated Private Post Disclosure No login needed |
≤ 3.1.1 |
CVE-2024-3235 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via HTML Tags |
≤ 4.8.8 |
CVE-2024-2736 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via "Price List" Element |
≤ 4.8.8 |
CVE-2024-2735 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via AI Features |
≤ 4.8.8 |
CVE-2024-2734 |
Wordfence | |
| 6.4 Medium | WP Radio – Worldwide Online Radio Stations Directory | Cross-Site Scripting Worldwide Online Radio Stations Directory for WordPress <= 3.1.9 - Authenticated(Subscriber+) Stored Cross-Site Scripting via Settings |
≤ 3.1.9 |
CVE-2024-1041 |
Wordfence | |
| 5.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Separator Element |
≤ 4.8.8 |
CVE-2024-2733 |
Wordfence | |
| 5.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 4.10.24 |
CVE-2024-2666 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.10.24 |
CVE-2024-2664 |
Wordfence | |
| 6.4 Medium | Premium Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button |
≤ 4.10.27 |
CVE-2024-2665 |
Wordfence | |
| 6.4 Medium | Beaver Themer | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode |
≤ 1.4.9 |
CVE-2023-6694 |
Wordfence | |
| 6.1 Medium | Invitation Code Content Restriction Plugin from CreativeMinds | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.5.4 |
CVE-2022-4965 |
Wordfence | |
| 6.1 Medium | Memberpress | Cross-Site Scripting Reflected Cross-Site Scripting via message and error No login needed |
≤ 1.11.26 |
CVE-2024-1412 |
Wordfence | |
| 6.5 Medium | Beaver Themer | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via shortcode |
≤ 1.4.9 |
CVE-2023-6695 |
Wordfence | |
| 6.4 Medium | Avada | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 7.11.6 |
CVE-2024-2311 |
Wordfence | |
| 6.4 Medium | JetWidgets For Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Box Widget |
≤ 1.0.15 |
CVE-2024-2138 |
Wordfence | |
| 6.4 Medium | Revslider | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 6.6.20 |
CVE-2024-2306 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Photo Stack Widget |
≤ 3.10.3 |
CVE-2024-1498 |
Wordfence | |
| 6.5 Medium | Classified Listing – Classified ads & Business Directory | Broken Access Control Classified ads & Business Directory Plugin <= 3.0.4 - Missing Authorization No login needed |
≤ 3.0.4 |
CVE-2024-1352 |
Wordfence | |
| 6.4 Medium | Bold Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bt_bb_price_list Shortcode |
≤ 4.8.8 |
CVE-2024-3267 |
Wordfence | |
| 7.2 High | WP ERP | SQL Injection Authenticated (Accounting Manager+) SQL Injection via id |
≤ 1.12.9 |
CVE-2024-0952 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Page Title HTML Tag |
≤ 3.10.4 |
CVE-2024-2787 |
Wordfence | |
| 6.4 Medium | Astra | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Display Name |
≤ 4.6.8 |
CVE-2024-2347 |
Wordfence | |
| 6.5 Medium | VK All in One Expansion Unit | Information Disclosure Information Exposure No login needed |
≤ 9.95.0.1 |
CVE-2024-2093 |
Wordfence | |
| 5.3 Medium | Relevanssi – A Better Search | Broken Access Control A Better Search <= 4.22.1 - Missing Authorization to Unauthenticated Count Option Update No login needed |
≤ 2.25.1, ≤ 4.22.1 |
CVE-2024-3213 |
Wordfence | |
| 8.8 High | Appointment Booking Calendar — Simply Schedule Appointments Booking | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 1.6.7.7 |
CVE-2024-2341 |
Wordfence | |
| 6.4 Medium | FooGallery | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 2.4.14 |
CVE-2024-2081 |
Wordfence | |
| 5.3 Medium | Graphene | Broken Access Control Missing Authorization No login needed |
≤ 2.9.2 |
CVE-2024-1984 |
Wordfence | |
| 6.4 Medium | Ecwid Ecommerce Shopping Cart | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 6.12.10 |
CVE-2024-2456 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Widget |
≤ 8.3.4 |
CVE-2024-1458 |
Wordfence | |
| 6.4 Medium | Elementor Addon Elements | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'Text Separator' and 'Image Compare' Widget |
≤ 1.13.2 |
CVE-2024-2792 |
Wordfence | |
| 6.4 Medium | Stackable – Page Builder Gutenberg Blocks | Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.12.11 - Authenticated(Contributor+) Stored Cross-Site Scripting via Posts Block |
≤ 3.12.11 |
CVE-2024-2039 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget |
≤ 8.3.4 |
CVE-2024-1461 |
Wordfence | |
| 8.8 High | Pods | Remote Code Execution Custom Content Types and Fields - Authenticated (Contributor+) Remote Code Execution |
< 2.7.31, 2.8 – < 2.8.23.2, 3 – < 3.0.10.2 Fixed in 2.7.31 |
CVE-2023-6999 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.4 - Authenticated (Contributor+) Stored Cross-site Scripting via QR Code Widget |
≤ 2.8.4 |
CVE-2024-2946 |
Wordfence | |
| 6.4 Medium | Global Elementor Buttons | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via button link |
≤ 1.1.0 |
CVE-2024-2327 |
Wordfence | |
| 7.2 High | Everest Forms | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via font_url No login needed |
≤ 2.0.7 |
CVE-2024-1812 |
Wordfence | |
| 6.4 Medium | Spectra – WordPress Gutenberg Blocks | Cross-Site Scripting WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS |
≤ 2.10.3 |
CVE-2023-6486 |
Wordfence | |
| 7.5 High | Hubbub Lite – Fast, Reliable Social Network Sharing Buttons | PHP Object Injection Fast, Reliable Social Network Sharing Buttons <= 1.33.1 - PHP Object Injection |
≤ 1.33.1 |
CVE-2024-2501 |
Wordfence | |
| 6.4 Medium | Sydney Toolbox | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery |
≤ 1.28 |
CVE-2024-3208 |
Wordfence | |
| 7.2 High | Avada | SQL Injection Authenticated (Admin+) SQL Injection via entry |
≤ 7.11.6 |
CVE-2024-2344 |
Wordfence | |
| 6.8 Medium | File Manager | Path Traversal Authenticated (Administrator+) Directory Traversal |
≤ 7.2.5 |
CVE-2024-2654 |
Wordfence | |
| 6.4 Medium | Elementor Website Builder – More than Just a Page Builder | Cross-Site Scripting More than Just a Page Builder <= 3.20.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Path Widget |
≤ 3.20.2 |
CVE-2024-2117 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes |
≤ 1.8.4 |
CVE-2024-2504 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.