WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,201–27,250 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 545 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High CMB2 Plugin cmb2 PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.10.1 CVE-2024-1792 Wordfence
4.3 Medium Pods Plugin pods Broken Access Control Custom Content Types and Fields - Missing Authorization < 2.7.31, 2.8 – < 2.8.23.2, 3 – < 3.0.10.2 Fixed in 2.7.31 CVE-2023-6965 Wordfence
6.4 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Cross-Site Scripting Donation Plugin and Fundraising Platform <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.5.1 CVE-2024-1424 Wordfence
6.4 Medium Watu Quiz Plugin watu Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2024-0873 Wordfence
4.3 Medium Advanced Classifieds & Directory Pro Plugin advanced-classifieds-and-directory-pro Broken Access Control Missing Authorization to Arbitrary Attachment Deletion ≤ 3.0.0 CVE-2024-2222 Wordfence
5.3 Medium Newsmatic Theme newsmatic Information Disclosure Unauthenticated Information Exposure via newsmatic_filter_posts_load_tab_content No login needed ≤ 1.3.4 CVE-2024-1587 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Calendy ≤ 3.10.4 CVE-2024-2789 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.11 CVE-2024-2623 Wordfence
6.1 Medium Link Library Plugin link-library Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.6.6 CVE-2024-2325 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget ≤ 3.2.25 CVE-2024-1999 Wordfence
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
6.4 Medium Knight Lab Timeline Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.3.3 CVE-2024-2287 Wordfence
4.3 Medium Happy Addons for Elementor Plugin happy-elementor-addons Broken Access Control Incorrect Authorization to Information Exposure ≤ 3.10.4 CVE-2024-1387 Wordfence
6.4 Medium Gum Elementor Addon Plugin gum-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta Widget ≤ 1.3.2 CVE-2024-2348 Wordfence
4.3 Medium Watu Quiz Plugin watu Information Disclosure Sensitive Information Disclosure ≤ 3.4.1 CVE-2024-0872 Wordfence
6.4 Medium Cards for Beaver Builder Plugin bb-bootstrap-cards Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via bootstrapcard link ≤ 1.1.2 CVE-2024-2305 Wordfence
4.4 Medium LearnPress Plugin learnpress Cross-Site Scripting Authenticated(LP Instructor+) Stored Cross-Site Scripting ≤ 4.2.6.3 CVE-2024-1463 Wordfence
6.4 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.6 CVE-2024-3167 Wordfence
8.8 High Easy Property Listings Plugin easy-property-listings SQL Injection Authenticated(Contributor+) SQL Injection via Shortcode ≤ 3.5.2 CVE-2024-1893 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Widget Button URL ≤ 1.0.16 CVE-2024-2507 Wordfence
6.4 Medium PowerPack Lite for Beaver Builder Plugin powerpack-addon-for-beaver-builder Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via element link ≤ 1.3.0 CVE-2024-2289 Wordfence
6.4 Medium WordPress File Upload Plugin Arbitrary File Upload Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.24.5 CVE-2024-2847 Wordfence
6.4 Medium Elements Plus! Plugin elements-plus Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via widget links ≤ 2.16.2 CVE-2024-2335 Wordfence
9.8 Critical MasterStudy LMS Plugin masterstudy-lms-learning-management-system Local File Inclusion Unauthenticated Local File Inclusion via template No login needed ≤ 3.3.3 CVE-2024-3136 Wordfence
6.4 Medium Media Library Assistant Plugin media-library-assistant SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 3.13 CVE-2024-2871 Wordfence
5.8 Medium Relevanssi – A Better Search Plugin relevanssi Content Injection A Better Search <= 4.22.1 - Unauthenticated Second Order CSV Injection No login needed ≤ 2.25.1, ≤ 4.22.1 CVE-2024-3214 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Carousel Widget ≤ 8.3.4 CVE-2024-1465 Wordfence
4.4 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings ≤ 3.2.17 CVE-2024-0598 Wordfence
5.3 Medium Avada Theme Information Disclosure Unauthenticated Sensitive Information Exposure via Form Uploads Directory Listing No login needed ≤ 7.11.6 CVE-2024-2340 Wordfence
9.8 Critical Simple Job Board Plugin simple-job-board PHP Object Injection Unauthenticated PHP Object Injection via Job Application Fields No login needed ≤ 2.11.0 CVE-2024-1813 Wordfence
7.5 High WP Compress – Image Optimizer Plugin wp-compress-image-optimizer Broken Access Control Image Optimizer <= 6.11.08 - Missing Authorization to Unauthenticated CDN Modification No login needed ≤ 6.11.10 CVE-2024-1934 Wordfence
6.4 Medium Passster Plugin content-protector Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via content_protector Shortcode ≤ 4.2.6.4 CVE-2024-2026 Wordfence
6.4 Medium Avada Theme Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via form_to_url_action ≤ 7.11.6 CVE-2024-2343 Wordfence
4.9 Medium Ajax Load More Plugin ajax-load-more Path Traversal Authenticated (Admin+) Directory Traversal to Arbitrary File Read ≤ 7.0.1 CVE-2024-1790 Wordfence
8.8 High Link Whisper Free Plugin link-whisper PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 0.7.1 CVE-2024-2693 Wordfence
6.4 Medium Rank Math SEO with AI SEO Tools Plugin seo-by-rank-math Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via HowTo block attributes ≤ 1.0.214 CVE-2024-2536 Wordfence
5.3 Medium s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions Plugin s2member Information Disclosure Best Membership Plugin for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions <= 230815 - Information Exposure No login needed ≤ 230815 CVE-2024-0899 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Slider Widget ≤ 8.3.4 CVE-2024-1464 Wordfence
7.5 High WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score Plugin Information Disclosure One Click Free SSL Certificate & SSL / HTTPS Redirect to Force HTTPS, SSL Score <= 7.0 - Sensitive Information Exposure via insufficiently protected files No login needed ≤ 7.0 CVE-2023-7046 Wordfence
5.3 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Information Disclosure Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.13 - Unauthenticated Sensitive Information Exposure No login needed ≤ 5.9.13 CVE-2024-2974 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Heading Widget ≤ 1.3.4 CVE-2024-2183 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.14 CVE-2024-3244 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 5.3.0.0 CVE-2024-1991 Wordfence
5.3 Medium WordPress Gallery Plugin – NextGEN Gallery Plugin nextgen-gallery Broken Access Control NextGEN Gallery <= 3.59 - Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 3.59 CVE-2024-3097 Wordfence
4.3 Medium Plugin Permalink Plugin Broken Access Control Missing Authorization via get_uri_editor ≤ 2.4.3.1 CVE-2024-2543 Wordfence
6.4 Medium Modal Window – create popup modal window Plugin modal-window Cross-Site Scripting create popup modal window <= 5.3.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.3.8 CVE-2024-2457 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Team Members Widget ≤ 1.3.4 CVE-2024-2186 Wordfence
6.4 Medium Happy Addons for Elementor Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title HTML Tag ≤ 3.10.4 CVE-2024-2788 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.11 CVE-2024-2650 Wordfence
6.4 Medium GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin Cross-Site Scripting The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.9.0 CVE-2024-2783 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only