WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,251–27,300 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 546 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Permalink Manager Lite and Permalink Manager Pro Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4.3.1 CVE-2024-2738 Wordfence
6.4 Medium Getwid – Gutenberg Blocks Plugin getwid Cross-Site Scripting Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content ≤ 2.0.5 CVE-2024-1948 Wordfence
4.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated Stored Cross-Site Scripting via Video Embed ≤ 9.2.1 CVE-2024-1571 Wordfence
4.3 Medium Paid Memberships Pro Plugin paid-memberships-pro Cross-Site Request Forgery No login needed ≤ 2.12.10 CVE-2024-0588 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget ≤ 1.3.4 CVE-2024-2181 Wordfence
5.9 Medium WP Reset Plugin wp-reset Information Disclosure Sensitive Information Exposure due to Insufficient Randomness No login needed ≤ 2.0 CVE-2023-6799 Wordfence
6.4 Medium Real Media Library: Media Library Folder & File Manager Plugin real-media-library-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.22.7 CVE-2024-2027 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 5.3.1.0 CVE-2024-1990 Wordfence
6.4 Medium Template Kit – Import Plugin template-kit-import Cross-Site Scripting Import <= 1.0.14 - Authenticated(Author+) Stored Cross-Site Scripting via template upload ≤ 1.0.14 CVE-2024-2334 Wordfence
6.4 Medium Elementor Addons by Livemesh Plugin addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Multislider Widget ≤ 8.3.4 CVE-2024-1466 Wordfence
6.1 Medium Contact Form by BestWebSoft Plugin contact-form-plugin Cross-Site Scripting Reflected Cross-Site Scripting via cntctfrm_contact_address No login needed ≤ 4.2.8 CVE-2024-2198 Wordfence
5.3 Medium WooCommerce Clover Payment Gateway Plugin woo-clover-gateway-by-zaytech Broken Access Control Missing Authorization via callback_handler No login needed ≤ 1.3.1 CVE-2024-0626 Wordfence
5.9 Medium Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder Plugin form-maker Information Disclosure Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.22 - Sensitive Information Exposure No login needed ≤ 1.15.22 CVE-2024-2112 Wordfence
4.4 Medium FancyBox Plugin fancybox-for-wordpress Cross-Site Scripting The FancyBox for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 3.0.2 to 3.3.3 due to insufficient input sanitization a… 3.0.2 – 3.3.3 CVE-2024-0662 Wordfence
6.4 Medium Lightweight Accordion Plugin lightweight-accordion Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.16 CVE-2024-2436 Wordfence
8.8 High Classified Listing Plugin classified-listing Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover via rtcl_update_user_account No login needed ≤ 3.0.4 CVE-2024-1315 Wordfence
6.4 Medium SEOPress – On-site SEO Plugin Cross-Site Scripting On-site SEO <= 7.5.2.1 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 7.5.2.1 CVE-2024-2165 Wordfence
5.3 Medium WP Go Maps (formerly WP Google Maps) Plugin Information Disclosure Information Exposure to Potential Denial of Service No login needed ≤ 9.0.34 CVE-2023-6777 Wordfence
5.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via title_tag ≤ 3.10.4 CVE-2024-2786 Wordfence
6.3 Medium AI Post Generator | AutoWriter Plugin Broken Access Control Missing Authorization ≤ 3.3 CVE-2024-1850 Wordfence
6.4 Medium Popup Maker – Popup for opt-ins, lead gen, & more Plugin Cross-Site Scripting Popup for opt-ins, lead gen, & more <= 1.18.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.18.2 CVE-2024-2336 Wordfence
7.5 High WooCommerce Cloak Affiliate Links Plugin woocommerce-cloak-affiliate-links Broken Access Control Missing Authorization to Unauthenticated Permalink Modification No login needed ≤ 1.0.33 CVE-2024-1308 Wordfence
6.4 Medium Qi Addons For Elementor Plugin qi-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.7 CVE-2024-0826 Wordfence
9.8 Critical Network Summary Plugin network-summary SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.11 CVE-2024-2804 Wordfence
6.4 Medium WP Chat App Plugin wp-whatsapp Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Block Image Attribute ≤ 3.6.2 CVE-2024-2513 Wordfence
8.8 High WP Activity Log Premium Plugin SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.6.4 CVE-2024-2018 Wordfence
6.4 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Banner Link ≤ 2.8.1 CVE-2024-1960 Wordfence
6.4 Medium UsersWP Plugin userswp Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.6 CVE-2024-2423 Wordfence
4.3 Medium Event Tickets and Registration Plugin event-tickets Information Disclosure Improper Authorization to Information Disclosure ≤ 5.8.2 CVE-2024-2261 Wordfence
6.4 Medium BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg Plugin Cross-Site Scripting Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.4.2 CVE-2024-2845 Wordfence
8.8 High EnvíaloSimple: Email Marketing y Newsletters Plugin envialosimple-email-marketing-y-newsletters-gratis Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.3 CVE-2024-2125 Wordfence
6.1 Medium Contact Form by BestWebSoft Plugin contact-form-plugin Cross-Site Scripting Reflected Cross-Site Scripting via cntctfrm_contact_subject No login needed ≤ 4.2.8 CVE-2024-2200 Wordfence
6.4 Medium Custom post types, Custom Fields & more Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.0.4 CVE-2023-6993 Wordfence
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widget URL Attribute ≤ 4.8.8 CVE-2024-3266 Wordfence
7.2 High Forminator Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via File Upload No login needed ≤ 1.29.0 CVE-2024-1794 Wordfence
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.4 CVE-2024-2226 Wordfence
4.3 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control Missing Authorization to Sensitive Information Exposure in search_posts ≤ 3.2.13 CVE-2024-1904 Wordfence
4.3 Medium 360 Javascript Viewer Plugin 360deg-javascript-viewer Broken Access Control Missing Authorization to Plugin Settings Update ≤ 1.7.12 CVE-2024-1637 Wordfence
8.8 High Pods Plugin pods SQL Injection Custom Content Types and Fields - Authenticated (Contributor+) SQL Injection via Shortcode < 2.7.31, 2.8 – < 2.8.23.2, 3 – < 3.0.10.2 Fixed in 2.7.31 CVE-2023-6967 Wordfence
6.4 Medium Elementor Addons, Widgets and Enhancements – Stax Plugin stax-addons-for-elementor Cross-Site Scripting Stax <= 1.4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.4.1 CVE-2024-3064 Wordfence
6.4 Medium Forminator – Contact Form, Payment Form & Custom Form Builder Plugin forminator Cross-Site Scripting Contact Form, Payment Form & Custom Form Builder <= 1.29.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via forminator_form Shortcode ≤ 1.29.2 CVE-2024-3053 Wordfence
8.8 High HT Mega – Absolute Addons For Elementor Plugin ht-mega-for-elementor Path Traversal Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal ≤ 2.4.6 CVE-2024-1974 Wordfence
6.4 Medium PowerPack Addons for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Twitter Tweet Widget ≤ 2.7.18 CVE-2024-2492 Wordfence
6.4 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Wrapper Link Widget ≤ 4.10.16 CVE-2024-0376 Wordfence
7.2 High Customily Product Personalizer Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.23.3 CVE-2024-1774 Wordfence
5.4 Medium Accordion Plugin accordions Broken Access Control Missing Authorization to Authenticated(Contributor+) Post Duplication ≤ 2.2.96 CVE-2024-1641 Wordfence
8.8 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin SQL Injection Authenticated (Contributor+) SQL Injection via Shortcode ≤ 1.6.7.7 CVE-2024-2342 Wordfence
6.5 Medium LearnPress Plugin learnpress Broken Access Control Insecure Direct Object Reference No login needed ≤ 4.2.6.3 CVE-2024-1289 Wordfence
5.3 Medium Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) Plugin easy-digital-downloads Information Disclosure Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.2.9 - Sensitive Information Exposure No login needed ≤ 3.2.9 CVE-2024-2302 Wordfence
4.3 Medium Video Conferencing with Zoom Plugin video-conferencing-with-zoom-api Information Disclosure Sensitive Information Exposure ≤ 4.4.5 CVE-2024-2033 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only