WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,301–27,350 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 547 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box Widget ≤ 1.3.4 CVE-2024-2185 Wordfence
7.2 High WP-Members Membership Plugin wp-members Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.4.9.2 CVE-2024-1852 Wordfence
6.4 Medium Beaver Builder Addons by WPZOOM Plugin wpzoom-addons-for-beaver-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonials Widget ≤ 1.3.4 CVE-2024-2187 Wordfence
8.5 High AIKit Plugin aikit-wordpress-ai-writing-assistant-using-gpt3 SQL Injection ≤ 4.14.1 CVE-2024-31370 Patchstack
5.4 Medium Soledad Theme Cross-Site Request Forgery No login needed ≤ 8.4.2 CVE-2024-31369 Patchstack
6.5 Medium Soledad Theme Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 8.4.2 CVE-2024-31368 Patchstack
7.1 High Soledad Theme Broken Access Control Authenticated Broken Access Control ≤ 8.4.2 CVE-2024-31367 Patchstack
7.1 High Post Type Builder (PTB) Plugin Broken Access Control Auth. Arbitrary Post/Page Creation ≤ 2.0.8 CVE-2024-31366 Patchstack
7.1 High Post Type Builder (PTB) Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-31365 Patchstack
6.1 Medium Responsive Gallery Grid Plugin responsive-gallery-grid Cross-Site Scripting Admin+ Stored XSS No login needed < 2.3.11 Fixed in 2.3.11 CVE-2024-1664 WPScan
7.5 High BackWPup Plugin backwpup Other Unauthenticated Backup Download No login needed < 4.0.4 Fixed in 4.0.4 CVE-2023-7164 WPScan
5.4 Medium WP2LEADS Plugin wp2leads Broken Access Control ≤ 3.2.7 Fixed in 3.2.8 CVE-2024-31375 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 1.5.2 Fixed in 1.6.0 CVE-2024-31357 Patchstack
4.8 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS < 2.7 Fixed in 2.7 CVE-2024-1958 WPScan
6.1 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS No login needed < 2.7 Fixed in 2.7 CVE-2024-1956 WPScan
6.1 Medium Font Farsi Plugin Cross-Site Scripting Admin+ Stored XSS in Settings No login needed ≤ 1.6.6 CVE-2024-1752 WPScan
6.1 Medium SendPress Newsletters Plugin Cross-Site Scripting Admin+ Stored XSS via Form Settings No login needed ≤ 1.23.11.6 CVE-2024-1589 WPScan
6.8 Medium SendPress Newsletters Plugin Cross-Site Scripting Admin+ Stored XSS via Settings ≤ 1.23.11.6 CVE-2024-1588 WPScan
4.7 Medium WPB Show Core Plugin Cross-Site Scripting Reflected XSS No login needed < 2.7 Fixed in 2.7 CVE-2024-1292 WPScan
4.3 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Broken Access Control IDOR on Friend Request ≤ 5.7.6 Fixed in 5.7.7 CVE-2024-31291 Patchstack
4.3 Medium BookingPress Plugin bookingpress-appointment-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.0.81 Fixed in 1.0.82 CVE-2024-31296 Patchstack
8.5 High Rehub Theme SQL Injection Auth. SQL Injection ≤ 19.6.1 Fixed in 19.6.2 CVE-2024-31233 Patchstack
8.5 High REHub Framework Plugin SQL Injection < 19.6.2 Fixed in 19.6.2 CVE-2024-31234 Patchstack
7.6 High LearnPress Export Import Plugin learnpress-import-export SQL Injection Auth. SQL Injection ≤ 4.0.3 Fixed in 4.0.4 CVE-2024-31241 Patchstack
7.6 High Edwiser Bridge Plugin edwiser-bridge SQL Injection ≤ 3.0.2 Fixed in 3.0.4 CVE-2024-31260 Patchstack
4.3 Medium WooCommerce Plugin woocommerce Cross-Site Request Forgery No login needed ≤ 8.5.2 Fixed in 8.6.0 CVE-2024-22155 Patchstack
6.5 Medium Royal Elementor Addons Plugin royal-elementor-addons Cross-Site Scripting ≤ 1.3.93 Fixed in 1.3.95 CVE-2024-31236 Patchstack
7.1 High ELEX WooCommerce Dynamic Pricing and Discounts Plugin elex-woocommerce-dynamic-pricing-and-discounts Cross-Site Scripting No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2024-31255 Patchstack
7.1 High WebinarPress Plugin wp-webinarsystem Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.33.10 Fixed in 1.3.11 CVE-2024-31256 Patchstack
6.5 Medium Formsite | Embed online forms to collect orders, registrations, leads, and surveys Plugin formsite Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-31257 Patchstack
6.5 Medium Form to Chat App Plugin form-to-chat Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2024-31258 Patchstack
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-31306 Patchstack
5.9 Medium Easy Login Styler – White Label Admin Login Page Plugin easy-login-styler Cross-Site Scripting ≤ 1.0.6 CVE-2024-31344 Patchstack
6.5 Medium Gradient Text Widget for Elementor Plugin gradient-text-widget-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-31346 Patchstack
6.5 Medium Testimonials Plugin super-testimonial Cross-Site Scripting ≤ 3.0.5 Fixed in 3.0.6 CVE-2024-31348 Patchstack
6.5 Medium MailMunch – Grow your Email List Plugin mailmunch Cross-Site Scripting Grow your Email List plugin <= 3.1.6 - Cross Site Scripting (XSS) ≤ 3.1.6 Fixed in 3.1.7 CVE-2024-31349 Patchstack
9.9 Critical Church Admin Plugin church-admin Arbitrary File Upload ≤ 4.1.5 Fixed in 4.1.6 CVE-2024-31280 Patchstack
9.9 Critical WP Photo Album Plus Plugin wp-photo-album-plus Arbitrary File Upload < 8.6.03.005 Fixed in 8.6.03.005 CVE-2024-31286 Patchstack
7.2 High Import XML and RSS Feeds Plugin import-xml-feed Arbitrary File Upload ≤ 2.1.5 Fixed in 2.1.6 CVE-2024-31292 Patchstack
9.1 Critical Auto Poster Plugin auto-poster Arbitrary File Upload ≤ 1.2 CVE-2024-31345 Patchstack
8.7 High Product Designer Plugin product-designer PHP Object Injection No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2024-31277 Patchstack
4.4 Medium WP Import Export Lite Plugin wp-import-export-lite PHP Object Injection ≤ 3.9.26 Fixed in 3.9.27 CVE-2024-31308 Patchstack
7.2 High RapidLoad Power-Up for Autoptimize Plugin unusedcss Server-Side Request Forgery No login needed ≤ 2.2.11 Fixed in 2.2.12 CVE-2024-31288 Patchstack
6.4 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message ≤ 4.3.3 CVE-2023-6877 Wordfence
5.5 Medium Photo Gallery by 10Web – Mobile-Friendly Image Gallery Plugin photo-gallery Cross-Site Scripting Mobile-Friendly Image Gallery <= 1.8.21 - Authenticated (Admin+) Stored Cross-Site Scripting via SVG ≤ 1.8.21 CVE-2024-2296 Wordfence
6.4 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Widget ≤ 1.4.0 CVE-2024-2132 Wordfence
6.4 Medium Powerkit – Supercharge your WordPress Site Plugin powerkit Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.9.1 CVE-2024-2458 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget ≤ 5.3.2 CVE-2024-0837 Wordfence
6.4 Medium Element Pack – Widgets, Templates & Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget ≤ 5.5.3 CVE-2024-1428 Wordfence
6.4 Medium Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel Plugin wp-carousel-free Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' ≤ 2.6.3 CVE-2024-2949 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only