WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,351–27,400 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 548 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium FooGallery Plugin Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Attachment Fields ≤ 2.4.14 CVE-2024-2471 Wordfence
4.8 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting Admin+ Stored XSS < 3.5.0 Fixed in 3.5.0 CVE-2024-2444 WPScan
5.3 Medium WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 4.4.2 CVE-2024-3216 Wordfence
5.3 Medium BoldGrid Easy SEO – Simple and Effective SEO Plugin boldgrid-easy-seo Information Disclosure Simple and Effective SEO <= 1.6.14 - Information Exposure No login needed ≤ 1.6.14 CVE-2024-2950 Wordfence
4.4 Medium Icegram Express Plugin email-subscribers Cross-Site Scripting Authenticated (Administrator+) Cross-Site Scripting via CSV import ≤ 5.7.15 CVE-2024-2656 Wordfence
7.1 High WP-Stateless – Google Cloud Storage Plugin wp-stateless Broken Access Control Google Cloud Storage <= 3.4.0 - Missing Authorization to Limited Arbitrary Options Update ≤ 3.4.0 CVE-2024-1385 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block ≤ 3.9.14 CVE-2024-3245 Wordfence
4.3 Medium Image Watermark Plugin image-watermark Broken Access Control Missing Authorization to Authenticated (Subscriber+) Watermark Modification ≤ 1.7.3 CVE-2024-1994 Wordfence
6.4 Medium Squelch Tabs and Accordions Shortcodes Plugin squelch-tabs-and-accordions-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via accordions Shortcode ≤ 0.4.3 CVE-2024-2499 Wordfence
5.3 Medium WordPress Core Information Disclosure Sensitive Information Exposure via redirect_guess_404_permalink No login needed ≤ 6.4.3 CVE-2023-5692 Wordfence
8.8 High WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 1.3.0 CVE-2024-3217 Wordfence
8.8 High LearnPress – WordPress LMS Plugin learnpress Cross-Site Request Forgery WordPress LMS Plugin <= 4.0.0 - Cross-Site Request Forgery to Privilege Escalation No login needed ≤ 4.0.0 CVE-2024-2115 Wordfence
6.5 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.26 Fixed in 3.2.26 CVE-2024-2509 WPScan
5.3 Medium CGC Maintenance Mode Plugin cgc-maintenance-mode Information Disclosure Sensitive Information Exposure No login needed ≤ 1.2 CVE-2024-1418 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget ≤ 3.2.31 CVE-2024-2919 Wordfence
8.8 High Modal Popup Box – Popup Builder, Show Offers And News in Popup Plugin modal-popup-box PHP Object Injection Popup Builder, Show Offers And News in Popup <= 1.5.2 - Authenticated (Contributor+) PHP Object Injection in awl_modal_popup_box_shortcode ≤ 1.5.2 CVE-2024-2008 Wordfence
6.4 Medium WordPress Tag and Category Manager – AI Autotagger Plugin simple-tags Cross-Site Scripting AI Autotagger <= 3.13.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.0 CVE-2024-2830 Wordfence
4.4 Medium Announce from the Dashboard Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.5.2 CVE-2024-3030 Wordfence
6.4 Medium ElementsKit Elementor addons Plugin elementskit-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 3.0.7 CVE-2024-2803 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout ≤ 2.8.3 CVE-2024-2868 Wordfence
7.2 High BookingPress – Appointment Booking Calendar Plugin and Online Scheduling Plugin bookingpress-appointment-booking Arbitrary File Upload Appointment Booking Calendar Plugin and Online Scheduling Plugin <= 1.0.87 - Authenticated (Admin+) Arbitrary File Upload ≤ 1.0.87 CVE-2024-3022 Wordfence
9.0 Critical VideoWhisper Live Streaming Integration Plugin videowhisper-live-streaming-integration Remote Code Execution No login needed ≤ 5.5.15 Fixed in 5.5.16 CVE-2023-25699 Patchstack
9.9 Critical Cwicly Plugin Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 1.4.0.2 Fixed in 1.4.0.3 CVE-2024-24707 Patchstack
10.0 Critical Canto Plugin canto Remote Code Execution Unauth. Remote Code Execution (RCE) No login needed ≤ 3.0.7 CVE-2024-25096 Patchstack
9.9 Critical InstaWP Connect Plugin instawp-connect Remote Code Execution ≤ 0.1.0.8 Fixed in 0.1.0.9 CVE-2024-25918 Patchstack
8.5 High Slivery Extender Plugin slivery-extender Remote Code Execution ≤ 1.0.2 Fixed in 1.0.3 CVE-2024-27191 Patchstack
9.1 Critical Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Remote Code Execution Auth. Remote Code Execution (RCE) ≤ 3.4.0 Fixed in 3.4.1 CVE-2024-27951 Patchstack
9.9 Critical WP Fusion Lite Plugin wp-fusion-lite Remote Code Execution ≤ 3.41.24 Fixed in 3.42.10 CVE-2024-27972 Patchstack
9.9 Critical Oxygen Builder Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 4.9 CVE-2024-31380 Patchstack
9.9 Critical Breakdance Plugin Remote Code Execution Authenticated Remote Code Execution (RCE) ≤ 1.7.2 CVE-2024-31390 Patchstack
5.3 Medium Survey Maker Plugin survey-maker Other Insufficient verification of data authenticity issue in Survey Maker prior to 3.6.4 allows a remote unauthenticated attacker to spoof an IP address when posting. No login needed prior to 4.1.0 CVE-2023-35764 jpcert
6.1 Medium Survey Maker Plugin survey-maker Cross-Site Scripting Survey Maker prior to 3.6.4 contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the… No login needed prior to 3.6.4 CVE-2023-34423 jpcert
6.8 Medium WooCommerce Cart Abandonment Recovery Plugin Cross-Site Request Forgery Templates/Abandoned Orders Deletion via CSRF < 1.2.27 Fixed in 1.2.27 CVE-2024-2322 WPScan
9.8 Critical LayerSlider Plugin SQL Injection The LayerSlider plugin for WordPress is vulnerable to SQL Injection via the ls_get_popup_markup action in versions 7.9.11 and 7.10.0 due to insufficient escaping on the user suppl… No login needed 7.9.11 – 7.10.0 CVE-2024-2879 Wordfence
6.4 Medium Jeg Elementor Kit Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial ≤ 2.6.3 CVE-2024-3162 Wordfence
6.4 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Box ≤ 2.6.3 CVE-2024-1327 Wordfence
4.9 Medium Nelio Content Plugin nelio-content Server-Side Request Forgery ≤ 3.2.0 Fixed in 3.2.1 CVE-2024-30531 Patchstack
4.9 Medium Builderall Builder Plugin builderall-cheetah-for-wp Server-Side Request Forgery ≤ 2.0.1 Fixed in 2.0.2 CVE-2024-30532 Patchstack
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.25 Fixed in 3.2.26 CVE-2024-24888 Patchstack
7.1 High Tax Rate Upload Plugin tax-rate-upload Cross-Site Request Forgery CSRF leading to Cross Site Scripting (XSS) No login needed ≤ 2.4.5 CVE-2024-31105 Patchstack
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack
6.4 Medium Genesis Blocks Plugin genesis-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Content ≤ 3.1.2 CVE-2024-1946 Wordfence
6.5 Medium Product Sort and Display for WooCommerce Plugin woocommerce-product-sort-and-display Broken Access Control Missing Authorization No login needed ≤ 2.4.1 CVE-2024-1807 Wordfence
5.3 Medium Sharkdropship for AliExpress Dropshipping and Affiliate Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 2.2.4 CVE-2024-1732 Wordfence
4.3 Medium WPFront User Role Editor Plugin wpfront-user-role-editor Information Disclosure Limited Information Exposure ≤ 3.2.1.11184 CVE-2024-2931 Wordfence
6.4 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Cross-Site Scripting WordPress Page Builder <= 2.8.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button ≤ 2.8.0.5 CVE-2024-2925 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.263 CVE-2024-2839 Wordfence
4.3 Medium SecuPress Free — WordPress Security Plugin secupress Cross-Site Request Forgery Cross-Site Request Forgery to Banned IP Address No login needed ≤ 2.2.5.1 CVE-2024-1504 Wordfence
6.4 Medium Creative Addons for Elementor Plugin creative-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.12 CVE-2024-2924 Wordfence
6.4 Medium Metform Elementor Contact Form Builder Plugin metform Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Widgets ≤ 3.8.5 CVE-2024-2791 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only