WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,701–27,750 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 555 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium Simple Ajax Chat Plugin simple-ajax-chat Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 20231101 CVE-2024-2956 Wordfence
7.1 High Advanced Sermons Plugin advanced-sermons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1 Fixed in 3.2 CVE-2024-29928 Patchstack
6.5 Medium WishSuite Plugin wishsuite Cross-Site Scripting ≤ 1.3.7 Fixed in 1.3.8 CVE-2024-29927 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.0.18 Fixed in 1.0.19 CVE-2024-29926 Patchstack
6.5 Medium Post Grid, Slider & Carousel Ultimate Plugin post-grid-carousel-ultimate Cross-Site Scripting ≤ 1.6.6 Fixed in 1.6.7 CVE-2024-29925 Patchstack
7.1 High Premium Packages Plugin wpdm-premium-packages Cross-Site Scripting No login needed ≤ 5.8.2 Fixed in 5.8.3 CVE-2024-29924 Patchstack
7.1 High PropertyHive Plugin propertyhive Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2024-29923 Patchstack
5.9 Medium Slider Hero Plugin slider-hero Cross-Site Scripting ≤ 8.6.1 Fixed in 8.7.0 CVE-2024-29922 Patchstack
5.9 Medium Photo Gallery by Supsystic Plugin gallery-by-supsystic Cross-Site Scripting ≤ 1.15.16 Fixed in 1.15.17 CVE-2024-29921 Patchstack
6.5 Medium Move Addons for Elementor Plugin move-addons Cross-Site Scripting ≤ 1.2.9 Fixed in 1.3.0 CVE-2024-29920 Patchstack
7.1 High Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.2 Fixed in 5.5.3 CVE-2024-29919 Patchstack
7.1 High Survey Maker Plugin survey-maker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.6 Fixed in 4.0.7 CVE-2024-29918 Patchstack
6.5 Medium Compact WP Audio Player Plugin compact-wp-audio-player Cross-Site Scripting ≤ 1.9.9 Fixed in 1.9.10 CVE-2024-29917 Patchstack
7.1 High Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2024-29915 Patchstack
6.5 Medium Stratum Plugin stratum Cross-Site Scripting Elementor Widgets plugin <= 1.3.15 - Cross Site Scripting (XSS) ≤ 1.3.15 Fixed in 1.3.16 CVE-2024-29914 Patchstack
6.5 Medium Tutor LMS Elementor Addons Plugin tutor-lms-elementor-addons Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-29913 Patchstack
6.5 Medium iCalendrier Plugin icalendrier Cross-Site Scripting ≤ 1.80 Fixed in 1.81 CVE-2024-29912 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Cross-Site Scripting ≤ 2.0.5.4.1 Fixed in 2.0.5.6 CVE-2024-29911 Patchstack
6.5 Medium Dropdown Multisite selector Plugin dropdown-multisite-selector Cross-Site Scripting ≤ 0.9.2 Fixed in 0.9.2.1 CVE-2024-29910 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.2.0 Fixed in 2.2.1 CVE-2024-29909 Patchstack
6.5 Medium Co-marquage service-public.fr Plugin co-marquage-service-public Cross-Site Scripting ≤ 0.5.71 Fixed in 0.5.72 CVE-2024-29908 Patchstack
6.5 Medium PDF Builder for WPForms Plugin pdf-builder-for-wpforms Cross-Site Scripting ≤ 1.2.88 Fixed in 1.2.89 CVE-2024-29820 Patchstack
5.9 Medium WordPress Meta Data and Taxonomies Filter (MDTF) Plugin wp-meta-data-filter-and-taxonomy-filter Cross-Site Scripting Meta Data and Taxonomies Filter plugin <= 1.3.2 - Cross Site Scripting (XSS) ≤ 1.3.2 Fixed in 1.3.3 CVE-2024-29906 Patchstack
7.1 High SEO Backlink Monitor Plugin seo-backlink-monitor Cross-Site Scripting No login needed ≤ 1.5.0 Fixed in 1.6.0 CVE-2024-29907 Patchstack
6.5 Medium GS Pins for Pinterest Plugin gs-pinterest-portfolio Cross-Site Scripting ≤ 1.8.2 Fixed in 1.8.3 CVE-2024-30192 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 4.1.17 Fixed in 4.1.18 CVE-2024-30193 Patchstack
7.2 High Action Network Plugin wp-action-network SQL Injection The Action Network plugin for WordPress is vulnerable to SQL Injection via the 'bulk-action' parameter in version 1.4.3 due to insufficient escaping on the user supplied parameter… 1.4.3 CVE-2024-2954 Wordfence
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Navigation ≤ 3.20.1 CVE-2024-2120 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Form Widget SVGZ File Upload ≤ 3.20.1 CVE-2024-1521 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via video_html_tag ≤ 3.20.1 CVE-2024-2781 Wordfence
5.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.1 CVE-2024-2121 Wordfence
6.4 Medium Elementor Website Builder Pro Plugin Cross-Site Scripting Authententicated (Contributor+) Stored Cross-Site Scripting ≤ 3.20.1 CVE-2024-1364 Wordfence
7.1 High Sunshine Photo Cart Plugin sunshine-photo-cart Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2024-30194 Patchstack
7.1 High New RoyalSlider Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2024-30195 Patchstack
7.1 High Easy Social Share Buttons Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.4 Fixed in 9.5 CVE-2024-30196 Patchstack
5.9 Medium Breeze Plugin breeze Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2024-27188 Patchstack
6.5 Medium Church Admin Plugin church-admin Cross-Site Scripting ≤ 4.0.26 Fixed in 4.0.27 CVE-2024-30197 Patchstack
5.8 Medium BuddyForms Plugin buddyforms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.8.5 Fixed in 2.8.6 CVE-2024-30198 Patchstack
7.1 High WordPress Importer Plugin wp-smart-import Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 Fixed in 1.0.5 CVE-2024-30201 Patchstack
7.1 High WP-Lister Lite for Amazon Plugin wp-lister-for-amazon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2024-30199 Patchstack
7.1 High FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.5.41.7212 Fixed in 7.5.44.7212 CVE-2024-22299 Patchstack
7.1 High Email Subscribers & Newsletters Plugin email-subscribers Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.7.11 Fixed in 5.7.12 CVE-2024-22300 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.24 Fixed in 2.0.25 CVE-2023-52228 Patchstack
7.1 High CformsII Plugin cforms2 Cross-Site Scripting No login needed ≤ 15.0.5 CVE-2024-22149 Patchstack
7.1 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.4.0 Fixed in 4.4.1 CVE-2024-22288 Patchstack
7.1 High WP Editor Plugin wp-editor Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2024-24700 Patchstack
7.1 High Product Feed PRO for WooCommerce Plugin woo-product-feed-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 13.2.5 Fixed in 13.2.6 CVE-2024-24800 Patchstack
6.5 Medium WP SMS Plugin wp-sms Cross-Site Scripting ≤ 6.3.4 Fixed in 6.4 CVE-2024-25920 Patchstack
7.1 High Widgets Controller Plugin widgets-controller Cross-Site Scripting No login needed ≤ 1.1 CVE-2024-25926 Patchstack
7.1 High Fusion Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39306 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only