WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 27,901–27,950 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 559 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Travelpayouts Plugin travelpayouts Open Redirect No login needed ≤ 1.1.15 CVE-2024-0337 WPScan
5.4 Medium System Dashboard Plugin system-dashboard Cross-Site Scripting XSS via Header Injection No login needed < 2.8.10 Fixed in 2.8.10 CVE-2023-7246 WPScan
6.4 Medium Standout Color Boxes and Buttons Plugin standout-color-boxes-and-buttons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.7.0 CVE-2024-2474 Wordfence
6.4 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Cross-Site Scripting Weglot <= 4.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 4.2.5 CVE-2024-2124 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.3 CVE-2024-2255 Wordfence
8.8 High GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in Plugin SQL Injection The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 6.8.6 CVE-2024-1799 Wordfence
6.4 Medium GamiPress – Button Plugin gamipress-button Cross-Site Scripting Button <= 1.0.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.7 CVE-2024-2460 Wordfence
4.3 Medium WooCommerce POS Plugin Information Disclosure Insufficient Verification of Data Authenticity to Authenticated (Customer+) Information Disclosure ≤ 1.4.11 CVE-2024-2384 Wordfence
4.3 Medium Smart Custom Fields Plugin smart-custom-fields Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure ≤ 4.2.2 CVE-2024-1995 Wordfence
6.4 Medium Contests by Rewards Fuel Plugin contests-from-rewards-fuel Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via update_rewards_fuel_api_key ≤ 2.0.64 CVE-2024-1787 Wordfence
5.4 Medium Contests by Rewards Fuel Plugin contests-from-rewards-fuel Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.0.62 CVE-2024-1785 Wordfence
6.1 Medium Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms Plugin advanced-form-integration SQL Injection Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id No login needed ≤ 1.82.0 CVE-2024-2387 Wordfence
5.9 Medium Survey Maker Plugin survey-maker Cross-Site Scripting ≤ 4.0.5 Fixed in 4.0.6 CVE-2024-27996 Patchstack
5.9 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.6.0 Fixed in 45.7.0 CVE-2024-27997 Patchstack
7.1 High Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2024-27998 Patchstack
6.5 Medium Five Star Restaurant Menu Plugin food-and-drink-menu Cross-Site Scripting ≤ 2.4.14 Fixed in 2.4.15 CVE-2024-29089 Patchstack
7.1 High WP Armour – Honeypot Anti Spam Plugin honeypot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.13 Fixed in 2.1.14 CVE-2024-29091 Patchstack
7.1 High Permalink Manager Lite Plugin permalink-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.3 Fixed in 2.4.3.1 CVE-2024-29092 Patchstack
4.3 Medium Builder for WooCommerce reviews shortcodes – ReviewShort Plugin woo-product-reviews-shortcode Cross-Site Request Forgery ReviewShort plugin <= 1.01.3 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.01.3 Fixed in 1.01.4 CVE-2024-29093 Patchstack
7.1 High HT Easy GA4 ( Google Analytics 4 ) Plugin ht-easy-google-analytics Cross-Site Scripting No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2024-29094 Patchstack
5.9 Medium Site Reviews Plugin site-reviews Cross-Site Scripting ≤ 6.11.6 Fixed in 6.11.7 CVE-2024-29095 Patchstack
6.5 Medium MJM Clinic Plugin mjm-clinic Cross-Site Scripting ≤ 1.1.22 Fixed in 1.1.23 CVE-2024-29096 Patchstack
6.3 Medium User profile Plugin user-profile Cross-Site Scripting Subscriber+ Stored Cross Site Scripting (XSS) ≤ 2.0.20 Fixed in 2.0.21 CVE-2024-29097 Patchstack
6.5 Medium WP Calameo Plugin wp-calameo Cross-Site Scripting ≤ 2.1.7 Fixed in 2.1.8 CVE-2024-29098 Patchstack
7.1 High Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2024-29099 Patchstack
6.5 Medium Jeg Elementor Kit Plugin jeg-elementor-kit Cross-Site Scripting ≤ 2.6.2 Fixed in 2.6.3 CVE-2024-29101 Patchstack
7.1 High Extensions For CF7 Plugin extensions-for-cf7 Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29102 Patchstack
7.1 High Database for Contact Form 7 Plugin cf7-database Cross-Site Scripting Unauthenticated Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2024-29103 Patchstack
6.5 Medium Ticket Tailor Plugin ticket-tailor Cross-Site Scripting ≤ 1.10 Fixed in 1.12 CVE-2024-29104 Patchstack
5.9 Medium WP Popups Plugin wp-popups-lite Cross-Site Scripting WordPress Popup builder plugin <= 2.1.5.5 - Cross Site Scripting (XSS) ≤ 2.1.5.5 Fixed in 2.1.5.6 CVE-2024-29105 Patchstack
6.5 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Scripting ≤ 4.10.16 Fixed in 4.10.17 CVE-2024-29106 Patchstack
6.5 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting ≤ 1.12.10 Fixed in 1.12.11 CVE-2024-29107 Patchstack
6.5 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting ≤ 3.10.1 Fixed in 3.10.2 CVE-2024-29108 Patchstack
6.5 Medium Shariff Wrapper Plugin shariff Cross-Site Scripting Contributor+ Cross Site Scripting (XSS) ≤ 4.6.10 Fixed in 4.6.11 CVE-2024-29109 Patchstack
7.1 High Table & Contact Form 7 Database – Tablesome Plugin tablesome Cross-Site Scripting No login needed ≤ 1.0.27 Fixed in 1.0.28 CVE-2024-29110 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2024-29111 Patchstack
5.9 Medium WooCommerce Google Feed Manager Plugin wp-product-feed-manager Cross-Site Scripting ≤ 2.2.0 Fixed in 2.3.0 CVE-2024-29112 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-29113 Patchstack
6.5 Medium Download Manager Plugin download-manager Cross-Site Scripting ≤ 3.2.84 Fixed in 3.2.85 CVE-2024-29114 Patchstack
6.5 Medium Smart Online Order for Clover Plugin clover-online-orders Cross-Site Scripting ≤ 1.5.5 Fixed in 1.5.6 CVE-2024-29115 Patchstack
7.1 High WooThumbs for WooCommerce by Iconic Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.5.3 Fixed in 5.5.4 CVE-2024-29116 Patchstack
7.1 High Contact Forms by Cimatti Plugin contact-forms Cross-Site Scripting Unauthenticated Stored Cross Site Scripting (XSS) No login needed ≤ 1.7.0 Fixed in 1.8.0 CVE-2024-29117 Patchstack
6.5 Medium Scrollsequence Plugin scrollsequence Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2024-29118 Patchstack
7.1 High WooCommerce License Manager Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2024-29121 Patchstack
6.5 Medium FV Flowplayer Video Player Plugin fv-wordpress-flowplayer Cross-Site Scripting ≤ 7.5.41.7212 Fixed in 7.5.44.7212 CVE-2024-29122 Patchstack
7.1 High Link Library Plugin link-library Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6 Fixed in 7.6.1 CVE-2024-29123 Patchstack
4.8 Medium Profile Box Shortcode And Widget Plugin facebook-likebox-widget-and-shortcode Cross-Site Scripting Profile Box Shortcode And Widget < 1.2.1 Admin+ Stored XSS < 1.2.1 Fixed in 1.2.1 CVE-2024-1401 WPScan
5.9 Medium Advanced Access Manager Plugin advanced-access-manager Cross-Site Scripting ≤ 6.9.20 Fixed in 6.9.21 CVE-2024-29124 Patchstack
7.1 High Coupon Affiliates Plugin woo-coupon-usage Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.12.7 Fixed in 5.12.8 CVE-2024-29125 Patchstack
7.1 High Specific Content For Mobile – Customize the mobile version without redirections Plugin specific-content-for-mobile Cross-Site Scripting No login needed ≤ 0.1.9.5 Fixed in 0.1.9.6 CVE-2024-29126 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only