WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 28,201–28,250 of 29,070 vulnerabilities
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Enhanced Text Widget | Cross-Site Scripting Admin+ Stored XSS No login needed |
< 1.6.6 Fixed in 1.6.6 |
CVE-2024-0559 |
WPScan | |
| 5.3 Medium | Seriously Simple Podcasting | Information Disclosure Unauthenticated Administrator Email Disclosure No login needed |
< 3.0.0 Fixed in 3.0.0 |
CVE-2023-6444 |
WPScan | |
| 4.3 Medium | Colibri Page Builder | Broken Access Control Missing Authorization |
≤ 1.0.260 |
CVE-2024-1870 |
Wordfence | |
| 6.4 Medium | Blocksy | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.26 |
CVE-2024-1767 |
Wordfence | |
| 5.4 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 3.4.3 |
CVE-2024-1125 |
Wordfence | |
| 6.5 Medium | EventPrime – Events Calendar, Bookings and Tickets | Cross-Site Scripting Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 3.4.3 |
CVE-2024-1320 |
Wordfence | |
| 6.5 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite |
≤ 3.4.2 |
CVE-2024-1123 |
Wordfence | |
| 4.3 Medium | EventPrime – Events Calendar, Bookings and Tickets | Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending |
≤ 3.4.3 |
CVE-2024-1124 |
Wordfence | |
| 4.3 Medium | affiliate-toolkit – WordPress Affiliate | Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_import_product |
≤ 3.5.4 |
CVE-2024-2298 |
Wordfence | |
| 6.3 Medium | affiliate-toolkit – WordPress Affiliate | Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list |
≤ 3.5.4 |
CVE-2024-1851 |
Wordfence | |
| 6.4 Medium | WP-Members Membership | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.4.9.1 |
CVE-2024-1987 |
Wordfence | |
| 8.8 High | Elite Booster for WooCommerce | Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload |
≤ 7.1.7 |
CVE-2024-1986 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block |
≤ 3.9.10 |
CVE-2024-1802 |
Wordfence | |
| 6.4 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Cross-Site Scripting Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes |
≤ 1.8.3 |
CVE-2024-2127 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget |
≤ 3.9.10 |
CVE-2024-2128 |
Wordfence | |
| 8.8 High | Digits: WordPress Mobile Number Signup and Login | Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed |
8.4.1 |
CVE-2024-0203 |
Wordfence | |
| 8.8 High | PDF Invoices and Packing Slips For WooCommerce | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 1.3.7 |
CVE-2024-1773 |
Wordfence | |
| 7.5 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload No login needed |
≤ 2.8.7 |
CVE-2024-1169 |
Wordfence | |
| 8.2 High | Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) | Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion No login needed |
≤ 2.8.7 |
CVE-2024-1170 |
Wordfence | |
| 6.4 Medium | Booster for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde |
≤ 7.1.7 |
CVE-2024-1534 |
Wordfence | |
| 6.4 Medium | WPKoi Templates for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget |
≤ 2.5.6 |
CVE-2024-2136 |
Wordfence | |
| 8.8 High | Restaurant Reservations | Path Traversal Directory Traversal to Authenticated (Contributor+) Local File Inclusion |
≤ 1.9 |
CVE-2024-1382 |
Wordfence | |
| 6.4 Medium | The Plus Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget |
≤ 5.4.0 |
CVE-2024-1419 |
Wordfence | |
| 6.4 Medium | Prime Slider – Addons For Elementor | Cross-Site Scripting Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget |
≤ 3.13.1 |
CVE-2024-1506 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget |
≤ 3.10.3 |
CVE-2024-1377 |
Wordfence | |
| 4.7 Medium | User Registration – Custom Registration Form, Login Form, and User Profile | Cross-Site Scripting Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting No login needed |
≤ 3.1.4 |
CVE-2024-1720 |
Wordfence | |
| 5.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget |
≤ 1.3.91 |
CVE-2024-1500 |
Wordfence | |
| 6.4 Medium | Happy Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget |
≤ 3.10.3 |
CVE-2024-1366 |
Wordfence | |
| 6.4 Medium | WP Chat App | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes |
≤ 3.6.1 |
CVE-2024-1761 |
Wordfence | |
| 6.4 Medium | Social Sharing Plugin – Sassy Social Share | Cross-Site Scripting Sassy Social Share <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.3.58 |
CVE-2024-1989 |
Wordfence | |
| 4.3 Medium | Total | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sections Update |
≤ 2.1.59 |
CVE-2024-1771 |
Wordfence | |
| 4.3 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Reset No login needed |
≤ 1.6.6.20 |
CVE-2024-1760 |
Wordfence | |
| 5.3 Medium | JM Twitter Cards | Information Disclosure Information Exposure via Meta Description No login needed |
≤ 14 |
CVE-2024-1769 |
Wordfence | |
| 5.3 Medium | Change Memory Limit | Broken Access Control Missing Authorization via admin_logic() No login needed |
≤ 1.0 |
CVE-2024-1093 |
Wordfence | |
| 6.5 Medium | Page Builder Sandwich – Front End WordPress Page Builder | Information Disclosure Front End WordPress Page Builder Plugin <= 5.1.0 - Sensitive Information Exposure |
≤ 5.1.0 |
CVE-2024-1381 |
Wordfence | |
| 8.8 High | Vimeography: Vimeo Video Gallery | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 2.3.2 |
CVE-2024-0825 |
Wordfence | |
| 5.3 Medium | Password Protected Store for WooCommerce | Information Disclosure Information Exposure via REST API No login needed |
≤ 2.2 |
CVE-2024-1088 |
Wordfence | |
| 8.8 High | Auto Refresh Single Page | PHP Object Injection Authenticated (Contributor+) PHP Object Injection |
≤ 1.1 |
CVE-2024-1731 |
Wordfence | |
| 6.5 Medium | Page Builder Sandwich | Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Post Editing |
≤ 5.1.0 |
CVE-2024-1285 |
Wordfence | |
| 5.3 Medium | Build & Control Block Patterns – Boost up Gutenberg Editor | Broken Access Control Boost up Gutenberg Editor <= 1.3.5.4 - Missing Authorization No login needed |
≤ 1.3.5.4 |
CVE-2024-1095 |
Wordfence | |
| 6.4 Medium | Easy!Appointments | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-0698 |
Wordfence | |
| 6.1 Medium | Blue Triad EZAnalytics | Cross-Site Scripting Reflected Cross-Site Scripting via 'bt_webid' No login needed |
≤ 1.0 |
CVE-2024-1782 |
Wordfence | |
| 5.3 Medium | Maintenance Mode | Information Disclosure Information Exposure No login needed |
≤ 3.0.1 |
CVE-2024-1478 |
Wordfence | |
| 5.3 Medium | SportsPress – Sports Club & League Manager | Broken Access Control Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update No login needed |
≤ 2.7.17 |
CVE-2024-1178 |
Wordfence | |
| 4.3 Medium | Event Tickets Plus | Information Disclosure Contributor+ Attendees Lists Disclosure |
< 5.9.1 Fixed in 5.9.1 |
CVE-2024-1319 |
WPScan | |
| 6.5 Medium | Event Tickets and Registration | Broken Access Control Contributor+ Arbitrary Events Access |
< 5.8.1, < 5.9.1 Fixed in 5.8.1 |
CVE-2024-1316 |
WPScan | |
| 6.4 Medium | Ultimate Bootstrap Elements for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.6 |
CVE-2024-1398 |
Wordfence | |
| 6.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.9.10 |
CVE-2024-1449 |
Wordfence | |
| 4.4 Medium | Master Slider – Responsive Touch Slider | Cross-Site Scripting Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback |
≤ 3.9.9 |
CVE-2024-0611 |
Wordfence | |
| 5.4 Medium | Master Slider - Responsive Touch Slider | Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed |
≤ 3.9.10 |
CVE-2023-6326 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.