WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 28,201–28,250 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 565 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Enhanced Text Widget Plugin enhanced-text-widget Cross-Site Scripting Admin+ Stored XSS No login needed < 1.6.6 Fixed in 1.6.6 CVE-2024-0559 WPScan
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Information Disclosure Unauthenticated Administrator Email Disclosure No login needed < 3.0.0 Fixed in 3.0.0 CVE-2023-6444 WPScan
4.3 Medium Colibri Page Builder Plugin colibri-page-builder Broken Access Control Missing Authorization ≤ 1.0.260 CVE-2024-1870 Wordfence
6.4 Medium Blocksy Theme blocksy Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.26 CVE-2024-1767 Wordfence
5.4 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 3.4.3 CVE-2024-1125 Wordfence
6.5 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Cross-Site Scripting Events Calendar, Bookings and Tickets <= 3.4.3 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.4.3 CVE-2024-1320 Wordfence
6.5 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.2 - Missing Authorization to Arbitrary Post Overwrite ≤ 3.4.2 CVE-2024-1123 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin Broken Access Control Events Calendar, Bookings and Tickets <= 3.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 3.4.3 CVE-2024-1124 Wordfence
4.3 Medium affiliate-toolkit – WordPress Affiliate Plugin affiliate-toolkit-starter Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_import_product ≤ 3.5.4 CVE-2024-2298 Wordfence
6.3 Medium affiliate-toolkit – WordPress Affiliate Plugin affiliate-toolkit-starter Broken Access Control WordPress Affiliate Plugin <= 3.5.4 - Missing Authorization via atkp_create_list ≤ 3.5.4 CVE-2024-1851 Wordfence
6.4 Medium WP-Members Membership Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.4.9.1 CVE-2024-1987 Wordfence
8.8 High Elite Booster for WooCommerce Plugin woocommerce-jetpack Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 7.1.7 CVE-2024-1986 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block ≤ 3.9.10 CVE-2024-1802 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes ≤ 1.8.3 CVE-2024-2127 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget ≤ 3.9.10 CVE-2024-2128 Wordfence
8.8 High Digits: WordPress Mobile Number Signup and Login Plugin Cross-Site Request Forgery The Digits plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.1. This is due to missing nonce validation in the 'digits_save_se… No login needed 8.4.1 CVE-2024-0203 Wordfence
8.8 High PDF Invoices and Packing Slips For WooCommerce Plugin pdf-invoices-and-packing-slips-for-woocommerce PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.3.7 CVE-2024-1773 Wordfence
7.5 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Upload No login needed ≤ 2.8.7 CVE-2024-1169 Wordfence
8.2 High Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) Plugin buddyforms Broken Access Control Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) <= 2.8.7 - Missing Authorization to Unauthenticated Media Deletion No login needed ≤ 2.8.7 CVE-2024-1170 Wordfence
6.4 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortocde ≤ 7.1.7 CVE-2024-1534 Wordfence
6.4 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget ≤ 2.5.6 CVE-2024-2136 Wordfence
8.8 High Restaurant Reservations Plugin nd-restaurant-reservations Path Traversal Directory Traversal to Authenticated (Contributor+) Local File Inclusion ≤ 1.9 CVE-2024-1382 Wordfence
6.4 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting Header Meta Content Widget ≤ 5.4.0 CVE-2024-1419 Wordfence
6.4 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Cross-Site Scripting Addons For Elementor <= 3.13.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Fiestar Widget ≤ 3.13.1 CVE-2024-1506 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Author Meta Widget ≤ 3.10.3 CVE-2024-1377 Wordfence
4.7 Medium User Registration – Custom Registration Form, Login Form, and User Profile Plugin user-registration Cross-Site Scripting Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting No login needed ≤ 3.1.4 CVE-2024-1720 Wordfence
5.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget ≤ 1.3.91 CVE-2024-1500 Wordfence
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Archive Title Widget ≤ 3.10.3 CVE-2024-1366 Wordfence
6.4 Medium WP Chat App Plugin wp-whatsapp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes ≤ 3.6.1 CVE-2024-1761 Wordfence
6.4 Medium Social Sharing Plugin – Sassy Social Share Plugin sassy-social-share Cross-Site Scripting Sassy Social Share <= 3.3.58 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.3.58 CVE-2024-1989 Wordfence
4.3 Medium Total Theme total Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sections Update ≤ 2.1.59 CVE-2024-1771 Wordfence
4.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Data Reset No login needed ≤ 1.6.6.20 CVE-2024-1760 Wordfence
5.3 Medium JM Twitter Cards Plugin jm-twitter-cards Information Disclosure Information Exposure via Meta Description No login needed ≤ 14 CVE-2024-1769 Wordfence
5.3 Medium Change Memory Limit Plugin change-memory-limit Broken Access Control Missing Authorization via admin_logic() No login needed ≤ 1.0 CVE-2024-1093 Wordfence
6.5 Medium Page Builder Sandwich – Front End WordPress Page Builder Plugin page-builder-sandwich Information Disclosure Front End WordPress Page Builder Plugin <= 5.1.0 - Sensitive Information Exposure ≤ 5.1.0 CVE-2024-1381 Wordfence
8.8 High Vimeography: Vimeo Video Gallery Plugin vimeography PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 2.3.2 CVE-2024-0825 Wordfence
5.3 Medium Password Protected Store for WooCommerce Plugin password-protected-woo-store Information Disclosure Information Exposure via REST API No login needed ≤ 2.2 CVE-2024-1088 Wordfence
8.8 High Auto Refresh Single Page Plugin auto-refresh-single-page PHP Object Injection Authenticated (Contributor+) PHP Object Injection ≤ 1.1 CVE-2024-1731 Wordfence
6.5 Medium Page Builder Sandwich Plugin page-builder-sandwich Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Post Editing ≤ 5.1.0 CVE-2024-1285 Wordfence
5.3 Medium Build & Control Block Patterns – Boost up Gutenberg Editor Plugin control-block-patterns Broken Access Control Boost up Gutenberg Editor <= 1.3.5.4 - Missing Authorization No login needed ≤ 1.3.5.4 CVE-2024-1095 Wordfence
6.4 Medium Easy!Appointments Plugin easyappointments Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-0698 Wordfence
6.1 Medium Blue Triad EZAnalytics Plugin blue-triad-ezanalytics Cross-Site Scripting Reflected Cross-Site Scripting via 'bt_webid' No login needed ≤ 1.0 CVE-2024-1782 Wordfence
5.3 Medium Maintenance Mode Plugin hkdev-maintenance-mode Information Disclosure Information Exposure No login needed ≤ 3.0.1 CVE-2024-1478 Wordfence
5.3 Medium SportsPress – Sports Club & League Manager Plugin sportspress Broken Access Control Sports Club & League Manager <= 2.7.17 - Missing Authorization to Unauthenticated Event Permalink Update No login needed ≤ 2.7.17 CVE-2024-1178 Wordfence
4.3 Medium Event Tickets Plus Plugin Information Disclosure Contributor+ Attendees Lists Disclosure < 5.9.1 Fixed in 5.9.1 CVE-2024-1319 WPScan
6.5 Medium Event Tickets and Registration Plugin event-tickets Broken Access Control Contributor+ Arbitrary Events Access < 5.8.1, < 5.9.1 Fixed in 5.8.1 CVE-2024-1316 WPScan
6.4 Medium Ultimate Bootstrap Elements for Elementor Plugin ultimate-bootstrap-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.6 CVE-2024-1398 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.9.10 CVE-2024-1449 Wordfence
4.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.9.9 - Authenticated(Editor+) Stored Cross-Site Scripting via slider callback ≤ 3.9.9 CVE-2024-0611 Wordfence
5.4 Medium Master Slider - Responsive Touch Slider Plugin master-slider Cross-Site Request Forgery Responsive Touch Slider <= 3.9.10 - Cross-Site Request Forgery via process_bulk_action No login needed ≤ 3.9.10 CVE-2023-6326 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only