WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 28,551–28,600 of 29,070 vulnerabilities

Known WordPress vulnerabilities, page 572 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Broken Access Control Missing Authorization to Settings Import No login needed ≤ 4.0.11 CVE-2024-1110 Wordfence
5.3 Medium Quiz Maker Plugin quiz-maker Broken Access Control Missing Authorization to Unauthenticated Quiz Data Retrieval No login needed ≤ 6.5.2.4 CVE-2024-1079 Wordfence
4.3 Medium Quiz Maker Plugin quiz-maker Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Quiz Creation & Modification ≤ 6.5.2.4 CVE-2024-1078 Wordfence
4.4 Medium Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline) Plugin timeline-widget-addon-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.3 CVE-2024-0977 Wordfence
6.1 Medium All-In-One Security (AIOS) – Security and Firewall Plugin all-in-one-wp-security-and-firewall Cross-Site Scripting Security and Firewall <= 5.2.5 - Reflected Cross-Site Scripting No login needed ≤ 5.2.5 CVE-2024-1037 Wordfence
3.8 Low WP RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Plugin wp-rss-aggregator Server-Side Request Forgery The WP RSS Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.23.5 via the RSS feed source in admin settings. Thi… 4.23.5 CVE-2024-0628 Wordfence
5.4 Medium PowerPack Addons for Elementor (Free Widgets, Extensions and Templates) Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.14 CVE-2024-1055 Wordfence
6.4 Medium Starbox Plugin starbox Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Display Name and Social Settings ≤ 3.4.8 CVE-2024-0256 Wordfence
8.8 High File Manager Pro Plugin filester Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload ≤ 8.3.4 CVE-2023-6846 Wordfence
6.4 Medium GeneratePress Premium Plugin Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Custom Meta ≤ 2.3.2 CVE-2023-6807 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 6.2.8.2 CVE-2023-6557 Wordfence
5.3 Medium ARMember Plugin armember-membership Broken Access Control Improper Access Control to Sensitive Information Exposure via REST API No login needed ≤ 4.0.24 CVE-2024-0969 Wordfence
6.4 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting Authenticated(Contributor+) Stored Cross-site Scripting via Pricing Table Elementor Widget ≤ 2.10.27 CVE-2024-0508 Wordfence
5.3 Medium UserPro Plugin Other Disabled Membership Registration Bypass No login needed ≤ 5.1.6 CVE-2024-0701 Wordfence
6.4 Medium Advanced Custom Fields Plugin advanced-custom-fields Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 6.2.4 CVE-2023-6701 Wordfence
6.6 Medium Advanced Database Cleaner Plugin advanced-database-cleaner PHP Object Injection Authenticated(Administrator+) PHP Object Injection via process_bulk_action ≤ 3.1.3 CVE-2024-0668 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Cross-Site Request Forgery Cross-Site Request Forgery via save_view No login needed ≤ 3.2.2 CVE-2024-0373 Wordfence
8.8 High Display custom fields in the frontend – Post and User Profile Fields Plugin shortcode-to-display-post-and-user-data Remote Code Execution Post and User Profile Fields <= 1.2.1 - Authenticated (Contributor+) Code Injection ≤ 1.2.1 CVE-2023-6996 Wordfence
5.3 Medium Getwid – Gutenberg Blocks Plugin getwid Authentication Bypass Gutenberg Blocks <= 2.0.4 - Captcha Bypass No login needed ≤ 2.0.4 CVE-2023-6963 Wordfence
7.1 High Index Now Plugin mihdan-index-now Cross-Site Request Forgery Cross-Site Request Forgery via reset_form No login needed ≤ 2.6.3 CVE-2024-0428 Wordfence
4.3 Medium Starbox – the Author Box for Humans Plugin starbox Broken Access Control the Author Box for Humans <= 3.4.7 - Insecure Direct Object Reference ≤ 3.4.7 CVE-2024-0366 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.4 - Authenticated (Contributor+) Stored Cross-Site Scritping ≤ 5.9.4 CVE-2024-0586 Wordfence
6.4 Medium WordPress Button Plugin MaxButtons Plugin maxbuttons Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 9.7.6 CVE-2023-7029 Wordfence
6.1 Medium Formidable Forms Plugin formidable Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 6.7.2 CVE-2024-0660 Wordfence
4.3 Medium WPvivid Plugin wpvivid-backuprestore Broken Access Control Missing Authorization ≤ 0.9.94 CVE-2023-4637 Wordfence
9.8 Critical Cryptocurrency Widgets – Price Ticker & Coins List Plugin cryptocurrency-price-ticker-widget SQL Injection Price Ticker & Coins List plugin for WordPress is vulnerable to SQL Injection via the 'coinslist' parameter in versions 2.0 to 2.6.5 due to insufficie… No login needed 2.0 – 2.6.5 CVE-2024-0709 Wordfence
4.9 Medium PDF Generator For Fluent Forms Plugin Cross-Site Scripting ≤ 1.1.7 CVE-2023-6953 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via API No login needed ≤ 4.10.2 CVE-2024-1208 Wordfence
4.4 Medium Content Views Plugin content-views-query-and-display-post-page Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via settings ≤ 3.6.2 CVE-2024-0612 Wordfence
6.4 Medium Booking for Appointments and Events Calendar – Amelia Plugin ameliabooking Cross-Site Scripting Amelia <= 1.0.93 - Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 1.0.93 CVE-2023-6808 Wordfence
4.3 Medium Views for WPForms Plugin views-for-wpforms-lite Broken Access Control Missing Authorization via create_view ≤ 3.2.2 CVE-2024-0371 Wordfence
6.4 Medium Plugin for Google Reviews Plugin widget-google-reviews Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via shortcode ≤ 3.1 CVE-2023-6884 Wordfence
4.4 Medium SEO Plugin by Squirrly SEO Plugin Cross-Site Scripting Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings ≤ 12.3.15 CVE-2024-0597 Wordfence
7.2 High Unlimited Addons for WPBakery Page Builder Plugin unlimited-addons-for-wpbakery-page-builder Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload ≤ 1.0.42 CVE-2023-6925 Wordfence
4.3 Medium RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Plugin feedzy-rss-feeds Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization ≤ 4.4.1 CVE-2024-1092 Wordfence
4.4 Medium WP RSS Aggregator Plugin wp-rss-aggregator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via RSS Feed Source ≤ 4.23.4 CVE-2024-0630 Wordfence
8.8 High Better Search Replace Plugin better-search-replace PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 1.4.4 CVE-2023-6933 Wordfence
6.4 Medium Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.9.7 CVE-2024-0954 Wordfence
5.3 Medium Advanced Forms for ACF Plugin advanced-forms Broken Access Control Missing Authorization to Unauthenticated Form Settings Export No login needed ≤ 1.9.3.2 CVE-2024-1121 Wordfence
6.4 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Cross-Site Scripting ProfilePress <= 4.14.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.14.3 CVE-2024-1046 Wordfence
3.7 Low Minimal Coming Soon – Coming Soon Page Plugin minimal-coming-soon-maintenance-mode Information Disclosure Coming Soon Page <= 2.37 - Unauthenticated Maintenance Mode Bypass No login needed ≤ 2.37 CVE-2024-1075 Wordfence
8.2 High Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Broken Access Control Missing Authorization via seedprod_lite_new_lpage No login needed ≤ 6.15.21 CVE-2024-1072 Wordfence
6.5 Medium Order Delivery Date for WP e-Commerce Plugin order-delivery-date Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2024-0678 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Recipe Notes ≤ 9.1.0 CVE-2024-0384 Wordfence
4.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification ≤ 2.0.4 CVE-2023-6959 Wordfence
5.3 Medium LearnDash LMS Plugin Information Disclosure Sensitive Information Exposure via assignments No login needed ≤ 4.10.1 CVE-2024-1209 Wordfence
6.4 Medium SiteOrigin Widgets Bundle Plugin so-widgets-bundle Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.58.1 CVE-2024-0961 Wordfence
6.4 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_to parameter in all versions up to, and including, 1.12.11 due to insuf… 1.12.11 CVE-2024-0834 Wordfence
6.1 Medium WP 404 Auto Redirect to Similar Post Plugin wp-404-auto-redirect-to-similar-post Cross-Site Scripting Reflected Cross-Site Scripting via request No login needed ≤ 1.0.3 CVE-2024-0509 Wordfence
5.3 Medium WP Club Manager – WordPress Sports Club Plugin Broken Access Control WordPress Sports Club Plugin <= 2.2.10 - Missing Authorization to Unauthenticated Event Permalink Update No login needed ≤ 2.2.10 CVE-2024-1177 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only