WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 251–300 of 404 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Enhanced YouTube Shortcode Plugin enhanced-youtube-shortcode Cross-Site Scripting ≤ 2.0.1 CVE-2025-23946 Patchstack
7.1 High Hack me if you can Plugin hack-me-if-you-can Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23713 Patchstack
7.1 High Shabbos and Yom Tov Plugin shabbos-and-yom-tov Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.9 CVE-2025-23694 Patchstack
7.1 High MDC YouTube Downloader Plugin mdc-youtube-downloader Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.0 CVE-2025-23639 Patchstack
7.1 High Find Your Reps Plugin find-your-reps Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.2 CVE-2025-23557 Patchstack
6.1 Medium Contact Form 7 Redirect & Thank You Page Plugin cf7-redirect-thank-you-page Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.7 CVE-2024-12423 Wordfence
5.4 Medium PixelYourSite – Your smart PIXEL (TAG) Manager Plugin pixelyoursite Cross-Site Request Forgery No login needed ≤ 10.0.1.2 Fixed in 10.0.2 CVE-2025-22300 Patchstack
4.3 Medium FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor Plugin post-block Broken Access Control Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor <= 6.0.0 - Missing Authorization to Authenticated (Subscriber+) Shortcode Export ≤ 6.0.0 CVE-2024-10536 Wordfence
5.3 Medium Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords Plugin muzaara-adwords-optimize-dashboard Information Disclosure Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposure No login needed ≤ 3.1 CVE-2024-12159 Wordfence
6.4 Medium YOGO Booking Plugin yogo-booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.2 CVE-2024-12462 Wordfence
9.8 Critical Themes Coder – Create Android & iOS Apps For Your Woocommerce Site Plugin tc-ecommerce Broken Access Control Create Android & iOS Apps For Your Woocommerce Site <= 1.3.4 - Insecure Direct Object Reference to Password Change/Account Takeover/Privilege Escalation No login needed ≤ 1.3.4 CVE-2024-12402 Wordfence
6.4 Medium WP Youtube Gallery Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.9 CVE-2024-12590 Wordfence
5.3 Medium YOP Poll Plugin yop-poll Authentication Bypass Vote Manipulation Due to Broken Captcha Control No login needed ≤ 6.5.28 Fixed in 6.5.29 CVE-2023-46611 Patchstack
5.3 Medium Convertful – Your Ultimate On-Site Conversion Tool Plugin convertful Broken Access Control Your Ultimate On-Site Conversion Tool plugin <= 2.5 - Broken Access Control No login needed ≤ 2.5 Fixed in 2.6 CVE-2023-46605 Patchstack
4.3 Medium ApplyOnline – Application Form Builder and Manager Plugin apply-online Broken Access Control Application Form Builder and Manager plugin <= 2.5.3 - Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2023-46080 Patchstack
6.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Arbitrary Shortcode Execution The Contact Form Builder That Grows With You <= 3.8.22 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.8.22 CVE-2024-12238 Wordfence
8.8 High PlugVersions – Easily rollback to previous versions of your plugins Plugin Broken Access Control Easily rollback to previous versions of your plugins <= 0.0.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Creation ≤ 0.0.7 CVE-2024-12881 Wordfence
5.4 Medium Serious Slider Plugin cryout-serious-slider Cross-Site Scripting Contributor+ Stored XSS via Shortcode < 1.2.7 Fixed in 1.2.7 CVE-2024-11108 WPScan
6.5 Medium Youtube Video Grid Plugin youmax-channel-embeds-for-youtube-businesses Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.9 CVE-2024-54408 Patchstack
6.4 Medium Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site Plugin kredeum-nfts Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.9 CVE-2024-11876 Wordfence
4.3 Medium Automatic YouTube Gallery Plugin automatic-youtube-gallery Broken Access Control ≤ 2.3.3 Fixed in 2.3.5 CVE-2023-41866 Patchstack
6.5 Medium YourMembership Single Sign On Plugin login-with-yourmembership Broken Access Control No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2023-37987 Patchstack
7.5 High Video Gallery – YouTube Gallery Plugin gallery-videos Broken Access Control YouTube Gallery plugin <= 1.7.6 - Broken Access Control No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2023-25988 Patchstack
7.2 High Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.19 - Unauthenticated Stored Cross-Site Scripting via Form Calculations No login needed ≤ 3.8.19 CVE-2024-11052 Wordfence
6.4 Medium WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more Plugin gs-books-showcase Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2024-11766 Wordfence
6.4 Medium Top and footer bars for announcements, notifications, advertisements, promotions – YooBar Plugin yoo-bar Cross-Site Scripting YooBar <= 2.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.6 CVE-2024-11410 Wordfence
7.3 High Grid Plus – Unlimited grid layout Plugin grid-plus Arbitrary Shortcode Execution Unlimited grid layout <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via grid_plus_load_by_category No login needed ≤ 1.3.5 CVE-2024-10910 Wordfence
6.4 Medium ONLYOFFICE DocSpace Plugin onlyoffice-docspace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.1 CVE-2024-11750 Wordfence
6.4 Medium Gutenberg Blocks and Page Layouts – Attire Blocks Plugin attire-blocks Cross-Site Scripting Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.5 CVE-2024-11914 Wordfence
6.4 Medium ONLYOFFICE Docs Plugin onlyoffice Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.0 CVE-2024-11450 Wordfence
7.2 High YouTube Gallery and Vimeo Gallery Plugin gallery-videos SQL Injection Authenticated (Administrator+) SQL Injection ≤ 2.4.2 CVE-2024-10247 Wordfence
4.3 Medium Dollie Hub – Build Your Own WordPress Cloud Platform Plugin Information Disclosure Build Your Own WordPress Cloud Platform <= 6.2.0 - Authenticated (Contributor+) Post Disclosure ≤ 6.2.0 CVE-2024-12099 Wordfence
6.4 Medium Responsive Videos Plugin responsive-youtube-videos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1 CVE-2024-11747 Wordfence
6.4 Medium WordPress Pinterest Plugin – Make a Popup, User Profile, Masonry and Gallery Layout Plugin gs-pinterest-portfolio Cross-Site Scripting Make a Popup, User Profile, Masonry and Gallery Layout <= 1.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.8 CVE-2024-11453 Wordfence
7.1 High Youneeq Recommendations Plugin youneeq-panel Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.7 CVE-2024-52457 Patchstack
7.1 High Protect Your Content Plugin protect-your-content Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2024-53728 Patchstack
6.5 Medium WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Scripting ≤ 0.3.1 CVE-2024-53757 Patchstack
7.1 High Footer Flyout Widget Plugin footer-flyout-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2024-53732 Patchstack
6.4 Medium StreamWeasels YouTube Integration Plugin streamweasels-youtube-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.6 CVE-2024-11788 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor <= 4.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'provider_name' ≤ 4.1.3 CVE-2024-11203 Wordfence
6.1 Medium MailMunch – Grow your Email List Plugin mailmunch Cross-Site Scripting Grow your Email List <= 3.1.8 - Reflected Cross-Site Scripting No login needed ≤ 3.1.8 CVE-2024-8735 Wordfence
5.5 Medium Mixed Media Gallery Blocks Plugin Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 3.2.4.2 CVE-2024-10034 Wordfence
4.3 Medium Ultimate YouTube Video & Shorts Player With Vimeo Plugin ultimate-youtube-video-player Broken Access Control Missing Authorization to Authenticated (Subscriber+) Setting Exposure ≤ 3.3 CVE-2024-11355 Wordfence
7.2 High Activity Log – Monitor & Record User Changes Plugin aryo-activity-log Cross-Site Scripting Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scripting via Event Context No login needed ≤ 2.11.1 CVE-2024-10788 Wordfence
4.3 Medium Ultimate YouTube Video & Shorts Player With Vimeo Plugin ultimate-youtube-video-player Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Playlist/Video Deletion ≤ 3.3 CVE-2024-11354 Wordfence
5.9 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) ≤ 3.8.16 Fixed in 3.8.18 CVE-2024-50514 Patchstack
5.9 Medium Ninja Forms Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You plugin <= 3.8.16 - Cross Site Scripting (XSS) ≤ 3.8.16 Fixed in 3.8.18 CVE-2024-50515 Patchstack
6.5 Medium MyOrderDesk Plugin myorderdesk Cross-Site Scripting ≤ 3.2.6 Fixed in 3.3.0 CVE-2024-50546 Patchstack
6.5 Medium MDC YouTube Downloader Plugin mdc-youtube-downloader Cross-Site Scripting ≤ 3.0.0 CVE-2024-51875 Patchstack
6.5 Medium Postify: Post Layout For Elementor Plugin postify-for-elementor Cross-Site Scripting ≤ 1.0.1 CVE-2024-51893 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only