WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.
Showing 251–300 of 308 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 8.3 High | Thrive Theme Builder | Broken Access Control Multiple Authenticated Broken Access Control |
< 3.24.0 Fixed in 3.24.0 |
CVE-2023-47783 |
Patchstack | |
| 8.5 High | Page Builder: Live Composer | PHP Object Injection Contributor+ PHP Object Injection |
≤ 1.5.42 |
CVE-2024-35780 |
Patchstack | |
| 8.1 High | Popup Builder – Create highly converting, mobile friendly marketing popups | Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure |
≤ 4.3.1 |
CVE-2023-6696 |
Wordfence | |
| 7.4 High | Popup Builder | Broken Access Control Missing Authorization in Multiple AJAX Actions |
≤ 4.3.0 |
CVE-2024-2544 |
Wordfence | |
| 8.1 High | Build App Online | Privilege Escalation Account Takeover via Weak Password Reset Mechanism No login needed |
≤ 1.0.22 |
CVE-2023-7264 |
Wordfence | |
| 7.4 High | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.4.43 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget Link To URL |
≤ 2.4.43 |
CVE-2024-3667 |
Wordfence | |
| 7.2 High | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form No login needed |
≤ 2.4.43 |
CVE-2024-2087 |
Wordfence | |
| 7.1 High | Brizy – Page Builder | Cross-Site Scripting Page Builder <= 2.4.41 - Authenticated(Contributor+) Stored Cross-Site Scripting |
≤ 2.4.41 |
CVE-2024-1940 |
Wordfence | |
| 8.1 High | Hash Form – Drag & Drop Form Builder | PHP Object Injection Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection No login needed |
≤ 1.1.0 |
CVE-2024-5085 |
Wordfence | |
| 8.8 High | Oxygen Builder | Remote Code Execution Authenticated (Contributor+) Remote Code Execution |
≤ 4.8.2 |
CVE-2024-4662 |
Wordfence | |
| 7.5 High | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | PHP Object Injection PHP Object Injection via extractDynamicValues |
≤ 5.1.15 |
CVE-2024-4157 |
Wordfence | |
| 7.5 High | Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder | Broken Access Control Missing Authorization to Setting Manipulation No login needed |
≤ 5.1.16 |
CVE-2024-2782 |
Wordfence | |
| 8.5 High | Elementor Website Builder | Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization |
≤ 3.19.0 Fixed in 3.19.1 |
CVE-2024-24934 |
Patchstack | |
| 8.8 High | Build App Online | Privilege Escalation Authenticated Privilege Escalation |
≤ 1.0.19 |
CVE-2023-51479 |
Patchstack | |
| 8.8 High | Ultimate Addons for Beaver Builder | Privilege Escalation |
≤ 1.35.14 Fixed in 1.35.15 |
CVE-2023-51398 |
Patchstack | |
| 8.8 High | Thrive Theme Builder | Privilege Escalation Authenticated Privilege Escalation |
< 3.24.0 Fixed in 3.24.0 |
CVE-2023-47782 |
Patchstack | |
| 7.1 High | Ultimate Addons for WPBakery Page Builder | Local File Inclusion No login needed |
≤ 3.19.14 Fixed in 3.19.15 |
CVE-2023-46205 |
Patchstack | |
| 7.2 High | JetFormBuilder | Privilege Escalation Authenticated Privilege Escalation |
≤ 3.0.8 Fixed in 3.0.9 |
CVE-2023-37866 |
Patchstack | |
| 7.1 High | Landing Page Builder | Cross-Site Scripting No login needed |
≤ 1.5.1.8 Fixed in 1.5.1.9 |
CVE-2024-34752 |
Patchstack | |
| 7.6 High | ARForms Form Builder | Broken Access Control No login needed |
≤ 1.6.1 Fixed in 1.6.2 |
CVE-2024-31270 |
Patchstack | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting No login needed |
≤ 5.3.2.0 Fixed in 5.3.2.1 |
CVE-2024-33947 |
Patchstack | |
| 7.2 High | Cost Calculator Builder Pro | Cross-Site Scripting Unauthenticated Cross-Site Scripting via SVG Upload No login needed |
≤ 3.1.67 |
CVE-2024-4097 |
Wordfence | |
| 7.1 High | ARForms Form Builder | Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion |
≤ 1.6.4 |
CVE-2024-1945 |
Wordfence | |
| 7.5 High | RegistrationMagic | Other Arbitrary Price Change No login needed |
≤ 5.1.9.2 Fixed in 5.1.9.3 |
CVE-2023-23976 |
Patchstack | |
| 7.1 High | WP Cost Estimation & Payment Forms Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 10.1.75 Fixed in 10.1.76 |
CVE-2024-32510 |
Patchstack | |
| 8.5 High | Gutenberg Blocks by Kadence Blocks – Page Builder Features | Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) |
≤ 3.1.26 |
CVE-2023-6964 |
Wordfence | |
| 8.8 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation |
≤ 5.3.0.0 |
CVE-2024-1991 |
Wordfence | |
| 8.8 High | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode |
≤ 5.3.1.0 |
CVE-2024-1990 |
Wordfence | |
| 7.1 High | Post Type Builder (PTB) | Broken Access Control Auth. Arbitrary Post/Page Creation |
≤ 2.0.8 |
CVE-2024-31366 |
Patchstack | |
| 7.1 High | Post Type Builder (PTB) | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
< 2.1.1 Fixed in 2.1.1 |
CVE-2024-31365 |
Patchstack | |
| 8.8 High | Modal Popup Box – Popup Builder, Show Offers And News in Popup | PHP Object Injection Popup Builder, Show Offers And News in Popup <= 1.5.2 - Authenticated (Contributor+) PHP Object Injection in awl_modal_popup_box_shortcode |
≤ 1.5.2 |
CVE-2024-2008 |
Wordfence | |
| 8.5 High | WP Cost Estimation & Payment Forms Builder | SQL Injection |
≤ 10.1.75 Fixed in 10.1.76 |
CVE-2024-30489 |
Patchstack | |
| 8.5 High | Easy Form Builder | SQL Injection |
≤ 3.7.4 Fixed in 3.7.5 |
CVE-2024-30535 |
Patchstack | |
| 7.6 High | 10Web Map Builder for Google Maps | SQL Injection |
≤ 1.0.74 |
CVE-2024-31116 |
Patchstack | |
| 8.5 High | Fusion Builder | SQL Injection Auth. SQL Injection |
≤ 3.11.1 Fixed in 3.11.2 |
CVE-2023-39309 |
Patchstack | |
| 7.1 High | Starter Templates — Elementor, WordPress & Beaver Builder Templates | Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins |
≤ 3.2.4 Fixed in 3.2.5 |
CVE-2023-34370 |
Patchstack | |
| 7.1 High | Fusion Builder | Cross-Site Request Forgery No login needed |
≤ 3.11.1 Fixed in 3.11.2 |
CVE-2023-39311 |
Patchstack | |
| 7.1 High | Fusion Builder | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 3.11.1 Fixed in 3.11.2 |
CVE-2023-39306 |
Patchstack | |
| 8.2 High | Social Media Share Buttons | PHP Object Injection |
≤ 2.1.0 |
CVE-2024-2721 |
Patchstack | |
| 7.1 High | RegistrationMagic | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 5.2.5.9 Fixed in 5.2.6.0 |
CVE-2024-29113 |
Patchstack | |
| 8.8 High | Social Media Share Buttons | PHP Object Injection Authenticated (Subscriber+) PHP Object Injection |
≤ 2.1.0 |
CVE-2024-1685 |
Wordfence | |
| 7.2 High | AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber | SQL Injection Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber <= 7.3.14 - Authenticated (Admin+) SQL Injection |
≤ 7.3.14 |
CVE-2024-1793 |
Wordfence | |
| 8.8 High | Brizy – Page Builder | Arbitrary File Upload Page Builder <= 2.4.40 - Authenticated (Contributor+) Arbitrary File Upload |
≤ 2.4.40 |
CVE-2024-1311 |
Wordfence | |
| 8.8 High | Elementor Addon Elements | Path Traversal Directory Traversal to Local File Inclusion |
≤ 1.12.12 |
CVE-2024-1358 |
Wordfence | |
| 7.4 High | Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders | Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar |
≤ 5.9.9 |
CVE-2024-1536 |
Wordfence | |
| 8.8 High | Avada | Website Builder For WordPress & WooCommerce | Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload |
≤ 7.11.4 |
CVE-2024-1468 |
Wordfence | |
| 7.6 High | Contact Form builder with drag & drop for WordPress – Kali Forms | Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation |
≤ 2.3.41 |
CVE-2024-1217 |
Wordfence | |
| 7.5 High | popup-builder | Server-Side Request Forgery Admin+ SSRF & File Read No login needed |
< 4.2.6 Fixed in 4.2.6 |
CVE-2023-6294 |
WPScan | |
| 8.7 High | ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed |
≤ 3.1.4 Fixed in 3.1.5 |
CVE-2024-23512 |
Patchstack | |
| 7.2 High | Unlimited Addons for WPBakery Page Builder | Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload |
≤ 1.0.42 |
CVE-2023-6925 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.