WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,413 vulnerabilities, 1,639 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 10, 2026.

Showing 251–300 of 308 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 7
Severity Component Vulnerability Affected versions Published CVE Source
8.3 High Thrive Theme Builder Theme Broken Access Control Multiple Authenticated Broken Access Control < 3.24.0 Fixed in 3.24.0 CVE-2023-47783 Patchstack
8.5 High Page Builder: Live Composer Plugin live-composer-page-builder PHP Object Injection Contributor+ PHP Object Injection ≤ 1.5.42 CVE-2024-35780 Patchstack
8.1 High Popup Builder – Create highly converting, mobile friendly marketing popups Plugin popup-builder Broken Access Control Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure ≤ 4.3.1 CVE-2023-6696 Wordfence
7.4 High Popup Builder Plugin popup-builder Broken Access Control Missing Authorization in Multiple AJAX Actions ≤ 4.3.0 CVE-2024-2544 Wordfence
8.1 High Build App Online Plugin build-app-online Privilege Escalation Account Takeover via Weak Password Reset Mechanism No login needed ≤ 1.0.22 CVE-2023-7264 Wordfence
7.4 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.43 - Authenticated (Contributor+) Store Cross-Site Scripting via Widget Link To URL ≤ 2.4.43 CVE-2024-3667 Wordfence
7.2 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.43 - Unauthenticated Stored Cross-Site Scripting via Form No login needed ≤ 2.4.43 CVE-2024-2087 Wordfence
7.1 High Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.4.41 - Authenticated(Contributor+) Stored Cross-Site Scripting ≤ 2.4.41 CVE-2024-1940 Wordfence
8.1 High Hash Form – Drag & Drop Form Builder Plugin hash-form PHP Object Injection Drag & Drop Form Builder <= 1.1.0 - Unauthenticated PHP Object Injection No login needed ≤ 1.1.0 CVE-2024-5085 Wordfence
8.8 High Oxygen Builder Plugin Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 4.8.2 CVE-2024-4662 Wordfence
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform PHP Object Injection PHP Object Injection via extractDynamicValues ≤ 5.1.15 CVE-2024-4157 Wordfence
7.5 High Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder Plugin fluentform Broken Access Control Missing Authorization to Setting Manipulation No login needed ≤ 5.1.16 CVE-2024-2782 Wordfence
8.5 High Elementor Website Builder Plugin elementor Arbitrary File Deletion Arbitrary File Deletion and Phar Deserialization ≤ 3.19.0 Fixed in 3.19.1 CVE-2024-24934 Patchstack
8.8 High Build App Online Plugin build-app-online Privilege Escalation Authenticated Privilege Escalation ≤ 1.0.19 CVE-2023-51479 Patchstack
8.8 High Ultimate Addons for Beaver Builder Plugin ultimate-addons-for-beaver-builder-lite Privilege Escalation ≤ 1.35.14 Fixed in 1.35.15 CVE-2023-51398 Patchstack
8.8 High Thrive Theme Builder Theme Privilege Escalation Authenticated Privilege Escalation < 3.24.0 Fixed in 3.24.0 CVE-2023-47782 Patchstack
7.1 High Ultimate Addons for WPBakery Page Builder Plugin Local File Inclusion No login needed ≤ 3.19.14 Fixed in 3.19.15 CVE-2023-46205 Patchstack
7.2 High JetFormBuilder Plugin jetformbuilder Privilege Escalation Authenticated Privilege Escalation ≤ 3.0.8 Fixed in 3.0.9 CVE-2023-37866 Patchstack
7.1 High Landing Page Builder Plugin page-builder-add Cross-Site Scripting No login needed ≤ 1.5.1.8 Fixed in 1.5.1.9 CVE-2024-34752 Patchstack
7.6 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2024-31270 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting No login needed ≤ 5.3.2.0 Fixed in 5.3.2.1 CVE-2024-33947 Patchstack
7.2 High Cost Calculator Builder Pro Plugin Cross-Site Scripting Unauthenticated Cross-Site Scripting via SVG Upload No login needed ≤ 3.1.67 CVE-2024-4097 Wordfence
7.1 High ARForms Form Builder Plugin arforms-form-builder Broken Access Control Missing Authorization to Authenticated(Subscriber+) Arbitrary Option Deletion ≤ 1.6.4 CVE-2024-1945 Wordfence
7.5 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Other Arbitrary Price Change No login needed ≤ 5.1.9.2 Fixed in 5.1.9.3 CVE-2023-23976 Patchstack
7.1 High WP Cost Estimation & Payment Forms Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-32510 Patchstack
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Privilege Escalation Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.0.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 5.3.0.0 CVE-2024-1991 Wordfence
8.8 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 5.3.1.0 - Authenticated (Contributor+) SQL Injection via Shortcode ≤ 5.3.1.0 CVE-2024-1990 Wordfence
7.1 High Post Type Builder (PTB) Plugin Broken Access Control Auth. Arbitrary Post/Page Creation ≤ 2.0.8 CVE-2024-31366 Patchstack
7.1 High Post Type Builder (PTB) Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed < 2.1.1 Fixed in 2.1.1 CVE-2024-31365 Patchstack
8.8 High Modal Popup Box – Popup Builder, Show Offers And News in Popup Plugin modal-popup-box PHP Object Injection Popup Builder, Show Offers And News in Popup <= 1.5.2 - Authenticated (Contributor+) PHP Object Injection in awl_modal_popup_box_shortcode ≤ 1.5.2 CVE-2024-2008 Wordfence
8.5 High WP Cost Estimation & Payment Forms Builder Plugin SQL Injection ≤ 10.1.75 Fixed in 10.1.76 CVE-2024-30489 Patchstack
8.5 High Easy Form Builder Plugin easy-form-builder SQL Injection ≤ 3.7.4 Fixed in 3.7.5 CVE-2024-30535 Patchstack
7.6 High 10Web Map Builder for Google Maps Plugin wd-google-maps SQL Injection ≤ 1.0.74 CVE-2024-31116 Patchstack
8.5 High Fusion Builder Plugin SQL Injection Auth. SQL Injection ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39309 Patchstack
7.1 High Starter Templates — Elementor, WordPress & Beaver Builder Templates Plugin astra-sites Server-Side Request Forgery Server Side Request Forgery (SSRF) vulnerability in Starter Templates plugins ≤ 3.2.4 Fixed in 3.2.5 CVE-2023-34370 Patchstack
7.1 High Fusion Builder Plugin fusion-builder Cross-Site Request Forgery No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39311 Patchstack
7.1 High Fusion Builder Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.11.1 Fixed in 3.11.2 CVE-2023-39306 Patchstack
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
7.1 High RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.5.9 Fixed in 5.2.6.0 CVE-2024-29113 Patchstack
8.8 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 2.1.0 CVE-2024-1685 Wordfence
7.2 High AWeber – Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber Plugin aweber-web-form-widget SQL Injection Free Sign Up Form and Landing Page Builder Plugin for Lead Generation and Email Newsletter Growth By AWeber <= 7.3.14 - Authenticated (Admin+) SQL Injection ≤ 7.3.14 CVE-2024-1793 Wordfence
8.8 High Brizy – Page Builder Plugin brizy Arbitrary File Upload Page Builder <= 2.4.40 - Authenticated (Contributor+) Arbitrary File Upload ≤ 2.4.40 CVE-2024-1311 Wordfence
8.8 High Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Path Traversal Directory Traversal to Local File Inclusion ≤ 1.12.12 CVE-2024-1358 Wordfence
7.4 High Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Plugin essential-addons-for-elementor-lite Cross-Site Scripting Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= 5.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Event Calendar ≤ 5.9.9 CVE-2024-1536 Wordfence
8.8 High Avada | Website Builder For WordPress & WooCommerce Theme Arbitrary File Upload Authenticated (Contributor+) Arbitrary File Upload ≤ 7.11.4 CVE-2024-1468 Wordfence
7.6 High Contact Form builder with drag & drop for WordPress – Kali Forms Plugin kali-forms Broken Access Control Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation ≤ 2.3.41 CVE-2024-1217 Wordfence
7.5 High popup-builder Plugin Server-Side Request Forgery Admin+ SSRF & File Read No login needed < 4.2.6 Fixed in 4.2.6 CVE-2023-6294 WPScan
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
7.2 High Unlimited Addons for WPBakery Page Builder Plugin unlimited-addons-for-wpbakery-page-builder Arbitrary File Upload Authenticated (Editor+) Arbitrary File Upload ≤ 1.0.42 CVE-2023-6925 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only