WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 251–300 of 355 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | Hello Event Widgets For Elementor | Cross-Site Scripting |
≤ 1.0.2 Fixed in 1.1.0 |
CVE-2024-54338 |
Patchstack | |
| 6.5 Medium | Events Addon for Elementor | Cross-Site Scripting |
≤ 2.2.2 Fixed in 2.2.3 |
CVE-2024-54315 |
Patchstack | |
| 5.3 Medium | The Events Calendar | Broken Access Control No login needed |
≤ 6.1.2.2 Fixed in 6.1.3 |
CVE-2023-35777 |
Patchstack | |
| 4.3 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Request Forgery Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 0.4.1 |
CVE-2024-12526 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode |
≤ 0.4.1 |
CVE-2024-12463 |
Wordfence | |
| 6.4 Medium | Arena.IM – Live Blogging for real-time events | Cross-Site Scripting Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.3.0 |
CVE-2024-11384 |
Wordfence | |
| 6.4 Medium | Add infos to the events calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.1 |
CVE-2024-11875 |
Wordfence | |
| 5.4 Medium | Tickera | Cross-Site Request Forgery WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change No login needed |
≤ 3.5.1.0 Fixed in 3.5.1.1 |
CVE-2023-23726 |
Patchstack | |
| 5.3 Medium | Quick Event Manager | Broken Access Control No login needed |
≤ 9.7.4 Fixed in 9.7.5 |
CVE-2023-23975 |
Patchstack | |
| 5.4 Medium | Eventin | Broken Access Control Authenticated Notice Dismissal |
≤ 3.3.52 Fixed in 3.3.53 |
CVE-2023-49756 |
Patchstack | |
| 5.4 Medium | Event Tickets with Ticket Scanner | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 2.4.3 |
CVE-2024-9866 |
Wordfence | |
| 6.5 Medium | Advanced Event Manager | Cross-Site Scripting |
≤ 1.1.6 |
CVE-2024-53721 |
Patchstack | |
| 6.5 Medium | EventPress | Cross-Site Scripting Stored Cross Site Scripting (XSS) |
≤ 1.0.0 |
CVE-2024-51861 |
Patchstack | |
| 6.5 Medium | Simpul Events by Esotech | Cross-Site Scripting |
≤ 1.8.5 |
CVE-2024-51867 |
Patchstack | |
| 4.3 Medium | Countdown Timer block – Display the event's date into a timer. | Information Disclosure Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure |
≤ 1.2.4 |
CVE-2024-10669 |
Wordfence | |
| 6.4 Medium | Event Post | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via events_cal Shortcode |
≤ 5.9.6 |
CVE-2024-10186 |
Wordfence | |
| 6.4 Medium | Registrations for the Events Calendar | Broken Access Control |
≤ 2.12.1 Fixed in 2.12.2 |
CVE-2024-43143 |
Patchstack | |
| 4.3 Medium | EventPrime | Broken Access Control |
≤ 4.0.3.2 Fixed in 4.0.4.0 |
CVE-2024-43223 |
Patchstack | |
| 6.5 Medium | WpEvently | Cross-Site Scripting |
≤ 4.2.5 Fixed in 4.2.6 |
CVE-2024-49703 |
Patchstack | |
| 6.1 Medium | EventPrime – Modern Events Calendar, Bookings and Tickets | Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 4.0.4.7 |
CVE-2024-9864 |
Wordfence | |
| 6.1 Medium | EventPrime – Modern Events Calendar, Bookings and Tickets | Cross-Site Scripting Modern Events Calendar, Bookings and Tickets <= 4.0.4.7 - Unauthenticated Stored Cross-Site Scripting via Transaction Log No login needed |
≤ 4.0.4.7 |
CVE-2024-9865 |
Wordfence | |
| 4.3 Medium | EventON PRO - WordPress Virtual Event Calendar | Cross-Site Request Forgery WordPress Virtual Event Calendar Plugin <= 4.6.8 - Cross-Site Request Forgery via admin_test_email No login needed |
≤ 4.6.8 |
CVE-2023-6243 |
Wordfence | |
| 6.5 Medium | Events Addon for Elementor | Cross-Site Scripting |
≤ 2.2.0 Fixed in 2.2.1 |
CVE-2024-49264 |
Patchstack | |
| 4.7 Medium | EventPrime | Open Redirect No login needed |
≤ 4.0.4.5 Fixed in 4.0.4.6 |
CVE-2024-47648 |
Patchstack | |
| 4.3 Medium | Easy PayPal Events | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Deletion No login needed |
≤ 1.2.1 |
CVE-2024-8476 |
Wordfence | |
| 6.1 Medium | Simple Calendar – Google Calendar | Cross-Site Scripting Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting No login needed |
≤ 3.4.2 |
CVE-2024-8549 |
Wordfence | |
| 4.3 Medium | Appointment & Event Booking Calendar Plugin – Webba Booking | Broken Access Control Webba Booking <= 5.0.48 - Missing Authorization to Authenticated (Subscriber+) CSS Settings Update |
≤ 5.0.48 |
CVE-2024-8432 |
Wordfence | |
| 5.3 Medium | EventPrime | Broken Access Control Missing Authorization to Unauthenticated Private or Password-Protected Events Disclosure No login needed |
≤ 4.0.4.3 |
CVE-2024-8369 |
Wordfence | |
| 4.8 Medium | EventON | Cross-Site Scripting Admin+ Stored XSS |
< 2.2.17 Fixed in 2.2.17 |
CVE-2024-6910 |
WPScan | |
| 6.4 Medium | Enter Addons – Ultimate Template Builder for Elementor | Cross-Site Scripting Ultimate Template Builder for Elementor <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Events Card Widget |
≤ 2.1.8 |
CVE-2024-7611 |
Wordfence | |
| 6.5 Medium | Booking for Appointments and Events Calendar – Amelia Premium | Broken Access Control Amelia Premium <= 7.7 and Lite <= 1.2.4 - Missing Authorization to Sensitive Information Exposure No login needed |
≤ 1.2.4, ≤ 7.7 |
CVE-2024-6332 |
Wordfence | |
| 4.3 Medium | Event Espresso 4 Decaf – Event Registration Event Ticketing | Broken Access Control Event Registration Event Ticketing <= 4.10.46.decaf- Authenticated (Subscriber+) Missing Authorization to Limited Plugin Settings Modification |
≤ 4.10.46.decaf |
CVE-2024-6883 |
Wordfence | |
| 6.5 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 3.13.0 - Missing Authorization to Unauthenticated Event Settings Update No login needed |
≤ 3.13.0 |
CVE-2024-5940 |
Wordfence | |
| 6.5 Medium | Event Manager for WooCommerce | Local File Inclusion |
≤ 4.2.1 Fixed in 4.2.2 |
CVE-2024-43138 |
Patchstack | |
| 5.3 Medium | Booking for Appointments and Events Calendar – Amelia | Information Disclosure Amelia <= 1.2 - Unauthenticated Full Path Disclosure No login needed |
≤ 1.2 |
CVE-2024-6552 |
Wordfence | |
| 4.8 Medium | Community Events | Cross-Site Scripting Admin+ Stored XSS |
< 1.5.1 Fixed in 1.5.1 |
CVE-2024-6270 |
WPScan | |
| 5.9 Medium | Eventin | Cross-Site Scripting |
≤ 4.0.5 Fixed in 4.0.6 |
CVE-2024-39648 |
Patchstack | |
| 5.5 Medium | Timetable and Event Schedule | PHP Object Injection |
≤ 2.4.13 |
CVE-2024-39630 |
Patchstack | |
| 5.4 Medium | Community Events | Cross-Site Request Forgery Event Deletion via CSRF No login needed |
< 1.5 Fixed in 1.5 |
CVE-2024-6271 |
WPScan | |
| 6.5 Medium | Eventin | Cross-Site Scripting |
≤ 3.3.57 Fixed in 4.0.0 |
CVE-2024-37507 |
Patchstack | |
| 6.5 Medium | WP Event Aggregator | Cross-Site Scripting |
≤ 1.7.9 Fixed in 1.8.0 |
CVE-2024-38703 |
Patchstack | |
| 4.3 Medium | Event Manager, Events Calendar, Tickets, Registrations – Eventin | Broken Access Control Eventin <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Event Data Import |
≤ 4.0.4 |
CVE-2024-6033 |
Wordfence | |
| 6.4 Medium | WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce | Cross-Site Scripting Events Calendar, Registrations, Sell Tickets with WooCommerce <= 3.1.43 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'events' Shortcode |
≤ 3.1.43 |
CVE-2024-2691 |
Wordfence | |
| 5.9 Medium | EventON | Cross-Site Scripting Admin+ Stored Cross-Site Scripting via event subtitle |
< 2.2.15 Fixed in 2.2.15 |
CVE-2024-4752 |
WPScan | |
| 6.5 Medium | Events Calendar for Google | Local File Inclusion |
≤ 2.1.0 |
CVE-2024-38716 |
Patchstack | |
| 4.3 Medium | Event post | Cross-Site Request Forgery No login needed |
≤ 5.9.10 |
CVE-2024-1375 |
Wordfence | |
| 6.4 Medium | Extensions for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via EE Events and EE Flipbox Widget |
≤ 2.0.32 |
CVE-2024-4868 |
Wordfence | |
| 6.1 Medium | Events Manager | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 6.4.8 |
CVE-2024-5889 |
Wordfence | |
| 5.3 Medium | Event Management Tickets Booking | Information Disclosure Sensitive Data Exposure No login needed |
≤ 1.4.0 |
CVE-2024-5059 |
Patchstack | |
| 4.3 Medium | Tickera | Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Ticket Deletion |
≤ 3.5.2.8 |
CVE-2024-5860 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.