WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 251–300 of 316 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.8 Medium | Image Photo Gallery Final Tiles Grid | Cross-Site Scripting Contributor+ Stored XSS |
< 3.6.0 Fixed in 3.6.0 |
CVE-2024-3710 |
WPScan | |
| 8.8 High | ProfileGrid – User Profiles, Groups and Communities | Broken Access Control User Profiles, Groups and Communities <= 5.8.9 - Authenticated (Subscriber+) Authorization Bypass to Privilege Escalation |
≤ 5.8.9 |
CVE-2024-6411 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference |
≤ 5.8.9 |
CVE-2024-6410 |
Wordfence | |
| 6.4 Medium | Elementor Addons by Livemesh | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Posts Grid |
≤ 8.3.7 |
CVE-2024-3639 |
Wordfence | |
| 6.4 Medium | The Post Grid | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via section title tag |
≤ 7.7.1 |
CVE-2024-1427 |
Wordfence | |
| 6.4 Medium | Ultimate Post Kit Addons for Elementor | Cross-Site Scripting (Post Grid, Post Carousel, Post Slider, Category List, Post Tabs, Timeline, Post Ticker, Tag Cloud) <= 3.11.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Social Count (Static) Widget |
≤ 3.11.7 |
CVE-2024-5662 |
Wordfence | |
| 6.4 Medium | Orbit Fox by ThemeIsle | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Services and Post Type Grid Widgets |
≤ 2.10.34 |
CVE-2024-2484 |
Wordfence | |
| 8.3 High | Essential Grid | Broken Access Control Multiple Authenticated Broken Access Control |
≤ 3.0.18 Fixed in 3.0.19 |
CVE-2023-47771 |
Patchstack | |
| 4.3 Medium | ProfileGrid | Broken Access Control |
≤ 5.6.6 Fixed in 5.6.7 |
CVE-2023-52117 |
Patchstack | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via onclick events |
≤ 5.6.11 |
CVE-2024-3925 |
Wordfence | |
| 6.5 Medium | The Post Grid | Cross-Site Scripting |
≤ 7.7.1 Fixed in 7.7.2 |
CVE-2024-35739 |
Patchstack | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attribute |
≤ 2.2.80 |
CVE-2024-4042 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-1988 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control Missing Authorization |
≤ 5.8.6 |
CVE-2024-5453 |
Wordfence | |
| 6.5 Medium | Post Grid Elementor Addon | Cross-Site Scripting |
≤ 2.0.16 Fixed in 2.0.17 |
CVE-2024-34789 |
Patchstack | |
| 8.8 High | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | Broken Access Control PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update |
≤ 4.1.2 |
CVE-2024-5326 |
Wordfence | |
| 6.4 Medium | Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX | Cross-Site Scripting PostX <= 4.1.1 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 4.1.1 |
CVE-2024-5223 |
Wordfence | |
| 6.4 Medium | WP Ultimate Post Grid | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpupg-text Shortcode |
≤ 3.9.1 |
CVE-2024-4043 |
Wordfence | |
| 6.4 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via custom_attributes |
≤ 5.6.1 |
CVE-2024-3926 |
Wordfence | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Other Form Submission Admin Email Bypass No login needed |
≤ 5.6.3 |
CVE-2024-3927 |
Wordfence | |
| 6.4 Medium | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks | Cross-Site Scripting Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.80 |
CVE-2024-3155 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Other Group Members Limit Bypass |
≤ 5.8.2 Fixed in 5.8.3 |
CVE-2024-32774 |
Patchstack | |
| 7.5 High | Total Upkeep | Path Traversal Arbitrary File Download No login needed |
≤ 1.15.8 Fixed in 1.15.9 |
CVE-2024-24869 |
Patchstack | |
| 6.4 Medium | Visual Portfolio, Photo Gallery & Post Grid | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via title_tag Parameter |
≤ 3.3.2 |
CVE-2024-4363 |
Wordfence | |
| 6.4 Medium | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via pagingType Parameter |
≤ 3.7.1 |
CVE-2024-4446 |
Wordfence | |
| 5.3 Medium | Post Grid Master | Broken Access Control No login needed |
≤ 3.4.7 Fixed in 3.4.8 |
CVE-2024-34372 |
Patchstack | |
| 6.5 Medium | Post Grid Master | Cross-Site Scripting Auth. Cross Site Scripting (XSS) |
≤ 3.4.8 |
CVE-2024-34390 |
Patchstack | |
| 4.3 Medium | The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid | Broken Access Control Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid <= 7.6.1 - Missing Authorization |
≤ 7.6.1 |
CVE-2024-3936 |
Wordfence | |
| 4.3 Medium | ProfileGrid – User Profiles, Memberships, Groups and Communities | Broken Access Control User Profiles, Memberships, Groups and Communities <= 5.8.3 - Missing Authorization |
≤ 5.8.3 |
CVE-2024-3606 |
Wordfence | |
| 7.5 High | Grid Gallery – Photo Image Grid Gallery | PHP Object Injection Photo Image Grid Gallery <= 1.4.3 - Authenticated (Contributor+) PHP Object Injection via shortcode |
≤ 1.4.3 |
CVE-2024-1897 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 2.4.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Image Grid Widget |
≤ 2.4.9 |
CVE-2024-3308 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flip Carousel, Flip Box, Post Grid, and Taxonomy List Widget Attributes |
≤ 1.3.971 |
CVE-2024-3675 |
Wordfence | |
| 6.4 Medium | Exclusive Addons for Elementor | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Post Grid |
≤ 2.6.9.2 |
CVE-2024-2503 |
Wordfence | |
| 6.4 Medium | Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) | Cross-Site Scripting Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget Post Overlay |
≤ 3.7.0 |
CVE-2024-3929 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-32772 |
Patchstack | |
| 5.4 Medium | ProfileGrid | Broken Access Control Insecure Direct Object Reference (IDOR) |
≤ 5.7.9 Fixed in 5.8.0 |
CVE-2024-32808 |
Patchstack | |
| 7.5 High | Post Grid | Information Disclosure Sensitive Data Exposure via API No login needed |
≤ 2.2.78 Fixed in 2.2.79 |
CVE-2024-32816 |
Patchstack | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Panel Slider Widget |
≤ 5.6.0 |
CVE-2024-1429 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Price List Widget |
≤ 5.6.0 |
CVE-2024-1426 |
Wordfence | |
| 4.3 Medium | ProfileGrid | Cross-Site Request Forgery User Profiles, Memberships, Groups and Communities plugin <= 5.7.8 - Cross Site Request Forgery (CSRF) No login needed |
≤ 5.7.8 Fixed in 5.7.9 |
CVE-2024-31362 |
Patchstack | |
| 5.3 Medium | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) | Information Disclosure Sensitive Information Exposure via element_pack_ajax_search No login needed |
≤ 5.5.6 |
CVE-2024-2966 |
Wordfence | |
| 7.2 High | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | PHP Object Injection Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Admin+) PHP Object Injection |
≤ 2.6.3 |
CVE-2024-3020 |
Wordfence | |
| 5.3 Medium | Essential Grid | Information Disclosure Unauthenticated Private Post Disclosure No login needed |
≤ 3.1.1 |
CVE-2024-3235 |
Wordfence | |
| 6.1 Medium | Responsive Gallery Grid | Cross-Site Scripting Admin+ Stored XSS No login needed |
< 2.3.11 Fixed in 2.3.11 |
CVE-2024-1664 |
WPScan | |
| 4.3 Medium | ProfileGrid | Broken Access Control IDOR on Friend Request |
≤ 5.7.6 Fixed in 5.7.7 |
CVE-2024-31291 |
Patchstack | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'Custom Gallery' Widget |
≤ 5.3.2 |
CVE-2024-0837 |
Wordfence | |
| 6.4 Medium | Element Pack – Widgets, Templates & Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Trailer Box Widget |
≤ 5.5.3 |
CVE-2024-1428 |
Wordfence | |
| 6.4 Medium | Carousel, Slider, Photo Gallery with Lightbox, Video Slider, by WP Carousel | Cross-Site Scripting Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sp_wp_carousel_shortcode' |
≤ 2.6.3 |
CVE-2024-2949 |
Wordfence | |
| 5.3 Medium | BoldGrid Easy SEO – Simple and Effective SEO | Information Disclosure Simple and Effective SEO <= 1.6.14 - Information Exposure No login needed |
≤ 1.6.14 |
CVE-2024-2950 |
Wordfence | |
| 6.4 Medium | BoldGrid Easy SEO – Simple and Effective SEO | Cross-Site Scripting Simple and Effective SEO <= 1.6.13 - Authenticated(Contributor+) Stored Cross-Site Scripting via Meta Description |
≤ 1.6.13 |
CVE-2024-1692 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.