WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 251–286 of 286 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Spectra – WordPress Gutenberg Blocks Plugin Cross-Site Scripting WordPress Gutenberg Blocks <= 2.10.3 - Authenticated(Contributor+) Cross-Site Scripting via Custom CSS ≤ 2.10.3 CVE-2023-6486 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.25 - Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Widget ≤ 3.2.25 CVE-2024-1999 Wordfence
8.5 High Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin Server-Side Request Forgery Page Builder Features <= 3.1.26 - Authenticated(Contributor+) Server-Side Request Forgery (SSRF) ≤ 3.1.26 CVE-2023-6964 Wordfence
4.4 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Authenticated(Editor+) Stored Cross-Site Scripting via Contact Form Message Settings ≤ 3.2.17 CVE-2024-0598 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.9.14 CVE-2024-3244 Wordfence
6.4 Medium Getwid – Gutenberg Blocks Plugin getwid Cross-Site Scripting Gutenberg Blocks <= 2.0.5 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Content ≤ 2.0.5 CVE-2024-1948 Wordfence
6.4 Medium BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg Plugin Cross-Site Scripting Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg <= 3.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.4.2 CVE-2024-2845 Wordfence
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.4 CVE-2024-2226 Wordfence
6.5 Medium Essential Blocks for Gutenberg Plugin essential-blocks Cross-Site Scripting ≤ 4.5.3 Fixed in 4.5.4 CVE-2024-31306 Patchstack
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block ≤ 3.9.14 CVE-2024-3245 Wordfence
6.5 Medium Gutenberg Blocks by Kadence Blocks Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.26 Fixed in 3.2.26 CVE-2024-2509 WPScan
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via CountUp Widget ≤ 3.2.31 CVE-2024-2919 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout ≤ 2.8.3 CVE-2024-2868 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.25 Fixed in 3.2.26 CVE-2024-24888 Patchstack
5.4 Medium Page Builder Gutenberg Blocks Plugin coblocks Cross-Site Scripting Contributor+ Stored XSS < 3.1.7 Fixed in 3.1.7 CVE-2024-2369 WPScan
6.4 Medium Gutenberg Block Editor Toolkit – EditorsKit Plugin block-options Cross-Site Scripting EditorsKit <= 1.40.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.40.4 CVE-2024-2794 Wordfence
6.5 Medium OpenStreetMap for Gutenberg and WPBakery Page Builder (formerly Visual Composer) Plugin stepbyteservice-openstreetmap Cross-Site Scripting ≤ 1.1.1 Fixed in 1.1.2 CVE-2024-30450 Patchstack
6.4 Medium Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Plugin otter-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.5 CVE-2024-2841 Wordfence
7.1 High Spectra Plugin ultimate-addons-for-gutenberg Server-Side Request Forgery ≤ 2.6.6 Fixed in 2.6.7 CVE-2023-36679 Patchstack
7.7 High Gutenberg Blocks by Kadence Blocks Plugin kadence-blocks Server-Side Request Forgery ≤ 3.2.19 Fixed in 3.2.20 CVE-2024-23500 Patchstack
6.4 Medium Page Builder Gutenberg Blocks – CoBlocks Plugin coblocks Cross-Site Scripting CoBlocks <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.6 CVE-2024-1049 Wordfence
5.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color' ≤ 3.9.12 CVE-2024-2688 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.3 CVE-2024-2255 Wordfence
6.4 Medium Gutenberg Blocks by Kadence Blocks – Page Builder Features Plugin kadence-blocks Cross-Site Scripting Page Builder Features <= 3.2.23 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.2.23 CVE-2024-1541 Wordfence
8.8 High Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget Plugin post-grid-carousel-ultimate PHP Object Injection with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.7 - Authenticated (Contributor+) PHP Object Injection in outpost_shortcode_metabox_markup ≤ 1.6.7 CVE-2024-2006 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.5.1 CVE-2024-1854 Wordfence
7.5 High Post Grid Combo – 36+ Gutenberg Blocks Plugin post-grid Information Disclosure Information Exposure via get_posts API Endpoint No login needed ≤ 2.2.68 CVE-2023-7072 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block ≤ 3.9.10 CVE-2024-1802 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget ≤ 3.9.10 CVE-2024-2128 Wordfence
5.3 Medium Build & Control Block Patterns – Boost up Gutenberg Editor Plugin control-block-patterns Broken Access Control Boost up Gutenberg Editor <= 1.3.5.4 - Missing Authorization No login needed ≤ 1.3.5.4 CVE-2024-1095 Wordfence
8.7 High ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks Plugin product-blocks PHP Object Injection Gutenberg WooCommerce Blocks Plugin <= 3.1.4 is vulnerable to PHP Object Injection No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2024-23512 Patchstack
5.3 Medium Getwid – Gutenberg Blocks Plugin getwid Authentication Bypass Gutenberg Blocks <= 2.0.4 - Captcha Bypass No login needed ≤ 2.0.4 CVE-2023-6963 Wordfence
4.3 Medium Getwid – Gutenberg Blocks Plugin getwid Broken Access Control Gutenberg Blocks <= 2.0.4 - Missing Authorization to Recaptcha API Key Modification ≤ 2.0.4 CVE-2023-6959 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.6 CVE-2023-7071 Wordfence
6.4 Medium Post Grid Combo – 36+ Gutenberg Blocks Plugin Cross-Site Scripting Authenticated (Contributor+) Cross-Site Scripting ≤ 2.2.64 CVE-2023-6645 Wordfence
6.4 Medium EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more Plugin embedpress Cross-Site Scripting Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor <= 3.9.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode < 3.9.5 Fixed in 3.9.5 CVE-2023-6986 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only