WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.
Showing 251–300 of 328 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 3.5 Low | NextGEN Gallery | Cross-Site Scripting Admin+ Stored XSS |
< 3.59.9 Fixed in 3.59.9 |
CVE-2024-10545 |
WPScan | |
| 3.5 Low | Ajax Search Lite | Cross-Site Scripting Admin+ Stored XSS |
< 4.12.5 Fixed in 4.12.5 |
CVE-2024-13585 |
WPScan | |
| 3.5 Low | Carousel, Slider, Gallery by WP Carousel | Cross-Site Scripting Admin+ Stored XSS |
< 2.7.4 Fixed in 2.7.4 |
CVE-2024-13314 |
WPScan | |
| 3.5 Low | Master Slider | Cross-Site Scripting Editor+ Stored XSS |
< 3.10.5 Fixed in 3.10.5 |
CVE-2024-12173 |
WPScan | |
| 3.5 Low | Simple Video Management System | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.0.4 |
CVE-2025-0692 |
WPScan | |
| 3.5 Low | Everest Forms | Cross-Site Scripting Admin+ Stored XSS |
< 3.0.8.1 Fixed in 3.0.8.1 |
CVE-2024-13125 |
WPScan | |
| 3.5 Low | Paid Membership | Cross-Site Scripting Admin+ Stored XSS |
< 4.15.20 Fixed in 4.15.20 |
CVE-2024-13121 |
WPScan | |
| 3.8 Low | Crelly Slider | Cross-Site Scripting Admin+ Stored XSS |
< 1.4.7 Fixed in 1.4.7 |
CVE-2024-13116 |
WPScan | |
| 3.8 Low | Contact Form by Bit Form | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 2.17.4 |
CVE-2024-13450 |
Wordfence | |
| 2.7 Low | Form Maker by 10Web | Cross-Site Scripting Admin+ Stored XSS |
< 1.15.31 Fixed in 1.15.31 |
CVE-2024-10562 |
WPScan | |
| 2.7 Low | Photo Gallery, Images, Slider in Rbs Image Gallery | Cross-Site Scripting Contributor+ Stored XSS |
< 3.2.22 Fixed in 3.2.22 |
CVE-2024-10102 |
WPScan | |
| 3.1 Low | Spacer | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Information Disclosure |
≤ 3.0.7 |
CVE-2024-10527 |
Wordfence | |
| 3.7 Low | Easy Digital Downloads | Broken Access Control Improper Authorization to Paywall Bypass No login needed |
3.1 – 3.3.4 |
CVE-2024-9654 |
Wordfence | |
| 3.5 Low | Analytify | Broken Access Control |
≤ 5.1.0 Fixed in 5.1.1 |
CVE-2023-41695 |
Patchstack | |
| 3.5 Low | Popup Maker | Broken Access Control |
≤ 1.17.1 Fixed in 1.18.0 |
CVE-2022-45819 |
Patchstack | |
| 3.7 Low | AR | Broken Access Control Missing Authorization to Unauthenticated Limited File Upload No login needed |
≤ 7.3 |
CVE-2024-12300 |
Wordfence | |
| 3.8 Low | CP Multi View Event Calendar | Broken Access Control |
≤ 1.4.13 Fixed in 1.4.15 |
CVE-2023-23814 |
Patchstack | |
| 3.1 Low | Spectra | Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Import_WPforms |
≤ 2.3.0 Fixed in 2.3.1 |
CVE-2023-23825 |
Patchstack | |
| 3.5 Low | WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) | Broken Access Control |
≤ 7.5.14 Fixed in 7.6.0 |
CVE-2023-24375 |
Patchstack | |
| 3.7 Low | WordPress Console | Broken Access Control No login needed |
≤ 0.3.9 |
CVE-2023-28168 |
Patchstack | |
| 3.5 Low | WPForms | Cross-Site Scripting Admin+ Stored XSS |
< 1.9.1.6 Fixed in 1.9.1.6 |
CVE-2024-7056 |
WPScan | |
| 3.5 Low | YaDisk Files | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.2.5 |
CVE-2024-10710 |
WPScan | |
| 3.5 Low | SEO Plugin by Squirrly SEO | Cross-Site Scripting Editor+ Stored XSS |
< 12.3.21 Fixed in 12.3.21 |
CVE-2024-10515 |
WPScan | |
| 2.7 Low | Otter - Gutenberg Block | Broken Access Control |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2024-51671 |
Patchstack | |
| 3.8 Low | CM Table Of Contents – WordPress TOC | Cross-Site Request Forgery WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF |
< 1.2.3 Fixed in 1.2.3 |
CVE-2024-5030 |
WPScan | |
| 2.7 Low | Multiple Page Generator Plugin – MPG | Path Traversal MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion |
≤ 4.0.2 |
CVE-2024-10672 |
Wordfence | |
| 2.7 Low | Uncanny Groups for LearnDash | Broken Access Control Missing Authorization to Authenticated (Group Leader+) User Group Add |
≤ 6.1.0.1 |
CVE-2024-8350 |
Wordfence | |
| 3.7 Low | W3 Total Cache | Information Disclosure Sensitive Credentials Stored in Plaintext No login needed |
≤ 2.7.5 |
CVE-2023-5359 |
Wordfence | |
| 3.7 Low | Maintenance Redirect | Authentication Bypass IP Bypass No login needed |
≤ 2.0.1 Fixed in 2.1.0 |
CVE-2024-45453 |
Patchstack | |
| 3.5 Low | WP ULike | Cross-Site Scripting Subscriber+ Stored-XSS |
4.7.1 – < 4.7.2.1 Fixed in 4.7.2.1 |
CVE-2024-6792 |
WPScan | |
| 3.7 Low | Maintenance & Coming Soon Redirect Animation | Authentication Bypass Bypass Vulnerability No login needed |
≤ 2.3.3 |
CVE-2024-43944 |
Patchstack | |
| 3.3 Low | Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) | Cross-Site Scripting Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text |
≤ 3.3.2 |
CVE-2024-6692 |
Wordfence | |
| 2.7 Low | WP Mail SMTP | Information Disclosure Authenticated (Admin+) SMTP Password Exposure |
≤ 4.0.1 |
CVE-2024-6694 |
Wordfence | |
| 3.8 Low | Photo Gallery by Ays | Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection |
< 5.7.1 Fixed in 5.7.1 |
CVE-2024-37442 |
Patchstack | |
| 2.7 Low | WP Directory Kit | Content Injection HTML Injection |
≤ 1.3.6 Fixed in 1.3.7 |
CVE-2024-37253 |
Patchstack | |
| 3.5 Low | WooCommerce | Content Injection |
≤ 8.9.2 Fixed in 9.0.0 |
CVE-2024-35777 |
Patchstack | |
| 3.5 Low | Academy LMS | Open Redirect |
≤ 2.0.4 |
CVE-2024-37234 |
Patchstack | |
| 3.1 Low | Premium Addons for Elementor | Denial of Service Regular Expressions Denial of Service |
≤ 4.10.35 |
CVE-2024-6434 |
Wordfence | |
| 3.7 Low | Solid Security | Denial of Service IP Spoofing Leading to Denial of Service No login needed |
≤ 9.3.1 Fixed in 9.3.2 |
CVE-2022-44593 |
Patchstack | |
| 2.7 Low | Easy WP SMTP by SendLayer | Information Disclosure Exposure of Sensitive Information via the UI |
≤ 2.3.0 |
CVE-2024-3073 |
Wordfence | |
| 3.8 Low | Search & Replace | SQL Injection Admin+ SQL injection |
< 3.2.2 Fixed in 3.2.2 |
CVE-2024-4145 |
WPScan | |
| 3.7 Low | Under Construction / Maintenance Mode from Acurax | Authentication Bypass IP Bypass No login needed |
≤ 2.6 |
CVE-2024-35749 |
Patchstack | |
| 3.7 Low | weForms | Broken Access Control No login needed |
≤ 1.6.20 Fixed in 1.6.21 |
CVE-2024-30512 |
Patchstack | |
| 3.5 Low | Insert or Embed Articulate Content into | Other Iframe Injection |
≤ 4.3000000023 |
CVE-2024-0756 |
WPScan | |
| 3.7 Low | All In One WP Security & Firewall | Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed |
≤ 5.2.4 Fixed in 5.2.5 |
CVE-2023-52147 |
Patchstack | |
| 3.7 Low | Ultimate Dashboard | Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed |
≤ 3.7.10 Fixed in 3.7.11 |
CVE-2023-49822 |
Patchstack | |
| 3.7 Low | WPS Hide Login | Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed |
≤ 1.9.11 Fixed in 1.9.12 |
CVE-2023-49748 |
Patchstack | |
| 3.7 Low | Coming soon and Maintenance mode | Authentication Bypass IP Filtering Bypass No login needed |
≤ 3.7.3 Fixed in 3.7.4 |
CVE-2023-49741 |
Patchstack | |
| 3.7 Low | Hide login page | Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed |
≤ 1.1.9 |
CVE-2023-48335 |
Patchstack | |
| 3.7 Low | LWS Hide Login | Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed |
≤ 2.1.8 Fixed in 2.1.9 |
CVE-2023-47818 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.