WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,007 vulnerabilities, 1,391 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 5, 2026.

Showing 251–300 of 328 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 6 of 1
Severity Component Vulnerability Affected versions Published CVE Source
3.5 Low NextGEN Gallery Plugin Cross-Site Scripting Admin+ Stored XSS < 3.59.9 Fixed in 3.59.9 CVE-2024-10545 WPScan
3.5 Low Ajax Search Lite Plugin ajax-search-lite Cross-Site Scripting Admin+ Stored XSS < 4.12.5 Fixed in 4.12.5 CVE-2024-13585 WPScan
3.5 Low Carousel, Slider, Gallery by WP Carousel Plugin Cross-Site Scripting Admin+ Stored XSS < 2.7.4 Fixed in 2.7.4 CVE-2024-13314 WPScan
3.5 Low Master Slider Plugin master-slider Cross-Site Scripting Editor+ Stored XSS < 3.10.5 Fixed in 3.10.5 CVE-2024-12173 WPScan
3.5 Low Simple Video Management System Plugin Cross-Site Scripting Admin+ Stored XSS ≤ 1.0.4 CVE-2025-0692 WPScan
3.5 Low Everest Forms Plugin everest-forms Cross-Site Scripting Admin+ Stored XSS < 3.0.8.1 Fixed in 3.0.8.1 CVE-2024-13125 WPScan
3.5 Low Paid Membership Plugin Cross-Site Scripting Admin+ Stored XSS < 4.15.20 Fixed in 4.15.20 CVE-2024-13121 WPScan
3.8 Low Crelly Slider Plugin crelly-slider Cross-Site Scripting Admin+ Stored XSS < 1.4.7 Fixed in 1.4.7 CVE-2024-13116 WPScan
3.8 Low Contact Form by Bit Form Plugin bit-form Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 2.17.4 CVE-2024-13450 Wordfence
2.7 Low Form Maker by 10Web Plugin form-maker Cross-Site Scripting Admin+ Stored XSS < 1.15.31 Fixed in 1.15.31 CVE-2024-10562 WPScan
2.7 Low Photo Gallery, Images, Slider in Rbs Image Gallery Plugin Cross-Site Scripting Contributor+ Stored XSS < 3.2.22 Fixed in 3.2.22 CVE-2024-10102 WPScan
3.1 Low Spacer Plugin spacer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Information Disclosure ≤ 3.0.7 CVE-2024-10527 Wordfence
3.7 Low Easy Digital Downloads Plugin easy-digital-downloads Broken Access Control Improper Authorization to Paywall Bypass No login needed 3.1 – 3.3.4 CVE-2024-9654 Wordfence
3.5 Low Analytify Plugin wp-analytify Broken Access Control ≤ 5.1.0 Fixed in 5.1.1 CVE-2023-41695 Patchstack
3.5 Low Popup Maker Plugin popup-maker Broken Access Control ≤ 1.17.1 Fixed in 1.18.0 CVE-2022-45819 Patchstack
3.7 Low AR Plugin ar-for-wordpress Broken Access Control Missing Authorization to Unauthenticated Limited File Upload No login needed ≤ 7.3 CVE-2024-12300 Wordfence
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.13 Fixed in 1.4.15 CVE-2023-23814 Patchstack
3.1 Low Spectra Plugin ultimate-addons-for-gutenberg Broken Access Control WordPress Gutenberg Blocks plugin <= 2.3.0 - Broken Access Control + CSRF on Import_WPforms ≤ 2.3.0 Fixed in 2.3.1 CVE-2023-23825 Patchstack
3.5 Low WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) Plugin miniorange-login-openid Broken Access Control ≤ 7.5.14 Fixed in 7.6.0 CVE-2023-24375 Patchstack
3.7 Low WordPress Console Plugin wordpress-console Broken Access Control No login needed ≤ 0.3.9 CVE-2023-28168 Patchstack
3.5 Low WPForms Plugin wpforms-lite Cross-Site Scripting Admin+ Stored XSS < 1.9.1.6 Fixed in 1.9.1.6 CVE-2024-7056 WPScan
3.5 Low YaDisk Files Plugin wp-yadisk-files Cross-Site Scripting Admin+ Stored XSS ≤ 1.2.5 CVE-2024-10710 WPScan
3.5 Low SEO Plugin by Squirrly SEO Plugin Cross-Site Scripting Editor+ Stored XSS < 12.3.21 Fixed in 12.3.21 CVE-2024-10515 WPScan
2.7 Low Otter - Gutenberg Block Plugin otter-blocks Broken Access Control ≤ 3.0.3 Fixed in 3.0.4 CVE-2024-51671 Patchstack
3.8 Low CM Table Of Contents – WordPress TOC Plugin Cross-Site Request Forgery WordPress TOC Plugin < 1.2.3 - Settings Reset via CSRF < 1.2.3 Fixed in 1.2.3 CVE-2024-5030 WPScan
2.7 Low Multiple Page Generator Plugin – MPG Plugin multiple-pages-generator-by-porthas Path Traversal MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion ≤ 4.0.2 CVE-2024-10672 Wordfence
2.7 Low Uncanny Groups for LearnDash Plugin Broken Access Control Missing Authorization to Authenticated (Group Leader+) User Group Add ≤ 6.1.0.1 CVE-2024-8350 Wordfence
3.7 Low W3 Total Cache Plugin w3-total-cache Information Disclosure Sensitive Credentials Stored in Plaintext No login needed ≤ 2.7.5 CVE-2023-5359 Wordfence
3.7 Low Maintenance Redirect Plugin jf3-maintenance-mode Authentication Bypass IP Bypass No login needed ≤ 2.0.1 Fixed in 2.1.0 CVE-2024-45453 Patchstack
3.5 Low WP ULike Plugin wp-ulike Cross-Site Scripting Subscriber+ Stored-XSS 4.7.1 – < 4.7.2.1 Fixed in 4.7.2.1 CVE-2024-6792 WPScan
3.7 Low Maintenance & Coming Soon Redirect Animation Plugin maintenance-coming-soon-redirect-animation Authentication Bypass Bypass Vulnerability No login needed ≤ 2.3.3 CVE-2024-43944 Patchstack
3.3 Low Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) Plugin easy-digital-downloads Cross-Site Scripting Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via Agreement Text ≤ 3.3.2 CVE-2024-6692 Wordfence
2.7 Low WP Mail SMTP Plugin wp-mail-smtp Information Disclosure Authenticated (Admin+) SMTP Password Exposure ≤ 4.0.1 CVE-2024-6694 Wordfence
3.8 Low Photo Gallery by Ays Plugin gallery-photo-gallery Content Injection Responsive Image Gallery plugin < 5.7.1 - HTML Injection < 5.7.1 Fixed in 5.7.1 CVE-2024-37442 Patchstack
2.7 Low WP Directory Kit Plugin wpdirectorykit Content Injection HTML Injection ≤ 1.3.6 Fixed in 1.3.7 CVE-2024-37253 Patchstack
3.5 Low WooCommerce Plugin woocommerce Content Injection ≤ 8.9.2 Fixed in 9.0.0 CVE-2024-35777 Patchstack
3.5 Low Academy LMS Plugin academy Open Redirect ≤ 2.0.4 CVE-2024-37234 Patchstack
3.1 Low Premium Addons for Elementor Plugin premium-addons-for-elementor Denial of Service Regular Expressions Denial of Service ≤ 4.10.35 CVE-2024-6434 Wordfence
3.7 Low Solid Security Plugin better-wp-security Denial of Service IP Spoofing Leading to Denial of Service No login needed ≤ 9.3.1 Fixed in 9.3.2 CVE-2022-44593 Patchstack
2.7 Low Easy WP SMTP by SendLayer Plugin Information Disclosure Exposure of Sensitive Information via the UI ≤ 2.3.0 CVE-2024-3073 Wordfence
3.8 Low Search & Replace Plugin SQL Injection Admin+ SQL injection < 3.2.2 Fixed in 3.2.2 CVE-2024-4145 WPScan
3.7 Low Under Construction / Maintenance Mode from Acurax Plugin coming-soon-maintenance-mode-from-acurax Authentication Bypass IP Bypass No login needed ≤ 2.6 CVE-2024-35749 Patchstack
3.7 Low weForms Plugin weforms Broken Access Control No login needed ≤ 1.6.20 Fixed in 1.6.21 CVE-2024-30512 Patchstack
3.5 Low Insert or Embed Articulate Content into Plugin Other Iframe Injection ≤ 4.3000000023 CVE-2024-0756 WPScan
3.7 Low All In One WP Security & Firewall Plugin all-in-one-wp-security-and-firewall Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 5.2.4 Fixed in 5.2.5 CVE-2023-52147 Patchstack
3.7 Low Ultimate Dashboard Plugin ultimate-dashboard Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 3.7.10 Fixed in 3.7.11 CVE-2023-49822 Patchstack
3.7 Low WPS Hide Login Plugin wps-hide-login Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2023-49748 Patchstack
3.7 Low Coming soon and Maintenance mode Plugin coming-soon-page Authentication Bypass IP Filtering Bypass No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2023-49741 Patchstack
3.7 Low Hide login page Plugin hide-login-page Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 1.1.9 CVE-2023-48335 Patchstack
3.7 Low LWS Hide Login Plugin lws-hide-login Information Disclosure Secret Login Page Location Disclosure on Multisites No login needed ≤ 2.1.8 Fixed in 2.1.9 CVE-2023-47818 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only