WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.
Showing 351–400 of 404 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Gutenberg Blocks and Page Layouts – Attire Blocks | Broken Access Control Attire Blocks <= 1.9.2 - Missing Authorization |
≤ 1.9.2 |
CVE-2024-4088 |
Wordfence | |
| 6.4 Medium | SureTriggers – Connect All Your Plugins, Apps, Tools & Automate Everything! | Cross-Site Scripting Connect All Your Plugins, Apps, Tools & Automate Everything! <= 1.0.46 - Authenticated (Contributor+) Stored Cross-Site Scripting via Trigger Link Shortcode |
≤ 1.0.47 |
CVE-2024-5485 |
Wordfence | |
| 7.2 High | Social Link Pages: link-in-bio landing pages for your social media profiles | Broken Access Control Missing Authorization to Arbitrary Page Creation and Cross-Site Scripting No login needed |
≤ 1.6.9 |
CVE-2024-3555 |
Wordfence | |
| 4.8 Medium | Playlist for Youtube | Cross-Site Scripting Editor+ Stored XSS |
≤ 1.32 |
CVE-2024-3937 |
WPScan | |
| 6.4 Medium | Custom Fonts – Host Your Fonts Locally | Cross-Site Scripting Host Your Fonts Locally <= 2.1.4 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 2.1.4 |
CVE-2024-1332 |
Wordfence | |
| 4.3 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Broken Access Control Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Insufficient Authorization Checks to Block Usual |
≤ 3.9.12 |
CVE-2024-1803 |
Wordfence | |
| 4.3 Medium | ApplyOnline – Application Form Builder and Manager | Broken Access Control Application Form Builder and Manager <= 2.6.2 - Missing Authorization to Sensitive Information Exposure |
≤ 2.6.2 |
CVE-2024-2036 |
Wordfence | |
| 5.3 Medium | YouTube Video Gallery by YouTube Showcase – Video Gallery | Broken Access Control Video Gallery Plugin for WordPress <= 3.3.6 - Missing Authorization to Arbitrary Post/Page Creation No login needed |
≤ 3.3.6 |
CVE-2024-3268 |
Wordfence | |
| 9.8 Critical | Masteriyo - LMS | Privilege Escalation No login needed |
≤ 1.7.2 Fixed in 1.7.3 |
CVE-2024-24882 |
Patchstack | |
| 6.4 Medium | Yoast SEO | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 22.6 |
CVE-2024-4984 |
Wordfence | |
| 4.3 Medium | Password Protected – Ultimate Plugin to Password Protect Your WordPress Content with Ease | Broken Access Control Ultimate Plugin to Password Protect Your WordPress Content with Ease <= 2.6.6 - Missing Authorization to Sensitive Information Exposure |
≤ 2.6.6 |
CVE-2024-0437 |
Wordfence | |
| 6.4 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via layout_html Parameter |
≤ 4.2.6.5 |
CVE-2024-4277 |
Wordfence | |
| 6.1 Medium | Yoast SEO | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 22.5 |
CVE-2024-4041 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 3.9.16 |
CVE-2024-4316 |
Wordfence | |
| 4.3 Medium | Video Gallery – Api Gallery, YouTube and Vimeo, Link Gallery | Broken Access Control Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Access Control |
≤ 1.5.3 Fixed in 1.5.4 |
CVE-2024-34377 |
Patchstack | |
| 5.5 Medium | Where Did You Hear About Us Checkout Field for WooCommerce | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2024-2752 |
Wordfence | |
| 5.3 Medium | Advanced Post Block – Display Posts, Pages, or Custom Posts on Your Page | Broken Access Control Display Posts, Pages, or Custom Posts on Your Page <= 1.13.4 - Missing Authorization to Information Disclosure No login needed |
≤ 1.13.4 |
CVE-2024-0908 |
Wordfence | |
| 8.3 High | ZD YouTube FLV Player | Server-Side Request Forgery No login needed |
≤ 1.2.6 |
CVE-2024-2663 |
Wordfence | |
| 4.3 Medium | Serious Slider | Cross-Site Request Forgery No login needed |
≤ 1.2.4 |
CVE-2024-33650 |
Patchstack | |
| 4.3 Medium | EleSpare – News, Magazine and Blog Addons for Elementor | Broken Access Control Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! <= 2.1.2 - Missing Authorization to Subscriber+ Arbitrary Post Creation |
≤ 2.1.2 |
CVE-2024-0900 |
Wordfence | |
| 6.5 Medium | DSGVO Youtube | Cross-Site Scripting |
≤ 1.4.5 Fixed in 1.4.6 |
CVE-2024-32596 |
Patchstack | |
| 6.4 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.7 - Authenticated(Contributor+) Blind Server-Side Request Forgery (SSRF) |
≤ 4.4.7 |
CVE-2023-6805 |
Wordfence | |
| 6.5 Medium | Yoga Schedule Momoyoga | Cross-Site Scripting |
≤ 2.7.0 |
CVE-2024-32529 |
Patchstack | |
| 4.3 Medium | Custom Thank You Page Customize For WooCommerce by Binary Carpenter | Broken Access Control |
≤ 1.4.12 Fixed in 1.4.14 |
CVE-2024-32517 |
Patchstack | |
| 4.3 Medium | NextMove Lite | Cross-Site Request Forgery No login needed |
≤ 2.18.1 Fixed in 2.18.2 |
CVE-2024-32104 |
Patchstack | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.9.14 |
CVE-2024-3244 |
Wordfence | |
| 6.5 Medium | MailMunch – Grow your Email List | Cross-Site Scripting Grow your Email List plugin <= 3.1.6 - Cross Site Scripting (XSS) |
≤ 3.1.6 Fixed in 3.1.7 |
CVE-2024-31349 |
Patchstack | |
| 6.4 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Cross-Site Scripting Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Error Message |
≤ 4.3.3 |
CVE-2023-6877 |
Wordfence | |
| 6.4 Medium | Powerkit – Supercharge your WordPress Site | Cross-Site Scripting Supercharge your WordPress Site <= 2.9.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.9.1 |
CVE-2024-2458 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Block |
≤ 3.9.14 |
CVE-2024-3245 |
Wordfence | |
| 6.4 Medium | ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) | Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) <= 2.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via WL Universal Product Layout |
≤ 2.8.3 |
CVE-2024-2868 |
Wordfence | |
| 7.1 High | Yoo Slider | Cross-Site Scripting Image Slider & Video Slider plugin <= 2.1.1 - Reflected Cross Site Scripting (XSS) No login needed |
≤ 2.1.1 |
CVE-2024-31106 |
Patchstack | |
| 7.5 High | Layouts for Elementor | Arbitrary File Upload No login needed |
< 1.8 Fixed in 1.8 |
CVE-2024-30533 |
Patchstack | |
| 6.5 Medium | B Slider - Slider for your block editor | Cross-Site Scripting |
≤ 1.1.12 Fixed in 1.1.13 |
CVE-2024-30432 |
Patchstack | |
| 7.3 High | Youzify - Buddypress Moderation | Cross-Site Scripting Buddypress Moderation plugin <= 1.2.5 - Unauthenticated Cross Site Scripting (XSS) No login needed |
≤ 1.2.5 |
CVE-2024-2864 |
Patchstack | |
| 5.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.12 - Authenticated (Contributor+) Stored Cross-site Scripting via 'embedpress_doc_custom_color' |
≤ 3.9.12 |
CVE-2024-2688 |
Wordfence | |
| 4.3 Medium | RevivePress – Keep your Old Content Evergreen | Broken Access Control Keep your Old Content Evergreen <= 1.5.6 - Missing Authorization |
≤ 1.5.6 |
CVE-2024-1844 |
Wordfence | |
| 6.1 Medium | Travelpayouts | Open Redirect No login needed |
≤ 1.1.15 |
CVE-2024-0337 |
WPScan | |
| 4.3 Medium | Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | Cross-Site Request Forgery Make Your Blog Posts Accessible With Text to Speech Audio <= 3.6.4 - Cross-Site Request Forgery No login needed |
≤ 3.6.4 |
CVE-2024-0827 |
Wordfence | |
| 8.8 High | Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | PHP Object Injection Make Your Blog Posts Accessible With Text to Speech Audio <= 3.6.4 - Authenticated (Contributor+) PHP Object Injection |
≤ 3.6.4 |
CVE-2024-1772 |
Wordfence | |
| 5.4 Medium | Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | Broken Access Control Make Your Blog Posts Accessible With Text to Speech Audio <= 3.6.4 - Missing Authorization |
≤ 3.6.4 |
CVE-2024-0828 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Wistia Block |
≤ 3.9.10 |
CVE-2024-1802 |
Wordfence | |
| 6.4 Medium | EmbedPress – PDF Embedder, Embed YouTube Videos, 3D FlipBook, Social feeds, Docs & more | Cross-Site Scripting Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor <= 3.9.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget |
≤ 3.9.10 |
CVE-2024-2128 |
Wordfence | |
| 5.3 Medium | NextMove Lite – Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce | Broken Access Control Thank You Page for WooCommerce & Finale Lite – Sales Countdown Timer & Discount for WooCommerce <= 2.17.0 - Missing Authorization to Unauthenticated System Information Disclosure No login needed |
≤ 2.17.0, ≤ 2.18.0 |
CVE-2024-1120 |
Wordfence | |
| 5.4 Medium | Thank You Page Customizer for WooCommerce – Increase Your Sales | Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Execution |
≤ 1.1.2 |
CVE-2024-1687 |
Wordfence | |
| 4.3 Medium | Thank You Page Customizer for WooCommerce – Increase Your Sales | Broken Access Control Increase Your Sales <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Data Export |
≤ 1.1.2 |
CVE-2024-1686 |
Wordfence | |
| 7.1 High | Sitepact | SQL Injection WordPress Sitepact's Contact Form 7 Extension For Klaviyo Plugin <= 1.0.5 is vulnerable to SQL Injection No login needed |
≤ 1.0.5 Fixed in 3.0.0 |
CVE-2024-25928 |
Patchstack | |
| 6.5 Medium | AMP for WP | Broken Access Control Authenticated(Contributor+) Arbitrary Post Deletion via amppb_remove_saved_layout_data |
≤ 1.0.93.1 |
CVE-2024-1043 |
Wordfence | |
| 6.5 Medium | My Agile Privacy – The only GDPR solution for WordPress that you can truly trust | Cross-Site Scripting WordPress My Agile Privacy Plugin <= 2.1.7 is vulnerable to Cross Site Scripting (XSS) |
≤ 2.1.7 Fixed in 2.1.8 |
CVE-2023-51404 |
Patchstack | |
| 4.3 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Broken Access Control Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 4.4.1 - Missing Authorization |
≤ 4.4.1 |
CVE-2024-1092 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.