WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 401–450 of 569 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 9 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Mobile DJ Manager Plugin mobile-dj-manager Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.5.6 Fixed in 1.7.6 CVE-2025-22714 Patchstack
6.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.9.0 CVE-2024-12118 Wordfence
7.1 High Ultimate Events Plugin ultimate-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-23610 Patchstack
6.5 Medium FAT Event Lite Plugin fat-event-lite Cross-Site Scripting ≤ 1.1 CVE-2025-22718 Patchstack
4.3 Medium Buzz Club – Night Club, DJ and Music Festival Event Theme Broken Access Control Night Club, DJ and Music Festival Event WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Option Update ≤ 2.0.4 CVE-2025-0515 Wordfence
6.5 Medium Eventer Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read ≤ 3.9.7 CVE-2024-10799 Wordfence
7.5 High FAT Event Lite Plugin fat-event-lite Local File Inclusion Authenticated Non-Arbitrary Local File Inclusion ≤ 1.1 CVE-2025-23915 Patchstack
7.1 High Event Countdown Timer Plugin by TechMix Plugin event-countdown-timer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-23699 Patchstack
6.4 Medium Event Registration Calendar By vcita Plugin event-registration-calendar-by-vcita Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.0 CVE-2024-11870 Wordfence
5.3 Medium Event monster Plugin event-monster Information Disclosure Information Exposure Via Visitors List Export No login needed ≤ 1.4.3 CVE-2024-11396 Wordfence
8.1 High FAT Event Lite Plugin fat-event-lite Local File Inclusion Unauthenticated Non-Arbitrary Local File Inclusion No login needed ≤ 1.1 CVE-2025-22508 Patchstack
5.3 Medium RSVP and Event Management Plugin rsvp Broken Access Control Missing Authorization No login needed ≤ 2.7.13 CVE-2024-12711 Wordfence
4.3 Medium Event Espresso 4 Decaf Plugin event-espresso-decaf Cross-Site Request Forgery No login needed ≤ 5.0.28.decaf Fixed in 5.0.31.decaf CVE-2024-56251 Patchstack
4.3 Medium Event Tickets Plugin event-tickets Cross-Site Request Forgery No login needed ≤ 5.11.0.4 Fixed in 5.11.0.5 CVE-2024-38762 Patchstack
4.3 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.5.1.4 Fixed in 6.5.1.5 CVE-2024-37518 Patchstack
6.5 Medium Eventin Plugin wp-event-solution Local File Inclusion Contributor+ Limited Local File Inclusion ≤ 4.0.7 Fixed in 4.0.9 CVE-2024-56213 Patchstack
5.3 Medium Content No Cache: prevent specific content from being cached Plugin content-no-cache Information Disclosure Unauthenticated Private Content Disclosure No login needed ≤ 0.1.2 CVE-2024-12103 Wordfence
6.5 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via app_export_db ≤ 4.9.2 CVE-2024-12558 Wordfence
6.4 Medium Sell Tickets Online – TicketSource Ticket Shop Plugin ticketsource-events Cross-Site Scripting TicketSource Ticket Shop for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.0.2 CVE-2024-11784 Wordfence
4.3 Medium Events Addon for Elementor Plugin Information Disclosure Authenticated (Contributor+) Post Disclosure ≤ 2.2.3 CVE-2024-12061 Wordfence
6.1 Medium WP BASE Booking of Appointments, Services and Events Plugin wp-base-booking-of-appointments-services-and-events Cross-Site Scripting Reflected Cross-Site Scripting via status Parameter No login needed ≤ 4.9.1 CVE-2024-12469 Wordfence
7.2 High EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Cross-Site Scripting Events Calendar, Bookings and Tickets <= 4.0.7.3 - Unauthenticated Stored Cross-Site Scripting via Ticket Category and Ticket Type Name No login needed ≤ 4.0.7.3 CVE-2024-12024 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Unauthenticated Password Protected Event Disclosure No login needed < 6.8.2.1 Fixed in 6.8.2.1 CVE-2024-5333 WPScan
6.1 Medium Import Eventbrite Events Plugin import-eventbrite-events Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.7.4 CVE-2024-12422 Wordfence
6.4 Medium Koalendar – Events & Appointments Booking Calendar Plugin koalendar-free-booking-widget Cross-Site Scripting Events & Appointments Booking Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via height Parameter ≤ 1.0.2 CVE-2024-11855 Wordfence
5.3 Medium Tickera – WordPress Event Ticketing Plugin Information Disclosure WordPress Event Ticketing <= 3.5.4.8 - Unauthenticated Customer Data Exposure No login needed ≤ 3.5.4.8 CVE-2024-12578 Wordfence
6.5 Medium Hello Event Widgets For Elementor Plugin hello-event-widgets-for-elementor Cross-Site Scripting ≤ 1.0.2 Fixed in 1.1.0 CVE-2024-54338 Patchstack
6.5 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2024-54315 Patchstack
5.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control No login needed ≤ 6.1.2.2 Fixed in 6.1.3 CVE-2023-35777 Patchstack
4.3 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Request Forgery Live Blogging for real-time events <= 0.4.1 - Cross-Site Request Forgery to Settings Update No login needed ≤ 0.4.1 CVE-2024-12526 Wordfence
6.4 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Scripting Live Blogging for real-time events <= 0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via arena_embed_amp Shortcode ≤ 0.4.1 CVE-2024-12463 Wordfence
6.4 Medium Arena.IM – Live Blogging for real-time events Plugin arena-liveblog-and-chat-tool Cross-Site Scripting Live Blogging for real-time events <= 0.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.3.0 CVE-2024-11384 Wordfence
6.4 Medium Add infos to the events calendar Plugin add-infos-to-the-events-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.4.1 CVE-2024-11875 Wordfence
3.8 Low CP Multi View Event Calendar Plugin cp-multi-view-calendar Broken Access Control ≤ 1.4.13 Fixed in 1.4.15 CVE-2023-23814 Patchstack
5.4 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery WordPress Event Ticketing plugin <= 3.5.1.0 - CSRF Leading To Post Status Change No login needed ≤ 3.5.1.0 Fixed in 3.5.1.1 CVE-2023-23726 Patchstack
5.3 Medium Quick Event Manager Plugin quick-event-manager Broken Access Control No login needed ≤ 9.7.4 Fixed in 9.7.5 CVE-2023-23975 Patchstack
5.4 Medium Eventin Plugin wp-event-solution Broken Access Control Authenticated Notice Dismissal ≤ 3.3.52 Fixed in 3.3.53 CVE-2023-49756 Patchstack
5.4 Medium Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 2.4.3 CVE-2024-9866 Wordfence
7.1 High Explara Events Plugin explara-events Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2024-52466 Patchstack
6.5 Medium Advanced Event Manager Plugin advanced-event-manager Cross-Site Scripting ≤ 1.1.6 CVE-2024-53721 Patchstack
7.2 High Activity Log – Monitor & Record User Changes Plugin aryo-activity-log Cross-Site Scripting Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scripting via Event Context No login needed ≤ 2.11.1 CVE-2024-10788 Wordfence
7.1 High Events Manager Pro – extended Plugin events-manager-pro-extended Cross-Site Request Forgery extended plugin <= 0.1 - CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2024-50532 Patchstack
6.5 Medium EventPress Plugin wp-eventpress Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.0 CVE-2024-51861 Patchstack
6.5 Medium Simpul Events by Esotech Plugin simpul-events-by-esotech Cross-Site Scripting ≤ 1.8.5 CVE-2024-51867 Patchstack
9.9 Critical Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Remote Code Execution ≤ 2.3.11 Fixed in 2.3.12 CVE-2024-52427 Patchstack
4.3 Medium Countdown Timer block – Display the event's date into a timer. Plugin Information Disclosure Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributor+) Post Disclosure ≤ 1.2.4 CVE-2024-10669 Wordfence
9.6 Critical Registrations for The Events Calendar Plugin registrations-for-the-events-calendar Cross-Site Scripting Unauthenticated Stored XSS No login needed < 2.12.4 Fixed in 2.12.4 CVE-2024-7982 WPScan
6.4 Medium Event Post Plugin event-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via events_cal Shortcode ≤ 5.9.6 CVE-2024-10186 Wordfence
7.3 High Tickera – WordPress Event Ticketing Plugin tickera-event-ticketing-system Arbitrary Shortcode Execution WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.5.4.4 CVE-2024-10263 Wordfence
6.4 Medium Registrations for the Events Calendar Plugin registrations-for-the-events-calendar Broken Access Control ≤ 2.12.1 Fixed in 2.12.2 CVE-2024-43143 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only