Skip to content

Every change, newest first

What a record said when it was published, what it says now, and the commit that changed it.

230 changes refused · newest first · grouped by dayCSVJSONRSS

SinceClear all
ChangedSourceRows

Showing changes seen on 2026-04-08. Every day

These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.

Rows we checked and refused, counted nowhere changed on 2026-04-08, newest first, one line per change to a CVE record, or per run of identical changes collapsed into one line.
Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin.KindRecord, Which record was edited, by its CVE id, or how many records one collapsed line stands on.Vendor · product, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry.What changedDays to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong.
Wed 8 Apr 2026· 100 changes
2026-04-08Affected range extendedCVE-2023-4948
yan&cowoocommerce cvr payment gateway
Wordfence
stated at publication 6.1.0, now states 6.1.0Release branch starts at 0.Not counted: Same claim, other operator. `lte` rewritten as `lt` on the same or the next release — the same claim under the other operatorTime to revision 938 days
2026-04-08Affected range extendedCVE-2024-12502
homeasapmy idx home search
Wordfence
stated at publication 2.0.1, now states 2.1.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpTime to revision 481 days
2026-04-08Affected range extendedCVE-2025-8484
nickclarkwebcode quality control tool
Wordfence
stated at publication 0.1, now states 2.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpTime to revision 179 days
2026-04-08Affected range extendedCVE-2024-10587
funnelformsinteractive contact form and multi step form builder with drag & drop editor – funnelforms free
Wordfence
stated at publication 3.7.4.1, now states 3.7.5.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpTime to revision 491 days
2026-04-08Affected range extendedCVE-2024-12024
metagausseventprime – events calendar, bookings and tickets
Wordfence
stated at publication 4.0.5.3, now states 4.0.7.3Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpTime to revision 477 days
2026-04-08Affected range extendedCVE-2025-6754
seometricspluginseo metrics
Wordfence
stated at publication 1.0.5, now states 1.0.15Release branch starts at 0.Not counted: Description already named the later value. the record's own description at publication already named 1.0.15 — the structured field was corrected to the value the prose stated, not a fix that movedTime to revision 249 days
2026-04-08Affected range extendedCVE-2024-11889
homeasapmy idx home search
Wordfence
stated at publication 2.0.1, now states 2.1.1Release branch starts at 0.Not counted: Product line renumbered. leading component changed with meaningful tail intact — product-line renumbering, not a fix bumpTime to revision 481 days
2026-04-08Product addedCVE-2023-0292Wordfencenot named as affected at publication, now names quiz and survey master (qsm) – easy quiz and survey makerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed expresstech/quiz and survey master – best quiz, exam and survey plugin for wordpress; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-0895Wordfencenot named as affected at publication, now names wp coder – insert & manage code snippetsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpcalc/wp coder – add custom html, css and js code; a new product identity is not establishedTime to revision 1,146 days
2026-04-08Product addedCVE-2023-1807Wordfencenot named as affected at publication, now names stax addons for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed staxwp/elementor addons, widgets and enhancements – stax; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-1889Wordfencenot named as affected at publication, now names directorist: ai-powered business directory, listings & classified adsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwax/directorist – wordpress business directory plugin with classified ads listings; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2083Wordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2085Wordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2087Wordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2170Wordfencenot named as affected at publication, now names tag, category, and taxonomy manager – ai autotagger with openaiNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stevejburge/taxopress is the wordpress tag, category, and taxonomy manager; a new product identity is not establishedTime to revision 1,085 days
2026-04-08Product addedCVE-2023-2275Wordfencenot named as affected at publication, now names wcfm – multivendor marketplace rest api for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wclovers/woocommerce multivendor marketplace – rest api; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2688Wordfencenot named as affected at publication, now names iptanus file uploadNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not establishedTime to revision 1,035 days
2026-04-08Product addedCVE-2023-2706Wordfencenot named as affected at publication, now names otp login & register woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed xootix/otp login woocommerce & gravity forms; a new product identity is not establishedTime to revision 1,058 days
2026-04-08Product addedCVE-2023-2717Wordfencenot named as affected at publication, now names groundhogg — crm, newsletters, and marketing automationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed trainingbusinesspros/wordpress crm, email & marketing automation for wordpress | award winner — groundhogg; a new product identity is not establishedTime to revision 1,055 days
2026-04-08Product addedCVE-2023-3087Wordfencenot named as affected at publication, now names fluentsmtp – wp smtp plugin with amazon ses, sendgrid, mailgun, postmark, google and any smtp providerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techjewel/fluentsmtp – wp mail smtp, amazon ses, sendgrid, mailgun and any smtp connector plugin; a new product identity is not establishedTime to revision 1,002 days
2026-04-08Product addedCVE-2023-3125Wordfencenot named as affected at publication, now names b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not establishedTime to revision 1,037 days
2026-04-08Product addedCVE-2023-3126Wordfencenot named as affected at publication, now names b2bking — ultimate woocommerce b2b and wholesale plugin — wholesale prices, bulk order form & moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webwizardsdev/b2bking — ultimate woocommerce wholesale and b2b solution; a new product identity is not establishedTime to revision 1,037 days
2026-04-08Product addedCVE-2023-3132Wordfencenot named as affected at publication, now names mainwp child – securely connects to the mainwp dashboard to manage multiple sitesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mainwp/mainwp child – securely connects sites to the mainwp wordpress manager dashboard; a new product identity is not establishedTime to revision 1,017 days
2026-04-08Product addedCVE-2023-3342Wordfencenot named as affected at publication, now names user registration & membership – free & paid memberships, subscriptions, content restriction, user profile, custom user registration & login builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/user registration – custom registration form, login form and user profile for wordpress; a new product identity is not establishedTime to revision 1,001 days
2026-04-08Product addedCVE-2023-3352Wordfencenot named as affected at publication, now names smush – image optimization, compression, lazy load, webp & cdnNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpmudev/smush image optimization – optimize images | compress & lazy load images | convert webp | image cdn; a new product identity is not establishedTime to revision 657 days
2026-04-08Product addedCVE-2023-3403Wordfencenot named as affected at publication, now names profilegrid – user profiles, groups and communitiesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/profilegrid – user profiles, memberships, groups and communities; a new product identity is not establishedTime to revision 996 days
2026-04-08Product addedCVE-2023-3714Wordfencenot named as affected at publication, now names profilegrid – user profiles, groups and communitiesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/profilegrid – user profiles, memberships, groups and communities; a new product identity is not establishedTime to revision 996 days
2026-04-08Product addedCVE-2023-3764Wordfencenot named as affected at publication, now names pdf builder for woocommerce. create invoices,packing slips and moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed edgarrojas/woocommerce pdf invoice builder, create invoices, packing slips and more; a new product identity is not establishedTime to revision 952 days
2026-04-08Product addedCVE-2023-4141Wordfencenot named as affected at publication, now names wp ultimate csv importer – import csv, xml & excel into wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smackcoders/import all pages, post types, products, orders, and users as xml & csv; a new product identity is not establishedTime to revision 979 days
2026-04-08Product addedCVE-2023-4142Wordfencenot named as affected at publication, now names wp ultimate csv importer – import csv, xml & excel into wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smackcoders/import all pages, post types, products, orders, and users as xml & csv; a new product identity is not establishedTime to revision 979 days
2026-04-08Product addedCVE-2023-4386Wordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedTime to revision 901 days
2026-04-08Product addedCVE-2023-4637Wordfencenot named as affected at publication, now names wpvivid — backup, migration & stagingNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpvividplugins/migration, backup, staging – wpvivid; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2023-4960Wordfencenot named as affected at publication, now names wcfm marketplace – multivendor marketplace for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wclovers/wcfm marketplace – best multivendor marketplace for woocommerce; a new product identity is not establishedTime to revision 818 days
2026-04-08Product addedCVE-2023-5121Wordfencenot named as affected at publication, now names wpvivid — backup, migration & stagingNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpvividplugins/migration, backup, staging – wpvivid; a new product identity is not establishedTime to revision 901 days
2026-04-08Product addedCVE-2023-5291Wordfencenot named as affected at publication, now names blog filter post filteringNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed awordpresslife/blog filter – advanced post filtering with categories or tags, post portfolio gallery, blog design template, post layout; a new product identity is not establishedTime to revision 918 days
2026-04-08Product addedCVE-2023-5467Wordfencenot named as affected at publication, now names geo my wpNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ninjew/geo my wordpress; a new product identity is not establishedTime to revision 912 days
2026-04-08Product addedCVE-2023-5504Wordfencenot named as affected at publication, now names backwpup – wordpress backup & restore pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wp_media/backwpup – wordpress backup plugin; a new product identity is not establishedTime to revision 818 days
2026-04-08Product addedCVE-2023-5741Wordfencenot named as affected at publication, now names custom form builder, contact forms, payment forms, surveys, pollsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed powr/contact form – custom builder, payment form, and more; a new product identity is not establishedTime to revision 877 days
2026-04-08Product addedCVE-2023-5982Wordfencenot named as affected at publication, now names updraftplus: wp backup & migration pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed davidanderson/updraftplus: wordpress backup & migration plugin; a new product identity is not establishedTime to revision 883 days
2026-04-08Product addedCVE-2023-6486Wordfencenot named as affected at publication, now names spectra gutenberg blocks – website builder for the block editorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/spectra – wordpress gutenberg blocks; a new product identity is not establishedTime to revision 729 days
2026-04-08Product addedCVE-2023-6493Wordfencenot named as affected at publication, now names depicter — popup & slider builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed averta/depicter slider – responsive image slider, video slider & post slider; a new product identity is not establishedTime to revision 825 days
2026-04-08Product addedCVE-2023-6884Wordfencenot named as affected at publication, now names rich showcase for google reviewsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed widgetpack/plugin for google reviews; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2023-6953Wordfencenot named as affected at publication, now names fluent pdf generatorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpmanageninja/pdf generator for fluent forms – the contact form plugin; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2023-6957Wordfencenot named as affected at publication, now names fluent forms – customizable contact forms, survey, quiz, & conversational form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techjewel/contact form plugin by fluent forms for quiz, survey, and drag & drop wp form builder; a new product identity is not establishedTime to revision 756 days
2026-04-08Product addedCVE-2023-7071Wordfencenot named as affected at publication, now names gutenberg essential blocks – page builder for gutenberg blocks & patternsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential blocks – page builder gutenberg blocks, patterns & templates; a new product identity is not establishedTime to revision 818 days
2026-04-08Product addedCVE-2024-0377Wordfencenot named as affected at publication, now names lifterlms – wp lms for elearning, online courses, & quizzesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed chrisbadgett/lifterlms – wordpress lms plugin for elearning; a new product identity is not establishedTime to revision 756 days
2026-04-08Product addedCVE-2024-0434Wordfencenot named as affected at publication, now names travelly – tour & travel booking manager for woocommerce | tour & hotel booking solutionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed magepeopleteam/wordpress tour & travel booking plugin for woocommerce – wptravelly; a new product identity is not establishedTime to revision 680 days
2026-04-08Product addedCVE-2024-0445Wordfencenot named as affected at publication, now names the plus addons for elementor – addons for elementor, page templates, widgets, mega menu, woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not establishedTime to revision 699 days
2026-04-08Product addedCVE-2024-0508Wordfencenot named as affected at publication, now names orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themeisle/orbit fox by themeisle; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2024-0511Wordfencenot named as affected at publication, now names royal addons for elementor – addons and templates kit for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not establishedTime to revision 791 days
2026-04-08Product addedCVE-2024-0512Wordfencenot named as affected at publication, now names royal addons for elementor – addons and templates kit for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not establishedTime to revision 778 days
2026-04-08Product addedCVE-2024-0514Wordfencenot named as affected at publication, now names royal addons for elementor – addons and templates kit for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not establishedTime to revision 778 days
2026-04-08Product addedCVE-2024-0515Wordfencenot named as affected at publication, now names royal addons for elementor – addons and templates kit for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not establishedTime to revision 778 days
2026-04-08Product addedCVE-2024-0516Wordfencenot named as affected at publication, now names royal addons for elementor – addons and templates kit for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not establishedTime to revision 778 days
2026-04-08Product addedCVE-2024-0586Wordfencenot named as affected at publication, now names essential addons for elementor – popular elementor templates & widgetsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2024-0612Wordfencenot named as affected at publication, now names content views – post grid & filter, recent posts, category posts … (shortcode, gutenberg blocks, and widgets for elementor)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed pt-guy/content views – post grid, slider, accordion (gutenberg blocks and shortcode); a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2024-0660Wordfencenot named as affected at publication, now names formidable forms – contact form plugin, survey, quiz, payment, calculator form & custom form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed strategy11team/formidable forms – contact form, survey, quiz, payment, calculator form & custom form builder; a new product identity is not establishedTime to revision 793 days
2026-04-08Product addedCVE-2024-0681Wordfencenot named as affected at publication, now names page and post restrictionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cyberlord92/page restriction wordpress (wp) – protect wp pages/post; a new product identity is not establishedTime to revision 756 days
2026-04-08Product addedCVE-2024-0836Wordfencenot named as affected at publication, now names review schema – review & structure data schema pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/wordpress review & structure data schema plugin – review schema; a new product identity is not establishedTime to revision 798 days
2026-04-08Product addedCVE-2024-0837Wordfencenot named as affected at publication, now names element pack – widgets, templates & addons for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid & carousel, remote arrows); a new product identity is not establishedTime to revision 732 days
2026-04-08Product addedCVE-2024-0952Wordfencenot named as affected at publication, now names erp: complete hr, accounting & crm suite with woocommerce crm supportNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp erp | complete hr solution with recruitment & job listings | woocommerce crm & accounting; a new product identity is not establishedTime to revision 729 days
2026-04-08Product addedCVE-2024-0957Wordfencenot named as affected at publication, now names webtoffee woocommerce pdf invoices, packing slips, delivery notes & shipping labelsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webtoffee/woocommerce pdf invoices, packing slips, delivery notes and shipping labels; a new product identity is not establishedTime to revision 748 days
2026-04-08Product addedCVE-2024-10055Wordfencenot named as affected at publication, now names wp click to chat – email, live chat, call & book now buttonsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ninjateam/click to chat – wp support all-in-one floating widget; a new product identity is not establishedTime to revision 537 days
2026-04-08Product addedCVE-2024-10174Wordfencenot named as affected at publication, now names project manager – ai powered project management, task management, kanban board & time trackerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp project manager – task, team, and project management plugin featuring kanban board and gantt charts; a new product identity is not establishedTime to revision 512 days
2026-04-08Product addedCVE-2024-10233Wordfencenot named as affected at publication, now names sms alert – sms & otp for woocommerce, order notifications & abandoned cart recoveryNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cozyvision1/sms alert order notifications – woocommerce; a new product identity is not establishedTime to revision 526 days
2026-04-08Product addedCVE-2024-10247Wordfencenot named as affected at publication, now names video gallery – youtube gallery, vimeo, video portfolio, image portfolio and image galleryNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed totalsoft/video gallery – youtube gallery and vimeo gallery; a new product identity is not establishedTime to revision 489 days
2026-04-08Product addedCVE-2024-10365Wordfencenot named as affected at publication, now names the plus addons for elementor – addons for elementor, page templates, widgets, mega menu, woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not establishedTime to revision 505 days
2026-04-08Product addedCVE-2024-10392Wordfencenot named as affected at publication, now names ai puffer – your ai engine for wordpress (formerly ai power)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed senols/ai power: complete ai pack; a new product identity is not establishedTime to revision 525 days
2026-04-08Product addedCVE-2024-10484Wordfencenot named as affected at publication, now names spectra gutenberg blocks – website builder for the block editorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/spectra – wordpress gutenberg blocks; a new product identity is not establishedTime to revision 492 days
2026-04-08Product addedCVE-2024-10508Wordfencenot named as affected at publication, now names registrationmagic – custom registration forms, user registration, payment, and user loginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/registrationmagic – user registration plugin with custom registration forms; a new product identity is not establishedTime to revision 515 days
2026-04-08Product addedCVE-2024-10536Wordfencenot named as affected at publication, now names fancypost – post blocks, grids & sliders for block editor and elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpqode/fancypost – best ultimate post block, post grid, layouts, carousel, slider for gutenberg & elementor; a new product identity is not establishedTime to revision 457 days
2026-04-08Product addedCVE-2024-10542Wordfencenot named as affected at publication, now names spam protection, honeypot, anti-spam by cleantalkNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cleantalk/spam protection, anti-spam, firewall by cleantalk; a new product identity is not establishedTime to revision 499 days
2026-04-08Product addedCVE-2024-10548Wordfencenot named as affected at publication, now names project manager – ai powered project management, task management, kanban board & time trackerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp project manager – task, team, and project management plugin featuring kanban board and gantt charts; a new product identity is not establishedTime to revision 476 days
2026-04-08Product addedCVE-2024-10666Wordfencenot named as affected at publication, now names feeds for twitter – embed social media posts with live updatesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bplugins/easy twitter feed – twitter feeds plugin for wp; a new product identity is not establishedTime to revision 503 days
2026-04-08Product addedCVE-2024-10675Wordfencenot named as affected at publication, now names affiliate-toolkit – multi-network affiliate & amazon product displayNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cservit/affiliate-toolkit – wp affiliate plugin with amazon; a new product identity is not establishedTime to revision 503 days
2026-04-08Product addedCVE-2024-10685Wordfencenot named as affected at publication, now names business essentials for contact form 7Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed scottpaterson/contact form 7 redirect & thank you page; a new product identity is not establishedTime to revision 513 days
2026-04-08Product addedCVE-2024-10687Wordfencenot named as affected at publication, now names contest gallery – upload & vote photos, media, sell with paypal & stripeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed contest-gallery/photos, files, youtube, twitter, instagram, tiktok, ecommerce contest gallery – upload, vote, sell via paypal, social share buttons; a new product identity is not establishedTime to revision 519 days
2026-04-08Product addedCVE-2024-10692Wordfencenot named as affected at publication, now names powerpack addons for elementor (free widgets, extensions and templates)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ideaboxcreations/powerpack elementor addons (free widgets, extensions and templates); a new product identity is not establishedTime to revision 488 days
2026-04-08Product addedCVE-2024-10878Wordfencenot named as affected at publication, now names sugar calendar – events calendar, event tickets, and events management platformNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smub/sugar calendar – event calendar, event tickets, and event management platform; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-10899Wordfencenot named as affected at publication, now names product table and list builder for woocommerce liteNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wcproducttable/woocommerce product table lite; a new product identity is not establishedTime to revision 505 days
2026-04-08Product addedCVE-2024-10970Wordfencenot named as affected at publication, now names motors – car dealership & classified listings pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stylemix/motors – car dealer, classifieds & listing; a new product identity is not establishedTime to revision 448 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm business directory – optimise and showcase local businessNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm business directory plugin – business listing directory; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm e-mail blacklist – simple email filtering for safer registrationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/name: cm e-mail registration blacklist; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm header and footer – add custom scripts and styles to your header and footer with easeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm header & footer script loader – insert script plugin; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm pop-up – create engaging popups to capture attention and boost interactionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm pop-up banners for wordpress; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm search and replace – optimize content edits with a powerful search and replace toolNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm wordpress search and replace plugin; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11202Wordfencenot named as affected at publication, now names cm video lessons manager – simplify video lessons management for better educationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/video lessons manager – wordpress lms plugin; a new product identity is not establishedTime to revision 498 days
2026-04-08Product addedCVE-2024-11265Wordfencenot named as affected at publication, now names easymedia – increase media upload file size | role-based upload limit | increase execution timeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed codepopular/increase maximum upload file size | increase execution time; a new product identity is not establishedTime to revision 502 days
2026-04-08Product addedCVE-2024-11270Wordfencenot named as affected at publication, now names webinarpress – webinar system for wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwebinarsystem/wordpress webinar plugin – webinarpress; a new product identity is not establishedTime to revision 456 days
2026-04-08Product addedCVE-2024-11275Wordfencenot named as affected at publication, now names timetics – appointment booking & schedulingNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed arraytics/wp timetics- ai-powered appointment booking calendar and online scheduling plugin; a new product identity is not establishedTime to revision 481 days
2026-04-08Product addedCVE-2024-11388Wordfencenot named as affected at publication, now names dino game – embed google chrome dinosaur game in your websiteNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed tahmidulkarim/dino game – embed google chrome dinosaur game in wordpress; a new product identity is not establishedTime to revision 504 days
2026-04-08Product addedCVE-2024-11635Wordfencenot named as affected at publication, now names iptanus file uploadNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nickboss/wordpress file upload; a new product identity is not establishedTime to revision 456 days
2026-04-08Product addedCVE-2024-11642Wordfencenot named as affected at publication, now names post grid master — post grids & ajax filtersNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mdshuvo/post grid master – custom post types, taxonomies & ajax filter everything with infinite scroll, load more, pagination & shortcode builder; a new product identity is not establishedTime to revision 454 days
2026-04-08Product addedCVE-2024-11684Wordfencenot named as affected at publication, now names kudos donations: easy donations with mollie | one-off & recurring | pdf invoices | buttons & formsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed iseardmedia/kudos donations – easy donations and payments with mollie; a new product identity is not establishedTime to revision 496 days
2026-04-08Product addedCVE-2024-11685Wordfencenot named as affected at publication, now names kudos donations: easy donations with mollie | one-off & recurring | pdf invoices | buttons & formsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed iseardmedia/kudos donations – easy donations and payments with mollie; a new product identity is not establishedTime to revision 496 days
2026-04-08Product addedCVE-2024-11712Wordfencenot named as affected at publication, now names wp job portal – ai-powered recruitment system for company or job board websiteNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not establishedTime to revision 481 days
2026-04-08Product addedCVE-2024-11724Wordfencenot named as affected at publication, now names cookie banner for gdpr / ccpa – wplp cookie consentNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wplegalpages/cookie consent, consent log, cookie scanner, script blocker (for gdpr, ccpa & eprivacy) : wp cookie consent; a new product identity is not establishedTime to revision 483 days
2026-04-08Product addedCVE-2024-11733Wordfencenot named as affected at publication, now names wp popular postsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed hcabrera/wordpress popular posts; a new product identity is not establishedTime to revision 460 days
2026-04-08Product addedCVE-2024-11756Wordfencenot named as affected at publication, now names sweepwidget – contests, giveaways, sweepstakes & photo contestsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sweepwidget/sweepwidget contests, giveaways, photo contests, competitions; a new product identity is not establishedTime to revision 457 days
2026-04-08Product addedCVE-2024-11766Wordfencenot named as affected at publication, now names gs books showcase – display books in grid, slider & more | library for wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed samdani/wordpress book plugin for displaying books in grid, flip, slider, popup layout and more; a new product identity is not establishedTime to revision 483 days

Rows, not records: a moved fix version and an added product count once per product, every other kind once per record or advisory.

Use arrow keys to move between days, Home or End to reach either end, and Enter to open a day.
4,561 record edits in the 52 weeks to 2026-09-07. Scroll for earlier dates.fewermore

What this page cannot see

Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.

A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

The units, the refusals, the cut-offs and every source, in full →

Paste your closed CVE tickets and see which of these changes hit them →