Every change, newest first
These rows are not counted anywhere on this site. Checked and refused means we compared this change and then rejected it: the false positive filter for this kind of change judged it to be a false positive rather than a real change. The row is shown so you can check the filter and disagree with us, and it is counted in no figure on this site. No advisory change is here: the advisory engine counts the 2,291 version pairs its filters refused by class rather than writing them out one by one, so this view holds CVE and KEV changes only.
| Changed on, The day the change first became visible in the catalog's public history. Not the day the record was amended, which is earlier by an unknown margin. | Kind | Record or advisory, Which record was edited: a CVE id where the change was to the CVE catalog or the CISA KEV list, a GHSA id where it was to a GitHub advisory. The two are different units and are never counted together. | Vendor or package, The vendor and product a CVE record names, with the organisation that publishes the record under them; or the package an advisory names and its registry. | What changed | Days to revision, The earlier stated value's interval. For a version boundary, it ends at the first replacement of that value; the reported current value may appear later. Starting points differ by kind: record publication, advisory publication, or the observed introduction of a KEV field value. Intervals are not directly comparable across kinds. Missing dates mean unknown, never zero. This does not date when a value became wrong. |
|---|---|---|---|---|---|
| Wed 8 Apr 2026· 169 record changes | |||||
| 2026-04-08 | Product added | CVE-2023-3352 | Wordfence | not named as affected at publication, now names smush – image optimization, compression, lazy load, webp & cdnNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpmudev/smush image optimization – optimize images | compress & lazy load images | convert webp | image cdn; a new product identity is not established | Days to revision 657 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names profilegrid – user profiles, groups and communitiesnot counted: Product identity rewritten with unchanged scope | Days to revision 706 to 996 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-3403 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/profilegrid – user profiles, memberships, groups and communities; a new product identity is not established | Days to revision 996 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-3714 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/profilegrid – user profiles, memberships, groups and communities; a new product identity is not established | Days to revision 996 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3606 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/profilegrid – user profiles, memberships, groups and communities; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | Product added | CVE-2023-3764 | Wordfence | not named as affected at publication, now names pdf builder for woocommerce. create invoices,packing slips and moreNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed edgarrojas/woocommerce pdf invoice builder, create invoices, packing slips and more; a new product identity is not established | Days to revision 952 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names wp ultimate csv importer – import csv, xml & excel into wordpressnot counted: Product identity rewritten with unchanged scope | Days to revision 979 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-4141 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smackcoders/import all pages, post types, products, orders, and users as xml & csv; a new product identity is not established | Days to revision 979 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-4142 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smackcoders/import all pages, post types, products, orders, and users as xml & csv; a new product identity is not established | Days to revision 979 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names wpvivid — backup, migration & stagingnot counted: Product identity rewritten with unchanged scope | Days to revision 726 to 901 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-4637 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpvividplugins/migration, backup, staging – wpvivid; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | same kind of change as the line above | CVE-2023-5121 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpvividplugins/migration, backup, staging – wpvivid; a new product identity is not established | Days to revision 901 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3054 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpvividplugins/migration, backup, staging – wpvivid; a new product identity is not established | Days to revision 726 |
| 2026-04-08 | Product added | CVE-2023-4960 | Wordfence | not named as affected at publication, now names wcfm marketplace – multivendor marketplace for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wclovers/wcfm marketplace – best multivendor marketplace for woocommerce; a new product identity is not established | Days to revision 818 |
| 2026-04-08 | Product added | CVE-2023-5291 | Wordfence | not named as affected at publication, now names blog filter post filteringNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed awordpresslife/blog filter – advanced post filtering with categories or tags, post portfolio gallery, blog design template, post layout; a new product identity is not established | Days to revision 918 |
| 2026-04-08 | Product added | CVE-2023-5467 | Wordfence | not named as affected at publication, now names geo my wpNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ninjew/geo my wordpress; a new product identity is not established | Days to revision 912 |
| 2026-04-08 | Product added | CVE-2023-5504 | Wordfence | not named as affected at publication, now names backwpup – wordpress backup & restore pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wp_media/backwpup – wordpress backup plugin; a new product identity is not established | Days to revision 818 |
| 2026-04-08 | Product added | CVE-2023-5741 | Wordfence | not named as affected at publication, now names custom form builder, contact forms, payment forms, surveys, pollsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed powr/contact form – custom builder, payment form, and more; a new product identity is not established | Days to revision 877 |
| 2026-04-08 | Product added | CVE-2023-5982 | Wordfence | not named as affected at publication, now names updraftplus: wp backup & migration pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed davidanderson/updraftplus: wordpress backup & migration plugin; a new product identity is not established | Days to revision 883 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names spectra gutenberg blocks – website builder for the block editornot counted: Product identity rewritten with unchanged scope | Days to revision 492 to 729 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-6486 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/spectra – wordpress gutenberg blocks; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10484 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/spectra – wordpress gutenberg blocks; a new product identity is not established | Days to revision 492 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1814 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/spectra – wordpress gutenberg blocks; a new product identity is not established | Days to revision 685 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names depicter — popup & slider buildernot counted: Product identity rewritten with unchanged scope | Days to revision 658 to 825 | |
| 2026-04-08 | same kind of change as the line above | CVE-2023-6493 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed averta/depicter slider – responsive image slider, video slider & post slider; a new product identity is not established | Days to revision 825 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4390 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed averta/slider & popup builder by depicter – add image slider, carousel slider, exit intent popup, popup modal, coupon popup, post slider carousel; a new product identity is not established | Days to revision 658 |
| 2026-04-08 | Product added | CVE-2023-6884 | Wordfence | not named as affected at publication, now names rich showcase for google reviewsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed widgetpack/plugin for google reviews; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | Product added | CVE-2023-6953 | Wordfence | not named as affected at publication, now names fluent pdf generatorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpmanageninja/pdf generator for fluent forms – the contact form plugin; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | Product added | CVE-2023-6957 | Wordfence | not named as affected at publication, now names fluent forms – customizable contact forms, survey, quiz, & conversational form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techjewel/contact form plugin by fluent forms for quiz, survey, and drag & drop wp form builder; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | Product added | CVE-2024-0377 | Wordfence | not named as affected at publication, now names lifterlms – wp lms for elearning, online courses, & quizzesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed chrisbadgett/lifterlms – wordpress lms plugin for elearning; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | Product added | CVE-2024-0434 | Wordfence | not named as affected at publication, now names travelly – tour & travel booking manager for woocommerce | tour & hotel booking solutionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed magepeopleteam/wordpress tour & travel booking plugin for woocommerce – wptravelly; a new product identity is not established | Days to revision 680 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names the plus addons for elementor – addons for elementor, page templates, widgets, mega menu, woocommercenot counted: Product identity rewritten with unchanged scope | Days to revision 432 to 699 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0445 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 699 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10365 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 505 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11829 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 432 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-2784 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 685 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-2785 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 699 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4484 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 685 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4983 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed posimyththemes/the plus addons for elementor – elementor addons, page templates, widgets, mega menu, woocommerce; a new product identity is not established | Days to revision 650 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names orbit fox: duplicate page, menu icons, svg support, cookie notice, custom fonts & morenot counted: Product identity rewritten with unchanged scope | Days to revision 454 to 793 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0508 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themeisle/orbit fox by themeisle; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13183 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themeisle/orbit fox by themeisle; a new product identity is not established | Days to revision 454 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1497 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themeisle/orbit fox by themeisle; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1499 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themeisle/orbit fox by themeisle; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names royal addons for elementor – addons and templates kit for elementornot counted: Product identity rewritten with unchanged scope | Days to revision 671 to 791 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0511 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 791 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0512 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0514 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0515 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0516 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4087 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 677 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4488 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wproyal/royal elementor addons and templates; a new product identity is not established | Days to revision 671 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names essential addons for elementor – popular elementor templates & widgetsnot counted: Product identity rewritten with unchanged scope | Days to revision 279 to 793 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0586 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1171 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1172 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1276 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-2623 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3333 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 721 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4624 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 694 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-5073 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/essential addons for elementor – best elementor templates, widgets, kits & woocommerce builders; a new product identity is not established | Days to revision 679 |
| 2 more rows in this change are not listed here. Open all 10 rows → | |||||
| 2026-04-08 | Product added | CVE-2024-0612 | Wordfence | not named as affected at publication, now names content views – post grid & filter, recent posts, category posts … (shortcode, gutenberg blocks, and widgets for elementor)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed pt-guy/content views – post grid, slider, accordion (gutenberg blocks and shortcode); a new product identity is not established | Days to revision 793 |
| 2026-04-08 | Product added | CVE-2024-0660 | Wordfence | not named as affected at publication, now names formidable forms – contact form plugin, survey, quiz, payment, calculator form & custom form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed strategy11team/formidable forms – contact form, survey, quiz, payment, calculator form & custom form builder; a new product identity is not established | Days to revision 793 |
| 2026-04-08 | Product added | CVE-2024-0681 | Wordfence | not named as affected at publication, now names page and post restrictionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cyberlord92/page restriction wordpress (wp) – protect wp pages/post; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | Product added | CVE-2024-0836 | Wordfence | not named as affected at publication, now names review schema – review & structure data schema pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/wordpress review & structure data schema plugin – review schema; a new product identity is not established | Days to revision 798 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names element pack – widgets, templates & addons for elementornot counted: Product identity rewritten with unchanged scope | Days to revision 473 to 732 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0837 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid & carousel, remote arrows); a new product identity is not established | Days to revision 732 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11852 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid, carousel and remote arrows); a new product identity is not established | Days to revision 473 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3926 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid & carousel, remote arrows); a new product identity is not established | Days to revision 686 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4359 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid & carousel, remote arrows); a new product identity is not established | Days to revision 608 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-5555 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bdthemes/element pack elementor addons (header footer, template library, dynamic grid & carousel, remote arrows); a new product identity is not established | Days to revision 629 |
| 2026-04-08 | Product added | CVE-2024-0952 | Wordfence | not named as affected at publication, now names erp: complete hr, accounting & crm suite with woocommerce crm supportNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp erp | complete hr solution with recruitment & job listings | woocommerce crm & accounting; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names webtoffee woocommerce pdf invoices, packing slips, delivery notes & shipping labelsnot counted: Product identity rewritten with unchanged scope | Days to revision 733 to 748 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-0957 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webtoffee/woocommerce pdf invoices, packing slips, delivery notes and shipping labels; a new product identity is not established | Days to revision 748 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3216 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webtoffee/woocommerce pdf invoices, packing slips, delivery notes and shipping labels; a new product identity is not established | Days to revision 733 |
| 2026-04-08 | Product added | CVE-2024-10055 | Wordfence | not named as affected at publication, now names wp click to chat – email, live chat, call & book now buttonsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ninjateam/click to chat – wp support all-in-one floating widget; a new product identity is not established | Days to revision 537 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names project manager – ai powered project management, task management, kanban board & time trackernot counted: Product identity rewritten with unchanged scope | Days to revision 417 to 512 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10174 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp project manager – task, team, and project management plugin featuring kanban board and gantt charts; a new product identity is not established | Days to revision 512 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10548 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp project manager – task, team, and project management plugin featuring kanban board and gantt charts; a new product identity is not established | Days to revision 476 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13752 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wedevs/wp project manager – task, team, and project management plugin featuring kanban board and gantt charts; a new product identity is not established | Days to revision 417 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names sms alert – sms & otp for woocommerce, order notifications & abandoned cart recoverynot counted: Product identity rewritten with unchanged scope | Days to revision 526 to 756 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10233 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cozyvision1/sms alert order notifications – woocommerce; a new product identity is not established | Days to revision 526 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1489 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cozyvision1/sms alert order notifications – woocommerce; a new product identity is not established | Days to revision 756 |
| 2026-04-08 | Product added | CVE-2024-10247 | Wordfence | not named as affected at publication, now names video gallery – youtube gallery, vimeo, video portfolio, image portfolio and image galleryNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed totalsoft/video gallery – youtube gallery and vimeo gallery; a new product identity is not established | Days to revision 489 |
| 2026-04-08 | Product added | CVE-2024-10392 | Wordfence | not named as affected at publication, now names ai puffer – your ai engine for wordpress (formerly ai power)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed senols/ai power: complete ai pack; a new product identity is not established | Days to revision 525 |
| 2026-04-08 | Product added | CVE-2024-10508 | Wordfence | not named as affected at publication, now names registrationmagic – custom registration forms, user registration, payment, and user loginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed metagauss/registrationmagic – user registration plugin with custom registration forms; a new product identity is not established | Days to revision 515 |
| 2026-04-08 | Product added | CVE-2024-10536 | Wordfence | not named as affected at publication, now names fancypost – post blocks, grids & sliders for block editor and elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpqode/fancypost – best ultimate post block, post grid, layouts, carousel, slider for gutenberg & elementor; a new product identity is not established | Days to revision 457 |
| 2026-04-08 | Product added | CVE-2024-10542 | Wordfence | not named as affected at publication, now names spam protection, honeypot, anti-spam by cleantalkNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cleantalk/spam protection, anti-spam, firewall by cleantalk; a new product identity is not established | Days to revision 499 |
| 2026-04-08 | Product added | CVE-2024-10666 | Wordfence | not named as affected at publication, now names feeds for twitter – embed social media posts with live updatesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bplugins/easy twitter feed – twitter feeds plugin for wp; a new product identity is not established | Days to revision 503 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names affiliate-toolkit – multi-network affiliate & amazon product displaynot counted: Product identity rewritten with unchanged scope | Days to revision 503 to 762 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10675 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cservit/affiliate-toolkit – wp affiliate plugin with amazon; a new product identity is not established | Days to revision 503 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1851 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cservit/affiliate-toolkit – wordpress affiliate plugin; a new product identity is not established | Days to revision 762 |
| 2026-04-08 | Product added | CVE-2024-10685 | Wordfence | not named as affected at publication, now names business essentials for contact form 7Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed scottpaterson/contact form 7 redirect & thank you page; a new product identity is not established | Days to revision 513 |
| 2026-04-08 | Product added | CVE-2024-10687 | Wordfence | not named as affected at publication, now names contest gallery – upload & vote photos, media, sell with paypal & stripeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed contest-gallery/photos, files, youtube, twitter, instagram, tiktok, ecommerce contest gallery – upload, vote, sell via paypal, social share buttons; a new product identity is not established | Days to revision 519 |
| 2026-04-08 | Product added | CVE-2024-10692 | Wordfence | not named as affected at publication, now names powerpack addons for elementor (free widgets, extensions and templates)Not counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ideaboxcreations/powerpack elementor addons (free widgets, extensions and templates); a new product identity is not established | Days to revision 488 |
| 2026-04-08 | Product added | CVE-2024-10878 | Wordfence | not named as affected at publication, now names sugar calendar – events calendar, event tickets, and events management platformNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed smub/sugar calendar – event calendar, event tickets, and event management platform; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names product table and list builder for woocommerce litenot counted: Product identity rewritten with unchanged scope | Days to revision 505 to 620 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-10899 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wcproducttable/woocommerce product table lite; a new product identity is not established | Days to revision 505 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-6458 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wcproducttable/woocommerce product table lite; a new product identity is not established | Days to revision 620 |
| 2026-04-08 | Product added | CVE-2024-10970 | Wordfence | not named as affected at publication, now names motors – car dealership & classified listings pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed stylemix/motors – car dealer, classifieds & listing; a new product identity is not established | Days to revision 448 |
| 2026-04-08 | Product added | CVE-2024-11202 | Wordfence | not named as affected at publication, now names cm business directory – optimise and showcase local business and 5 morenot counted: Product identity rewritten with unchanged scope | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm business directory – optimise and showcase local businessNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm business directory plugin – business listing directory; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm e-mail blacklist – simple email filtering for safer registrationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/name: cm e-mail registration blacklist; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm header and footer – add custom scripts and styles to your header and footer with easeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm header & footer script loader – insert script plugin; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm pop-up – create engaging popups to capture attention and boost interactionNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm pop-up banners for wordpress; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm search and replace – optimize content edits with a powerful search and replace toolNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/cm wordpress search and replace plugin; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11202 | same vendor as the line above | not named as affected at publication, now names cm video lessons manager – simplify video lessons management for better educationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed creativemindssolutions/video lessons manager – wordpress lms plugin; a new product identity is not established | Days to revision 498 |
| 2026-04-08 | Product added | CVE-2024-11265 | Wordfence | not named as affected at publication, now names easymedia – increase media upload file size | role-based upload limit | increase execution timeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed codepopular/increase maximum upload file size | increase execution time; a new product identity is not established | Days to revision 502 |
| 2026-04-08 | Product added | CVE-2024-11270 | Wordfence | not named as affected at publication, now names webinarpress – webinar system for wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpwebinarsystem/wordpress webinar plugin – webinarpress; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | Product added | CVE-2024-11275 | Wordfence | not named as affected at publication, now names timetics – appointment booking & schedulingNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed arraytics/wp timetics- ai-powered appointment booking calendar and online scheduling plugin; a new product identity is not established | Days to revision 481 |
| 2026-04-08 | Product added | CVE-2024-11388 | Wordfence | not named as affected at publication, now names dino game – embed google chrome dinosaur game in your websiteNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed tahmidulkarim/dino game – embed google chrome dinosaur game in wordpress; a new product identity is not established | Days to revision 504 |
| 2026-04-08 | Product added | CVE-2024-11642 | Wordfence | not named as affected at publication, now names post grid master — post grids & ajax filtersNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mdshuvo/post grid master – custom post types, taxonomies & ajax filter everything with infinite scroll, load more, pagination & shortcode builder; a new product identity is not established | Days to revision 454 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names kudos donations: easy donations with mollie | one-off & recurring | pdf invoices | buttons & formsnot counted: Product identity rewritten with unchanged scope | Days to revision 496 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11684 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed iseardmedia/kudos donations – easy donations and payments with mollie; a new product identity is not established | Days to revision 496 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11685 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed iseardmedia/kudos donations – easy donations and payments with mollie; a new product identity is not established | Days to revision 496 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names wp job portal – ai-powered recruitment system for company or job board websitenot counted: Product identity rewritten with unchanged scope | Days to revision 432 to 481 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-11712 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 481 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12131 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12132 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 460 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13371 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 432 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13372 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 432 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13428 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpjobportal/wp job portal – a complete recruitment system for company or job board website; a new product identity is not established | Days to revision 432 |
| 2026-04-08 | Product added | CVE-2024-11724 | Wordfence | not named as affected at publication, now names cookie banner for gdpr / ccpa – wplp cookie consentNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wplegalpages/cookie consent, consent log, cookie scanner, script blocker (for gdpr, ccpa & eprivacy) : wp cookie consent; a new product identity is not established | Days to revision 483 |
| 2026-04-08 | Product added | CVE-2024-11733 | Wordfence | not named as affected at publication, now names wp popular postsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed hcabrera/wordpress popular posts; a new product identity is not established | Days to revision 460 |
| 2026-04-08 | Product added | CVE-2024-11756 | Wordfence | not named as affected at publication, now names sweepwidget – contests, giveaways, sweepstakes & photo contestsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sweepwidget/sweepwidget contests, giveaways, photo contests, competitions; a new product identity is not established | Days to revision 457 |
| 2026-04-08 | Product added | CVE-2024-11766 | Wordfence | not named as affected at publication, now names gs books showcase – display books in grid, slider & more | library for wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed samdani/wordpress book plugin for displaying books in grid, flip, slider, popup layout and more; a new product identity is not established | Days to revision 483 |
| 2026-04-08 | Product added | CVE-2024-11826 | Wordfence | not named as affected at publication, now names quill forms | conversational multi step forms, surveys & quizzesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed mdmag/quill forms | the best typeform alternative | create conversational multi step form, survey, quiz, cost estimation or donation form on wordpress; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | Product added | CVE-2024-11855 | Wordfence | not named as affected at publication, now names koalendar – easy appointment scheduling & booking pluginNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed koalendar/koalendar – events & appointments booking calendar; a new product identity is not established | Days to revision 481 |
| 2026-04-08 | Product added | CVE-2024-11880 | Wordfence | not named as affected at publication, now names b testimonial – customer testimonials in custom layoutsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bplugins/b testimonial – testimonial plugin for wp; a new product identity is not established | Days to revision 490 |
| 2026-04-08 | Product added | CVE-2024-11930 | Wordfence | not named as affected at publication, now names taskbuilder – project management & task management tool with kanban boardNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed taskbuilder/taskbuilder – wordpress project & task management plugin; a new product identity is not established | Days to revision 459 |
| 2026-04-08 | Product added | CVE-2024-12112 | Wordfence | not named as affected at publication, now names easy form builder by whitestudio — drag & drop form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed hassantafreshi/easy form builder – wordpress plugin form builder: contact form, survey form, payment form, and custom form builder; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | Product added | CVE-2024-12156 | Wordfence | not named as affected at publication, now names qc seo help for llms.txt, ai analytics, ai content writer, subtitle to articleNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed quantumcloud/ai content writer, rss feed to post, autoblogging seo help; a new product identity is not established | Days to revision 483 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names bit form – custom contact form, multi step, conversational form & payment form buildernot counted: Product identity rewritten with unchanged scope | Days to revision 281 to 470 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12190 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bitpressadmin/contact form by bit form: multi step form, calculation contact form, payment contact form & custom contact form builder; a new product identity is not established | Days to revision 470 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13450 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bitpressadmin/contact form by bit form: multi step form, calculation contact form, payment contact form & custom contact form builder; a new product identity is not established | Days to revision 438 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13451 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bitpressadmin/contact form by bit form: multi step form, calculation contact form, payment contact form & custom contact form builder; a new product identity is not established | Days to revision 281 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names wc affiliate – woocommerce affiliate pluginnot counted: Product identity rewritten with unchanged scope | Days to revision 390 to 437 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12334 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed codexpert/wc affiliate – a complete woocommerce affiliate plugin; a new product identity is not established | Days to revision 437 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12336 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed codexpert/wc affiliate – a complete woocommerce affiliate plugin; a new product identity is not established | Days to revision 390 |
| 2026-04-08 | Product added | CVE-2024-12338 | Wordfence | not named as affected at publication, now names website toolbox forumNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed websitetoolbox/website toolbox community; a new product identity is not established | Days to revision 483 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names binary mlm for woocommercenot counted: Product identity rewritten with unchanged scope | Days to revision 457 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12383 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed letscms/binary mlm woocommerce; a new product identity is not established | Days to revision 457 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-12384 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed letscms/binary mlm woocommerce; a new product identity is not established | Days to revision 457 |
| 2026-04-08 | Product added | CVE-2024-12395 | Wordfence | not named as affected at publication, now names additional fees for woocommerce checkoutNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed amitwpdeveloper/woocommerce additional fees on checkout (free); a new product identity is not established | Days to revision 477 |
| 2026-04-08 | Product added | CVE-2024-12412 | Wordfence | not named as affected at publication, now names booking and rental manager for bike | car | resort | appointment | dress | equipmentNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed magepeopleteam/rental and booking manager for bike, car, dress, resort with woocommerce integration – wprently | wordpress plugin; a new product identity is not established | Days to revision 453 |
| 2026-04-08 | Product added | CVE-2024-12544 | Wordfence | not named as affected at publication, now names surveyjs: drag & drop form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devsoftbaltic/surveyjs: drag & drop wordpress form builder to create, style and embed multiple forms of any complexity; a new product identity is not established | Days to revision 404 |
| 2026-04-08 | Product added | CVE-2024-12560 | Wordfence | not named as affected at publication, now names button block – design stylish, interactive, and multi-functional buttonsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed bplugins/button block – get fully customizable & multi-functional buttons; a new product identity is not established | Days to revision 476 |
| 2026-04-08 | Product added | CVE-2024-12584 | Wordfence | not named as affected at publication, now names xpro addons — 140+ widgets for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed xpro/140+ widgets | xpro addons for elementor – free; a new product identity is not established | Days to revision 456 |
| 2026-04-08 | Product added | CVE-2024-13354 | Wordfence | not named as affected at publication, now names responsive addons for elementor – free elementor addons, kits and elementor templatesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cyberchimps/responsive addons for elementor – free elementor addons plugin and elementor templates; a new product identity is not established | Days to revision 439 |
| 2026-04-08 | Product added | CVE-2024-13487 | Wordfence | not named as affected at publication, now names curcy – multi currency for woocommerce – smoothly on woocommerce 9.xNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed villatheme/curcy – multi currency for woocommerce – the best free currency exchange plugin – run smoothly on woocommerce 9.x; a new product identity is not established | Days to revision 427 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names nex-forms – ultimate forms plugin for wordpressnot counted: Product identity rewritten with unchanged scope | Days to revision 393 to 798 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13498 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webaways/nex-forms – ultimate form builder – contact forms and much more; a new product identity is not established | Days to revision 393 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1130 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed webaways/nex-forms – ultimate form builder – contact forms and much more; a new product identity is not established | Days to revision 798 |
| 2026-04-08 | Product added | CVE-2024-13541 | Wordfence | not named as affected at publication, now names adirectory – wp business directory plugin and classified ads listings directoryNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed adirectory/adirectory – wordpress directory listing plugin; a new product identity is not established | Days to revision 421 |
| 2026-04-08 | Product added | CVE-2024-13606 | Wordfence | not named as affected at publication, now names js help desk – ai-powered support & ticketing systemNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed rabilal/js help desk – the ultimate help desk & support plugin; a new product identity is not established | Days to revision 419 |
| 2026-04-08 | Product added | CVE-2024-13697 | Wordfence | not named as affected at publication, now names better messages – live chat, chat rooms, real-time messaging & private messagesNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wordplus/better messages – live chat for wordpress, buddypress, peepso, ultimate member, buddyboss; a new product identity is not established | Days to revision 403 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names responsive plus – elementor templates & starter sitesnot counted: Product identity rewritten with unchanged scope | Days to revision 417 to 673 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-13834 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cyberchimps/responsive plus – starter templates, advanced features and customizer settings for responsive theme.; a new product identity is not established | Days to revision 417 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-5222 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed cyberchimps/responsive addons – starter templates, advanced features and customizer settings for responsive theme.; a new product identity is not established | Days to revision 673 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names easy social feed – social photos gallery and post feed for wordpressnot counted: Product identity rewritten with unchanged scope | Days to revision 757 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1214 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sjaved/easy social feed – social photos gallery – post feed – like box; a new product identity is not established | Days to revision 757 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1278 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sjaved/easy social feed – social photos gallery – post feed – like box; a new product identity is not established | Days to revision 757 |
| 2026-04-08 | Product added | CVE-2024-1294 | Wordfence | not named as affected at publication, now names sunshine photo cart – client photo gallery & photo proofing for photographersNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed sunshinephotocart/sunshine photo cart: free client galleries for photographers; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names jeg kit for elementor – powerful addons for elementor, widgets & templates for wordpressnot counted: Product identity rewritten with unchanged scope | Days to revision 663 to 757 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1326 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not established | Days to revision 757 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3162 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not established | Days to revision 736 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4479 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed jegtheme/jeg elementor kit; a new product identity is not established | Days to revision 663 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names classified listing – ai-powered classified ads & business directory pluginnot counted: Product identity rewritten with unchanged scope | Days to revision 713 to 729 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1352 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/classified listing – classified ads & business directory plugin; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3893 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed techlabpro1/classified listing – classified ads & business directory plugin; a new product identity is not established | Days to revision 713 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names lead form builder & contact formnot counted: Product identity rewritten with unchanged scope | Days to revision 706 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1415 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themehunk/responsive contact form builder & lead generation plugin; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1416 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed themehunk/responsive contact form builder & lead generation plugin; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names ht mega addons for elementor – elementor widgets & template buildernot counted: Product identity rewritten with unchanged scope | Days to revision 652 to 757 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1421 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not established | Days to revision 757 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-3307 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-4875 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not established | Days to revision 687 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-5173 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed devitemsllc/ht mega – absolute addons for elementor; a new product identity is not established | Days to revision 652 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names livemesh addons by elementornot counted: Product identity rewritten with unchanged scope | Days to revision 729 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1458 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed livemesh/elementor addons by livemesh; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1461 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed livemesh/elementor addons by livemesh; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | Product added | CVE-2024-1467 | Wordfence | not named as affected at publication, now names starter templates – ai-powered templates for elementor & gutenbergNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed brainstormforce/starter templates — elementor, wordpress & beaver builder templates; a new product identity is not established | Days to revision 699 |
| 2026-04-08 | Product added | CVE-2024-1562 | Wordfence | not named as affected at publication, now names gsheetconnector for woocommerce – send your orders and products to google sheet in real-timeNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed westerndeal/woocommerce google sheet connector; a new product identity is not established | Days to revision 778 |
| 2026-04-08 | Product added | CVE-2024-1698 | Wordfence | not named as affected at publication, now names notificationx – fomo, live sales notification, woocommerce sales popup, gdpr, social proof, announcement banner & floating notification barNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpdevteam/notificationx – best fomo, social proof, woocommerce sales popup & notification bar plugin with elementor; a new product identity is not established | Days to revision 772 |
| 2026-04-08 | Product added | CVE-2024-1716 | Wordfence | not named as affected at publication, now names admin bar editor – toolbar customization with user role based access & custom menusNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed litonice13/admin bar editor – hide toolbar by user roles; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | Product added | Wordfence | not named as affected at publication, now names wp ulike – like & dislike buttons for engagement and feedbacknot counted: Product identity rewritten with unchanged scope | Days to revision 706 | |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1759 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed alimir/wp ulike – most advanced wordpress marketing toolkit; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | same kind of change as the line above | CVE-2024-1797 | same vendor as the line above | same change as the line aboveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed alimir/wp ulike – most advanced wordpress marketing toolkit; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | Product added | CVE-2024-1812 | Wordfence | not named as affected at publication, now names everest forms – contact form, payment form, quiz, survey & custom form builderNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed wpeverest/everest forms – build contact forms, surveys, polls, quizzes, newsletter & application forms, and many more with ease!; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | Product added | CVE-2024-2086 | Wordfence | not named as affected at publication, now names file manager for google drive – integrate google driveNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed princeahmed/integrate google drive – browse, upload, download, embed, play, share, gallery, and manage your google drive files into your wordpress site; a new product identity is not established | Days to revision 740 |
| 2026-04-08 | Product added | CVE-2024-2124 | Wordfence | not named as affected at publication, now names translate wordpress with weglot – multilingual ai translationNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed remyb92/translate wordpress and go multilingual – weglot; a new product identity is not established | Days to revision 750 |
| 2026-04-08 | Product added | CVE-2024-2324 | Wordfence | not named as affected at publication, now names fileorganizer – wordpress file managerNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed softaculous/fileorganizer – manage wordpress and website files; a new product identity is not established | Days to revision 706 |
| 2026-04-08 | Product added | CVE-2024-2348 | Wordfence | not named as affected at publication, now names gum addon for elementorNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed celomitan/gum elementor addon; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | Product added | CVE-2024-2381 | Wordfence | not named as affected at publication, now names aliexpress dropshipping plugin for woocommerce & wordpressNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ali2woo/aliexpress dropshipping with alinext lite; a new product identity is not established | Days to revision 659 |
| 2026-04-08 | Product added | CVE-2024-2384 | Wordfence | not named as affected at publication, now names wcpos – point of sale (pos) plugin for woocommerceNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed kilbot/woocommerce pos; a new product identity is not established | Days to revision 750 |
| 2026-04-08 | Product added | CVE-2024-2456 | Wordfence | not named as affected at publication, now names ecwid by lightspeed ecommerce shopping cartNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed ecwid/ecwid ecommerce shopping cart; a new product identity is not established | Days to revision 729 |
| 2026-04-08 | Product added | CVE-2024-2501 | Wordfence | not named as affected at publication, now names hubbub lite – fast, free social sharing and follow buttonsNot counted: Product identity rewritten with unchanged scope. unchanged affected scope with a rewritten title of removed nerdpressteam/hubbub lite – fast, reliable social sharing buttons; a new product identity is not established | Days to revision 729 |
Two units, never added: changes to a CVE record or KEV entry, and changes to a GitHub advisory. Rows, not records: a moved fix version or an extended range counts once per record, product and release branch; an added product once per record and product; every other kind once per record or advisory. Days to revision is how long the value first stated stood: from the record's or advisory's publication, or from the day a KEV field value was first seen, to the first commit that replaced it. An addition to KEV has no earlier value and shows none. A collapsed line is one publisher's run of identical changes on one day; it says how many, and opens to all of them.
Data sources and quality
Not checked: A CVE record published before 2023, and a KEV listing added before 2025-01-27, were never seen changing. An absence here is not evidence that a record held.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
The units, the refusals, the cut-offs and every source, in full →