WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 1–50 of 50 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
8.6 High Pro Like Button Plugin SQL Injection Unauthenticated SQLi via 'postid' Parameter No login needed < 2.0 Fixed in 2.0 CVE-2026-89296 WPScan
7.1 High Razorpay Payment Button Plugin razorpay-payment-button Cross-Site Scripting No login needed ≤ 2.4.9 Fixed in 2.5.0 CVE-2026-94179 Patchstack
7.1 High Social Media Share Buttons & Social Sharing Icons Plugin ultimate-social-media-icons Cross-Site Scripting Reflected XSS via Pin It Share Handler No login needed < 3.0.1 Fixed in 3.0.1 CVE-2026-19723 WPScan
7.5 High HEL Online Classroom: AI-powered Online Classrooms Plugin Information Disclosure Unauthenticated BigBlueButton API Secret Disclosure No login needed ≤ 1.0.3 CVE-2026-77007 WPScan
8.5 High Like Button Rating Plugin likebtn-like-button SQL Injection ≤ 2.6.61 Fixed in 2.6.62 CVE-2026-78285 Patchstack
7.5 High Lead Generation Contact Widget & AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads Plugin siteleads Information Disclosure SiteLeads plugin <= 1.2.0 - Sensitive Data Exposure No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2026-78268 Patchstack
7.1 High Blog Floating Button Plugin blog-floating-button Cross-Site Scripting No login needed ≤ 1.4.20 Fixed in 1.4.21 CVE-2026-28170 Patchstack
7.1 High Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting No login needed ≤ 2.0.4 Fixed in 2.0.5 CVE-2026-65517 Patchstack
7.5 High Chat Help – Click to Chat Button & Form Plugin chat-help Broken Access Control Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 3.1.3 CVE-2026-15291 Wordfence
7.4 High Chatway Live Chat – AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons Plugin chatway-live-chat Information Disclosure AI Chatbot, Customer Support, FAQ & Helpdesk Customer Service & Chat Buttons plugin <= 1.4.8 - Sensitive Data Exposure ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-49082 Patchstack
7.5 High Simple Social Media Share Buttons Plugin simple-social-buttons Cross-Site Request Forgery No login needed ≤ 6.2.0 Fixed in 6.2.1 CVE-2026-34904 Patchstack
7.1 High Easy Social Share Buttons Plugin easy-social-share-buttons3 Cross-Site Scripting No login needed ≤ 10.7.1 Fixed in 10.7.1 CVE-2025-64198 Patchstack
7.1 High ShareBang, Ultimate Social Share Buttons Plugin sharebang Cross-Site Scripting No login needed ≤ 1.4 CVE-2025-49953 Patchstack
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI <= 26.1.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.1.0 CVE-2025-7725 Wordfence
7.1 High Contact Form 7 Editor Button Plugin cf7-editor-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-48345 Patchstack
8.8 High Game Users Share Buttons Plugin game-users-share-buttons Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion via themeNameId Parameter ≤ 1.3.0 CVE-2025-6755 Wordfence
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.1 High WP Twitter Button Plugin wp-twitter-button Cross-Site Request Forgery No login needed ≤ 1.4.1 CVE-2025-39420 Patchstack
7.1 High WP Sticky Side Buttons Plugin wp-sticky-side-buttons Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-39421 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
7.2 High Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote, Sell via PayPal, Social Share Buttons <= 26.0.0.1 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 26.0.0.1 CVE-2025-1513 Wordfence
7.1 High Page/Post Specific Social Share Buttons Plugin pagepost-specific-social-share-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26580 Patchstack
7.1 High On Page SEO + Whatsapp Chat Button Plugin ops-robots-txt Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-25138 Patchstack
7.1 High Radio Buttons and Swatches for WooCommerce Plugin variations-radio-buttons-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.20 Fixed in 1.1.21 CVE-2025-24551 Patchstack
7.1 High Sticky Button Plugin sticky-chat-button Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23839 Patchstack
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.1 High Pootle button Plugin pootle-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-23758 Patchstack
7.1 High Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3 CVE-2025-23898 Patchstack
7.1 High ECT Add to Cart Button Plugin ect-add-to-cart-button Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23471 Patchstack
7.1 High Bootstrap Buttons Plugin bootstrap-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2024-49677 Patchstack
7.1 High CRUDLab Google Plus Button Plugin crudlab-google-plus Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2024-54399 Patchstack
7.1 High Google Plus Share and +1 Button Plugin google-plus-share-and-plusone-button Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2024-53723 Patchstack
7.3 High Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form Popup – Product Quotation Plugin get-a-quote-button-for-woocommerce Arbitrary Shortcode Execution Get a Quote Button – Product Enquiry Form Popup – Product Quotation <= 1.4 - Unauthenticated Arbitrary Shortcode Execution via fire_contact_form No login needed ≤ 1.4 CVE-2024-11034 Wordfence
7.3 High WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Plugin wpb-popup-for-contact-form-7 Arbitrary Shortcode Execution Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form No login needed ≤ 1.7.5 CVE-2024-11038 Wordfence
8.5 High Share Buttons – Social Media Plugin rich-web-share-button SQL Injection Social Media plugin <= 1.0.2 - SQL Injection ≤ 1.0.2 CVE-2024-51845 Patchstack
7.5 High Instant Chat Floating Button for WordPress Websites Plugin instant-chat-wp Local File Inclusion No login needed ≤ 1.0.5 CVE-2024-44018 Patchstack
7.1 High Like Button Rating Plugin likebtn-like-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.53 Fixed in 2.6.54 CVE-2024-44064 Patchstack
8.5 High Easy Social Share Buttons Plugin Local File Inclusion ≤ 9.4 Fixed in 9.5 CVE-2024-31300 Patchstack
7.1 High CodeBard's Patron Button and Widgets for Patreon Plugin patron-button-and-widgets-by-codebard Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.0 CVE-2024-33928 Patchstack
7.5 High Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Button Deletion via CSRF < 3.2.4 Fixed in 3.2.4 CVE-2024-3475 WPScan
8.8 High Wow Skype Buttons Plugin Cross-Site Request Forgery Button Deletion via CSRF No login needed < 4.0.4 Fixed in 4.0.4 CVE-2024-3474 WPScan
7.5 High Hubbub Lite – Fast, Reliable Social Network Sharing Buttons Plugin social-pug PHP Object Injection Fast, Reliable Social Network Sharing Buttons <= 1.33.1 - PHP Object Injection ≤ 1.33.1 CVE-2024-2501 Wordfence
7.1 High Woocommerce Social Media Share Buttons Plugin woocommerce-social-media-share-buttons Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2024-31109 Patchstack
8.8 High Button Plugin button PHP Object Injection Authenticated (Contributor+) PHP Object Injection in button_shortcode ≤ 1.1.27 CVE-2024-1872 Wordfence
7.1 High Easy Social Share Buttons Plugin Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.4 Fixed in 9.5 CVE-2024-30196 Patchstack
8.2 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection ≤ 2.1.0 CVE-2024-2721 Patchstack
8.8 High Social Media Share Buttons Plugin social-media-builder PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 2.1.0 CVE-2024-1685 Wordfence
8.8 High Podlove Subscribe button Plugin podlove-subscribe-button SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.3.10 CVE-2024-1118 Wordfence
8.8 High Slick Social Share Buttons Plugin slick-social-share-buttons Broken Access Control Authenticated (Subscriber+) Arbitrary Option Update ≤ 2.4.11 CVE-2023-6878 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only