WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 1–50 of 103 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 1 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'platform_user_photo' Custom Field No login needed ≤ 3.3.11 CVE-2026-96650 Wordfence
6.5 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting ≤ 3.3.11 Fixed in 3.3.12 CVE-2026-97286 Patchstack
5.8 Medium Testimonials Widget Plugin Server-Side Request Forgery Unauthenticated SSRF via Featured Image URL No login needed ≤ 4.0.4 CVE-2026-96533 WPScan
7.5 High Testimonials Widget Plugin Broken Access Control Unauthenticated Arbitrary Post Update No login needed ≤ 4.0.4 CVE-2026-96532 WPScan
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute ≤ 3.3.8 CVE-2026-92622 Wordfence
6.4 Medium Live Composer Plugin live-composer-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode ≤ 2.1.19 CVE-2026-16786 Wordfence
5.4 Medium BNE Testimonials Plugin bne-testimonials Cross-Site Scripting Contributor+ Stored XSS via Slider Shortcode < 2.0.8.2 Fixed in 2.0.8.2 CVE-2026-15245 WPScan
7.2 High Real Testimonials Plugin testimonial-free PHP Object Injection ≤ 3.1.15 Fixed in 3.1.16 CVE-2026-59521 Patchstack
6.5 Medium BNE Testimonials Plugin bne-testimonials Cross-Site Scripting ≤ 2.0.8 CVE-2025-68075 Patchstack
6.4 Medium Fancy Testimonials Plugin fancy-testimonials Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.0 CVE-2026-8039 Wordfence
6.4 Medium Testimonial Slider and Showcase Plugin testimonial-slider-and-showcase Cross-Site Scripting WordPress Plugin Testimonial Slider and Showcase 2.2.6 Stored XSS 2.2.6 CVE-2022-50947 VulnCheck
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via testimonial_view Shortcode ≤ 3.2.21 CVE-2026-3239 Wordfence
6.5 Medium Testimonial Slider Plugin testimonial Broken Access Control ≤ 2.0.15 CVE-2025-68000 Patchstack
4.4 Medium Client Testimonial Slider Plugin wp-client-testimonial Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Testimonial Heading' Setting ≤ 2.0 CVE-2026-2716 Wordfence
6.5 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control ≤ 3.2.20 Fixed in 3.2.21 CVE-2026-24957 Patchstack
6.4 Medium Canto Testimonials Plugin canto-testimonials Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'fx' Shortcode Attribute ≤ 1.0 CVE-2026-1095 Wordfence
4.4 Medium Testimonials Creator Plugin testimonials-creator Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting 1.6 CVE-2025-14379 Wordfence
6.4 Medium Client Testimonial Slider Plugin wp-client-testimonial Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aft_testimonial_meta_name' Metabox Field ≤ 2.0 CVE-2025-13897 Wordfence
6.1 Medium Testimonial Master Plugin testimonial-master Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.2.1 CVE-2025-14127 Wordfence
4.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control Missing Authorization to Authenticated (Contributor+) Rating Meta Update ≤ 3.2.18 CVE-2025-14426 Wordfence
6.5 Medium Stars Testimonials Plugin stars-testimonials-with-slider-and-masonry-grid Cross-Site Scripting ≤ 3.3.4 Fixed in 3.3.5 CVE-2025-67912 Patchstack
6.4 Medium MarqueeAddons Plugin marquee-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget ≤ 2.4.3 CVE-2025-8199 Wordfence
4.4 Medium Quick Testimonials Plugin quick-testimonials Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.1 CVE-2025-14378 Wordfence
7.2 High Creta Testimonial Showcase Plugin creta-testimonial-showcase Local File Inclusion Editor+ Local File Inclusion < 1.2.4 Fixed in 1.2.4 CVE-2025-10686 WPScan
4.3 Medium Strong Testimonials Plugin strong-testimonials Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.16 CVE-2025-11268 Wordfence
4.9 Medium Easy Testimonial Slider and Form Plugin easy-testimonial-rotator SQL Injection Authenticated (Admin+) SQL injection ≤ 1.0.2 CVE-2015-10147 Wordfence
7.1 High Awesome Testimonials Plugin awesome-testimonials Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-62933 Patchstack
6.5 Medium Testimonial Slider Plugin testimonial Broken Access Control ≤ 2.0.15 CVE-2025-62929 Patchstack
6.4 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 11.6.2 CVE-2025-8666 Wordfence
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.29 Fixed in 5.30 CVE-2025-62071 Patchstack
7.5 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion ≤ 2.1.7 CVE-2025-32657 Patchstack
8.8 High Testimonial Slider Plugin testimonial-add Local File Inclusion ≤ 3.5.8.6 CVE-2025-60126 Patchstack
6.5 Medium Testimonial Plugin indianic-testimonial SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3 CVE-2025-7826 Wordfence
10.0 Critical TC Testimonials Plugin tc-testimonial Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2025-49410 Patchstack
6.4 Medium Testimonial Post type Plugin testimonial-post-type Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_play Parameter ≤ 1.2.1 CVE-2025-5800 Wordfence
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields ≤ 3.2.11 CVE-2025-7367 Wordfence
7.1 High Testimonials Showcase Plugin testimonials-showcase Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49245 Patchstack
4.3 Medium Testimonials Showcase Plugin testimonials-showcase Broken Access Control ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49246 Patchstack
5.3 Medium GS Testimonial Slider Plugin gs-testimonial Content Injection No login needed ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-47481 Patchstack
4.3 Medium GS Testimonial Slider Plugin gs-testimonial Broken Access Control ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-47467 Patchstack
6.5 Medium Real Testimonials Plugin testimonial-free Cross-Site Scripting ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-22269 Patchstack
8.1 High Testimonial Slider And Showcase Pro Plugin testimonial-slider-showcase-pro Local File Inclusion No login needed ≤ 2.3.15 CVE-2025-32656 Patchstack
8.8 High Testimonial Slider Plugin testimonial PHP Object Injection ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-30889 Patchstack
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.21 Fixed in 5.22 CVE-2025-31886 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
5.9 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Scripting ≤ 1.0.1 CVE-2025-31587 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Broken Access Control ≤ 1.0.1 CVE-2025-31584 Patchstack
7.1 High TBTestimonials Plugin tb-testimonials Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 CVE-2025-26584 Patchstack
5.3 Medium Strong Testimonials Plugin strong-testimonials Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-26975 Patchstack
7.2 High Super Testimonials Plugin sola-testimonials Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2024-13704 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only