WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 451–500 of 1,027 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 21
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Information Disclosure Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.8.1 CVE-2024-13498 Wordfence
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 CVE-2025-1664 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence
6.4 Medium Page Builder by SiteOrigin Plugin siteorigin-panels Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.31.4 CVE-2025-1459 Wordfence
6.4 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Cross-Site Scripting Portfolio Gallery <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-1757 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.3 CVE-2024-13803 Wordfence
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 10.8 Fixed in 10.9 CVE-2025-26884 Patchstack
6.5 Medium Popup Builder Plugin easy-notify-lite Cross-Site Scripting ≤ 1.1.33 Fixed in 1.1.35 CVE-2025-26882 Patchstack
6.5 Medium Elementor Website Builder Plugin elementor Cross-Site Scripting ≤ 3.25.10 Fixed in 3.25.11 CVE-2024-54444 Patchstack
6.4 Medium Elementor Website Builder – More Than Just a Page Builder Plugin elementor Cross-Site Scripting More Than Just a Page Builder <= 3.27.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.27.4 CVE-2024-13445 Wordfence
5.3 Medium WordPress Portfolio Builder – Portfolio Gallery Plugin uber-grid Broken Access Control Portfolio Gallery <= 1.1.7 - Missing Authorization to Unauthenticated Portfolio Update No login needed ≤ 1.1.7 CVE-2024-13231 Wordfence
6.4 Medium Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-13591 Wordfence
4.3 Medium FormCraft Plugin formcraft-form-builder Broken Access Control Missing Authorization to Plugin Data Export in formcraft-main.php ≤ 3.9.11 CVE-2024-13783 Wordfence
6.4 Medium Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) Plugin simple-pricing-tables-vc-extension Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2024-13582 Wordfence
4.3 Medium Team Builder – Meet the Team Plugin team-display Broken Access Control Meet the Team <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.3 CVE-2024-13687 Wordfence
6.4 Medium Zigaform – Form Builder Lite Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite <= 7.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.4.7 CVE-2024-13573 Wordfence
6.4 Medium Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite <= 7.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.4.7 CVE-2024-13587 Wordfence
6.5 Medium Vertex Addons for Elementor Plugin addons-for-elementor-builder Cross-Site Scripting ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-26769 Patchstack
6.4 Medium Brizy – Page Builder Plugin brizy Cross-Site Scripting Page Builder <= 2.6.8 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.6.8 CVE-2024-10322 Wordfence
6.4 Medium Rise Blocks – A Complete Gutenberg Page Builder Plugin rise-blocks Cross-Site Scripting A Complete Gutenberg Page Builder <= 3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via TitleTag Parameter ≤ 3.6 CVE-2025-0506 Wordfence
6.5 Medium Easy Chart Builder Plugin easy-chart-builder Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3 CVE-2025-25077 Patchstack
4.3 Medium Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time Plugin builder-shortcode-extras Information Disclosure WordPress Shortcodes Collection to Save You Time <= 1.0.0 - Authenticated (Contributor+) Post Disclosure ≤ 1.0.0 CVE-2024-13841 Wordfence
6.5 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function ≤ 1.27.6 CVE-2025-0859 Wordfence
5.3 Medium WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Information Disclosure Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.0.8 CVE-2024-13829 Wordfence
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7 CVE-2024-13733 Wordfence
6.1 Medium iBuildApp Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.2.0 CVE-2024-13326 WPScan
6.3 Medium MagicForm - WordPress Form Builder Plugin magicform Broken Access Control WordPress Form Builder <= 1.6.2 - Missing Authorization ≤ 1.6.2 CVE-2025-0939 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.1.8 CVE-2024-11829 Wordfence
6.5 Medium AI Infographic Maker Plugin infographic-and-list-builder-ilist Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.9.0 CVE-2024-12415 Wordfence
4.3 Medium Elementor Website Builder Pro – More than Just a Page Builder Plugin Information Disclosure More than Just a Page Builder <= 3.25.10 - Authenticated (Contributor+) Sensitive Information Exposure via Shortcode ≤ 3.25.10 CVE-2024-8494 Wordfence
6.4 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Scripting The Contact Form Builder That Grows With You <= 3.8.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.8.24 CVE-2024-13470 Wordfence
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
6.5 Medium PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce Cross-Site Scripting ≤ 4.6.0 Fixed in 4.7.0 CVE-2025-24755 Patchstack
5.9 Medium FAQ Builder AYS Plugin faq-builder-ays Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-24722 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
4.3 Medium Internal Links Manager Plugin seo-automated-link-building Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-24679 Patchstack
5.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Broken Access Control No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-24633 Patchstack
6.5 Medium Form Builder CP Plugin cp-easy-form-builder SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2.41 CVE-2024-13680 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting in Multiple Widgets ≤ 3.11.11 CVE-2024-12477 Wordfence
6.1 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.6.5 CVE-2024-13319 Wordfence
6.4 Medium Stackable – Page Builder Gutenberg Blocks Plugin stackable-ultimate-gutenberg-blocks Cross-Site Scripting Page Builder Gutenberg Blocks <= 3.13.11 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.13.11 CVE-2024-12117 Wordfence
6.4 Medium Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Scripting Turnkey Video Site Builder Script <= 2.6.31 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.31 CVE-2024-13393 Wordfence
6.1 Medium Kubio AI Page Builder Plugin kubio Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.5 CVE-2024-13516 Wordfence
6.5 Medium GMAPS for WPBakery Page Builder Free Plugin gmaps-for-visual-composer-free Cross-Site Scripting ≤ 1.2 CVE-2025-23775 Patchstack
4.3 Medium Build Private Store For Woocommerce Plugin build-private-store-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.1 CVE-2025-22731 Patchstack
6.5 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Scripting Visual Drag and Drop Editor plugin <= 1.27.5 - Cross Site Scripting (XSS) ≤ 1.27.5 Fixed in 1.27.6 CVE-2025-22759 Patchstack
4.3 Medium Elementor Addon Elements Plugin addon-elements-for-elementor-page-builder Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup ≤ 1.13.10 CVE-2024-13215 Wordfence
6.4 Medium PDF for WPForms + Drag and Drop Template Builder Plugin pdf-for-wpforms Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yeepdf_dotab Shortcode ≤ 4.6.0 CVE-2024-12593 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only