WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 451–500 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Fast Cache Plugin wp-fast-cache Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2023-22675 Patchstack
5.4 Medium GiveWP Plugin give Cross-Site Request Forgery No login needed ≤ 4.13.1 Fixed in 4.13.2 CVE-2025-67467 Patchstack
4.3 Medium KALLYAS Theme kallyas Cross-Site Request Forgery No login needed ≤ 4.25.0 Fixed in 4.25.0 CVE-2025-63060 Patchstack
4.3 Medium WP Hotel Booking Plugin wp-hotel-booking Cross-Site Request Forgery No login needed ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-63012 Patchstack
4.9 Medium Hercules Core Plugin hercules-core Server-Side Request Forgery ≤ 7.4 CVE-2025-63010 Patchstack
4.3 Medium WP Flashy Marketing Automation Plugin wp-flashy-marketing-automation Cross-Site Request Forgery No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-62873 Patchstack
4.3 Medium Social Photo Fetcher Plugin facebook-photo-fetcher Cross-Site Request Forgery No login needed ≤ 3.0.4 CVE-2025-62872 Patchstack
4.3 Medium Just TinyMCE Custom Styles Plugin just-tinymce-styles Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-62871 Patchstack
4.3 Medium Auto Alt Text Plugin auto-alt-text Cross-Site Request Forgery No login needed ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-62866 Patchstack
4.3 Medium SMTP Mail Plugin smtp-mail Cross-Site Request Forgery No login needed ≤ 1.3.51 CVE-2025-62762 Patchstack
6.5 Medium Add Custom Codes Plugin add-custom-codes Cross-Site Request Forgery No login needed ≤ 4.80 Fixed in 5.0 CVE-2025-62739 Patchstack
4.3 Medium Media Library Downloader Plugin media-library-downloader Cross-Site Request Forgery No login needed ≤ 1.4.0 CVE-2025-62734 Patchstack
4.3 Medium Custom Sidebars by ProteusThemes Plugin custom-sidebars-by-proteusthemes Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-62733 Patchstack
4.3 Medium Media Library File Download Plugin media-download Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62103 Patchstack
4.3 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Request Forgery No login needed ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-62102 Patchstack
4.3 Medium Duplicate Content Cure Plugin duplicate-content-cure Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-59132 Patchstack
4.3 Medium SupportCandy Plugin supportcandy Cross-Site Request Forgery No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-67598 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Cross-Site Request Forgery No login needed ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-67596 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.82 Fixed in 6.7.0.83 CVE-2025-67595 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.48 Fixed in 1.2.49 CVE-2025-67593 Patchstack
4.3 Medium JNews Paywall Plugin jnews-paywall Cross-Site Request Forgery No login needed ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67591 Patchstack
4.3 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67590 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
4.3 Medium WP Landing Page Plugin wp-landing-page Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Meta Update No login needed ≤ 0.9.3 CVE-2025-13629 Wordfence
4.3 Medium WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors Plugin wc-vendors Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed ≤ 2.6.4 CVE-2025-12130 Wordfence
4.3 Medium ARK Related Posts Plugin ark-relatedpost Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.19 CVE-2025-13684 Wordfence
4.3 Medium Torod – The smart shipping and delivery portal for e-shops and retailers Plugin torod Cross-Site Request Forgery The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification No login needed ≤ 1.9 CVE-2025-12373 Wordfence
4.3 Medium Image Optimizer by wps.sk Plugin image-optimizer-wpssk Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Image Optimization No login needed ≤ 1.2.0 CVE-2025-12190 Wordfence
4.3 Medium Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents Plugin bread-butter Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 7.11.1374 CVE-2025-12189 Wordfence
4.3 Medium Hide Categories Or Products On Shop Page Plugin hide-categories-or-products-on-shop-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.7 CVE-2025-12128 Wordfence
4.3 Medium Time Sheets Plugin time-sheets Cross-Site Request Forgery No login needed ≤ 2.1.3 CVE-2025-10055 Wordfence
4.3 Medium Quantic Social Image Hover Plugin tw-image-hover-share Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.8 CVE-2025-13360 Wordfence
6.1 Medium dream gallery Plugin dream-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed ≤ 1.0 CVE-2025-13621 Wordfence
4.3 Medium ContentStudio Plugin contentstudio Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.3.7 CVE-2025-13144 Wordfence
4.3 Medium Norby AI Plugin norby-ai Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.3 CVE-2025-13362 Wordfence
4.3 Medium Backup, Restore and Migrate your sites with XCloner Plugin xcloner-backup-and-restore Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed ≤ 4.8.2 CVE-2025-11759 Wordfence
4.3 Medium ShopEngine Plugin shopengine Cross-Site Request Forgery Cross-Site Request Forgery to Wishlist Manipulation No login needed ≤ 4.8.5 CVE-2025-12358 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.5 Medium Export All Posts, Products, Orders, Refunds & Users Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed ≤ 2.19 CVE-2025-13606 Wordfence
4.3 Medium Nextend Social Login and Register Plugin nextend-facebook-connect Cross-Site Request Forgery Cross-Site Request Forgery to Unlink User Social Login No login needed ≤ 3.1.21 CVE-2025-13737 Wordfence
6.5 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed ≤ 2.7.0 CVE-2025-13378 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only