WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 451–500 of 2,544 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP Media Categories Plugin wp-media-categories Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-60134 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60132 Patchstack
4.4 Medium Icegram Express Pro Plugin email-subscribers-premium Server-Side Request Forgery ≤ 5.9.5 Fixed in 5.9.6 CVE-2025-49917 Patchstack
5.4 Medium Captcha.eu Plugin captcha-eu Server-Side Request Forgery No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2025-49374 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Request Forgery No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-49373 Patchstack
4.7 Medium Search & Filter Plugin search-filter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Open Redirect No login needed ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-48099 Patchstack
3.8 Low Pz-LinkCard Plugin pz-linkcard Server-Side Request Forgery Contributor+ SSRF < 2.5.7 Fixed in 2.5.7 CVE-2025-8594 WPScan
5.4 Medium Silencesoft RSS Reader Plugin external-rss-reader Server-Side Request Forgery No login needed ≤ 0.6 CVE-2025-60181 Patchstack
7.1 High GST for WooCommerce Plugin gst-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-60173 Patchstack
7.1 High Flytedesk Digital Plugin flytedesk-digital Cross-Site Request Forgery No login needed ≤ 20181101 CVE-2025-60172 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High HTACCESS IP Blocker Plugin htaccess-ip-blocker Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-60170 Patchstack
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
7.1 High NewsmanApp Plugin newsmanapp Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 3.0.0 CVE-2025-60164 Patchstack
5.4 Medium ZoloBlocks Plugin zoloblocks Server-Side Request Forgery No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-60161 Patchstack
9.6 Critical AR Plugin ar-for-wordpress Cross-Site Request Forgery No login needed ≤ 8.34 CVE-2025-60156 Patchstack
4.3 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60145 Patchstack
4.3 Medium Sendle Shipping Plugin official-sendle-shipping-method Cross-Site Request Forgery No login needed ≤ 6.02 Fixed in 6.03 CVE-2025-60139 Patchstack
4.3 Medium Post Featured Video Plugin post-featured-video Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-60137 Patchstack
4.3 Medium Vehica Core Plugin vehica-core Cross-Site Request Forgery No login needed ≤ 1.0.100 Fixed in 1.0.101 CVE-2025-60117 Patchstack
4.3 Medium Instapage Plugin instapage Cross-Site Request Forgery No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2025-60115 Patchstack
4.3 Medium Groovy Menu Plugin groovy-menu-free Cross-Site Request Forgery No login needed ≤ 1.4.3 CVE-2025-60113 Patchstack
8.8 High Javo Core Plugin javo-core Cross-Site Request Forgery No login needed ≤ 3.0.0.266 CVE-2025-60111 Patchstack
4.3 Medium Download Manager Plugin download-manager Cross-Site Request Forgery No login needed ≤ 3.3.24 Fixed in 3.3.25 CVE-2025-60093 Patchstack
4.3 Medium Di Themes Demo Site Importer Plugin di-themes-demo-site-importer Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Plugin Activation No login needed ≤ 1.2 CVE-2025-58914 Patchstack
7.1 High WP Attractive Donations System Plugin wp-attractive-donations-system-easy-stripe-paypal-donations Cross-Site Request Forgery No login needed ≤ 1.29 Fixed in 1.29 CVE-2025-58956 Patchstack
6.4 Medium Publitio Plugin publitio Server-Side Request Forgery ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-58962 Patchstack
4.3 Medium Zoho Flow Plugin zoho-flow Cross-Site Request Forgery No login needed ≤ 2.14.1 Fixed in 2.14.2 CVE-2025-59568 Patchstack
8.8 High WorkScout-Core Plugin workscout-core Cross-Site Request Forgery No login needed ≤ 1.7.06 Fixed in 1.7.06 CVE-2025-59572 Patchstack
6.5 Medium Penci Shortcodes & Performance Plugin penci-shortcodes Cross-Site Scripting ≤ 6.1 Fixed in 6.1 CVE-2025-59587 Patchstack
5.4 Medium Mihdan: No External Links Plugin mihdan-no-external-links Cross-Site Request Forgery No login needed ≤ 5.1.6.2 Fixed in 5.1.7 CVE-2025-53451 Patchstack
4.3 Medium SEO Backlink Monitor Plugin seo-backlink-monitor Cross-Site Request Forgery No login needed ≤ 1.8.0 CVE-2025-53456 Patchstack
4.4 Medium SEO Backlink Monitor Plugin seo-backlink-monitor Server-Side Request Forgery ≤ 1.8.0 CVE-2025-53457 Patchstack
4.4 Medium Beaf Plugin image-compare-block Server-Side Request Forgery ≤ 1.6.2 CVE-2025-53461 Patchstack
6.5 Medium RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Plugin ris-version-switcher Cross-Site Request Forgery Downgrade or Upgrade WP Versions Easily Plugin <= 1.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.0 CVE-2025-57902 Patchstack
4.3 Medium AgreeMe Checkboxes For WooCommerce Plugin agreeme-checkboxes-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-57905 Patchstack
4.3 Medium TOCHAT.BE Plugin tochat-be Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-57915 Patchstack
4.3 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-57914 Patchstack
7.1 High LinkedInclude Plugin linkedinclude Cross-Site Request Forgery No login needed ≤ 3.0.4 CVE-2025-57918 Patchstack
4.3 Medium Developer Plugin developer Cross-Site Request Forgery No login needed ≤ 1.2.6 CVE-2025-57924 Patchstack
4.3 Medium Dashboard Notepad Plugin dashboard-notepad Cross-Site Request Forgery No login needed ≤ 1.42 CVE-2025-57927 Patchstack
4.3 Medium Double the Donation Plugin double-the-donation Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57930 Patchstack
4.3 Medium Piotnet Forms Plugin piotnetforms Cross-Site Request Forgery No login needed ≤ 1.0.30 CVE-2025-57933 Patchstack
6.5 Medium PowerFolio Plugin portfolio-elementor Cross-Site Scripting ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-57932 Patchstack
4.3 Medium LWS Affiliation Plugin lws-affiliation Cross-Site Request Forgery No login needed ≤ 2.3.6 CVE-2025-57934 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 9.3 Fixed in 9.4 CVE-2025-57942 Patchstack
4.4 Medium Skimlinks Affiliate Marketing Tool Plugin skimlinks Server-Side Request Forgery ≤ 1.3.1 CVE-2025-57943 Patchstack
5.4 Medium payOS Plugin payos Cross-Site Request Forgery No login needed ≤ 1.0.73 CVE-2025-57946 Patchstack
4.3 Medium Travel Map Plugin travelmap-blog Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-57960 Patchstack
4.3 Medium SALESmanago & Leadoo Plugin salesmanago Cross-Site Request Forgery No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-57970 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only