WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 451–500 of 1,492 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 10 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium WP YouTube Live Plugin wp-youtube-live Cross-Site Request Forgery No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-53261 Patchstack
4.3 Medium Cyrlitera Plugin cyrlitera Cross-Site Request Forgery No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-53254 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
4.3 Medium Cookiebot Plugin cookiebot Cross-Site Request Forgery No login needed ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-53197 Patchstack
4.3 Medium Burst Statistics Plugin burst-statistics Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.8 CVE-2025-53193 Patchstack
4.3 Medium DarkMySite Plugin darkmysite Cross-Site Request Forgery No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-32281 Patchstack
4.3 Medium ClipLink Plugin cliplink Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49964 Patchstack
4.3 Medium Oganro Travel Portal Search Widget for HotelBeds APITUDE API Plugin oganro-travel-portal-search-widget-for-hotelbeds-apitude-api Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49966 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium XML Travel Portal Widget Plugin oganro-reservation-widget Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-49968 Patchstack
4.3 Medium Live Sports Streamthunder Plugin live-sports-streamthunder Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-49967 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-49975 Patchstack
4.3 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Request Forgery No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-49977 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.13.11 Fixed in 11.13.12 CVE-2025-49984 Patchstack
4.9 Medium WPThumb Plugin wp-thumb Server-Side Request Forgery ≤ 0.10 CVE-2025-49983 Patchstack
4.9 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery ≤ 3.3.2 CVE-2025-49985 Patchstack
5.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.12.18 Fixed in 1.12.19 CVE-2025-49997 Patchstack
6.5 Medium Mailing Group Listserv Plugin wp-mailing-group Cross-Site Request Forgery No login needed ≤ 3.0.5 CVE-2025-50036 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-50044 Patchstack
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
4.3 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-49856 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-49865 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium Wp Easy Allopass Plugin wordpress-easy-allopass Cross-Site Request Forgery No login needed ≤ 4.1.1 CVE-2025-49435 Patchstack
4.3 Medium WP Security Master Plugin wp-security-master Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-49440 Patchstack
4.3 Medium Admin Notes Plugin admin-note Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49446 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
5.4 Medium Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Request Forgery No login needed ≤ 1.0.4 CVE-2025-24772 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
4.3 Medium WP Media File Type Manager Plugin wp-media-file-type-manager Cross-Site Request Forgery No login needed ≤ 2.3.1 CVE-2025-27359 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
4.3 Medium CubePoints Plugin cubepoints Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-28952 Patchstack
4.3 Medium Subscription Renewal Reminders for WooCommerce Plugin subscriptions-renewal-reminders Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.4.2 CVE-2025-28984 Patchstack
4.3 Medium HR Management Lite Plugin hr-management-lite Cross-Site Request Forgery No login needed ≤ 3.6 CVE-2025-29005 Patchstack
4.9 Medium SocialMark Plugin socialmark Server-Side Request Forgery ≤ 2.0.7 CVE-2025-29008 Patchstack
4.3 Medium Bitly URL Shortener Plugin codehaveli-bitly-url-shortener Cross-Site Request Forgery No login needed ≤ 1.4.1 Fixed in 1.5.0 CVE-2025-30629 Patchstack
5.4 Medium Global Translator Plugin global-translator Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2025-30632 Patchstack
4.3 Medium Custom Bulk/Quick Edit Plugin custom-bulkquick-edit Cross-Site Request Forgery No login needed ≤ 1.6.10 CVE-2025-30946 Patchstack
4.3 Medium Layouts for Elementor Plugin layouts-for-elementor Cross-Site Request Forgery No login needed ≤ 1.11 CVE-2025-30948 Patchstack
4.3 Medium Booqable Rental Plugin booqable-rental-reservations Cross-Site Request Forgery No login needed ≤ 2.4.25 CVE-2025-30956 Patchstack
5.4 Medium Advanced Post List Plugin advanced-post-list Cross-Site Request Forgery No login needed ≤ 0.5.6.2 CVE-2025-30968 Patchstack
4.9 Medium Nexa Blocks Plugin nexa-blocks Server-Side Request Forgery ≤ 1.1.1 CVE-2025-30976 Patchstack
6.3 Medium WP-Recall Plugin wp-recall Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 16.26.14 CVE-2025-30981 Patchstack
4.3 Medium Simple Keyword to Link Plugin simple-keyword-to-link Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30980 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only