WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,051–5,100 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 102 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium weForms Plugin weforms Broken Access Control No login needed ≤ 1.6.25 Fixed in 1.6.26 CVE-2025-69028 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 3.2.0 - Broken Access Control No login needed ≤ 3.2.0 Fixed in 3.3.0 CVE-2025-69027 Patchstack
4.3 Medium PopupKit Plugin popup-builder-block Information Disclosure Sensitive Data Exposure ≤ 2.1.5 Fixed in 2.2.1 CVE-2025-69026 Patchstack
4.3 Medium Poptics Plugin poptics Information Disclosure Sensitive Data Exposure ≤ 1.0.20 Fixed in 1.0.21 CVE-2025-69025 Patchstack
6.5 Medium BizPrint Plugin print-google-cloud-print-gcp-woocommerce Broken Access Control ≤ 4.6.7 Fixed in 4.7.1 CVE-2025-69024 Patchstack
4.3 Medium Discussion Board Plugin wp-discussion-board Broken Access Control ≤ 2.5.7 Fixed in 2.5.8 CVE-2025-69023 Patchstack
5.4 Medium HR Management Lite Plugin hr-management-lite Broken Access Control No login needed ≤ 3.6 CVE-2025-69022 Patchstack
5.4 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 6.0.7 Fixed in 6.0.8 CVE-2025-69021 Patchstack
6.5 Medium Newsletters Plugin newsletters-lite Cross-Site Scripting ≤ 4.12 Fixed in 4.13 CVE-2025-69020 Patchstack
6.5 Medium FlippingBook Plugin flippingbook Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-69019 Patchstack
6.5 Medium Web Directory Free Plugin web-directory-free Cross-Site Scripting ≤ 1.7.12 Fixed in 1.7.13 CVE-2025-69018 Patchstack
6.5 Medium RestroPress Plugin restropress Cross-Site Scripting ≤ 3.2.8.6 Fixed in 3.2.8.6.1 CVE-2025-69017 Patchstack
4.3 Medium Shortcodes and extra features for Phlox Plugin auxin-elements Broken Access Control ≤ 2.17.22 Fixed in 2.17.24 CVE-2025-69016 Patchstack
3.8 Low Crowdsignal Forms Plugin crowdsignal-forms Broken Access Control ≤ 1.7.2 Fixed in 1.8.0 CVE-2025-69015 Patchstack
4.9 Medium Youzify Plugin youzify Server-Side Request Forgery ≤ 1.3.7 CVE-2025-69014 Patchstack
4.3 Medium Stratum Plugin stratum Broken Access Control ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-69013 Patchstack
4.3 Medium Event Organiser Plugin event-organiser Broken Access Control ≤ 3.12.8 CVE-2025-69012 Patchstack
5.3 Medium Themebeez Toolkit Plugin themebeez-toolkit Broken Access Control No login needed ≤ 1.3.5 CVE-2025-69010 Patchstack
5.3 Medium Medicalequipment Theme medicalequipment Broken Access Control No login needed ≤ 1.0.9 CVE-2025-69009 Patchstack
5.9 Medium Inboxify Sign Up Form Plugin inboxify-sign-up-form Cross-Site Scripting ≤ 1.0.4 CVE-2025-69008 Patchstack
5.9 Medium Popping Sidebars and Widgets Light Plugin popping-sidebars-and-widgets-light Cross-Site Scripting ≤ 1.27 CVE-2025-69007 Patchstack
5.9 Medium AM Events Plugin am-events Cross-Site Scripting ≤ 1.13.1 CVE-2025-69006 Patchstack
5.4 Medium Heateor Social Login Plugin heateor-social-login Cross-Site Request Forgery No login needed ≤ 1.1.39 CVE-2025-68998 Patchstack
5.3 Medium wpDiscuz Plugin wpdiscuz Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 7.6.43 Fixed in 7.6.44 CVE-2025-68997 Patchstack
7.5 High Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Local File Inclusion ≤ 15.1 CVE-2025-68996 Patchstack
4.3 Medium My Sticky Elements Plugin mystickyelements Broken Access Control ≤ 2.3.3 Fixed in 2.3.4 CVE-2025-68995 Patchstack
5.3 Medium Product Loops for WooCommerce Plugin product-loops Broken Access Control No login needed ≤ 2.1.2 CVE-2025-68994 Patchstack
5.3 Medium Share, Print and PDF Products for WooCommerce Plugin share-print-pdf-woocommerce Broken Access Control No login needed ≤ 3.1.2 CVE-2025-68993 Patchstack
6.5 Medium BWL Knowledge Base Manager Plugin bwl-kb-manager Cross-Site Scripting ≤ 1.6.3 CVE-2025-68992 Patchstack
6.5 Medium BWL Pro Voting Manager Plugin bwl-pro-voting-manager Cross-Site Scripting ≤ 1.4.9 CVE-2025-68991 Patchstack
8.5 High BWL Pro Voting Manager Plugin bwl-pro-voting-manager SQL Injection ≤ 1.4.9 CVE-2025-68990 Patchstack
4.3 Medium contact-form-7-mailchimp-extension Plugin contact-form-7-mailchimp-extension Information Disclosure Sensitive Data Exposure ≤ 0.9.68 Fixed in 0.9.69 CVE-2025-68989 Patchstack
5.3 Medium E-Invoice App Malaysia Plugin einvoiceapp-malaysia Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.0 CVE-2025-68988 Patchstack
7.5 High Cinerama Theme cinerama Local File Inclusion ≤ 2.9 CVE-2025-68987 Patchstack
7.5 High Aora Theme aora Local File Inclusion ≤ 1.3.15 CVE-2025-68985 Patchstack
7.5 High Puca Plugin puca Local File Inclusion ≤ 2.6.39 CVE-2025-68984 Patchstack
7.5 High Greenmart Plugin greenmart Local File Inclusion ≤ 4.2.11 CVE-2025-68983 Patchstack
5.3 Medium DesignThemes LMS Addon Plugin designthemes-lms-addon Broken Access Control No login needed ≤ 2.6 CVE-2025-68982 Patchstack
5.3 Medium HomeFix Elementor Portfolio Plugin homefix-ele-portfolio Broken Access Control No login needed ≤ 1.0.1 CVE-2025-68981 Patchstack
5.3 Medium WeDesignTech Portfolio Plugin wedesigntech-portfolio Broken Access Control No login needed ≤ 1.0.2 CVE-2025-68980 Patchstack
5.3 Medium Google Calendar Events Plugin google-calendar-events Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.5.9 Fixed in 3.6.0 CVE-2025-68979 Patchstack
6.5 Medium DesignThemes Core Plugin designthemes-core Cross-Site Scripting ≤ 1.6 CVE-2025-68978 Patchstack
6.5 Medium DesignThemes Portfolio Addon Plugin designthemes-portfolio-addon Cross-Site Scripting ≤ 1.5 CVE-2025-68977 Patchstack
5.4 Medium Eagle Booking Plugin eagle-booking Broken Access Control Settings Change ≤ 1.3.4.3 CVE-2025-68976 Patchstack
4.3 Medium Eagle Booking Plugin eagle-booking Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.3.4.3 CVE-2025-68975 Patchstack
6.6 Medium WordPress Social Login and Register Plugin miniorange-login-openid Local File Inclusion ≤ 7.7.0 CVE-2025-68974 Patchstack
7.1 High Off Page SEO Plugin off-page-seo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.3 CVE-2025-23554 Patchstack
7.1 High Product Puller Plugin product-puller Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-23550 Patchstack
7.1 High Sleekplan Plugin sleekplan Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.0 CVE-2025-23469 Patchstack
7.1 High Ads24 Lite Plugin wp-ad-management Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23458 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only