WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,151–5,200 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 104 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Virusdie Plugin virusdie Information Disclosure Sensitive Data Exposure ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-68576 Patchstack
5.3 Medium Wappointment Plugin wappointment Broken Access Control No login needed ≤ 2.7.6 CVE-2025-68575 Patchstack
5.9 Medium WPBakery Visual Composer WHMCS Elements Plugin void-visual-whmcs-element Cross-Site Scripting ≤ 1.0.4.3 CVE-2025-68574 Patchstack
5.4 Medium Simple Keyword to Link Plugin simple-keyword-to-link Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-68573 Patchstack
5.3 Medium BBP Core Plugin bbp-core Broken Access Control No login needed ≤ 1.4.1 Fixed in 2.0.0 CVE-2025-68572 Patchstack
5.3 Medium SALESmanago & Leadoo Plugin salesmanago Broken Access Control No login needed ≤ 3.9.0 Fixed in 3.9.1 CVE-2025-68571 Patchstack
7.6 High Captivate Sync Plugin captivatesync-trade SQL Injection ≤ 3.2.2 Fixed in 3.3.0 CVE-2025-68570 Patchstack
6.5 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.2.39 Fixed in 1.2.40 CVE-2025-68569 Patchstack
5.3 Medium Claspo – Popups, Spin the Wheel & Email Capture Plugin claspo Broken Access Control Popups, Spin the Wheel & Email Capture plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-68568 Patchstack
5.4 Medium My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-68567 Patchstack
5.9 Medium My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting ≤ 3.6.35 CVE-2025-68566 Patchstack
5.3 Medium Twitch Player Plugin ttv-easy-embed-player Broken Access Control No login needed ≤ 2.1.3 CVE-2025-68565 Patchstack
8.1 High Docket Cache Plugin docket-cache Local File Inclusion No login needed ≤ 24.07.03 Fixed in 24.07.04 CVE-2025-68506 Patchstack
7.2 High Icegram Express Pro Plugin email-subscribers-premium PHP Object Injection ≤ 5.9.14 Fixed in 5.9.14 CVE-2025-68038 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-67909 Patchstack
5.9 Medium Greenhouse Job Board Plugin greenhouse-job-board Cross-Site Scripting ≤ 2.7.3 CVE-2025-67633 Patchstack
5.9 Medium Google AdSense for Responsive Design – GARD Plugin google-adsense-for-responsive-design-gard Cross-Site Scripting GARD plugin <= 2.23 - Cross Site Scripting (XSS) ≤ 2.23 CVE-2025-67632 Patchstack
5.9 Medium Gift Hunt Plugin gift-hunt Cross-Site Scripting ≤ 2.0.2 CVE-2025-67631 Patchstack
5.9 Medium WH Tweaks Plugin wh-tweaks Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-67630 Patchstack
5.9 Medium Basticom Framework Plugin basticom-framework Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67629 Patchstack
5.9 Medium Review Disclaimer Plugin review-disclaimer Cross-Site Scripting ≤ 2.0.3 CVE-2025-67628 Patchstack
5.9 Medium Draft Notify Plugin draft-notify Cross-Site Scripting ≤ 1.5 CVE-2025-67627 Patchstack
4.3 Medium Trade Runner Plugin traderunner Cross-Site Request Forgery No login needed ≤ 3.14 CVE-2025-67625 Patchstack
5.4 Medium 6Storage Rentals Plugin 6storage-rentals Server-Side Request Forgery No login needed ≤ 2.22.0 CVE-2025-67623 Patchstack
7.1 High Evergreen Post Tweeter Plugin evergreen-post-tweeter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.8.9 CVE-2025-67622 Patchstack
4.3 Medium Eight Day Week Print Workflow Plugin eight-day-week-print-workflow Information Disclosure Sensitive Data Exposure ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-67621 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control No login needed ≤ 2.0.5.3 Fixed in 2.0.5.4.1 CVE-2023-40679 Patchstack
8.6 High WPJobBoard Plugin wpjobboard SQL Injection Unauth. Blind SQL Injection (SQLi) No login needed ≤ 5.9.0 Fixed in 5.10.1 CVE-2023-36525 Patchstack
5.9 Medium Hostel Plugin hostel Cross-Site Scripting ≤ 1.1.5.1 Fixed in 1.1.5.2 CVE-2023-32120 Patchstack
4.3 Medium Resoto Theme resoto Broken Access Control Broken Access Control to Arbitrary Plugin Activation ≤ 1.0.8 CVE-2023-28619 Patchstack
7.5 High Userpro Plugin userpro Broken Access Control No login needed ≤ 5.1.9 CVE-2025-68608 Patchstack
7.5 High Subscribe to Unlock Lite Plugin subscribe-to-unlock-lite Local File Inclusion ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-68563 Patchstack
7.5 High Fana Plugin fana Local File Inclusion ≤ 1.1.35 Fixed in 1.1.36 CVE-2025-68540 Patchstack
7.5 High Zota Plugin zota Local File Inclusion ≤ 1.3.14 Fixed in 1.3.15 CVE-2025-68537 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.5.7.1 Fixed in 3.5.7.2 CVE-2025-68535 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-68533 Patchstack
6.5 Medium ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68532 Patchstack
7.5 High Bookory Theme bookory Local File Inclusion ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-68530 Patchstack
4.3 Medium WP Email Capture Plugin wp-email-capture Cross-Site Request Forgery No login needed ≤ 3.12.5 Fixed in 3.12.6 CVE-2025-68529 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-68528 Patchstack
6.5 Medium Academy LMS Plugin academy Cross-Site Scripting ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-68527 Patchstack
5.9 Medium Category Icon Plugin category-icon Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-68525 Patchstack
4.3 Medium Spiffy Calendar Plugin spiffy-calendar Broken Access Control ≤ 5.0.7 Fixed in 5.0.8 CVE-2025-68523 Patchstack
4.3 Medium WpStream Plugin wpstream Broken Access Control ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68522 Patchstack
5.3 Medium WpStream Plugin wpstream Broken Access Control No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68521 Patchstack
8.5 High Brands for WooCommerce Plugin brands-for-woocommerce SQL Injection ≤ 3.8.6.3 Fixed in 3.8.6.4 CVE-2025-68519 Patchstack
5.4 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68517 Patchstack
5.0 Medium Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68516 Patchstack
6.5 Medium Bold Timeline Lite Plugin bold-timeline-lite Cross-Site Scripting ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-68513 Patchstack
6.5 Medium Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 4.11.4 Fixed in 4.16.4 CVE-2025-68512 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only