WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,151–5,200 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 104 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Broken Access Control ≤ 1.2.39 Fixed in 1.2.40 CVE-2025-68569 Patchstack
5.3 Medium Claspo – Popups, Spin the Wheel & Email Capture Plugin claspo Broken Access Control Popups, Spin the Wheel & Email Capture plugin <= 1.0.7 - Broken Access Control No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-68568 Patchstack
5.4 Medium My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Request Forgery No login needed ≤ 3.6.33 Fixed in 3.6.34 CVE-2025-68567 Patchstack
5.9 Medium My auctions allegro Plugin my-auctions-allegro-free-edition Cross-Site Scripting ≤ 3.6.35 CVE-2025-68566 Patchstack
5.3 Medium Twitch Player Plugin ttv-easy-embed-player Broken Access Control No login needed ≤ 2.1.3 CVE-2025-68565 Patchstack
5.9 Medium Greenhouse Job Board Plugin greenhouse-job-board Cross-Site Scripting ≤ 2.7.3 CVE-2025-67633 Patchstack
5.9 Medium Google AdSense for Responsive Design – GARD Plugin google-adsense-for-responsive-design-gard Cross-Site Scripting GARD plugin <= 2.23 - Cross Site Scripting (XSS) ≤ 2.23 CVE-2025-67632 Patchstack
5.9 Medium Gift Hunt Plugin gift-hunt Cross-Site Scripting ≤ 2.0.2 CVE-2025-67631 Patchstack
5.9 Medium WH Tweaks Plugin wh-tweaks Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-67630 Patchstack
5.9 Medium Basticom Framework Plugin basticom-framework Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67629 Patchstack
5.9 Medium Review Disclaimer Plugin review-disclaimer Cross-Site Scripting ≤ 2.0.3 CVE-2025-67628 Patchstack
5.9 Medium Draft Notify Plugin draft-notify Cross-Site Scripting ≤ 1.5 CVE-2025-67627 Patchstack
4.3 Medium Trade Runner Plugin traderunner Cross-Site Request Forgery No login needed ≤ 3.14 CVE-2025-67625 Patchstack
5.4 Medium 6Storage Rentals Plugin 6storage-rentals Server-Side Request Forgery No login needed ≤ 2.22.0 CVE-2025-67623 Patchstack
4.3 Medium Eight Day Week Print Workflow Plugin eight-day-week-print-workflow Information Disclosure Sensitive Data Exposure ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-67621 Patchstack
6.5 Medium Master Addons for Elementor Plugin master-addons Broken Access Control No login needed ≤ 2.0.5.3 Fixed in 2.0.5.4.1 CVE-2023-40679 Patchstack
5.9 Medium Hostel Plugin hostel Cross-Site Scripting ≤ 1.1.5.1 Fixed in 1.1.5.2 CVE-2023-32120 Patchstack
4.3 Medium Resoto Theme resoto Broken Access Control Broken Access Control to Arbitrary Plugin Activation ≤ 1.0.8 CVE-2023-28619 Patchstack
4.3 Medium Sunshine Photo Cart Plugin sunshine-photo-cart Broken Access Control ≤ 3.5.7.1 Fixed in 3.5.7.2 CVE-2025-68535 Patchstack
6.5 Medium WC Builder Plugin wc-builder Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-68533 Patchstack
6.5 Medium ModelTheme Addons for WPBakery and Elementor Plugin modeltheme-addons-for-wpbakery Cross-Site Scripting ≤ 1.5.6 Fixed in 1.5.6 CVE-2025-68532 Patchstack
4.3 Medium WP Email Capture Plugin wp-email-capture Cross-Site Request Forgery No login needed ≤ 3.12.5 Fixed in 3.12.6 CVE-2025-68529 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.9 Fixed in 2.5.0 CVE-2025-68528 Patchstack
6.5 Medium Academy LMS Plugin academy Cross-Site Scripting ≤ 3.4.0 Fixed in 3.4.1 CVE-2025-68527 Patchstack
5.9 Medium Category Icon Plugin category-icon Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-68525 Patchstack
4.3 Medium Spiffy Calendar Plugin spiffy-calendar Broken Access Control ≤ 5.0.7 Fixed in 5.0.8 CVE-2025-68523 Patchstack
4.3 Medium WpStream Plugin wpstream Broken Access Control ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68522 Patchstack
5.3 Medium WpStream Plugin wpstream Broken Access Control No login needed ≤ 4.9.5 Fixed in 4.9.6 CVE-2025-68521 Patchstack
5.4 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68517 Patchstack
5.0 Medium Tablesome Plugin tablesome Information Disclosure Sensitive Data Exposure ≤ 1.1.35.1 Fixed in 1.1.35.2 CVE-2025-68516 Patchstack
6.5 Medium Bold Timeline Lite Plugin bold-timeline-lite Cross-Site Scripting ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-68513 Patchstack
6.5 Medium Real 3D FlipBook Plugin real3d-flipbook-lite Cross-Site Scripting ≤ 4.11.4 Fixed in 4.16.4 CVE-2025-68512 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-68511 Patchstack
4.7 Medium User Submitted Posts Plugin user-submitted-posts Open Redirect No login needed ≤ 20251121 Fixed in 20251210 CVE-2025-68509 Patchstack
5.3 Medium Brave Plugin brave-popup-builder Broken Access Control No login needed ≤ 0.8.3 Fixed in 0.8.4 CVE-2025-68508 Patchstack
5.3 Medium H5P Plugin h5p Broken Access Control No login needed ≤ 1.16.1 Fixed in 1.16.2 CVE-2025-68505 Patchstack
4.9 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) ≤ 4.0.10 Fixed in 4.1.0 CVE-2025-68500 Patchstack
5.9 Medium Astra Widgets Plugin astra-widgets Cross-Site Scripting ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-68497 Patchstack
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.11.53 Fixed in 4.11.54 CVE-2025-68494 Patchstack
6.8 Medium GravityForms Plugin Arbitrary File Upload Unauthenticated Arbitrary File Upload < 2.9.23.1 Fixed in 2.9.23.1 CVE-2025-13407 WPScan
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.0 - Broken Access Control No login needed ≤ 2.7.0 Fixed in 2.7.1 CVE-2023-52210 Patchstack
6.5 Medium Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Cross-Site Scripting ≤ 15.2 Fixed in 15.3 CVE-2025-68548 Patchstack
6.5 Medium VPSUForm Plugin v-form Information Disclosure Sensitive Data Exposure ≤ 3.2.24 Fixed in 3.2.25 CVE-2025-68551 Patchstack
5.3 Medium HAPPY Plugin happy-helpdesk-support-ticket-system Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-68556 Patchstack
4.3 Medium Chakra test Plugin chakra-test Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-68557 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68559 Patchstack
6.4 Medium Happy Addons for Elementor Plugin happy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom JS ≤ 3.20.3 CVE-2025-14635 Wordfence
6.4 Medium Membership Plugin – Restrict Content Plugin restrict-content Cross-Site Scripting Restrict Content <= 3.2.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcodes ≤ 3.2.15 CVE-2025-14000 Wordfence
4.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Cross-Site Request Forgery Cross-Site Request Forgery via 'insert_inner_template' No login needed ≤ 4.11.53 CVE-2025-14163 Wordfence
6.4 Medium Calendar Plugin calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'event_desc' ≤ 1.3.16 CVE-2025-14548 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only