WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,201–5,250 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 105 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-68511 Patchstack
4.7 Medium User Submitted Posts Plugin user-submitted-posts Open Redirect No login needed ≤ 20251121 Fixed in 20251210 CVE-2025-68509 Patchstack
5.3 Medium Brave Plugin brave-popup-builder Broken Access Control No login needed ≤ 0.8.3 Fixed in 0.8.4 CVE-2025-68508 Patchstack
5.3 Medium H5P Plugin h5p Broken Access Control No login needed ≤ 1.16.1 Fixed in 1.16.2 CVE-2025-68505 Patchstack
4.9 Medium Prime Slider – Addons For Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons For Elementor plugin <= 4.0.10 - Server Side Request Forgery (SSRF) ≤ 4.0.10 Fixed in 4.1.0 CVE-2025-68500 Patchstack
5.9 Medium Astra Widgets Plugin astra-widgets Cross-Site Scripting ≤ 1.2.16 Fixed in 1.2.17 CVE-2025-68497 Patchstack
7.6 High User Feedback Plugin userfeedback-lite SQL Injection ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-68496 Patchstack
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 4.11.53 Fixed in 4.11.54 CVE-2025-68494 Patchstack
7.5 High PowerPack Pro for Elementor Plugin powerpack-elements Broken Access Control Unauthenticated Plugin Settings Reset No login needed ≤ 2.10.6 Fixed in 2.10.8 CVE-2024-24844 Patchstack
5.3 Medium Product Delivery Date for WooCommerce – Lite Plugin product-delivery-date-for-woocommerce-lite Broken Access Control Lite plugin <= 2.7.0 - Broken Access Control No login needed ≤ 2.7.0 Fixed in 2.7.1 CVE-2023-52210 Patchstack
7.5 High Nika Plugin nika Local File Inclusion ≤ 1.2.14 Fixed in 1.2.15 CVE-2025-68546 Patchstack
7.5 High Diza Theme diza Local File Inclusion ≤ 1.3.15 Fixed in 1.3.16 CVE-2025-68544 Patchstack
6.5 Medium Responsive Posts Carousel Pro Plugin responsive-posts-carousel-pro Cross-Site Scripting ≤ 15.2 Fixed in 15.3 CVE-2025-68548 Patchstack
7.6 High WPBulky Plugin wpbulky-wp-bulk-edit-post-types SQL Injection ≤ 1.1.13 Fixed in 1.1.14 CVE-2025-68550 Patchstack
6.5 Medium VPSUForm Plugin v-form Information Disclosure Sensitive Data Exposure ≤ 3.2.24 Fixed in 3.2.25 CVE-2025-68551 Patchstack
5.3 Medium HAPPY Plugin happy-helpdesk-support-ticket-system Broken Access Control No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-68556 Patchstack
4.3 Medium Chakra test Plugin chakra-test Broken Access Control ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-68557 Patchstack
6.5 Medium TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68559 Patchstack
7.5 High TheGem Theme Elements (for Elementor) Plugin thegem-elements-elementor Local File Inclusion ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-68560 Patchstack
7.6 High AutomatorWP Plugin automatorwp SQL Injection ≤ 5.2.4 Fixed in 5.2.5 CVE-2025-68561 Patchstack
8.1 High Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Update ≤ 2.9.4.1 CVE-2025-12934 Wordfence
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0.1.2 CVE-2025-62094 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-62107 Patchstack
4.3 Medium Custom 404 Pro Plugin custom-404-pro Cross-Site Request Forgery No login needed ≤ 3.12.0 CVE-2025-62880 Patchstack
6.5 Medium WP Microdata Plugin wp-microdata Cross-Site Scripting ≤ 1.0 CVE-2025-62901 Patchstack
6.5 Medium TempTool [Show Current Template Info] Plugin current-template-name Cross-Site Scripting ≤ 1.3.1 CVE-2025-62926 Patchstack
4.3 Medium TempTool [Show Current Template Info] Plugin current-template-name Information Disclosure Sensitive Data Exposure ≤ 1.3.1 CVE-2025-62955 Patchstack
7.2 High ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.3.4 CVE-2025-9343 Wordfence
7.5 High Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder PHP Object Injection Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) PHP Object Injection via dslc_module_posts_output Shortcode ≤ 2.0.2 CVE-2025-14071 Wordfence
6.1 Medium Five Star Restaurant Reservations – WordPress Booking Plugin Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2025-11496 Wordfence
4.3 Medium WP Affiliate Disclosure Plugin wp-affiliate-disclosure Information Disclosure Broken Access Control + CSRF ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-47232 Patchstack
7.7 High HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25446 Patchstack
5.4 Medium HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25445 Patchstack
4.3 Medium Magazine Edge Theme magazine-edge Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 1.13 CVE-2023-25068 Patchstack
5.4 Medium Construction Light Plugin construction-light Broken Access Control ≤ 1.6.7 CVE-2025-62960 Patchstack
5.4 Medium Sparkle FSE Plugin sparkle-fse Broken Access Control ≤ 1.0.9 CVE-2025-62961 Patchstack
5.0 Medium WP AI CoPilot Plugin ai-co-pilot-for-wp Information Disclosure Sensitive Data Exposure ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-62998 Patchstack
5.3 Medium Sermon Manager Plugin sermon-manager-for-wordpress Broken Access Control No login needed ≤ 2.30.0 CVE-2025-63002 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Tuturn Plugin tuturn Path Traversal Arbitrary File Download < 3.6 Fixed in 3.6 CVE-2025-64235 Patchstack
9.8 Critical Tuturn Plugin tuturn Authentication Bypass Broken Authentication No login needed < 3.6 Fixed in 3.6 CVE-2025-64236 Patchstack
4.3 Medium Radius Blocks Plugin radius-blocks Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.2.1 CVE-2025-64282 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12 Fixed in 2.7.12.1 CVE-2025-64355 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
6.5 Medium WP ERP Plugin erp Information Disclosure Sensitive Data Exposure ≤ 1.16.6 Fixed in 1.16.7 CVE-2025-67546 Patchstack
7.1 High Hostel Plugin hostel Cross-Site Scripting No login needed ≤ 1.1.5.9 Fixed in 1.1.6 CVE-2025-66119 Patchstack
7.1 High Sprout Clients Plugin sprout-clients Cross-Site Scripting No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2025-66118 Patchstack
7.5 High Easy Form Plugin easy-form Broken Access Control No login needed ≤ 2.7.8 Fixed in 2.7.9 CVE-2025-66117 Patchstack
7.5 High Ultimate Member Widgets for Elementor Plugin ultimate-member-widgets-for-elementor Information Disclosure Sensitive Data Exposure No login needed ≤ 2.3 Fixed in 2.4 CVE-2025-66116 Patchstack
6.5 Medium Offload, AI & Optimize with Cloudflare Images Plugin cf-images Broken Access Control ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-66104 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only