WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,201–5,250 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 105 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Shipping with Venipak for WooCommerce Plugin wc-venipak-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.22.3 Fixed in 1.22.5 CVE-2025-24553 Patchstack
7.1 High WP Log Action Plugin wp-log-action Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.51 Fixed in 0.52 CVE-2025-24619 Patchstack
7.1 High Shipment Tracker for Woocommerce Plugin shipment-tracker-for-woocommerce Cross-Site Scripting No login needed ≤ 1.4.23 Fixed in 1.4.23.1 CVE-2025-24586 Patchstack
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-24621 Patchstack
7.1 High Beacon Lead Magnets and Lead Capture Plugin beacon-by Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-24637 Patchstack
7.1 High HT Event Plugin ht-event Cross-Site Scripting WordPress Event Manager Plugin for Elementor Plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-24624 Patchstack
7.1 High Empty Tags Remover Plugin empty-tags-remover Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 1.1.0 CVE-2025-24640 Patchstack
7.1 High Eazy Under Construction Plugin eazy-under-construction Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 Fixed in 2.0 CVE-2025-24645 Patchstack
7.1 High Term Taxonomy Converter Plugin term-taxonomy-converter Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-24670 Patchstack
7.1 High Wishlist Plugin wishlist Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.39 Fixed in 1.0.40 CVE-2025-24655 Patchstack
7.1 High Essential Addons for Elementor Plugin essential-addons-for-elementor-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.0.14 Fixed in 6.0.15 CVE-2025-24752 Patchstack
7.1 High Classified Listing Plugin classified-listing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-24745 Patchstack
7.1 High Flagged Content Plugin flagged-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-27284 Patchstack
7.1 High Easy Form Plugin easy-form Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-27285 Patchstack
7.1 High File Icons Plugin file-icons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-27288 Patchstack
7.1 High Restrict Taxonomies Plugin restrict-taxonomies Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-27289 Patchstack
7.1 High WPYog Documents Plugin wpyog-documents Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-27292 Patchstack
7.1 High WordPress Photo Gallery – Image Gallery Plugin photo-image-gallery Cross-Site Scripting Image Gallery Plugin <= 2.0.4 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-27291 Patchstack
7.1 High Live css Plugin css-live Cross-Site Scripting No login needed ≤ 1.3 CVE-2025-27295 Patchstack
7.1 High Shipmozo Courier Tracking Plugin webparex Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-27293 Patchstack
7.1 High WP Video Posts Plugin wp-video-posts Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.5.1 CVE-2025-27308 Patchstack
7.1 High flickr-slideshow-wrapper Plugin flickr-slideshow-wrapper Cross-Site Scripting No login needed ≤ 5.4.6 CVE-2025-27309 Patchstack
7.1 High Google Maps GPX Viewer Plugin google-maps-gpx-viewer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.6 CVE-2025-27313 Patchstack
7.1 High Kush Micro News Plugin kush-micro-news Cross-Site Scripting No login needed ≤ 1.6.7 CVE-2025-27314 Patchstack
7.1 High QR Code for WooCommerce Plugin wc-qr-codes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-27322 Patchstack
7.1 High User List Plugin user-list Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.1 CVE-2025-27319 Patchstack
7.1 High 17TRACK for WooCommerce Plugin 17track Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.10 CVE-2025-27324 Patchstack
7.1 High Fontsampler Plugin fontsampler Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.4.14 CVE-2025-27337 Patchstack
7.1 High Protected wp-login Plugin protected-wp-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-27333 Patchstack
7.1 High List Urls Plugin list-urls Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-27338 Patchstack
7.1 High Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.19 Fixed in 1.1.20 CVE-2025-27345 Patchstack
7.1 High WooCommerce HTML5 Video Plugin woocommerce-html5-video Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.10 CVE-2025-27343 Patchstack
7.1 High Simple Email Subscriber Plugin simple-email-subscriber Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3 CVE-2025-27354 Patchstack
7.1 High Rebuild Permalinks Plugin rebuild-permalinks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-27346 Patchstack
7.1 High Activity Reactions For Buddypress Plugin activity-reactions-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.22 CVE-2025-31006 Patchstack
7.5 High Ray Enterprise Translation Plugin lingotek-translation Local File Inclusion Local File Inclusion via CSRF No login needed ≤ 1.7.0 Fixed in 1.7.1 CVE-2025-31030 Patchstack
7.1 High FireDrum Email Marketing Plugin firedrum-email-marketing Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.64 Fixed in 1.65 CVE-2025-31018 Patchstack
7.1 High Silvasoft boekhouden Plugin silvasoft-boekhouden Cross-Site Scripting No login needed ≤ 3.0.6 Fixed in 3.0.7 CVE-2025-32504 Patchstack
7.1 High wp secure Plugin wp-secure-by-sitesecuritymonitorcom Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-32490 Patchstack
7.1 High Event Espresso – Custom Email Template Shortcode Plugin email-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-32507 Patchstack
7.1 High AT Internet SmartTag Plugin at-internet Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2 CVE-2025-32506 Patchstack
7.1 High Course Booking System Plugin course-booking-system Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-32508 Patchstack
7.1 High Revamp CRM for WooCommerce Plugin revampcrm-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-32512 Patchstack
7.1 High Make Email Customizer for WooCommerce Plugin make-email-customizer-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6 CVE-2025-32511 Patchstack
7.1 High WooCommerce Estimate and Quote Plugin wc-estimate-and-quote Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2.5 CVE-2025-32514 Patchstack
7.1 High Nomupay Payment Processing Gateway Plugin totalprocessing-card-payments Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.1.6 Fixed in 7.1.7 CVE-2025-32513 Patchstack
7.1 High Terminal Africa Plugin terminal-africa Cross-Site Scripting No login needed ≤ 1.13.24 CVE-2025-32515 Patchstack
7.1 High WordPress Health and Server Condition – Integrated with Google Page Speed Plugin wp-condition Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.1 CVE-2025-32520 Patchstack
7.1 High Related Videos for JW Player Plugin related-videos-for-jw-player Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-32516 Patchstack
7.1 High Cool Flipbox – Shortcode & Gutenberg Block Plugin flip-boxes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-32521 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only