WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,201–5,250 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 105 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Premium Addons for Elementor Plugin premium-addons-for-elementor Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content' No login needed ≤ 4.11.53 CVE-2025-14155 Wordfence
6.5 Medium Void Elementor WHMCS Elements For Elementor Page Builder Plugin void-elementor-whmcs-elements Cross-Site Scripting ≤ 2.0.1.2 CVE-2025-62094 Patchstack
4.3 Medium Feather Login Page Plugin feather-login-page Cross-Site Request Forgery No login needed ≤ 1.1.7 CVE-2025-62107 Patchstack
4.3 Medium Custom 404 Pro Plugin custom-404-pro Cross-Site Request Forgery No login needed ≤ 3.12.0 CVE-2025-62880 Patchstack
6.5 Medium WP Microdata Plugin wp-microdata Cross-Site Scripting ≤ 1.0 CVE-2025-62901 Patchstack
6.5 Medium TempTool [Show Current Template Info] Plugin current-template-name Cross-Site Scripting ≤ 1.3.1 CVE-2025-62926 Patchstack
4.3 Medium TempTool [Show Current Template Info] Plugin current-template-name Information Disclosure Sensitive Data Exposure ≤ 1.3.1 CVE-2025-62955 Patchstack
4.3 Medium Web to SugarCRM Lead Plugin web-to-sugarcrm-lead Cross-Site Request Forgery Cross-Site Request Forgery to Custom Field Deletion No login needed ≤ 1.0.0 CVE-2025-13361 Wordfence
6.4 Medium Ultimate Member Plugin ultimate-member Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 2.11.0 CVE-2025-13220 Wordfence
6.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting ≤ 3.6.8 CVE-2025-13693 Wordfence
6.1 Medium Product Table for WooCommerce Plugin woo-product-table Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.0.8 CVE-2025-12398 Wordfence
4.4 Medium WC Builder Plugin wc-builder Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'heading_color' Shortcode Attribute ≤ 1.2.0 CVE-2025-14054 Wordfence
5.3 Medium Tainacan Plugin tainacan Broken Access Control Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation No login needed ≤ 1.0.1 CVE-2025-14043 Wordfence
6.4 Medium WishSuite Plugin wishsuite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute ≤ 1.5.1 CVE-2025-13838 Wordfence
5.3 Medium Frontend Post Submission Manager Lite Plugin frontend-post-submission-manager-lite Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Modification No login needed ≤ 1.2.5 CVE-2025-14080 Wordfence
6.1 Medium Five Star Restaurant Reservations – WordPress Booking Plugin Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.7.5 CVE-2025-11496 Wordfence
4.3 Medium WP Affiliate Disclosure Plugin wp-affiliate-disclosure Information Disclosure Broken Access Control + CSRF ≤ 1.2.6 Fixed in 1.2.7 CVE-2023-47232 Patchstack
5.4 Medium HappyFiles Pro Plugin happyfiles-pro Broken Access Control ≤ 1.8.1 Fixed in 1.8.2 CVE-2023-25445 Patchstack
4.3 Medium Magazine Edge Theme magazine-edge Broken Access Control Authenticated Arbitrary Plugin Activation ≤ 1.13 CVE-2023-25068 Patchstack
4.3 Medium WP JobHunt Plugin Broken Access Control Authenticated (Candidate+) Insecure Direct Object Reference ≤ 7.7 CVE-2025-7733 Wordfence
5.4 Medium FiboSearch – Ajax Search for WooCommerce Plugin ajax-search-for-woocommerce Cross-Site Scripting Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via thegem_te_search Shortcode ≤ 1.32.0 CVE-2025-14298 Wordfence
5.3 Medium Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin ultimate-member Information Disclosure User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure No login needed ≤ 2.11.0 CVE-2025-12492 Wordfence
5.3 Medium Pure WC Variation Swatches Plugin Broken Access Control Unauthenticated Settings Update No login needed ≤ 1.1.7 CVE-2025-12820 WPScan
6.1 Medium WP Hallo Welt Plugin wp-hallo-welt Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.4. CVE-2025-13365 Wordfence
4.3 Medium WP DB Booster Plugin wp-db-booster Cross-Site Request Forgery Cross-Site Request Forgery to Database Cleanup No login needed ≤ 1.0.1 CVE-2025-14168 Wordfence
6.1 Medium Attachments Handler Plugin attachments-handler Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.7 CVE-2025-12581 Wordfence
5.3 Medium F70 Lead Document Download Plugin f70-lead-document-download Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media File Download No login needed ≤ 1.4.4 CVE-2025-14633 Wordfence
6.1 Medium Overstock Affiliate Links Plugin overstock-affiliate-links Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 1.1 CVE-2025-13624 Wordfence
5.4 Medium Amazon affiliate lite Plugin afiliados-de-amazon-lite Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 1.0.0 CVE-2025-14734 Wordfence
5.5 Medium Responsive and Swipe slider Plugin responsive-and-swipe-slider Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.2 CVE-2025-14721 Wordfence
5.3 Medium Pretty Google Calendar Plugin pretty-google-calendar Broken Access Control Missing Authorization to Unauthenticated Google API Key Exposure No login needed ≤ 2.0.0 CVE-2025-12898 Wordfence
4.4 Medium Amazon affiliate lite Plugin afiliados-de-amazon-lite Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-14735 Wordfence
4.3 Medium Quran Gateway Plugin quran-gateway Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.5 CVE-2025-14164 Wordfence
5.4 Medium Image Photo Gallery Final Tiles Grid Plugin final-tiles-grid-gallery-lite Broken Access Control Missing Authorization to Authenticated (Contributor+) Gallery Management ≤ 3.6.7 CVE-2025-14455 Wordfence
4.3 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program Plugin mycred Broken Access Control Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 - Missing Authorization to Sensitive Information Exposure ≤ 2.9.7.1 CVE-2025-12361 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.345 CVE-2025-11747 Wordfence
6.4 Medium BA Book Everything Plugin ba-book-everything Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via babe-search-form Shortcode ≤ 1.8.14 CVE-2025-14449 Wordfence
5.3 Medium Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.6.9.16 CVE-2025-13754 Wordfence
5.4 Medium Construction Light Plugin construction-light Broken Access Control ≤ 1.6.7 CVE-2025-62960 Patchstack
5.4 Medium Sparkle FSE Plugin sparkle-fse Broken Access Control ≤ 1.0.9 CVE-2025-62961 Patchstack
5.0 Medium WP AI CoPilot Plugin ai-co-pilot-for-wp Information Disclosure Sensitive Data Exposure ≤ 1.2.7 Fixed in 1.2.8 CVE-2025-62998 Patchstack
5.3 Medium Sermon Manager Plugin sermon-manager-for-wordpress Broken Access Control No login needed ≤ 2.30.0 CVE-2025-63002 Patchstack
5.3 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 2.3.23 CVE-2025-63043 Patchstack
6.5 Medium Tuturn Plugin tuturn Path Traversal Arbitrary File Download < 3.6 Fixed in 3.6 CVE-2025-64235 Patchstack
4.3 Medium Radius Blocks Plugin radius-blocks Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.2.1 CVE-2025-64282 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.12 Fixed in 2.7.12.1 CVE-2025-64355 Patchstack
6.5 Medium Post Grid and Gutenberg Blocks Plugin post-grid Broken Access Control ≤ 2.3.17 Fixed in 2.3.18 CVE-2025-66058 Patchstack
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin woocommerce-products-filter Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' ≤ 1.3.7.3 CVE-2025-13110 Wordfence
4.3 Medium Sweet Energy Efficiency Plugin sweet-energy-efficiency Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Graph Deletion ≤ 1.0.6 CVE-2025-14618 Wordfence
4.3 Medium Prime Slider – Addons for Elementor Plugin bdthemes-prime-slider-lite Server-Side Request Forgery Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 4.0.9 CVE-2025-14277 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only