WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 5,201–5,250 of 17,767 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Premium Addons for Elementor | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure via 'get_template_content' No login needed |
≤ 4.11.53 |
CVE-2025-14155 |
Wordfence | |
| 6.5 Medium | Void Elementor WHMCS Elements For Elementor Page Builder | Cross-Site Scripting |
≤ 2.0.1.2 |
CVE-2025-62094 |
Patchstack | |
| 4.3 Medium | Feather Login Page | Cross-Site Request Forgery No login needed |
≤ 1.1.7 |
CVE-2025-62107 |
Patchstack | |
| 4.3 Medium | Custom 404 Pro | Cross-Site Request Forgery No login needed |
≤ 3.12.0 |
CVE-2025-62880 |
Patchstack | |
| 6.5 Medium | WP Microdata | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-62901 |
Patchstack | |
| 6.5 Medium | TempTool [Show Current Template Info] | Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-62926 |
Patchstack | |
| 4.3 Medium | TempTool [Show Current Template Info] | Information Disclosure Sensitive Data Exposure |
≤ 1.3.1 |
CVE-2025-62955 |
Patchstack | |
| 4.3 Medium | Web to SugarCRM Lead | Cross-Site Request Forgery Cross-Site Request Forgery to Custom Field Deletion No login needed |
≤ 1.0.0 |
CVE-2025-13361 |
Wordfence | |
| 6.4 Medium | Ultimate Member | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 2.11.0 |
CVE-2025-13220 |
Wordfence | |
| 6.4 Medium | Image Photo Gallery Final Tiles Grid | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via 'Custom Scripts' Setting |
≤ 3.6.8 |
CVE-2025-13693 |
Wordfence | |
| 6.1 Medium | Product Table for WooCommerce | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.0.8 |
CVE-2025-12398 |
Wordfence | |
| 4.4 Medium | WC Builder | Cross-Site Scripting Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'heading_color' Shortcode Attribute |
≤ 1.2.0 |
CVE-2025-14054 |
Wordfence | |
| 5.3 Medium | Tainacan | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Metadata Section Creation No login needed |
≤ 1.0.1 |
CVE-2025-14043 |
Wordfence | |
| 6.4 Medium | WishSuite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'button_text' Shortcode Attribute |
≤ 1.5.1 |
CVE-2025-13838 |
Wordfence | |
| 5.3 Medium | Frontend Post Submission Manager Lite | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Modification No login needed |
≤ 1.2.5 |
CVE-2025-14080 |
Wordfence | |
| 6.1 Medium | Five Star Restaurant Reservations – WordPress Booking | Cross-Site Scripting WordPress Booking Plugin <= 2.7.5 - Unauthenticated Stored Cross-Site Scripting No login needed |
≤ 2.7.5 |
CVE-2025-11496 |
Wordfence | |
| 4.3 Medium | WP Affiliate Disclosure | Information Disclosure Broken Access Control + CSRF |
≤ 1.2.6 Fixed in 1.2.7 |
CVE-2023-47232 |
Patchstack | |
| 5.4 Medium | HappyFiles Pro | Broken Access Control |
≤ 1.8.1 Fixed in 1.8.2 |
CVE-2023-25445 |
Patchstack | |
| 4.3 Medium | Magazine Edge | Broken Access Control Authenticated Arbitrary Plugin Activation |
≤ 1.13 |
CVE-2023-25068 |
Patchstack | |
| 4.3 Medium | WP JobHunt | Broken Access Control Authenticated (Candidate+) Insecure Direct Object Reference |
≤ 7.7 |
CVE-2025-7733 |
Wordfence | |
| 5.4 Medium | FiboSearch – Ajax Search for WooCommerce | Cross-Site Scripting Ajax Search for WooCommerce <= 1.32.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via thegem_te_search Shortcode |
≤ 1.32.0 |
CVE-2025-14298 |
Wordfence | |
| 5.3 Medium | Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership | Information Disclosure User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.11.0 - Unauthenticated Sensitive Information Exposure No login needed |
≤ 2.11.0 |
CVE-2025-12492 |
Wordfence | |
| 5.3 Medium | Pure WC Variation Swatches | Broken Access Control Unauthenticated Settings Update No login needed |
≤ 1.1.7 |
CVE-2025-12820 |
WPScan | |
| 6.1 Medium | WP Hallo Welt | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.4. |
CVE-2025-13365 |
Wordfence | |
| 4.3 Medium | WP DB Booster | Cross-Site Request Forgery Cross-Site Request Forgery to Database Cleanup No login needed |
≤ 1.0.1 |
CVE-2025-14168 |
Wordfence | |
| 6.1 Medium | Attachments Handler | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.1.7 |
CVE-2025-12581 |
Wordfence | |
| 5.3 Medium | F70 Lead Document Download | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Media File Download No login needed |
≤ 1.4.4 |
CVE-2025-14633 |
Wordfence | |
| 6.1 Medium | Overstock Affiliate Links | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 1.1 |
CVE-2025-13624 |
Wordfence | |
| 5.4 Medium | Amazon affiliate lite | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-14734 |
Wordfence | |
| 5.5 Medium | Responsive and Swipe slider | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.2 |
CVE-2025-14721 |
Wordfence | |
| 5.3 Medium | Pretty Google Calendar | Broken Access Control Missing Authorization to Unauthenticated Google API Key Exposure No login needed |
≤ 2.0.0 |
CVE-2025-12898 |
Wordfence | |
| 4.4 Medium | Amazon affiliate lite | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-14735 |
Wordfence | |
| 4.3 Medium | Quran Gateway | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.5 |
CVE-2025-14164 |
Wordfence | |
| 5.4 Medium | Image Photo Gallery Final Tiles Grid | Broken Access Control Missing Authorization to Authenticated (Contributor+) Gallery Management |
≤ 3.6.7 |
CVE-2025-14455 |
Wordfence | |
| 4.3 Medium | myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program | Broken Access Control Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 - Missing Authorization to Sensitive Information Exposure |
≤ 2.9.7.1 |
CVE-2025-12361 |
Wordfence | |
| 6.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0.345 |
CVE-2025-11747 |
Wordfence | |
| 6.4 Medium | BA Book Everything | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via babe-search-form Shortcode |
≤ 1.8.14 |
CVE-2025-14449 |
Wordfence | |
| 5.3 Medium | Appointment Booking Calendar — Simply Schedule Appointments Booking | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.6.9.16 |
CVE-2025-13754 |
Wordfence | |
| 5.4 Medium | Construction Light | Broken Access Control |
≤ 1.6.7 |
CVE-2025-62960 |
Patchstack | |
| 5.4 Medium | Sparkle FSE | Broken Access Control |
≤ 1.0.9 |
CVE-2025-62961 |
Patchstack | |
| 5.0 Medium | WP AI CoPilot | Information Disclosure Sensitive Data Exposure |
≤ 1.2.7 Fixed in 1.2.8 |
CVE-2025-62998 |
Patchstack | |
| 5.3 Medium | Sermon Manager | Broken Access Control No login needed |
≤ 2.30.0 |
CVE-2025-63002 |
Patchstack | |
| 5.3 Medium | Post Grid and Gutenberg Blocks | Broken Access Control Insecure Direct Object References (IDOR) No login needed |
≤ 2.3.23 |
CVE-2025-63043 |
Patchstack | |
| 6.5 Medium | Tuturn | Path Traversal Arbitrary File Download |
< 3.6 Fixed in 3.6 |
CVE-2025-64235 |
Patchstack | |
| 4.3 Medium | Radius Blocks | Broken Access Control Insecure Direct Object References (IDOR) |
≤ 2.2.1 |
CVE-2025-64282 |
Patchstack | |
| 6.5 Medium | JetElements For Elementor | Cross-Site Scripting |
≤ 2.7.12 Fixed in 2.7.12.1 |
CVE-2025-64355 |
Patchstack | |
| 6.5 Medium | Post Grid and Gutenberg Blocks | Broken Access Control |
≤ 2.3.17 Fixed in 2.3.18 |
CVE-2025-66058 |
Patchstack | |
| 4.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.3 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_subscr' |
≤ 1.3.7.3 |
CVE-2025-13110 |
Wordfence | |
| 4.3 Medium | Sweet Energy Efficiency | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Graph Deletion |
≤ 1.0.6 |
CVE-2025-14618 |
Wordfence | |
| 4.3 Medium | Prime Slider – Addons for Elementor | Server-Side Request Forgery Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 4.0.9 |
CVE-2025-14277 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.