WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,251–5,300 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 106 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Zephyr Project Manager Plugin zephyr-project-manager Cross-Site Scripting No login needed ≤ 3.3.101 Fixed in 3.3.102 CVE-2025-32526 Patchstack
7.1 High License Manager for WooCommerce Plugin license-manager-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-32522 Patchstack
7.1 High T&P Gallery Slider Plugin tp-gallery-slider Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-32527 Patchstack
7.1 High iONE360 configurator Plugin ione360-configurator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.57 CVE-2025-32529 Patchstack
7.1 High iCal Feeds Plugin ical-feeds Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32528 Patchstack
7.1 High Arconix FAQ Plugin arconix-faq Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-32531 Patchstack
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.8 Fixed in 2.6.9 CVE-2025-32530 Patchstack
7.1 High UXsniff Plugin ux-sniff Cross-Site Scripting No login needed ≤ 1.3.3 CVE-2025-32532 Patchstack
7.1 High DN Shipping by Weight for WooCommerce Plugin dn-shipping-by-weight Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 Fixed in 1.2.1 CVE-2025-32535 Patchstack
7.1 High Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.7 Fixed in 2.2.0 CVE-2025-32533 Patchstack
7.1 High Feedify – Web Push Notifications Plugin push-notification-by-feedify Cross-Site Scripting Web Push Notifications plugin <= 2.4.5 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-32540 Patchstack
7.1 High WooCommerce Products without featured images Plugin woocommerce-products-without-featured-images Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-32545 Patchstack
7.5 High WooCommerce Loyal Customers Plugin woocommerce-loyal-customer Broken Access Control No login needed ≤ 2.6 CVE-2025-32544 Patchstack
7.1 High All push notification for WP Plugin all-push-notification Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32546 Patchstack
7.1 High MSRP (RRP) Pricing for WooCommerce Plugin msrp-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.1 Fixed in 2.0.0 CVE-2025-32552 Patchstack
7.1 High Hamburger Icon Menu Lite Plugin hamburger-icon-menu-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-32548 Patchstack
7.1 High WP Featured Screenshot Plugin wp-featured-screenshot Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-32557 Patchstack
7.1 High Raptive Ads Plugin adthrive-ads Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.3 Fixed in 3.7.4 CVE-2025-32554 Patchstack
7.1 High WP_DEBUG Toggle Plugin enable-wp-debug-toggle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-32561 Patchstack
7.1 High WP-Hijri Plugin wp-hijri Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.3 CVE-2025-32560 Patchstack
7.1 High WP Easy Poll Plugin wp-easy-poll-afo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.9 CVE-2025-32562 Patchstack
7.1 High License For Envato Plugin license-envato Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 Fixed in 1.1.0 CVE-2025-32566 Patchstack
7.1 High Stop Registration Spam Plugin stop-registration-spam Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.24 CVE-2025-32564 Patchstack
8.8 High TuriTop Booking System Plugin turitop-booking-system PHP Object Injection ≤ 1.0.10 CVE-2025-32571 Patchstack
8.5 High KiotViet Sync Plugin kiotvietsync SQL Injection ≤ 1.8.3 CVE-2025-32573 Patchstack
7.1 High WP AutoKeyword Plugin wp-autokeyword Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-32582 Patchstack
7.1 High Coming Soon Countdown Plugin coming-soon-countdown Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2 CVE-2025-32578 Patchstack
7.1 High Web2application Plugin web2application Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 6.1 CVE-2025-32590 Patchstack
7.1 High Credova_Financial Plugin credova-financial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-32588 Patchstack
8.2 High Add Product Frontend for WooCommerce Plugin add-product-frontend-for-woocommerce Broken Access Control Arbitrary Content Deletion No login needed ≤ 1.0.8 CVE-2025-32593 Patchstack
7.1 High TableOn Plugin posts-table-filterable Cross-Site Scripting No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-32592 Patchstack
7.5 High Simple WP Events Plugin simple-wp-events Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.17 Fixed in 1.9.0 CVE-2025-32594 Patchstack
7.1 High WooMS Plugin wooms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 9.12 CVE-2025-32602 Patchstack
7.3 High Real Estate Manager Plugin real-estate-manager Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.3 CVE-2025-32596 Patchstack
7.1 High MemberPress Discord Addon Plugin expresstechsoftwares-memberpress-discord-add-on Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-32605 Patchstack
7.1 High AWSA Shipping Plugin awsa-shipping Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2025-32604 Patchstack
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
7.1 High Verowa Connect Plugin verowa-connect Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-32609 Patchstack
7.1 High Movylo Marketing Automation Plugin movylo-widget Cross-Site Scripting No login needed ≤ 2.0.7 CVE-2025-32608 Patchstack
7.1 High Debug Log Manager Plugin debug-log-manager Cross-Site Scripting No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-32613 Patchstack
7.1 High WooCommerce TBC Credit Card Payment Gateway (Free) Plugin woo-tbc-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-32611 Patchstack
7.1 High Clinked Client Portal Plugin clinked-client-portal Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.10 CVE-2025-32615 Patchstack
7.1 High OTP-less one tap Sign in Plugin otpless Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.58 Fixed in 2.0.59 CVE-2025-32622 Patchstack
7.1 High Doppler Forms Plugin doppler-form Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-32620 Patchstack
7.1 High Mobile Pages Plugin mobile-pages Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-32625 Patchstack
7.1 High Crowdfunding for WooCommerce Plugin crowdfunding-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.12 Fixed in 3.1.13 CVE-2025-32628 Patchstack
7.1 High Run Contests, Raffles, and Giveaways with ContestsWP Plugin contest-code-checker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.1 CVE-2025-32634 Patchstack
7.1 High WP-BusinessDirectory Plugin wp-businessdirectory Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-32630 Patchstack
7.5 High Hive Support Plugin hive-support Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-32635 Patchstack
7.1 High WP Donate Plugin wp-donate Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-32637 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only