WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,251–5,300 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 106 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium OpenID Connect Generic Client Plugin daggerhart-openid-connect-generic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.10.0 CVE-2025-13730 Wordfence
6.5 Medium WP ERP Plugin erp Information Disclosure Sensitive Data Exposure ≤ 1.16.6 Fixed in 1.16.7 CVE-2025-67546 Patchstack
6.5 Medium Offload, AI & Optimize with Cloudflare Images Plugin cf-images Broken Access Control ≤ 1.9.5 Fixed in 1.9.6 CVE-2025-66104 Patchstack
6.5 Medium RestroPress Plugin restropress Broken Access Control ≤ 3.2.3.5 Fixed in 3.2.3.6 CVE-2025-66100 Patchstack
6.5 Medium InstaWP Connect Plugin instawp-connect Broken Access Control No login needed ≤ 0.1.1.9 Fixed in 0.1.2.0 CVE-2025-66068 Patchstack
6.5 Medium WP Social Ninja Plugin wp-social-reviews Broken Access Control No login needed ≤ 3.20.1 Fixed in 3.20.2 CVE-2025-64375 Patchstack
6.5 Medium All In One SEO Pack Plugin all-in-one-seo-pack Information Disclosure Sensitive Data Exposure ≤ 4.8.6.1 Fixed in 4.8.7 CVE-2025-64295 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64273 Patchstack
6.5 Medium Email marketing for WordPress by GetResponse Official Plugin getresponse-official Information Disclosure Sensitive Data Exposure ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-64272 Patchstack
6.5 Medium Masteriyo - LMS Plugin learning-management-system Information Disclosure LMS plugin <= 2.0.3 - Sensitive Data Exposure ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-64270 Patchstack
6.5 Medium Stockie Extra Plugin stockie-extra Content Injection No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64225 Patchstack
6.3 Medium XStore Theme xstore Broken Access Control ≤ 9.6 Fixed in 9.6 CVE-2025-64192 Patchstack
6.5 Medium ListingPro Theme listingpro Broken Access Control ≤ 2.9.9 CVE-2025-63039 Patchstack
6.5 Medium WebinarIgnition Plugin webinar-ignition Broken Access Control ≤ 4.06.04 Fixed in 4.06.05 CVE-2025-60088 Patchstack
6.5 Medium Molla Plugin molla Remote Code Execution Multipurpose Responsive Shopify theme <= 1.5.13 - Arbitrary Code Execution No login needed ≤ 1.5.13 CVE-2025-60070 Patchstack
6.5 Medium Javo Core Plugin javo-core Remote Code Execution Arbitrary Code Execution No login needed ≤ 3.0.0.266 CVE-2025-60068 Patchstack
6.5 Medium MapSVG Plugin mapsvg Path Traversal Arbitrary File Download ≤ 8.6.12 Fixed in 8.6.12 CVE-2025-54748 Patchstack
6.5 Medium miniOrange's Google Authenticator Plugin miniorange-2-factor-authentication Broken Access Control ≤ 6.1.1 Fixed in 6.1.2 CVE-2025-54745 Patchstack
5.8 Medium Download After Email Plugin download-after-email Broken Access Control Other Vulnerability Type No login needed ≤ 2.1.5-2.1.6 Fixed in 2.1.7 CVE-2025-54743 Patchstack
6.5 Medium Super Blank Plugin super-blank Broken Access Control Arbitrary Content Deletion ≤ 1.2.0 Fixed in 1.3.0 CVE-2025-54741 Patchstack
5.8 Medium eRoom Plugin eroom-zoom-meetings-webinar Information Disclosure Sensitive Data Exposure No login needed ≤ 1.5.6 Fixed in 1.5.7 CVE-2025-49919 Patchstack
5.9 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-49918 Patchstack
6.5 Medium Restaurant Menu by MotoPress Plugin mp-restaurant-menu Information Disclosure Sensitive Data Exposure ≤ 2.4.7 Fixed in 2.4.8 CVE-2025-49914 Patchstack
6.5 Medium Login Page Customizer – Customizer Login Page, Admin Page, Custom Design Plugin customizer-login-page Broken Access Control Customizer Login Page, Admin Page, Custom Design plugin <= 2.1.1 - Broken Access Control No login needed ≤ 2.1.1 Fixed in 2.1.2 CVE-2025-49902 Patchstack
6.5 Medium Get Cash Plugin get-cash Broken Access Control No login needed ≤ 3.2.3 CVE-2025-49041 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.3.60 Fixed in 1.3.61 CVE-2025-10019 Patchstack
4.3 Medium Download Manager Plugin download-manager Broken Access Control Missing Authorization to Authenticated (Subscriber+) Media Attachment Password Disclosure ≤ 3.3.32 CVE-2025-13498 Wordfence
6.4 Medium Events Manager Plugin events-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'events_list_grouped' Shortcode ≤ 7.2.2.1 CVE-2025-12976 Wordfence
6.4 Medium Embed Any Document Plugin embed-any-document Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.7.10 CVE-2025-12885 Wordfence
6.8 Medium auth0-PHP Plugin Broken Access Control Auth0-PHP SDK has Improper Audience Validation >= 8.0.0, < 8.18.0 CVE-2025-68129 GitHub_M
4.3 Medium Ultimate Member Plugin ultimate-member Broken Access Control Authenticated (Subscriber+) Profile Privacy Setting Bypass ≤ 2.11.0 CVE-2025-14081 Wordfence
6.4 Medium Live Composer – Free WordPress Website Builder Plugin live-composer-page-builder Cross-Site Scripting Free WordPress Website Builder <= 2.0.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.0.2 CVE-2025-13537 Wordfence
6.4 Medium Ultimate Member Plugin ultimate-member Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via 'value' ≤ 2.11.0 CVE-2025-13217 Wordfence
4.3 Medium Download Plugins and Themes from Dashboard Plugin download-plugins-dashboard Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Plugin/Theme Archival No login needed ≤ 1.9.6 CVE-2025-14399 Wordfence
4.9 Medium Zephyr Project Manager Plugin zephyr-project-manager Path Traversal Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery ≤ 3.3.203 CVE-2025-12496 Wordfence
4.3 Medium Converter for Media Plugin webp-converter-for-media Broken Access Control Missing Authorization to Authenticated (Subscriber+) Optimized Image Deletion via regenerate-attachment REST Endpoint ≤ 6.3.2 CVE-2025-13750 Wordfence
5.3 Medium Cookie Banner for GDPR / CCPA – WPLP Cookie Consent Plugin gdpr-cookie-consent Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 4.0.7 CVE-2025-14061 Wordfence
6.1 Medium Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss Plugin bp-better-messages Cross-Site Scripting Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss <= 2.10.2 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 2.10.2 CVE-2025-14154 Wordfence
6.4 Medium WP Recipe Maker Plugin wp-recipe-maker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 10.2.3 CVE-2025-14385 Wordfence
6.5 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Broken Access Control Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 4.0.1 - Missing Authorization to Unauthenticated Plugin's Settings Disclosure And Modification No login needed ≤ 4.0.1 CVE-2025-13880 Wordfence
6.1 Medium HTML Forms – Simple WordPress Forms Plugin html-forms Cross-Site Scripting Simple WordPress Forms Plugin <= 1.6.0 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.6.0 CVE-2025-13861 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates & Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates & Widgets <= 6.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.5.3 CVE-2025-13977 Wordfence
4.3 Medium Essential Blocks Plugin essential-blocks Broken Access Control Missing Authorization To Authenticated (Author+) Information Disclosure ≤ 5.7.2 CVE-2025-11369 Wordfence
4.3 Medium Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories Plugin post-expirator Broken Access Control Missing Authorization to Authenticated (Contributor+) Authors' Emails Exposure ≤ 4.9.2 CVE-2025-13741 Wordfence
6.4 Medium Elementor Plugin elementor Cross-Site Scripting Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Text Path ≤ 3.33.3 CVE-2025-11220 Wordfence
6.5 Medium Fancy Product Designer | WooCommerce Plugin Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed ≤ 6.4.8 CVE-2025-13231 Wordfence
5.4 Medium Huger for Elementor Plugin huger-elementor Broken Access Control ≤ 1.1.5 CVE-2025-68088 Patchstack
5.4 Medium Modalier for Elementor Plugin modalier-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68087 Patchstack
5.4 Medium Reformer for Elementor Plugin reformer-elementor Broken Access Control ≤ 1.0.6 CVE-2025-68086 Patchstack
5.4 Medium Buttoner for Elementor Plugin buttoner-elementor Broken Access Control Settings Change ≤ 1.0.6 CVE-2025-68085 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only