WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,351–5,400 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 108 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Health Check & Troubleshooting Plugin health-check Path Traversal ≤ 1.7.1 CVE-2025-64253 Patchstack
4.9 Medium Ultimate Learning Pro Plugin indeed-learning-pro Broken Access Control Arbitrary Content Deletion ≤ 3.9.3 CVE-2025-64251 Patchstack
4.7 Medium Directorist Plugin directorist Open Redirect No login needed ≤ 8.6.6 Fixed in 8.6.7 CVE-2025-64250 Patchstack
4.3 Medium Protect WP Admin Plugin protect-wp-admin Broken Access Control No login needed ≤ 4.1 Fixed in 4.2 CVE-2025-64249 Patchstack
4.3 Medium Request a Quote Plugin request-a-quote Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-64248 Patchstack
4.3 Medium Read More & Accordion Plugin expand-maker Broken Access Control ≤ 3.5.5.1 Fixed in 3.5.6 CVE-2025-64247 Patchstack
4.3 Medium Accessibility by AudioEye Plugin accessibility-by-audioeye Broken Access Control ≤ 1.0.49 Fixed in 1.1.0 CVE-2025-64246 Patchstack
4.3 Medium Import external attachments Plugin import-external-attachments Broken Access Control ≤ 1.5.12 CVE-2025-64245 Patchstack
4.3 Medium Restrict Elementor Widgets, Columns and Sections Plugin restrict-elementor-widgets Broken Access Control ≤ 1.12 CVE-2025-64244 Patchstack
4.3 Medium Directory Pro Plugin directory-pro Broken Access Control ≤ 2.5.6 CVE-2025-64243 Patchstack
4.3 Medium Easy Property Listings Plugin easy-property-listings Broken Access Control ≤ 3.5.22 Fixed in 3.5.23 CVE-2025-64242 Patchstack
4.3 Medium WP Coupons and Deals Plugin wp-coupons-and-deals Broken Access Control ≤ 3.2.4 Fixed in 3.2.5 CVE-2025-64241 Patchstack
4.3 Medium Freshchat Plugin freshchat Cross-Site Request Forgery No login needed ≤ 2.3.4 CVE-2025-64240 Patchstack
4.3 Medium RTL Tester Plugin rtl-tester Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-64239 Patchstack
4.3 Medium WPS Bidouille Plugin wps-bidouille Broken Access Control ≤ 1.33.1 Fixed in 1.33.2 CVE-2025-64238 Patchstack
4.3 Medium Quick Interest Slider Plugin quick-interest-slider Cross-Site Request Forgery No login needed ≤ 3.1.5 Fixed in 3.1.6 CVE-2025-64237 Patchstack
4.3 Medium Listify Plugin listify Cross-Site Request Forgery No login needed ≤ 3.2.5 CVE-2025-59009 Patchstack
4.3 Medium Salient Core Plugin salient-core Broken Access Control ≤ 3.0.8 Fixed in 3.0.9 CVE-2025-59001 Patchstack
4.3 Medium WP Attractive Donations System - Easy Stripe & Paypal donations Plugin wp_attractivedonationssystem Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.25 CVE-2025-58999 Patchstack
4.3 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Broken Access Control ≤ 1.5.5 CVE-2025-54045 Patchstack
4.3 Medium SKT Page Builder Plugin skt-builder Broken Access Control ≤ 4.9 Fixed in 5.0 CVE-2025-54005 Patchstack
5.3 Medium JetFormBuilder Plugin jetformbuilder Broken Access Control Missing Authorization to Unauthenticated Form Generation No login needed ≤ 3.5.3 CVE-2025-11991 Wordfence
5.9 Medium Fancy Product Designer | WooCommerce Plugin Information Disclosure Unauthenticated Information Disclosure and PHAR Deserialization via 'url' Parameter No login needed ≤ 6.4.8 CVE-2025-13439 Wordfence
5.3 Medium dokan pro Plugin Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 4.1.3 CVE-2025-12809 Wordfence
4.3 Medium Auto Featured Image Plugin auto-post-thumbnail Broken Access Control Missing Authorization to Authenticated (Contributor+) Post Thumbnail Modification ≤ 4.2.1 CVE-2025-13794 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.3.1 - Missing Authorization to Unauthenticated Orders Statistics Exposure No login needed ≤ 4.3.1 CVE-2025-13956 Wordfence
6.4 Medium LearnPress – WordPress LMS Plugin Cross-Site Scripting WordPress LMS Plugin <= 4.3.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via get_profile_social ≤ 4.3.1 CVE-2025-14387 Wordfence
5.3 Medium OneSignal – Web Push Notifications Plugin onesignal-free-web-push-notifications Broken Access Control Web Push Notifications <= 3.6.1 - Missing Authorization to Unauthenticated Plugin Settings Update No login needed ≤ 3.6.1 CVE-2025-13950 Wordfence
6.4 Medium FluentAuth - Auth Security Plugin fluent-security Cross-Site Scripting Auth Security Plugin <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluent_auth_reset_password' Shortcode ≤ 2.0.3 CVE-2025-13728 Wordfence
4.3 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird Broken Access Control WordPress Media Library Folders & File Manager <= 6.5.1 - Missing Authorization to Authenticated (Author+) Global Folders Tampering ≤ 6.5.1 CVE-2025-12900 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Broken Access Control Photo Grid & Video Gallery <= 2.13.3 - Missing Authorization to Authenticated (Author+) Arbitrary Gallery Modification ≤ 2.13.3 CVE-2025-14003 Wordfence
6.4 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'RM_Forms' Shortcode ≤ 6.0.6.7 CVE-2025-13610 Wordfence
6.4 Medium User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Plugin user-registration Cross-Site Scripting Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 4.4.6 CVE-2025-13367 Wordfence
6.4 Medium CC Child Pages Plugin cc-child-pages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'child_pages' Shortcode ≤ 2.0.0 CVE-2025-13608 Wordfence
5.3 Medium Royal Elementor Addons and Templates Plugin Arbitrary File Upload Unauthenticated Media File Upload No login needed < 1.7.1037 Fixed in 1.7.1037 CVE-2025-11363 WPScan
6.4 Medium Lightweight Accordion Plugin lightweight-accordion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.20 CVE-2025-13740 Wordfence
5.3 Medium HelloLeads CRM Form Shortcode Plugin Cross-Site Request Forgery Unauthenticated Settings Reset No login needed ≤ 1.0 CVE-2025-12696 WPScan
6.4 Medium Addon Elements for Elementor Plugin addon-elements-for-elementor-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.14.3 CVE-2025-12537 Wordfence
6.4 Medium Popup Builder – Create highly converting, mobile friendly marketing popups. Plugin popup-builder Cross-Site Scripting Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.4.1 CVE-2025-9856 Wordfence
6.4 Medium Livemesh SiteOrigin Widgets Plugin livemesh-siteorigin-widgets Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Hero Header and Pricing Table Widgets ≤ 3.9.1 CVE-2025-8780 Wordfence
6.4 Medium Enter Addons Plugin enteraddons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown and Image Comparison Widgets ≤ 2.2.7 CVE-2025-8687 Wordfence
6.4 Medium MarqueeAddons Plugin marquee-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Testimonial Marquee Widget ≤ 2.4.3 CVE-2025-8199 Wordfence
6.4 Medium JetWidgets For Elementor Plugin jetwidgets-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Image Comparison and Subscribe Widgets ≤ 1.0.20 CVE-2025-8195 Wordfence
6.4 Medium King Addons for Elementor Plugin king-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 51.1.39 CVE-2025-7960 Wordfence
6.5 Medium Brizy – Page Builder Plugin brizy Information Disclosure Page Builder <= 2.7.16 - Authenticated (Contributor+) Sensitive Information Exposure via get_users Function ≤ 2.7.16 CVE-2025-0969 Wordfence
5.9 Medium Filter & Grids Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 3.2.0 CVE-2025-10289 Wordfence
6.4 Medium All-in-One Addons for Elementor – WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting WidgetKit <= 2.5.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Team and Countdown Widgets ≤ 2.5.6 CVE-2025-8779 Wordfence
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Content Injection Unauthenticated HTML Injection No login needed ≤ 2.10.0 CVE-2025-9207 Wordfence
5.8 Medium WPS Visitor Counter Plugin wps-visitor-counter Cross-Site Scripting Reflected XSS via $_SERVER['REQUEST_URI'] No login needed ≤ 1.4.8 CVE-2025-9116 WPScan
5.3 Medium myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program Plugin mycred Broken Access Control Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 - Missing Authorization to Unauthenticated Withdrawal Request Approval No login needed ≤ 2.9.7 CVE-2025-12362 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only