WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,401–5,450 of 8,943 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 109 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Xola Plugin xola-bookings-for-tours-activities Broken Access Control ≤ 1.6 CVE-2025-23955 Patchstack
5.4 Medium Mark Posts Plugin mark-posts Broken Access Control ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-23963 Patchstack
4.3 Medium Goldstar Plugin goldstar Broken Access Control ≤ 2.1.1 CVE-2025-23962 Patchstack
4.3 Medium Salvador – AI Image Generator Plugin salvador-ai-image-generator Broken Access Control AI Image Generator plugin <= 1.0.11 - Broken Access Control ≤ 1.0.11 CVE-2025-23954 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 1.1 CVE-2025-23939 Patchstack
6.5 Medium EZPlayer Plugin ezplayer Cross-Site Scripting ≤ 1.0.10 CVE-2025-23950 Patchstack
6.5 Medium Enhanced YouTube Shortcode Plugin enhanced-youtube-shortcode Cross-Site Scripting ≤ 2.0.1 CVE-2025-23946 Patchstack
6.5 Medium PDF.js Shortcode Plugin pdfjs-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23943 Patchstack
6.5 Medium MeinTurnierplan.de Widget Viewer Plugin meinturnierplande-widget-viewer Cross-Site Scripting ≤ 1.1 CVE-2025-23941 Patchstack
6.5 Medium Gallery: Hybrid – Advanced Visual Gallery Plugin hybrid-gallery Cross-Site Scripting Advanced Visual Gallery plugin <= 1.4.0.2 - Cross Site Scripting (XSS) ≤ 1.4.0.2 CVE-2025-23951 Patchstack
6.5 Medium WP-Player Plugin wp-player Cross-Site Scripting ≤ 2.6.1 CVE-2025-23947 Patchstack
6.5 Medium Giveaways and Contests by PromoSimple Plugin giveaways-contests-by-promosimple Cross-Site Scripting ≤ 1.24 CVE-2025-23934 Patchstack
6.5 Medium Image Switcher Plugin image-switcher Cross-Site Scripting ≤ 0.1.1 CVE-2025-23940 Patchstack
6.5 Medium Google Org Chart Plugin google-org-chart Cross-Site Scripting ≤ 1.0.1 CVE-2025-23928 Patchstack
6.5 Medium WP Photo Sphere Plugin wp-photo-sphere Cross-Site Scripting ≤ 3.8 CVE-2025-23924 Patchstack
6.5 Medium Magic Google Maps Plugin magic-google-maps Cross-Site Scripting ≤ 1.0.4 CVE-2025-23935 Patchstack
6.5 Medium WpF Ultimate Carousel Plugin wpf-ultimate-carousel Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.11 CVE-2025-23933 Patchstack
4.3 Medium PayPal Marketing Solutions Plugin paypal-promotions-and-insights Broken Access Control ≤ 1.2 CVE-2025-23930 Patchstack
5.4 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control ≤ 3.3.8 CVE-2025-23917 Patchstack
6.5 Medium CC Circle Progress Bar Plugin cc-circle-progress-bar Cross-Site Scripting ≤ 1.0.0 CVE-2025-23936 Patchstack
6.5 Medium Feedburner Optin Form Plugin feedburner-optin-form Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.2.8 CVE-2025-23925 Patchstack
6.5 Medium Incredible Font Awesome Plugin incredible-font-awesome Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23927 Patchstack
4.3 Medium Email Capture & Lead Generation Plugin email-capture-lead-generation Broken Access Control ≤ 1.0.2 CVE-2025-23929 Patchstack
6.5 Medium Ajax WP Query Search Filter Plugin ajax-wp-query-search-filter Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0.7 CVE-2025-23926 Patchstack
5.4 Medium WP Meetup Plugin wp-meetup Broken Access Control Settings Change ≤ 2.3.0 CVE-2025-23916 Patchstack
5.4 Medium Slides & Presentations Plugin slide Content Injection ≤ 0.0.39 CVE-2025-23919 Patchstack
6.5 Medium Compare Ninja Plugin compare-ninja-comparison-tables Cross-Site Scripting ≤ 2.1.0 CVE-2025-23909 Patchstack
6.5 Medium Pastebin Plugin pastebin-embed Cross-Site Scripting ≤ 1.5 CVE-2025-23908 Patchstack
6.5 Medium Bookalet Plugin bookalet Cross-Site Scripting ≤ 1.0.3 CVE-2025-23899 Patchstack
6.5 Medium Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Scripting ≤ 2.3 CVE-2025-23897 Patchstack
6.5 Medium Blog Summary Plugin blog-summary Cross-Site Scripting ≤ 0.1.2 β CVE-2025-23887 Patchstack
6.5 Medium Yet Another Countdown Plugin yacp Cross-Site Scripting ≤ 1.0.1 CVE-2025-23891 Patchstack
6.5 Medium Progress Tracker Plugin progress-tracker Cross-Site Scripting ≤ 0.9.3 CVE-2025-23892 Patchstack
6.5 Medium Mindmeister Shortcode Plugin mindmeister-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-23896 Patchstack
6.5 Medium Easy Tweet Embed Plugin easy-tweet-embed Cross-Site Scripting ≤ 1.7 CVE-2025-23890 Patchstack
6.5 Medium WP krpano Plugin wp-krpano Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.2.1 CVE-2025-23876 Patchstack
6.5 Medium GMap Shortcode Plugin gmap-shortcode Cross-Site Scripting ≤ 2.0 CVE-2025-23893 Patchstack
6.5 Medium Annie Plugin annie Cross-Site Scripting ≤ 2.1.1 CVE-2025-23886 Patchstack
5.9 Medium Post-to-Post Links Plugin easy-post-to-post-links Cross-Site Scripting ≤ 4.2 CVE-2025-23878 Patchstack
6.5 Medium Category D3 Tree Plugin category-d3-tree Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23873 Patchstack
6.5 Medium Nite Shortcodes Plugin nite-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23877 Patchstack
6.5 Medium WCS QR Code Generator Plugin wcs-qr-code-generator Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.0 CVE-2025-23864 Patchstack
6.5 Medium Chess Tempo Viewer Plugin chesstempoviewer Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 0.9.5 CVE-2025-23868 Patchstack
6.5 Medium Winning Portfolio Plugin winning-portfolio Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.1 CVE-2025-23865 Patchstack
6.5 Medium Rollover Tab Plugin rollover-tab Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 1.3.2 CVE-2025-23863 Patchstack
5.9 Medium Shoutcast and Icecast HTML5 Web Radio Player by YesStreaming.com Plugin shoutcast-and-icecast-html5-web-radio-player-by-yesstreaming-com Cross-Site Scripting ≤ 3.3 CVE-2025-23854 Patchstack
6.5 Medium Daily Proverb Plugin daily-proverb Cross-Site Scripting ≤ 2.0.3 CVE-2025-23859 Patchstack
5.3 Medium Contact Form 7 Anti Spambot Plugin contact-form-7-anti-spambot Broken Access Control No login needed ≤ 1.0.1 CVE-2025-23862 Patchstack
6.5 Medium Charity-thermometer Plugin charitydonation-thermometer Cross-Site Scripting ≤ 1.1.2 CVE-2025-23860 Patchstack
6.5 Medium Simple Vertical Timeline Plugin simple-vertical-timeline Cross-Site Scripting ≤ 0.1 CVE-2025-23856 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only