WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 5,401–5,450 of 17,767 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.4 Medium | Popup Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Reset |
≤ 1.1.37 |
CVE-2025-14446 |
Wordfence | |
| 6.4 Medium | Redux Framework | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via data Parameter |
≤ 4.5.8 |
CVE-2025-9488 |
Wordfence | |
| 4.3 Medium | Popover Windows | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Popover Configuration Update No login needed |
≤ 1.2 |
CVE-2025-14394 |
Wordfence | |
| 5.3 Medium | Devs CRM – Manage tasks, attendance and teams all together | Broken Access Control Manage tasks, attendance and teams all together <= 1.1.8 - Unauthenticated Information Expsoure No login needed |
≤ 1.1.8 |
CVE-2025-13092 |
Wordfence | |
| 6.4 Medium | Header Footer Script Adder – Insert Code in Header, Body & Footer | Cross-Site Scripting Insert Code in Header, Body & Footer <= 2.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.5 |
CVE-2025-12109 |
Wordfence | |
| 5.3 Medium | Eyewear prescription form | Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Category Deletion No login needed |
≤ 6.0.1 |
CVE-2025-14365 |
Wordfence | |
| 6.1 Medium | WP to LinkedIn Auto Publish | Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed |
≤ 1.9.8 |
CVE-2025-12077 |
Wordfence | |
| 5.3 Medium | Login Lockdown & Protection | Other IP Block Bypass No login needed |
≤ 2.14 |
CVE-2025-11707 |
Wordfence | |
| 4.3 Medium | Mavix Education | Broken Access Control Missing Authorization to Authenticated (Subscriber+) 'Creativ Demo Importer' Plugin Activation |
≤ 1.0 |
CVE-2025-11164 |
Wordfence | |
| 5.4 Medium | Shortcode Loader | Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution via 'code' Parameter |
≤ 1.0 |
CVE-2025-14539 |
Wordfence | |
| 6.5 Medium | MediaCommander – Bring Folders to Media, Posts, and Pages | Broken Access Control Bring Folders to Media, Posts, and Pages <= 2.3.1 - Missing Authorization to Authenticated (Author+) Media Folder Deletion |
≤ 2.3.1 |
CVE-2025-14508 |
Wordfence | |
| 5.3 Medium | Easy Theme Options | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Import No login needed |
≤ 1.0 |
CVE-2025-14367 |
Wordfence | |
| 6.4 Medium | YITH WooCommerce Quick View | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via yith_quick_view Shortcode |
≤ 2.7.0 |
CVE-2025-8617 |
Wordfence | |
| 6.4 Medium | Kingcabs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via progressbarLayout Parameter |
≤ 1.1.9 |
CVE-2025-7058 |
Wordfence | |
| 5.3 Medium | Devs CRM – Manage tasks, attendance and teams all together | Broken Access Control Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update No login needed |
≤ 1.1.8 |
CVE-2025-13093 |
Wordfence | |
| 6.1 Medium | Social Media Auto Publish | Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed |
≤ 3.6.5 |
CVE-2025-12076 |
Wordfence | |
| 4.7 Medium | Solutions Ad Manager | Open Redirect Unauthenticated Open Redirect via 'sam-redirect-to' Parameter No login needed |
≤ 1.0.0 |
CVE-2025-14451 |
Wordfence | |
| 4.3 Medium | Gallery Blocks with Lightbox | Broken Access Control Missing Authorization to Authenticated (Contributor+) Plugin Settings Modification |
≤ 3.3.0 |
CVE-2025-14288 |
Wordfence | |
| 6.4 Medium | Custom Frames | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'class' Shortcode Parameter |
≤ 1.0.1 |
CVE-2025-13705 |
Wordfence | |
| 4.3 Medium | Lucky Draw Contests | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 4.2 |
CVE-2025-14462 |
Wordfence | |
| 6.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.335 |
CVE-2025-11376 |
Wordfence | |
| 4.3 Medium | Userback | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin's Configuration Exposure |
≤ 1.0.15 |
CVE-2025-14540 |
Wordfence | |
| 4.3 Medium | AnnunciFunebri Impresa | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Deletion |
≤ 4.7.0 |
CVE-2025-14447 |
Wordfence | |
| 4.4 Medium | Quick Testimonials | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.1 |
CVE-2025-14378 |
Wordfence | |
| 5.3 Medium | Eyewear prescription form | Broken Access Control Missing Authorization to Unauthenticated Arbitrary WooCommerce Product Creation No login needed |
≤ 6.0.1 |
CVE-2025-14366 |
Wordfence | |
| 6.4 Medium | a3 Lazy Load | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.7.5 |
CVE-2025-9873 |
Wordfence | |
| 4.3 Medium | Popover Windows | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Popover Configuration Update via AJAX Actions |
≤ 1.2 |
CVE-2025-14395 |
Wordfence | |
| 4.4 Medium | Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated | Server-Side Request Forgery AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated <= 1.0.9 - Authenticated (Admin+) Server-Side Request Forgery |
≤ 1.0.9 |
CVE-2025-11970 |
Wordfence | |
| 4.3 Medium | Image Slider by Ays- Responsive Slider and Carousel | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed |
≤ 2.7.0 |
CVE-2025-14454 |
Wordfence | |
| 4.9 Medium | Design Import/Export | SQL Injection Authenticated (Administrator+) SQL Injection via XML File Import |
≤ 2.2 |
CVE-2025-14050 |
Wordfence | |
| 6.4 Medium | HT Slider for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.4 |
CVE-2025-14278 |
Wordfence | |
| 4.4 Medium | Custom Post Type UI | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'label' Import Parameter |
≤ 1.18.1 |
CVE-2025-14056 |
Wordfence | |
| 4.3 Medium | GenerateBlocks | Information Disclosure Authenticated (Contributor+) Information Exposure via Metadata |
≤ 2.1.2 |
CVE-2025-12512 |
Wordfence | |
| 4.3 Medium | HAPPY – Helpdesk Support Ticket System | Broken Access Control Helpdesk Support Ticket System <= 1.0.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ticket Reply |
≤ 1.0.9 |
CVE-2025-14581 |
Wordfence | |
| 4.9 Medium | 404 Solution | SQL Injection Authenticated (Admin+) SQL Injection via 'filterText' Parameter |
≤ 3.1.0 |
CVE-2025-14477 |
Wordfence | |
| 4.3 Medium | Employee Spotlight – Team Member Showcase & Meet the Team | Broken Access Control Team Member Showcase & Meet the Team Plugin <= 5.1.3 - Missing Authorization to Authenticated (Subscriber+) Tracking Opt-In/Opt-Out Modification |
≤ 5.1.3 |
CVE-2025-13403 |
Wordfence | |
| 6.4 Medium | AI Feeds | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'aife_post_meta' Shortcode |
≤ 1.0.22 |
CVE-2025-14030 |
Wordfence | |
| 4.3 Medium | Events Manager – Calendar, Bookings, Tickets, and more! | Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed |
≤ 7.2.2.2 |
CVE-2025-12407 |
Wordfence | |
| 6.4 Medium | Magical Posts Display | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Magical Posts Accordion Widget |
≤ 1.2.54 |
CVE-2025-12965 |
Wordfence | |
| 5.3 Medium | Events Manager | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 7.2.2.2 |
CVE-2025-12408 |
Wordfence | |
| 5.3 Medium | Secure Copy Content Protection and Content Locking | Information Disclosure Unauthenticated Sensitive Information Exposure via Exposed CSV Export File No login needed |
≤ 4.9.2 |
CVE-2025-14442 |
Wordfence | |
| 4.3 Medium | Secure Copy Content Protection and Content Locking | Cross-Site Request Forgery Cross-Site Request Forgery to Data Export No login needed |
≤ 4.9.2 |
CVE-2025-14159 |
Wordfence | |
| 4.3 Medium | Simple Bike Rental | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Booking Data Exposure |
≤ 1.0.6 |
CVE-2025-14065 |
Wordfence | |
| 5.3 Medium | Bookit | Broken Access Control Unauthenticated Settings Update No login needed |
< 2.5.1 Fixed in 2.5.1 |
CVE-2025-12841 |
WPScan | |
| 5.5 Medium | MailerLite – Signup forms (official) | Cross-Site Scripting Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.7.16 |
CVE-2025-13993 |
Wordfence | |
| 5.3 Medium | Email Subscribers & Newsletters | Broken Access Control Missing Authentication to Unauthenticated Action Scheduler Task Execution No login needed |
≤ 5.9.10 |
CVE-2025-12348 |
Wordfence | |
| 4.3 Medium | PDF for Contact Form 7 + Drag and Drop Template Builder | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Duplication |
≤ 6.3.3 |
CVE-2025-14074 |
Wordfence | |
| 6.5 Medium | Simple CSV Table | Path Traversal Directory Traversal to Authenticated (Contributor+) Arbitrary File Read |
≤ 1.0.1 |
CVE-2025-12960 |
Wordfence | |
| 6.5 Medium | Image Gallery – Photo Grid & Video Gallery (Modula) | Broken Access Control Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing |
≤ 2.13.3 |
CVE-2025-13891 |
Wordfence | |
| 6.1 Medium | VikRentItems Flexible Rental Management System | Cross-Site Scripting Reflected Cross-Site Scripting via 'delto' Parameter No login needed |
≤ 1.2.0 |
CVE-2025-14049 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.