WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 501–550 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 11 of 29
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection ≤ 9.1.6 CVE-2025-10185 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode ≤ 1.0.334 CVE-2025-9560 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block SQL Injection Unauthenticated SQL Injection via 'id' No login needed ≤ 2.1.3 CVE-2025-10862 Wordfence
5.3 Medium Chartify – WordPress Chart Plugin chart-builder Authentication Bypass WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function No login needed ≤ 3.5.9 CVE-2025-11171 Wordfence
7.2 High RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager SQL Injection Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.6.2 - Authenticated (Administrator+) SQL Injection ≤ 6.0.6.2 CVE-2025-11204 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
8.1 High Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control Authenticated (Subscriber+) Missing Authorization via get_cc_orders/update_order_status Functions ≤ 3.5.32 CVE-2025-9243 Wordfence
8.8 High TextBuilder Plugin textbuilder Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Account Takeover No login needed 1.0.0 – 1.1.1 CVE-2025-9213 Wordfence
4.3 Medium cForms – Light speed fast Form Builder Plugin cforms-plugin Cross-Site Request Forgery Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-9898 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
7.7 High BM Content Builder Plugin bm-builder Arbitrary File Deletion ≤ 3.16.3.3 Fixed in 3.16.3.3 CVE-2025-59002 Patchstack
2.7 Low ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution Plugin Broken Access Control All in One WooCommerce Solution <= 4.8.3 - Insufficient Authorization to Authenticated (Editor+) Settings Update ≤ 4.8.3 CVE-2025-10173 Wordfence
6.4 Medium Themify Builder Plugin themify-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 7.6.9 CVE-2025-9353 Wordfence
6.5 Medium Fusion Page Builder : Extension – Gallery Plugin fusion-extension-gallery Cross-Site Scripting Gallery Plugin <= 1.7.6 - Cross Site Scripting (XSS) ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-58965 Patchstack
6.5 Medium HT Mega – Absolute Addons for WPBakery Page Builder Plugin ht-mega-for-wpbakery Cross-Site Scripting Absolute Addons for WPBakery Page Builder Plugin <= 1.0.9 - Cross Site Scripting (XSS) ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-53463 Patchstack
5.9 Medium Draft Plugin website-builder Cross-Site Scripting ≤ 3.0.9 CVE-2025-58033 Patchstack
6.5 Medium SQL Chart Builder Plugin sql-chart-builder Cross-Site Scripting ≤ 2.3.7.2 CVE-2025-58233 Patchstack
6.5 Medium StylePress for Elementor Plugin full-site-builder-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2025-58254 Patchstack
4.3 Medium Internal Links Manager Plugin seo-automated-link-building Cross-Site Request Forgery No login needed ≤ 3.0.1 CVE-2025-9949 Wordfence
4.3 Medium SureForms – Drag and Drop Form Builder Plugin sureforms Broken Access Control Drag and Drop Form Builder for WordPress <= 1.12.0 - Missing Authorization to Authenticated (Contributor+) Form Creation ≤ 1.12.0 CVE-2025-10489 Wordfence
5.4 Medium Kubio AI Page Builder Plugin kubio Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Installation ≤ 2.6.3 CVE-2025-8487 Wordfence
8.0 High User Meta – User Profile Builder and User management Plugin user-meta Arbitrary File Deletion User Profile Builder and User management plugin <= 3.1.2 - Authenticated (Subscriber+) Arbitrary File Deletion ≤ 3.1.2 CVE-2025-9693 Wordfence
6.4 Medium Smart Table Builder Plugin smart-table-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.0.1 CVE-2025-9126 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
6.1 Medium Beaver Builder Plugin (Lite Version) Plugin beaver-builder-lite-version Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.9.2.1 CVE-2025-8897 Wordfence
8.8 High Video Share VOD – Turnkey Video Site Builder Script Plugin video-share-vod Cross-Site Request Forgery Turnkey Video Site Builder Script <= 2.7.6 - Cross-Site Request Forgery to Command Injection No login needed ≤ 2.7.6 CVE-2025-7812 Wordfence
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Cross-Site Scripting ≤ 6.2.0 Fixed in 6.3.0 CVE-2025-58208 Patchstack
6.5 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.9 Fixed in 1.2.10 CVE-2025-58198 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-58194 Patchstack
4.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 12.1.1 Fixed in 12.1.2 CVE-2025-57884 Patchstack
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control ≤ 7.6.7 Fixed in 7.6.8 CVE-2025-49396 Patchstack
8.8 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Request Forgery No login needed ≤ 9.1.3 Fixed in 9.1.4 CVE-2025-49399 Patchstack
7.1 High Multimedia Playlist Slider Addon for WPBakery Page Builder Plugin lbg_vp_youtube_vimeo_addon_visual_composer Cross-Site Scripting No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-48154 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg-universal-video-player-addon-visual-composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-48170 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg-universal-video-player-addon-visual-composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-53559 Patchstack
7.1 High Universal Video Player - Addon for WPBakery Page Builder Plugin lbg_universal_video_player_addon_visual_composer Cross-Site Scripting Addon for WPBakery Page Builder <= 3.2.1 - Cross Site Scripting (XSS) No login needed ≤ 3.2.1 Fixed in 3.2.2.0 CVE-2025-53562 Patchstack
7.1 High HTML5 Radio Player - WPBakery Page Builder Addon Plugin lbg_radio_player_addon_visual_composer Cross-Site Scripting WPBakery Page Builder Addon <= 2.5 - Cross Site Scripting (XSS) No login needed ≤ 2.5 Fixed in 2.5.2 CVE-2025-53564 Patchstack
6.5 Medium JetWooBuilder Plugin jet-woo-builder Information Disclosure Sensitive Data Exposure ≤ 2.1.20 Fixed in 2.1.20.1 CVE-2025-53998 Patchstack
7.5 High Funnel Builder by FunnelKit Plugin funnel-builder Local File Inclusion No login needed ≤ 3.11.1 Fixed in 3.12.0 CVE-2025-54750 Patchstack
7.5 High JS Archive List Plugin jquery-archive-list-widget SQL Injection Unauthenticated SQL Injection via build_sql_where Function No login needed ≤ 6.1.5 CVE-2025-7670 Wordfence
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.14.3 CVE-2025-8896 Wordfence
6.4 Medium WP Table Builder – WordPress Table Plugin wp-table-builder Cross-Site Scripting WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.0.12 CVE-2025-8604 Wordfence
6.5 Medium Build App Online Plugin build-app-online Cross-Site Request Forgery No login needed ≤ 1.0.23 CVE-2025-53249 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.15.0 Fixed in 45.15.0 CVE-2025-55709 Patchstack
6.5 Medium WP Table Builder Plugin wp-table-builder Cross-Site Scripting ≤ 2.0.12 Fixed in 2.0.13 CVE-2025-55711 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Broken Access Control ≤ 6.3.13 Fixed in 6.3.14 CVE-2025-55712 Patchstack
6.5 Medium WPBITS Addons For Elementor Page Builder Plugin wpbits-addons-for-elementor Cross-Site Scripting ≤ 1.5 Fixed in 1.5.1 CVE-2024-37945 Patchstack
9.3 Critical Easy Form Builder Plugin easy-form-builder SQL Injection No login needed ≤ 3.8.15 Fixed in 3.8.16 CVE-2025-54678 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-54673 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only