WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.
Showing 501–550 of 1,928 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Reuters Direct | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed |
≤ 3.0.0 |
CVE-2025-12578 |
Wordfence | |
| 4.3 Medium | Peer Publish | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-12587 |
Wordfence | |
| 4.3 Medium | Conditional Maintenance Mode | Cross-Site Request Forgery No login needed |
≤ 1.0.0 |
CVE-2025-12586 |
Wordfence | |
| 6.1 Medium | Job Board by BestWebSoft | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage No login needed |
≤ 1.2.1 |
CVE-2025-13383 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 7.4.5 |
CVE-2025-12800 |
Wordfence | |
| 4.3 Medium | I Order Terms | Cross-Site Request Forgery No login needed |
≤ 1.5.0 Fixed in 1.5.1 |
CVE-2025-66097 |
Patchstack | |
| 4.3 Medium | Giveaways and Contests by RafflePress | Cross-Site Request Forgery No login needed |
≤ 1.12.20 Fixed in 1.12.21 |
CVE-2025-66064 |
Patchstack | |
| 4.3 Medium | Seriously Simple Podcasting | Cross-Site Request Forgery No login needed |
≤ 3.13.0 Fixed in 3.14.0 |
CVE-2025-66061 |
Patchstack | |
| 6.1 Medium | AuthorSure | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.3 |
CVE-2025-13134 |
Wordfence | |
| 4.3 Medium | Custom Post Type | Cross-Site Request Forgery Cross-Site Request Forgery to Custom Post Type Deletion No login needed |
≤ 1.0 |
CVE-2025-13142 |
Wordfence | |
| 5.3 Medium | SureForms | Cross-Site Request Forgery Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution No login needed |
≤ 1.13.1 |
CVE-2025-12535 |
Wordfence | |
| 5.4 Medium | Responsive Lightbox & Gallery | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery |
≤ 2.5.3 |
CVE-2025-12359 |
Wordfence | |
| 6.4 Medium | Icon List Block – Add Icon-Based Lists with Custom Styles | Server-Side Request Forgery Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 1.2.1 |
CVE-2025-12376 |
Wordfence | |
| 6.8 Medium | AI Engine | Server-Side Request Forgery Authenticated (Editor+) Server-Side Request Forgery |
≤ 3.1.8 |
CVE-2025-8084 |
Wordfence | |
| 5.8 Medium | WP Migrate Lite | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 2.7.6 |
CVE-2025-11427 |
Wordfence | |
| 6.1 Medium | Project Honey Pot Spam Trap | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-12406 |
Wordfence | |
| 4.3 Medium | WP Admin Microblog | Cross-Site Request Forgery Cross-Site Request Forgery to Message Creation No login needed |
≤ 3.1.1 |
CVE-2025-12173 |
Wordfence | |
| 4.3 Medium | Top Friends | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 0.3 |
CVE-2025-12827 |
Wordfence | |
| 6.4 Medium | Local Syndication | Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Shortcode |
≤ 1.5a |
CVE-2025-12962 |
Wordfence | |
| 6.1 Medium | Like-it | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.2 |
CVE-2025-12404 |
Wordfence | |
| 4.3 Medium | Coil Web Monetization | Cross-Site Request Forgery No login needed |
≤ 2.0.2 |
CVE-2025-9625 |
Wordfence | |
| 4.3 Medium | WP Plugin Manager | Cross-Site Request Forgery No login needed |
≤ 1.4.7 Fixed in 1.4.8 |
CVE-2025-64271 |
Patchstack | |
| 6.5 Medium | Auto Prune Posts | Cross-Site Request Forgery No login needed |
≤ 3.0.0 Fixed in 3.1.0 |
CVE-2025-64262 |
Patchstack | |
| 4.3 Medium | Asgaros Forum | Cross-Site Request Forgery Cross-Site Request Forgery to Subscription Settings Update No login needed |
≤ 3.2.1 |
CVE-2025-12901 |
Wordfence | |
| 6.1 Medium | YSlider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-12590 |
Wordfence | |
| 4.3 Medium | USB Qr Code Scanner For Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-12588 |
Wordfence | |
| 6.1 Medium | WP-Walla | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.5.3.5 |
CVE-2025-12589 |
Wordfence | |
| 4.3 Medium | WP Custom Admin Login Page Logo | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.4.8.4 |
CVE-2025-12132 |
Wordfence | |
| 4.3 Medium | CTL Arcade Lite | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Activation and Deactivation No login needed |
≤ 1.0 |
CVE-2025-11886 |
Wordfence | |
| 4.3 Medium | Contest Gallery | Cross-Site Request Forgery No login needed |
≤ 28.0.0 Fixed in 28.0.1 |
CVE-2025-62950 |
Patchstack | |
| 4.3 Medium | Blog2Social: Social Media Auto Post & Scheduler | Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url |
≤ 8.6.0 |
CVE-2025-12560 |
Wordfence | |
| 4.3 Medium | Easy Email Subscription | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Subscriber Deletion No login needed |
≤ 1.3 |
CVE-2025-10691 |
Wordfence | |
| 6.4 Medium | B Carousel Block – Responsive Image and Content Carousel | Broken Access Control Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 1.1.5 |
CVE-2025-12388 |
Wordfence | |
| 6.4 Medium | WPeMatico RSS Feed Fetcher | Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via wpematico_test_feed |
≤ 2.8.11 |
CVE-2025-11917 |
Wordfence | |
| 6.1 Medium | Associados Amazon | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.8 |
CVE-2025-12403 |
Wordfence | |
| 6.1 Medium | Visit Counter | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
1.0 |
CVE-2025-12452 |
Wordfence | |
| 6.1 Medium | MapMap | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update and Stored Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-12415 |
Wordfence | |
| 6.1 Medium | LinkedIn Resume | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.00 |
CVE-2025-12402 |
Wordfence | |
| 6.1 Medium | Centangle Team Showcase | Cross-Site Request Forgery Cross-Site Request Forgery To Plugin's Settings Modification And Stored Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2025-12456 |
Wordfence | |
| 6.1 Medium | LMB^Box Smileys | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 3.2 |
CVE-2025-12400 |
Wordfence | |
| 6.1 Medium | SH Contextual Help | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 3.2.1 |
CVE-2025-12410 |
Wordfence | |
| 5.4 Medium | Social Media WPCF7 Stop Words | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1.3 |
CVE-2025-12413 |
Wordfence | |
| 6.1 Medium | Pagerank Tools | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.1.5 |
CVE-2025-12416 |
Wordfence | |
| 6.1 Medium | Top Bar Notification | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.12 |
CVE-2025-12412 |
Wordfence | |
| 4.3 Medium | Posts Navigation Links for Sections and Headings - Free by WP Masters | Cross-Site Request Forgery Free by WP Masters <= 1.0.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.1 |
CVE-2025-12188 |
Wordfence | |
| 4.3 Medium | WP Global Screen Options | Cross-Site Request Forgery Cross-Site Request Forgery to Screen Options Update No login needed |
≤ 0.2 |
CVE-2025-12069 |
Wordfence | |
| 6.1 Medium | Label Plugins | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.5 |
CVE-2025-12401 |
Wordfence | |
| 4.3 Medium | ViaAds | Cross-Site Request Forgery Cross-Site Request Forgery to API Key Update No login needed |
≤ 2.1.2 |
CVE-2025-12070 |
Wordfence | |
| 5.4 Medium | Bard | Cross-Site Request Forgery No login needed |
≤ 1.6 Fixed in 1.7 |
CVE-2025-64368 |
Patchstack | |
| 4.3 Medium | Advanced Database Cleaner | Cross-Site Request Forgery No login needed |
≤ 3.1.6 Fixed in 3.1.7 |
CVE-2025-64357 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.