WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 5,601–5,650 of 9,029 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 113 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Support Helpdesk Ticket System Lite Plugin ticket-help-desk-system-lite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.5.2 Fixed in 5.0.0 CVE-2025-31626 Patchstack
7.1 High Contact Form vCard Generator Plugin contact-form-vcard-generator Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-31582 Patchstack
7.1 High PeproDev CF7 Database Plugin pepro-cf7-database Cross-Site Scripting No login needed ≤ 2.0.0 CVE-2025-31573 Patchstack
7.1 High CF7 Spreadsheets Plugin cf7-spreadsheets Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.2 CVE-2025-31536 Patchstack
7.1 High WP_Identicon Plugin wp-identicon Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-31468 Patchstack
7.1 High Flickr Photostream Plugin flickr-photostream Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1.8 CVE-2025-31467 Patchstack
7.1 High Search engine keywords highlighter Plugin keywords-highlight-tool Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.3 CVE-2025-31442 Patchstack
7.1 High Blubrry PowerPress Podcasting plugin MultiSite add-on Plugin powerpress-multisite Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1 CVE-2025-31436 Patchstack
7.5 High DeBounce Email Validator Plugin debounce-io-email-validator Local File Inclusion No login needed ≤ 5.7 Fixed in 5.7.1 CVE-2025-31098 Patchstack
7.1 High Web Directory Free Plugin web-directory-free Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.8 CVE-2025-30908 Patchstack
8.8 High Testimonial Slider Plugin testimonial PHP Object Injection ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-30889 Patchstack
7.1 High Snow Storm Plugin snow-storm Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-30858 Patchstack
7.1 High Latest Custom Post Type Updates Plugin latest-custom-post-type-updates Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.0 CVE-2025-30616 Patchstack
7.1 High Wptobe-signinup Plugin wptobe-signinup Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.2 CVE-2025-30611 Patchstack
8.8 High Shopper Approved Reviews Plugin shopperapproved-reviews Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update 2.0 – 2.1 CVE-2025-3063 Wordfence
8.5 High Actionwear products sync Plugin actionwear-products-sync SQL Injection ≤ 2.3.3 CVE-2025-31619 Patchstack
7.1 High Auto scroll for reading Plugin auto-scroll-for-reading Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.4 CVE-2025-31594 Patchstack
7.5 High Ni WooCommerce Product Enquiry Plugin ni-woocommerce-product-enquiry Broken Access Control No login needed ≤ 4.1.8 CVE-2025-31580 Patchstack
7.1 High Fonts Manager | Custom Fonts Plugin fonts-manager-custom-fonts Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-31578 Patchstack
7.1 High The Logo Slider Plugin the-logo-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-31571 Patchstack
7.1 High LeadLab by wiredminds Plugin wiredminds-leadlab Cross-Site Scripting No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-31568 Patchstack
8.5 High Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin ai-auto-tool SQL Injection ≤ 2.2.6 Fixed in 2.2.8 CVE-2025-31564 Patchstack
7.1 High AI Search Bar Plugin open-ai-search-bar Cross-Site Scripting No login needed ≤ 2.1 CVE-2025-31563 Patchstack
8.5 High Ultimate Push Notifications Plugin ultimate-push-notifications SQL Injection ≤ 1.2.0 CVE-2025-31561 Patchstack
7.2 High Salon booking system Plugin salon-booking-system Privilege Escalation ≤ 10.15 Fixed in 10.15 CVE-2025-31560 Patchstack
7.1 High Ultimate Push Notifications Plugin ultimate-push-notifications Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-31548 Patchstack
7.1 High Bulk NoIndex & NoFollow Toolkit Plugin bulk-noindex-nofollow-toolkit-by-mad-fish Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.16 Fixed in 2.20 CVE-2025-31537 Patchstack
7.1 High CGM Event Calendar Plugin cgm-event-calendar Cross-Site Scripting No login needed ≤ 0.8.5 CVE-2025-31462 Patchstack
7.1 High NanoSupport Plugin nanosupport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.6.0 CVE-2025-31461 Patchstack
7.1 High Limit Max IPs Per User Plugin limit-max-ips-per-user Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5 CVE-2025-31455 Patchstack
7.1 High Delete Post Revision Plugin delete-post-revision Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31454 Patchstack
7.1 High WP Cleaner Plugin wpcleaner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-31446 Patchstack
7.1 High Pages Order Plugin pages-order Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.3 CVE-2025-31445 Patchstack
7.1 High WordPress Galleria Plugin wp-galleria Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-31441 Patchstack
7.1 High WP Bookmarks Plugin wp-bookmarks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-31431 Patchstack
8.1 High Material Dashboard Plugin material-dashboard Local File Inclusion No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-31097 Patchstack
8.5 High Order Splitter for WooCommerce Plugin woo-order-splitter SQL Injection ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-31089 Patchstack
7.1 High Product Table by WBW Plugin woo-product-tables Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-31086 Patchstack
7.1 High xili-language Plugin xili-language Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.21.2 Fixed in 2.21.3 CVE-2025-31085 Patchstack
8.1 High News & Blog Designer Pack Plugin blog-designer-pack Local File Inclusion No login needed ≤ 4.0 Fixed in 4.0.1 CVE-2025-31082 Patchstack
7.1 High Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.5 Fixed in 4.1.6 CVE-2025-31081 Patchstack
7.1 High HTML Forms Plugin html-forms Cross-Site Scripting No login needed ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-31080 Patchstack
7.1 High Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition Cross-Site Scripting Worldwide Express Edition plugin <= 5.2.18 - Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.18 Fixed in 5.2.19 CVE-2025-31078 Patchstack
7.1 High Access Areas Plugin wp-access-areas Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.19 Fixed in 1.5.20 CVE-2025-30913 Patchstack
7.1 High Plugin Oficial – Getnet para WooCommerce Plugin wc-checkout-getnet Cross-Site Scripting Getnet para WooCommerce plugin <= 1.7.3 - Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.3 Fixed in 1.8.0 CVE-2025-30906 Patchstack
7.1 High Secure Copy Content Protection and Content Locking Plugin secure-copy-content-protection Cross-Site Scripting No login needed ≤ 4.4.3 Fixed in 4.4.5 CVE-2025-30905 Patchstack
8.8 High WpTravelly Plugin tour-booking-manager PHP Object Injection ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-30892 Patchstack
7.1 High Oracle Cards Lite Plugin oracle-cards Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-30852 Patchstack
7.1 High Watu Quiz Plugin watu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-30844 Patchstack
8.8 High WPC Smart Linked Products - Upsells & Cross-sells for WooCommerce Plugin wpc-smart-linked-products Privilege Escalation ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-30825 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only