WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,651–5,700 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 114 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Image Caption Hover Pro Plugin image-caption-hover-pro Broken Access Control ≤ 20.0 Fixed in 20.0 CVE-2025-67562 Patchstack
5.4 Medium Debug Log Viewer Plugin debug-log-viewer Broken Access Control ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-67561 Patchstack
5.4 Medium Listdom Plugin listdom Broken Access Control ≤ 5.0.1 Fixed in 5.1.0 CVE-2025-67560 Patchstack
5.4 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Broken Access Control ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67559 Patchstack
5.9 Medium Rencontre Plugin rencontre Cross-Site Scripting ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67558 Patchstack
5.9 Medium WP eBay Product Feeds Plugin ebay-feeds-for-wordpress Cross-Site Scripting ≤ 3.4.9 Fixed in 3.4.10 CVE-2025-67557 Patchstack
5.9 Medium Advanced FAQ Manager Plugin advanced-faq-manager Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67556 Patchstack
5.9 Medium UseStrict's Calendly Embedder Plugin cal-embedder-lite Cross-Site Scripting ≤ 1.1.7.2 Fixed in 1.2 CVE-2025-67555 Patchstack
5.9 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting ≤ 2.5.8 Fixed in 2.5.9 CVE-2025-67554 Patchstack
6.5 Medium Advanced FAQ Manager Plugin advanced-faq-manager Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67553 Patchstack
6.5 Medium Walker Core Plugin walker-core Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2025-67552 Patchstack
6.5 Medium Wappointment Plugin wappointment Cross-Site Scripting ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-67551 Patchstack
6.5 Medium Donation Thermometer Plugin donation-thermometer Cross-Site Scripting ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-67550 Patchstack
6.5 Medium oik Plugin oik Cross-Site Scripting ≤ 4.15.3 Fixed in 4.15.4 CVE-2025-67549 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Broken Access Control ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-67548 Patchstack
6.5 Medium FireBox Plugin firebox Cross-Site Scripting ≤ 3.1.0-free Fixed in 3.1.1-free CVE-2025-67545 Patchstack
6.5 Medium Shopkeeper Extender Plugin shopkeeper-extender Cross-Site Scripting ≤ 7.0 Fixed in 7.0 CVE-2025-67544 Patchstack
6.5 Medium Essential Widgets Plugin essential-widgets Cross-Site Scripting ≤ 2.2.2 Fixed in 2.3 CVE-2025-67543 Patchstack
6.5 Medium Multi-Step Checkout for WooCommerce Plugin wp-multi-step-checkout Cross-Site Scripting ≤ 2.33 Fixed in 2.34 CVE-2025-67542 Patchstack
6.5 Medium WP-ShowHide Plugin wp-showhide Cross-Site Scripting ≤ 1.05 Fixed in 1.06 CVE-2025-67541 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Broken Access Control Arbitrary Content Deletion ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-67540 Patchstack
6.5 Medium Select Core Plugin select-core Cross-Site Scripting ≤ 2.6 Fixed in 2.6 CVE-2025-67539 Patchstack
6.5 Medium JNews Gallery Plugin jnews-gallery Cross-Site Scripting ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67538 Patchstack
6.5 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Scripting ≤ 3.11.8 Fixed in 3.11.9 CVE-2025-67537 Patchstack
6.5 Medium LearnPress Plugin learnpress Cross-Site Scripting ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-67536 Patchstack
6.6 Medium WP Maps Plugin wp-google-map-plugin PHP Object Injection ≤ 4.8.6 Fixed in 4.8.7 CVE-2025-67535 Patchstack
4.3 Medium ForumWP Plugin forumwp Broken Access Control ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-67474 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium Portfolio and Projects Plugin portfolio-and-projects Information Disclosure Sensitive Data Exposure ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-67470 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-67468 Patchstack
4.3 Medium Trinity Audio Plugin trinity-audio Broken Access Control ≤ 5.23.3 Fixed in 5.24 CVE-2025-67466 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium The Aisle Theme theaisle Broken Access Control ≤ 2.9 Fixed in 2.9.1 CVE-2025-66534 Patchstack
4.3 Medium Powerlift Theme powerlift Broken Access Control ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-66532 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-66530 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Lobo Theme lobo Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-66527 Patchstack
4.3 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.34 Fixed in 1.1.35.1 CVE-2025-66526 Patchstack
4.3 Medium Elastic Email Sender Plugin elastic-email-sender Broken Access Control ≤ 1.2.20 Fixed in 1.2.21 CVE-2025-66525 Patchstack
4.3 Medium My Tickets Plugin my-tickets Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-64257 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Information Disclosure WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.9.4 CVE-2025-12558 Wordfence
6.6 Medium CSV to SortTable Plugin Local File Inclusion Contributor+ LFI ≤ 4.2 CVE-2025-13070 WPScan
5.9 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Cross-Site Scripting Contributor+ Stored XSS < 2.8.13 Fixed in 2.8.13 CVE-2025-13031 WPScan
5.3 Medium Fluent Forms Plugin fluentform Broken Access Control Unauthenticated Insecure Direct Object Reference to Payment Status Tampering via submission_id No login needed ≤ 6.1.7 CVE-2025-13748 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only