WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,701–5,750 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 115 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting ≤ 2.5.8 Fixed in 2.5.9 CVE-2025-67554 Patchstack
6.5 Medium Advanced FAQ Manager Plugin advanced-faq-manager Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-67553 Patchstack
6.5 Medium Walker Core Plugin walker-core Cross-Site Scripting ≤ 1.3.17 Fixed in 1.3.18 CVE-2025-67552 Patchstack
6.5 Medium Wappointment Plugin wappointment Cross-Site Scripting ≤ 2.6.9 Fixed in 2.7.0 CVE-2025-67551 Patchstack
6.5 Medium Donation Thermometer Plugin donation-thermometer Cross-Site Scripting ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-67550 Patchstack
6.5 Medium oik Plugin oik Cross-Site Scripting ≤ 4.15.3 Fixed in 4.15.4 CVE-2025-67549 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Broken Access Control ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-67548 Patchstack
6.5 Medium FireBox Plugin firebox Cross-Site Scripting ≤ 3.1.0-free Fixed in 3.1.1-free CVE-2025-67545 Patchstack
6.5 Medium Shopkeeper Extender Plugin shopkeeper-extender Cross-Site Scripting ≤ 7.0 Fixed in 7.0 CVE-2025-67544 Patchstack
6.5 Medium Essential Widgets Plugin essential-widgets Cross-Site Scripting ≤ 2.2.2 Fixed in 2.3 CVE-2025-67543 Patchstack
6.5 Medium Multi-Step Checkout for WooCommerce Plugin wp-multi-step-checkout Cross-Site Scripting ≤ 2.33 Fixed in 2.34 CVE-2025-67542 Patchstack
6.5 Medium WP-ShowHide Plugin wp-showhide Cross-Site Scripting ≤ 1.05 Fixed in 1.06 CVE-2025-67541 Patchstack
6.5 Medium Animation Addons for Elementor Plugin animation-addons-for-elementor Broken Access Control Arbitrary Content Deletion ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-67540 Patchstack
6.5 Medium Select Core Plugin select-core Cross-Site Scripting ≤ 2.6 Fixed in 2.6 CVE-2025-67539 Patchstack
6.5 Medium JNews Gallery Plugin jnews-gallery Cross-Site Scripting ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67538 Patchstack
6.5 Medium ThirstyAffiliates Plugin thirstyaffiliates Cross-Site Scripting ≤ 3.11.8 Fixed in 3.11.9 CVE-2025-67537 Patchstack
6.5 Medium LearnPress Plugin learnpress Cross-Site Scripting ≤ 4.2.9.4 Fixed in 4.3.0 CVE-2025-67536 Patchstack
6.6 Medium WP Maps Plugin wp-google-map-plugin PHP Object Injection ≤ 4.8.6 Fixed in 4.8.7 CVE-2025-67535 Patchstack
7.1 High Rencontre Plugin rencontre Cross-Site Request Forgery No login needed ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67534 Patchstack
7.1 High Themify Portfolio Post Plugin themify-portfolio-post Cross-Site Scripting No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-67533 Patchstack
7.5 High Hara Plugin hara Local File Inclusion ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-67532 Patchstack
7.5 High Turitor Theme turitor Local File Inclusion ≤ 1.5.3 Fixed in 1.5.3 CVE-2025-67531 Patchstack
7.5 High Besa Plugin besa Local File Inclusion ≤ 2.3.15 Fixed in 2.3.16 CVE-2025-67530 Patchstack
7.5 High Fashion Theme fashion2 Local File Inclusion ≤ 5.3.0 Fixed in 5.3.0 CVE-2025-67529 Patchstack
7.5 High Urna Plugin urna Local File Inclusion ≤ 2.5.12 Fixed in 2.5.13 CVE-2025-67528 Patchstack
7.5 High Digiqole Theme digiqole Local File Inclusion ≤ 2.2.7 Fixed in 2.2.7 CVE-2025-67527 Patchstack
7.5 High Sailing Theme sailing Local File Inclusion ≤ 4.4.6 Fixed in 4.4.6 CVE-2025-67526 Patchstack
7.5 High ekommart Theme ekommart Local File Inclusion ≤ 4.3.1 Fixed in 4.3.1 CVE-2025-67525 Patchstack
7.5 High Jobmonster Elementor Addon Plugin jobmonster-addon Local File Inclusion ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-67524 Patchstack
7.5 High Exhibz Theme exhibz Local File Inclusion ≤ 3.0.9 Fixed in 3.0.10 CVE-2025-67523 Patchstack
7.5 High Jobmonster Theme noo-jobmonster Local File Inclusion ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-67522 Patchstack
7.5 High Select Core Plugin select-core Local File Inclusion ≤ 2.6 Fixed in 2.6 CVE-2025-67521 Patchstack
7.6 High Media Library Tools Plugin media-library-tools SQL Injection ≤ 1.6.15 Fixed in 1.7.0 CVE-2025-67520 Patchstack
7.6 High Ninja Tables Plugin ninja-tables SQL Injection ≤ 5.2.3 Fixed in 5.2.4 CVE-2025-67519 Patchstack
8.5 High Accordion Slider PRO Plugin accordion_slider_pro SQL Injection ≤ 1.2 Fixed in 1.3 CVE-2025-67518 Patchstack
8.5 High ArtPlacer Widget Plugin artplacer-widget SQL Injection ≤ 2.22.9.2 Fixed in 2.23 CVE-2025-67517 Patchstack
8.5 High Store Locator Plugin agile-store-locator SQL Injection ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-67516 Patchstack
8.8 High Wilmër Plugin wilmer Local File Inclusion ≤ 3.5 Fixed in 3.5 CVE-2025-67515 Patchstack
4.3 Medium ForumWP Plugin forumwp Broken Access Control ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-67474 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium Portfolio and Projects Plugin portfolio-and-projects Information Disclosure Sensitive Data Exposure ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-67470 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms Plugin cf7-salesforce Broken Access Control ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-67468 Patchstack
4.3 Medium Trinity Audio Plugin trinity-audio Broken Access Control ≤ 5.23.3 Fixed in 5.24 CVE-2025-67466 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium The Aisle Theme theaisle Broken Access Control ≤ 2.9 Fixed in 2.9.1 CVE-2025-66534 Patchstack
4.3 Medium Powerlift Theme powerlift Broken Access Control ≤ 3.2.1 Fixed in 3.2.1 CVE-2025-66532 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only