WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 5,701–5,750 of 17,767 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.3 Medium | Accessiy By CodeConfig Accessibility | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Page Creation No login needed |
≤ 1.0.0 |
CVE-2025-13358 |
Wordfence | |
| 6.1 Medium | CSV Sumotto | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-13894 |
Wordfence | |
| 4.3 Medium | Accessiy By CodeConfig Accessibility – Easy One-Click Accessibility Toolbar That Truly Matters | Broken Access Control Easy One-Click Accessibility Toolbar That Truly Matters <= 1.0.2 - Authenticated (Subscriber+) Missing Authorization to Modify Accessibility Settings |
≤ 1.0.2 |
CVE-2025-13309 |
Wordfence | |
| 6.4 Medium | Yet Another WebClap | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 0.2 |
CVE-2025-13857 |
Wordfence | |
| 4.3 Medium | Search, Filters & Merchandising for WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Deactivation |
≤ 3.0.67 |
CVE-2025-12091 |
Wordfence | |
| 6.4 Medium | Extra Post Images | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0 |
CVE-2025-13856 |
Wordfence | |
| 6.4 Medium | CSS3 Buttons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 0.1 |
CVE-2025-13907 |
Wordfence | |
| 6.4 Medium | RevInsite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.1.0 |
CVE-2025-13863 |
Wordfence | |
| 6.4 Medium | List Attachments Shortcode | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via list-attachments Shortcode |
≤ 0.4.1a |
CVE-2025-12717 |
Wordfence | |
| 4.3 Medium | Listar – Directory Listing & Classifieds | Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Listing Update |
≤ 3.0.0 |
CVE-2025-12577 |
Wordfence | |
| 6.4 Medium | Canadian Nutrition Facts Label | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Nutrition Label Custom Post Type |
≤ 3.0 |
CVE-2025-12715 |
Wordfence | |
| 6.4 Medium | Cute News Ticker | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute |
≤ 1.0 |
CVE-2025-13656 |
Wordfence | |
| 6.4 Medium | TR Timthumb | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.4 |
CVE-2025-13899 |
Wordfence | |
| 5.3 Medium | Helloprint | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Order Status Modification No login needed |
≤ 2.1.2 |
CVE-2025-13666 |
Wordfence | |
| 5.4 Medium | Application Passwords | Cross-Site Scripting Reflected Cross-Site Scripting via reject_url |
≤ 0.1.3 |
CVE-2025-13308 |
Wordfence | |
| 4.3 Medium | WP Landing Page | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Meta Update No login needed |
≤ 0.9.3 |
CVE-2025-13629 |
Wordfence | |
| 5.3 Medium | g-FFL Cockpit | Broken Access Control Improper Authorization to Unauthenticated Product Deletion No login needed |
≤ 1.7.1 |
CVE-2025-12720 |
Wordfence | |
| 4.3 Medium | Listar – Directory Listing & Classifieds | Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 3.0.0 |
CVE-2025-12574 |
Wordfence | |
| 6.4 Medium | Social Feed Gallery Portfolio | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'id' Shortcode Attribute |
≤ 1.3 |
CVE-2025-13896 |
Wordfence | |
| 5.3 Medium | g-FFL Cockpit | Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 1.7.1 |
CVE-2025-12721 |
Wordfence | |
| 6.4 Medium | Ultra Skype Button | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'btn_id' Shortcode Attribute |
≤ 1.0 |
CVE-2025-13898 |
Wordfence | |
| 6.1 Medium | Live Sales Notification for Woocommerce – Woomotiv | Cross-Site Scripting Woomotiv <= 3.6.3 - Reflected Cross-Site Scripting No login needed |
≤ 3.6.3 |
CVE-2025-13137 |
Wordfence | |
| 6.1 Medium | myLCO | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 0.8.1 |
CVE-2025-13626 |
Wordfence | |
| 6.5 Medium | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | SQL Injection AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection via ORDER BY Clause |
≤ 3.40.1 |
CVE-2025-13922 |
Wordfence | |
| 5.4 Medium | weDocs | Broken Access Control Missing Authorization to Settings Update |
≤ 2.1.14 |
CVE-2025-12505 |
Wordfence | |
| 6.1 Medium | Link Whisper Free | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.8.8 |
CVE-2025-11263 |
Wordfence | |
| 5.3 Medium | Wp Social Login and Register Social Counter | Broken Access Control Missing Authorization in Cache REST Endpoints to Social Counter Tampering No login needed |
≤ 3.1.3 |
CVE-2025-13620 |
Wordfence | |
| 4.4 Medium | Trail Manager | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-13682 |
Wordfence | |
| 6.4 Medium | Thai Lottery Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 2.5 |
CVE-2025-13678 |
Wordfence | |
| 6.4 Medium | CryptX | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.0.5 |
CVE-2025-13739 |
Wordfence | |
| 5.3 Medium | Projectopia – WordPress Project Management | Broken Access Control WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed |
≤ 5.1.19 |
CVE-2025-12876 |
Wordfence | |
| 4.3 Medium | WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors | Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed |
≤ 2.6.4 |
CVE-2025-12130 |
Wordfence | |
| 4.3 Medium | ARK Related Posts | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 2.19 |
CVE-2025-13684 |
Wordfence | |
| 6.1 Medium | Nouri.sh Newsletter | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 1.0.1.3 |
CVE-2025-13515 |
Wordfence | |
| 5.3 Medium | Payaza | Broken Access Control Missing Authorization to Unauthenticated Order Status Update No login needed |
≤ 0.3.8 |
CVE-2025-12355 |
Wordfence | |
| 5.3 Medium | Voidek Employee Portal | Broken Access Control Missing Authorization No login needed |
≤ 1.0.7 |
CVE-2025-12093 |
Wordfence | |
| 4.3 Medium | Torod – The smart shipping and delivery portal for e-shops and retailers | Cross-Site Request Forgery The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification No login needed |
≤ 1.9 |
CVE-2025-12373 |
Wordfence | |
| 4.3 Medium | Live CSS Preview | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 2.1.4 |
CVE-2025-12354 |
Wordfence | |
| 4.4 Medium | Weekly Planner | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-12186 |
Wordfence | |
| 6.4 Medium | Easy Jump Links Menus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 1.0.0 |
CVE-2025-13860 |
Wordfence | |
| 5.3 Medium | Feedback Modal for Website | Broken Access Control Missing Authorization to Unauthenticated Arbitrary Feedback Data Exfiltration via 'export_data' Parameter No login needed |
≤ 1.0.1 |
CVE-2025-13528 |
Wordfence | |
| 5.4 Medium | PDF Catalog for WooCommerce | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 1.1.18 |
CVE-2025-12191 |
Wordfence | |
| 4.3 Medium | Image Optimizer by wps.sk | Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Image Optimization No login needed |
≤ 1.2.0 |
CVE-2025-12190 |
Wordfence | |
| 4.3 Medium | Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed |
≤ 7.11.1374 |
CVE-2025-12189 |
Wordfence | |
| 4.3 Medium | EPROLO Dropshipping | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Tracking Data Modification |
≤ 2.3.1 |
CVE-2025-12133 |
Wordfence | |
| 4.3 Medium | Hide Categories Or Products On Shop Page | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.7 |
CVE-2025-12128 |
Wordfence | |
| 6.1 Medium | Twitscription | Cross-Site Scripting Reflected Cross-Site Scripting via admin.php PATH_INFO No login needed |
≤ 0.1.1 |
CVE-2025-13623 |
Wordfence | |
| 4.3 Medium | Takeads | Broken Access Control Missing Authorization to Plugin Settings Deletion |
≤ 1.0.13 |
CVE-2025-12370 |
Wordfence | |
| 6.1 Medium | Jabbernotification | Cross-Site Scripting Reflected Cross-Site Scripting via admin.php PATH_INFO No login needed |
≤ 0.99-RC2 |
CVE-2025-13622 |
Wordfence | |
| 4.3 Medium | Time Sheets | Cross-Site Request Forgery No login needed |
≤ 2.1.3 |
CVE-2025-10055 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.