WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,751–5,800 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 116 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Webba Booking Plugin webba-booking-lite Broken Access Control ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-66530 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Thank You Page Customizer for WooCommerce Plugin woo-thank-you-page-customizer Broken Access Control ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-66528 Patchstack
4.3 Medium Lobo Theme lobo Broken Access Control ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-66527 Patchstack
4.3 Medium Tablesome Plugin tablesome Broken Access Control ≤ 1.1.34 Fixed in 1.1.35.1 CVE-2025-66526 Patchstack
4.3 Medium Elastic Email Sender Plugin elastic-email-sender Broken Access Control ≤ 1.2.20 Fixed in 1.2.21 CVE-2025-66525 Patchstack
4.3 Medium My Tickets Plugin my-tickets Broken Access Control ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-64257 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
2.7 Low Admin and Site Enhancements (ASE) Plugin admin-site-enhancements Broken Access Control ≤ 8.0.8 Fixed in 8.1.0 CVE-2025-64255 Patchstack
2.7 Low Photo Block Plugin photo-block Broken Access Control ≤ 1.5.1 Fixed in 1.6.0 CVE-2025-64254 Patchstack
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Information Disclosure WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure ≤ 2.9.4 CVE-2025-12558 Wordfence
6.4 Medium Yet Another WebClap Plugin yet-another-webclap-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes ≤ 0.2 CVE-2025-13857 Wordfence
4.3 Medium Listar – Directory Listing & Classifieds Plugin listar-directory-listing Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Listing Update ≤ 3.0.0 CVE-2025-12577 Wordfence
4.3 Medium Listar – Directory Listing & Classifieds Plugin listar-directory-listing Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 3.0.0 CVE-2025-12574 Wordfence
5.3 Medium Projectopia – WordPress Project Management Plugin projectopia-core Broken Access Control WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 5.1.19 CVE-2025-12876 Wordfence
6.4 Medium Sermon Manager Plugin sermon-manager-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.30.0 CVE-2025-12368 Wordfence
4.4 Medium FitVids Plugin fitvids-for-wordpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.0.1 CVE-2025-12124 Wordfence
5.3 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed ≤ 1.1.5 CVE-2025-13006 Wordfence
6.4 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.5 CVE-2025-12417 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering ≤ 2.9.4 CVE-2025-12782 Wordfence
5.3 Medium Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed ≤ 2.3.8 CVE-2025-10304 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed ≤ 2.5.5 CVE-2025-12585 Wordfence
6.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action ≤ 3.3.2 CVE-2025-13534 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification ≤ 2.9.4 CVE-2025-11726 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
6.5 Medium Visualizer: Tables and Charts Manager Plugin visualizer SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.11.12 CVE-2025-12483 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute ≤ 2.2.13 CVE-2025-13697 Wordfence
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.20 CVE-2025-13835 Patchstack
6.5 Medium AI Engine for WordPress: ChatGPT, GPT Content Generator Plugin liquid-chatgpt Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.0.1 CVE-2025-13380 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
7.5 High Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager Plugin SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id No login needed ≤ 4.95 CVE-2025-7402 Wordfence
6.6 Medium Easy Invoice Plugin easy-invoice Local File Inclusion ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-66115 Patchstack
5.3 Medium Show Variations as Single Products Woocommerce Plugin woo-show-single-variations-shop-category Broken Access Control No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-66114 Patchstack
5.3 Medium Better Chat Support for Messenger Plugin better-chat-support Broken Access Control No login needed ≤ 1.2.18 Fixed in 1.2.19 CVE-2025-66113 Patchstack
4.3 Medium Accessibility Toolkit by WebYes Plugin accessibility-plus Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66112 Patchstack
6.5 Medium Nelio Popups Plugin nelio-popups Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-66111 Patchstack
5.3 Medium Tiktok Feed Plugin b-tiktok-feed Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2025-66110 Patchstack
5.3 Medium Cart Weight for WooCommerce Plugin woo-cart-weight Broken Access Control No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66109 Patchstack
4.3 Medium TNC Toolbox: Web Performance Plugin tnc-toolbox Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66108 Patchstack
5.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-66107 Patchstack
4.3 Medium Featured Post Creative Plugin featured-post-creative Broken Access Control ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-66106 Patchstack
4.3 Medium CBX Bookmark & Favorite Plugin cbxwpbookmark Broken Access Control ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-66101 Patchstack
5.3 Medium Chat Help Plugin chat-help Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-66099 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-66098 Patchstack
4.3 Medium I Order Terms Plugin i-order-terms Cross-Site Request Forgery No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-66097 Patchstack
4.3 Medium Table Block by Tableberg Plugin tableberg Broken Access Control ≤ 0.6.9 Fixed in 0.6.10 CVE-2025-66096 Patchstack
8.5 High KiviCare Plugin kivicare-clinic-management-system SQL Injection ≤ 3.6.13 Fixed in 3.6.14 CVE-2025-66095 Patchstack
6.5 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting ≤ 4.8 Fixed in 4.9 CVE-2025-66093 Patchstack
6.5 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting ≤ 1.9.13 Fixed in 1.9.14 CVE-2025-66092 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.1.5 Fixed in 8.1.6 CVE-2025-66091 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only