WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 5,751–5,800 of 17,220 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | Webba Booking | Broken Access Control |
≤ 6.2.1 Fixed in 6.2.2 |
CVE-2025-66530 |
Patchstack | |
| 4.3 Medium | Chartify | Cross-Site Request Forgery No login needed |
≤ 3.6.3 Fixed in 3.6.4 |
CVE-2025-66529 |
Patchstack | |
| 4.3 Medium | Thank You Page Customizer for WooCommerce | Broken Access Control |
≤ 1.1.8 Fixed in 1.1.9 |
CVE-2025-66528 |
Patchstack | |
| 4.3 Medium | Lobo | Broken Access Control |
≤ 2.8.6 Fixed in 2.8.7 |
CVE-2025-66527 |
Patchstack | |
| 4.3 Medium | Tablesome | Broken Access Control |
≤ 1.1.34 Fixed in 1.1.35.1 |
CVE-2025-66526 |
Patchstack | |
| 4.3 Medium | Elastic Email Sender | Broken Access Control |
≤ 1.2.20 Fixed in 1.2.21 |
CVE-2025-66525 |
Patchstack | |
| 4.3 Medium | My Tickets | Broken Access Control |
≤ 2.1.0 Fixed in 2.1.1 |
CVE-2025-64257 |
Patchstack | |
| 4.3 Medium | Simple Folio | Cross-Site Request Forgery No login needed |
≤ 1.1.0 Fixed in 1.1.1 |
CVE-2025-64256 |
Patchstack | |
| 2.7 Low | Admin and Site Enhancements (ASE) | Broken Access Control |
≤ 8.0.8 Fixed in 8.1.0 |
CVE-2025-64255 |
Patchstack | |
| 2.7 Low | Photo Block | Broken Access Control |
≤ 1.5.1 Fixed in 1.6.0 |
CVE-2025-64254 |
Patchstack | |
| 4.3 Medium | Beaver Builder – WordPress Page Builder | Information Disclosure WordPress Page Builder <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure |
≤ 2.9.4 |
CVE-2025-12558 |
Wordfence | |
| 6.4 Medium | Yet Another WebClap | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 0.2 |
CVE-2025-13857 |
Wordfence | |
| 4.3 Medium | Listar – Directory Listing & Classifieds | Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Listing Update |
≤ 3.0.0 |
CVE-2025-12577 |
Wordfence | |
| 4.3 Medium | Listar – Directory Listing & Classifieds | Broken Access Control Directory Listing & Classifieds WordPress Plugin <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion |
≤ 3.0.0 |
CVE-2025-12574 |
Wordfence | |
| 5.3 Medium | Projectopia – WordPress Project Management | Broken Access Control WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed |
≤ 5.1.19 |
CVE-2025-12876 |
Wordfence | |
| 6.4 Medium | Sermon Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.30.0 |
CVE-2025-12368 |
Wordfence | |
| 4.4 Medium | FitVids | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 4.0.1 |
CVE-2025-12124 |
Wordfence | |
| 5.3 Medium | SurveyFunnel – Survey | Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed |
≤ 1.1.5 |
CVE-2025-13006 |
Wordfence | |
| 6.4 Medium | SurveyFunnel – Survey | Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.1.5 |
CVE-2025-12417 |
Wordfence | |
| 4.3 Medium | Beaver Builder – WordPress Page Builder | Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering |
≤ 2.9.4 |
CVE-2025-12782 |
Wordfence | |
| 5.3 Medium | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning | Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed |
≤ 2.3.8 |
CVE-2025-10304 |
Wordfence | |
| 5.3 Medium | MxChat – AI Chatbot | Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed |
≤ 2.5.5 |
CVE-2025-12585 |
Wordfence | |
| 6.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action |
≤ 3.3.2 |
CVE-2025-13534 |
Wordfence | |
| 4.3 Medium | Beaver Builder – WordPress Page Builder | Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification |
≤ 2.9.4 |
CVE-2025-11726 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed |
≤ 1.12.20 |
CVE-2025-13140 |
Wordfence | |
| 6.5 Medium | Visualizer: Tables and Charts Manager | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 3.11.12 |
CVE-2025-12483 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute |
≤ 2.2.13 |
CVE-2025-13697 |
Wordfence | |
| 6.5 Medium | Arconix Shortcodes | Cross-Site Scripting |
≤ 2.1.20 |
CVE-2025-13835 |
Patchstack | |
| 6.5 Medium | AI Engine for WordPress: ChatGPT, GPT Content Generator | Path Traversal Authenticated (Contributor+) Arbitrary File Read |
≤ 1.0.1 |
CVE-2025-13380 |
Wordfence | |
| 4.3 Medium | Conditional Maintenance Mode | Cross-Site Request Forgery No login needed |
≤ 1.0.0 |
CVE-2025-12586 |
Wordfence | |
| 7.5 High | Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager | SQL Injection Multi-Purpose WordPress Advertising Manager <= 4.95 - Unauthenticated SQL Injection via site_id No login needed |
≤ 4.95 |
CVE-2025-7402 |
Wordfence | |
| 6.6 Medium | Easy Invoice | Local File Inclusion |
≤ 2.1.4 Fixed in 2.1.5 |
CVE-2025-66115 |
Patchstack | |
| 5.3 Medium | Show Variations as Single Products Woocommerce | Broken Access Control No login needed |
≤ 2.0 Fixed in 3.0 |
CVE-2025-66114 |
Patchstack | |
| 5.3 Medium | Better Chat Support for Messenger | Broken Access Control No login needed |
≤ 1.2.18 Fixed in 1.2.19 |
CVE-2025-66113 |
Patchstack | |
| 4.3 Medium | Accessibility Toolkit by WebYes | Broken Access Control |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2025-66112 |
Patchstack | |
| 6.5 Medium | Nelio Popups | Cross-Site Scripting |
≤ 1.3.0 Fixed in 1.3.1 |
CVE-2025-66111 |
Patchstack | |
| 5.3 Medium | Tiktok Feed | Broken Access Control No login needed |
≤ 1.0.23 Fixed in 1.0.24 |
CVE-2025-66110 |
Patchstack | |
| 5.3 Medium | Cart Weight for WooCommerce | Broken Access Control No login needed |
≤ 1.9.11 Fixed in 1.9.12 |
CVE-2025-66109 |
Patchstack | |
| 4.3 Medium | TNC Toolbox: Web Performance | Broken Access Control |
≤ 2.0.4 Fixed in 2.0.5 |
CVE-2025-66108 |
Patchstack | |
| 5.3 Medium | Subscriptions & Memberships for PayPal | Broken Access Control No login needed |
≤ 1.1.7 Fixed in 1.1.8 |
CVE-2025-66107 |
Patchstack | |
| 4.3 Medium | Featured Post Creative | Broken Access Control |
≤ 1.5.5 Fixed in 1.5.6 |
CVE-2025-66106 |
Patchstack | |
| 4.3 Medium | CBX Bookmark & Favorite | Broken Access Control |
≤ 2.0.1 Fixed in 2.0.2 |
CVE-2025-66101 |
Patchstack | |
| 5.3 Medium | Chat Help | Broken Access Control No login needed |
≤ 3.1.3 Fixed in 3.1.4 |
CVE-2025-66099 |
Patchstack | |
| 6.5 Medium | Travelers' Map | Cross-Site Scripting |
≤ 2.3.2 Fixed in 2.3.3 |
CVE-2025-66098 |
Patchstack | |
| 4.3 Medium | I Order Terms | Cross-Site Request Forgery No login needed |
≤ 1.5.0 Fixed in 1.5.1 |
CVE-2025-66097 |
Patchstack | |
| 4.3 Medium | Table Block by Tableberg | Broken Access Control |
≤ 0.6.9 Fixed in 0.6.10 |
CVE-2025-66096 |
Patchstack | |
| 8.5 High | KiviCare | SQL Injection |
≤ 3.6.13 Fixed in 3.6.14 |
CVE-2025-66095 |
Patchstack | |
| 6.5 Medium | Extensions for Leaflet Map | Cross-Site Scripting |
≤ 4.8 Fixed in 4.9 |
CVE-2025-66093 |
Patchstack | |
| 6.5 Medium | Accordion Slider | Cross-Site Scripting |
≤ 1.9.13 Fixed in 1.9.14 |
CVE-2025-66092 |
Patchstack | |
| 6.5 Medium | Stylish Cost Calculator | Cross-Site Scripting |
≤ 8.1.5 Fixed in 8.1.6 |
CVE-2025-66091 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.