WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,751–5,800 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 116 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium WP-SOS-Donate Donation Sidebar Plugin wp-sos-donate Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.9.2 CVE-2025-13625 Wordfence
4.3 Medium Quantic Social Image Hover Plugin tw-image-hover-share Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.8 CVE-2025-13360 Wordfence
6.4 Medium Sermon Manager Plugin sermon-manager-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.30.0 CVE-2025-12368 Wordfence
6.1 Medium dream gallery Plugin dream-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed ≤ 1.0 CVE-2025-13621 Wordfence
4.3 Medium Webcake – Landing Page Builder Plugin webcake Broken Access Control Landing Page Builder <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.1 CVE-2025-12165 Wordfence
6.1 Medium CoSign Single Signon Plugin cosign-sso Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.3.1 CVE-2025-13512 Wordfence
6.4 Medium Omnipress Plugin omnipress Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.6.5 CVE-2025-12163 Wordfence
4.3 Medium ContentStudio Plugin contentstudio Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.3.7 CVE-2025-13144 Wordfence
4.4 Medium FitVids Plugin fitvids-for-wordpress Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.0.1 CVE-2025-12124 Wordfence
5.3 Medium CRM Memberships Plugin crm-memberships Broken Access Control Missing Authorization to Unauthenticated 'ntzcrm_add_new_tag' AJAX Action No login needed ≤ 2.5 CVE-2025-13312 Wordfence
5.3 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed ≤ 1.1.5 CVE-2025-13006 Wordfence
5.3 Medium SSP Debug Plugin ssp-debugging Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 1.0.0 CVE-2025-13494 Wordfence
4.3 Medium Norby AI Plugin norby-ai Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.3 CVE-2025-13362 Wordfence
6.4 Medium SurveyFunnel – Survey Plugin surveyfunnel-lite Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.5 CVE-2025-12417 Wordfence
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode ≤ 10.14.6 CVE-2025-12804 Wordfence
4.3 Medium Backup, Restore and Migrate your sites with XCloner Plugin xcloner-backup-and-restore Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed ≤ 4.8.2 CVE-2025-11759 Wordfence
4.8 Medium Custom Post Type UI Plugin custom-post-type-ui Broken Access Control Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification No login needed ≤ 1.18.0 CVE-2025-12826 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering ≤ 2.9.4 CVE-2025-12782 Wordfence
6.1 Medium Clik stats Plugin clikstats Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed ≤ 0.8 CVE-2025-13513 Wordfence
5.3 Medium WebP Express Plugin webp-express Information Disclosure Unauthenticated Information Exposure No login needed ≤ 0.25.9 CVE-2025-11379 Wordfence
4.3 Medium Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution Plugin fluent-booking Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management ≤ 1.9.11 CVE-2025-13756 Wordfence
6.5 Medium Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Plugin SQL Injection AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection ≤ 3.40.1 CVE-2025-13359 Wordfence
6.4 Medium Autoptimize Plugin autoptimize Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.13 CVE-2025-13401 Wordfence
4.3 Medium Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Plugin Broken Access Control AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation ≤ 3.40.1 CVE-2025-13354 Wordfence
4.3 Medium HUSKY – Products Filter Professional for WooCommerce Plugin Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' ≤ 1.3.7.2 CVE-2025-13109 Wordfence
4.3 Medium ShopEngine Plugin shopengine Cross-Site Request Forgery Cross-Site Request Forgery to Wishlist Manipulation No login needed ≤ 4.8.5 CVE-2025-12358 Wordfence
5.4 Medium Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App Plugin Broken Access Control Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update ≤ 3.6.1 CVE-2025-12887 Wordfence
5.3 Medium Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed ≤ 2.3.8 CVE-2025-10304 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed ≤ 2.5.5 CVE-2025-12585 Wordfence
4.9 Medium FluentCart A New Era of eCommerce Plugin fluent-cart SQL Injection Authenticated (Administrator+) SQL Injection via 'groupKey' Parameter ≤ 1.3.1 CVE-2025-13495 Wordfence
6.4 Medium CSSIgniter Shortcodes Plugin cssigniter-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute ≤ 2.4.1 CVE-2025-13448 Wordfence
4.9 Medium Upload.am File Hosting VPN Plugin Information Disclosure Contributor+ Arbitrary Option Disclosure < 1.0.1 Fixed in 1.0.1 CVE-2025-12630 WPScan
6.4 Medium Nexter Extension Plugin nexter-extension Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.1 CVE-2025-13731 Wordfence
4.9 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.4.6 CVE-2025-13090 Wordfence
6.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action ≤ 3.3.2 CVE-2025-13534 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification ≤ 2.9.4 CVE-2025-11726 Wordfence
5.3 Medium Zigaform Plugin zigaform-calculator-cost-estimation-form-builder-lite Information Disclosure Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint No login needed ≤ 7.6.5 CVE-2025-13696 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
6.5 Medium Visualizer: Tables and Charts Manager Plugin visualizer SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.11.12 CVE-2025-12483 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.1 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Cross-Site Scripting Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import No login needed ≤ 3.20.3 CVE-2025-13007 Wordfence
4.1 Medium Donation Plugin SQL Injection Admin+ SQLi ≤ 1.0 CVE-2025-13001 WPScan
6.5 Medium Export All Posts, Products, Orders, Refunds & Users Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed ≤ 2.19 CVE-2025-13606 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute ≤ 2.2.13 CVE-2025-13697 Wordfence
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.20 CVE-2025-13835 Patchstack
4.3 Medium Nextend Social Login and Register Plugin nextend-facebook-connect Cross-Site Request Forgery Cross-Site Request Forgery to Unlink User Social Login No login needed ≤ 3.1.21 CVE-2025-13737 Wordfence
4.3 Medium Folders Plugin folders Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation ≤ 3.1.5 CVE-2025-12971 Wordfence
4.3 Medium WP Fastest Cache Plugin wp-fastest-cache Broken Access Control Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions ≤ 1.4.0 CVE-2025-10476 Wordfence
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control Missing Authorization to Unauthenticated Media File Uploads No login needed ≤ 2.7.0 CVE-2025-13381 Wordfence
5.3 Medium Quick View for WooCommerce Plugin woo-quickview Information Disclosure Unauthenticated Private Product Disclosure No login needed ≤ 2.2.17 CVE-2025-12584 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only