WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.
Showing 5,751–5,800 of 17,767 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.1 Medium | WP-SOS-Donate Donation Sidebar | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 0.9.2 |
CVE-2025-13625 |
Wordfence | |
| 4.3 Medium | Quantic Social Image Hover | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.8 |
CVE-2025-13360 |
Wordfence | |
| 6.4 Medium | Sermon Manager | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.30.0 |
CVE-2025-12368 |
Wordfence | |
| 6.1 Medium | dream gallery | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed |
≤ 1.0 |
CVE-2025-13621 |
Wordfence | |
| 4.3 Medium | Webcake – Landing Page Builder | Broken Access Control Landing Page Builder <= 1.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.1 |
CVE-2025-12165 |
Wordfence | |
| 6.1 Medium | CoSign Single Signon | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 0.3.1 |
CVE-2025-13512 |
Wordfence | |
| 6.4 Medium | Omnipress | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 1.6.5 |
CVE-2025-12163 |
Wordfence | |
| 4.3 Medium | ContentStudio | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.3.7 |
CVE-2025-13144 |
Wordfence | |
| 4.4 Medium | FitVids | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 4.0.1 |
CVE-2025-12124 |
Wordfence | |
| 5.3 Medium | CRM Memberships | Broken Access Control Missing Authorization to Unauthenticated 'ntzcrm_add_new_tag' AJAX Action No login needed |
≤ 2.5 |
CVE-2025-13312 |
Wordfence | |
| 5.3 Medium | SurveyFunnel – Survey | Information Disclosure Survey Plugin for WordPress <= 1.1.5 - Unauthenticated Information Exposure No login needed |
≤ 1.1.5 |
CVE-2025-13006 |
Wordfence | |
| 5.3 Medium | SSP Debug | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.0.0 |
CVE-2025-13494 |
Wordfence | |
| 4.3 Medium | Norby AI | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.3 |
CVE-2025-13362 |
Wordfence | |
| 6.4 Medium | SurveyFunnel – Survey | Cross-Site Scripting Survey Plugin for WordPress <= 1.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.1.5 |
CVE-2025-12417 |
Wordfence | |
| 6.4 Medium | Booking Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via bookingcalendar Shortcode |
≤ 10.14.6 |
CVE-2025-12804 |
Wordfence | |
| 4.3 Medium | Backup, Restore and Migrate your sites with XCloner | Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed |
≤ 4.8.2 |
CVE-2025-11759 |
Wordfence | |
| 4.8 Medium | Custom Post Type UI | Broken Access Control Missing Authorization to Unauthenticated (Previously Administrator+) Custom Post Type Modification No login needed |
≤ 1.18.0 |
CVE-2025-12826 |
Wordfence | |
| 4.3 Medium | Beaver Builder – WordPress Page Builder | Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Builder Status Tampering |
≤ 2.9.4 |
CVE-2025-12782 |
Wordfence | |
| 6.1 Medium | Clik stats | Cross-Site Scripting Reflected Cross-Site Scripting via $_SERVER['PHP_SELF'] No login needed |
≤ 0.8 |
CVE-2025-13513 |
Wordfence | |
| 5.3 Medium | WebP Express | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 0.25.9 |
CVE-2025-11379 |
Wordfence | |
| 4.3 Medium | Fluent Booking – The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution | Broken Access Control The Ultimate Appointments Scheduling, Events Booking, Events Calendar Solution <= 1.9.11 - Authenticated (Subscriber+) Missing Authorization to Calendar Import and Management |
≤ 1.9.11 |
CVE-2025-13756 |
Wordfence | |
| 6.5 Medium | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | SQL Injection AI Autotagger with OpenAI <= 3.40.1 - Authenticated (Contributor+) SQL Injection |
≤ 3.40.1 |
CVE-2025-13359 |
Wordfence | |
| 6.4 Medium | Autoptimize | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.1.13 |
CVE-2025-13401 |
Wordfence | |
| 4.3 Medium | Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI | Broken Access Control AI Autotagger with OpenAI <= 3.40.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Taxonomy Term Manipulation |
≤ 3.40.1 |
CVE-2025-13354 |
Wordfence | |
| 4.3 Medium | HUSKY – Products Filter Professional for WooCommerce | Broken Access Control Products Filter Professional for WooCommerce <= 1.3.7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'woof_add_query/woof_remove_query' |
≤ 1.3.7.2 |
CVE-2025-13109 |
Wordfence | |
| 4.3 Medium | ShopEngine | Cross-Site Request Forgery Cross-Site Request Forgery to Wishlist Manipulation No login needed |
≤ 4.8.5 |
CVE-2025-12358 |
Wordfence | |
| 5.4 Medium | Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App | Broken Access Control Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App <= 3.6.1 - Missing Authorization to Authenticated (Subscriber+) OAuth Token Update |
≤ 3.6.1 |
CVE-2025-12887 |
Wordfence | |
| 5.3 Medium | Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning | Broken Access Control WordPress Cloud Backup, Migration, Restore & Cloning Plugin <= 2.3.8 - Missing Authorization to Unauthenticated Backup Failure No login needed |
≤ 2.3.8 |
CVE-2025-10304 |
Wordfence | |
| 5.3 Medium | MxChat – AI Chatbot | Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed |
≤ 2.5.5 |
CVE-2025-12585 |
Wordfence | |
| 4.9 Medium | FluentCart A New Era of eCommerce | SQL Injection Authenticated (Administrator+) SQL Injection via 'groupKey' Parameter |
≤ 1.3.1 |
CVE-2025-13495 |
Wordfence | |
| 6.4 Medium | CSSIgniter Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute |
≤ 2.4.1 |
CVE-2025-13448 |
Wordfence | |
| 4.9 Medium | Upload.am File Hosting VPN | Information Disclosure Contributor+ Arbitrary Option Disclosure |
< 1.0.1 Fixed in 1.0.1 |
CVE-2025-12630 |
WPScan | |
| 6.4 Medium | Nexter Extension | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 4.4.1 |
CVE-2025-13731 |
Wordfence | |
| 4.9 Medium | WP Directory Kit | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 1.4.6 |
CVE-2025-13090 |
Wordfence | |
| 6.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action |
≤ 3.3.2 |
CVE-2025-13534 |
Wordfence | |
| 4.3 Medium | Beaver Builder – WordPress Page Builder | Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification |
≤ 2.9.4 |
CVE-2025-11726 |
Wordfence | |
| 5.3 Medium | Zigaform | Information Disclosure Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint No login needed |
≤ 7.6.5 |
CVE-2025-13696 |
Wordfence | |
| 4.3 Medium | SurveyJS: Drag & Drop WordPress Form Builder | Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed |
≤ 1.12.20 |
CVE-2025-13140 |
Wordfence | |
| 6.5 Medium | Visualizer: Tables and Charts Manager | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 3.11.12 |
CVE-2025-12483 |
Wordfence | |
| 4.3 Medium | Photo Gallery by Ays | Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed |
≤ 6.4.8 |
CVE-2025-13685 |
Wordfence | |
| 6.1 Medium | WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets | Cross-Site Scripting Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import No login needed |
≤ 3.20.3 |
CVE-2025-13007 |
Wordfence | |
| 4.1 Medium | Donation | SQL Injection Admin+ SQLi |
≤ 1.0 |
CVE-2025-13001 |
WPScan | |
| 6.5 Medium | Export All Posts, Products, Orders, Refunds & Users | Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed |
≤ 2.19 |
CVE-2025-13606 |
Wordfence | |
| 6.4 Medium | BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library | Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute |
≤ 2.2.13 |
CVE-2025-13697 |
Wordfence | |
| 6.5 Medium | Arconix Shortcodes | Cross-Site Scripting |
≤ 2.1.20 |
CVE-2025-13835 |
Patchstack | |
| 4.3 Medium | Nextend Social Login and Register | Cross-Site Request Forgery Cross-Site Request Forgery to Unlink User Social Login No login needed |
≤ 3.1.21 |
CVE-2025-13737 |
Wordfence | |
| 4.3 Medium | Folders | Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation |
≤ 3.1.5 |
CVE-2025-12971 |
Wordfence | |
| 4.3 Medium | WP Fastest Cache | Broken Access Control Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions |
≤ 1.4.0 |
CVE-2025-10476 |
Wordfence | |
| 5.3 Medium | AI ChatBot with ChatGPT and Content Generator by AYS | Broken Access Control Missing Authorization to Unauthenticated Media File Uploads No login needed |
≤ 2.7.0 |
CVE-2025-13381 |
Wordfence | |
| 5.3 Medium | Quick View for WooCommerce | Information Disclosure Unauthenticated Private Product Disclosure No login needed |
≤ 2.2.17 |
CVE-2025-12584 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.