WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,801–5,850 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 117 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.5 Fixed in 2.6 CVE-2025-66090 Patchstack
4.3 Medium Product Feed for WooCommerce Plugin webtoffee-product-feed Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-66089 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66087 Patchstack
5.3 Medium SMS Alert Order Notifications Plugin sms-alert Broken Access Control No login needed ≤ 3.8.8 Fixed in 3.8.9 CVE-2025-66086 Patchstack
4.3 Medium Arconix Shortcodes Plugin arconix-shortcodes Broken Access Control ≤ 2.1.18 Fixed in 2.1.19 CVE-2025-66085 Patchstack
4.3 Medium FluentCommunity Plugin fluent-community Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-66084 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66083 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66082 Patchstack
5.9 Medium Head Meta Data Plugin head-meta-data Cross-Site Scripting ≤ 20250327 Fixed in 20251118 CVE-2025-66081 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.2.0 Fixed in 2.3.0 CVE-2025-66079 Patchstack
5.3 Medium Legal Pages Plugin legal-pages Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-66077 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-66075 Patchstack
7.2 High WP Webhooks Plugin wp-webhooks PHP Object Injection ≤ 3.3.8 Fixed in 3.3.9 CVE-2025-66073 Patchstack
5.3 Medium UsersWP Plugin userswp Broken Access Control No login needed ≤ 1.2.47 Fixed in 1.2.48 CVE-2025-66072 Patchstack
5.3 Medium Custom Order Numbers for WooCommerce Plugin custom-order-numbers-for-woocommerce Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2025-66071 Patchstack
4.3 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control ≤ 33.0.16 Fixed in 33.0.17 CVE-2025-66069 Patchstack
6.5 Medium Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting ≤ 3.13.1.2 Fixed in 3.13.1.3 CVE-2025-66067 Patchstack
6.5 Medium Envo Extra Plugin envo-extra Cross-Site Scripting ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66066 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Broken Access Control ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-66065 Patchstack
4.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Request Forgery No login needed ≤ 1.12.20 Fixed in 1.12.21 CVE-2025-66064 Patchstack
5.4 Medium WP Google Review Slider Plugin wp-google-places-review-slider Broken Access Control ≤ 17.4 Fixed in 17.6 CVE-2025-66063 Patchstack
3.4 Low WP YouTube Lyte Plugin wp-youtube-lyte Open Redirect No login needed ≤ 1.7.28 Fixed in 1.7.29 CVE-2025-66062 Patchstack
4.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Request Forgery No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66061 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Broken Access Control No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66060 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Information Disclosure Sensitive Data Exposure No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66059 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.5.2 Fixed in 5.5.3 CVE-2025-66057 Patchstack
4.3 Medium Uncanny Automator Plugin uncanny-automator Information Disclosure Sensitive Data Exposure ≤ 6.10.0 Fixed in 6.10.0 CVE-2025-66056 Patchstack
7.2 High Email Subscribers & Newsletters Plugin email-subscribers PHP Object Injection ≤ 5.9.10 Fixed in 5.9.11 CVE-2025-66055 Patchstack
6.5 Medium Enfold Plugin enfold Cross-Site Scripting ≤ 7.1.2 Fixed in 7.1.3 CVE-2025-66053 Patchstack
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client' ≤ 3.2.9 CVE-2025-10039 Wordfence
6.4 Medium FluentCRM - Marketing Automation Plugin fluent-crm Cross-Site Scripting Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode ≤ 2.9.84 CVE-2025-12935 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Role Removal ≤ 3.3.1 CVE-2025-10054 Wordfence
9.8 Critical ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Arbitrary File Upload Unauthenticated Arbitrary File Upload No login needed ≤ 3.3.1 CVE-2025-11456 Wordfence
5.3 Medium Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure No login needed ≤ 2.14.17 CVE-2025-12894 Wordfence
6.4 Medium BrightTALK WordPress Shortcode Plugin brighttalk-wp-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2025-11770 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion ≤ 3.3.0 CVE-2025-12169 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Restore ≤ 3.3.1 CVE-2025-12022 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Empty ≤ 3.3.1 CVE-2025-12085 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Ticket Restore ≤ 3.3.1 CVE-2025-12023 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure No login needed ≤ 4.2.9.4 CVE-2025-11368 Wordfence
7.2 High WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer PHP Object Injection Ultimate CSV XML Importer for WordPress <= 7.33.1 - Authenticated (Administrator+) PHP Object Injection via CSV Import ≤ 7.33.1 CVE-2025-13145 Wordfence
4.3 Medium WSChat – WordPress Live Chat Plugin wschat-live-chat Broken Access Control WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 3.1.6 CVE-2025-12751 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions ≤ 1.12.0 CVE-2025-12377 Wordfence
5.3 Medium JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-64384 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64383 Patchstack
4.3 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-64382 Patchstack
6.5 Medium Booking Calendar Plugin booking Cross-Site Scripting ≤ 10.14.7 Fixed in 10.14.8 CVE-2025-64381 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting ≤ 7.3.2 Fixed in 7.4.0 CVE-2025-64380 Patchstack
4.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control ≤ 7.4.0 Fixed in 7.5.0 CVE-2025-64379 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only