WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,801–5,850 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 117 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High GNUCommerce Plugin gnucommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.5.4 CVE-2025-26564 Patchstack
7.1 High WP Contact Form III Plugin wp-contact-form-iii Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.2d CVE-2025-26560 Patchstack
7.1 High Cookies Pro Plugin cookies-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-26546 Patchstack
7.1 High UTM tags tracking for Contact Form 7 Plugin cf7-utm-tracking Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-26544 Patchstack
7.1 High Zalo Live Chat Plugin zalo-live-chat Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.0 CVE-2025-26542 Patchstack
7.1 High Bitcoin / AltCoin Payment Gateway for WooCommerce Plugin woo-altcoin-payment-gateway Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 CVE-2025-26541 Patchstack
7.1 High Another Events Calendar Plugin another-events-calendar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.0 CVE-2025-26536 Patchstack
7.1 High Theme Demo Bar Plugin wordpress-theme-demo-bar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-25134 Patchstack
8.1 High Formality Plugin formality Local File Inclusion No login needed ≤ 1.5.7 Fixed in 1.5.8 CVE-2025-24690 Patchstack
7.1 High Google Plus Plugin google-plus-google Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.2 CVE-2025-23964 Patchstack
8.1 High custom-field-list-widget Plugin custom-field-list-widget Local File Inclusion No login needed ≤ 1.5.1 CVE-2025-23952 Patchstack
8.1 High LinkedIn Lite Plugin linkedin-lite Local File Inclusion No login needed ≤ 1.0 CVE-2025-23937 Patchstack
7.1 High Infugrator Plugin infugrator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.3 CVE-2025-23735 Patchstack
7.1 High AuMenu Plugin aumenu Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.5 CVE-2025-23728 Patchstack
7.1 High AppReview Plugin appreview Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.2.9 CVE-2025-23714 Patchstack
7.1 High Your Lightbox Plugin your-lightbox Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23704 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
7.1 High Management-screen-droptiles Plugin cxc-sawa Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23666 Patchstack
7.1 High Frontend Post Submission Plugin frontend-post-submission Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23638 Patchstack
7.1 High WP Database Audit Plugin database-audit Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23633 Patchstack
7.1 High CG Button Plugin content-glass-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.5.6 CVE-2025-23632 Patchstack
7.1 High Pixobe Cartography Plugin pixobe-cartography Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23612 Patchstack
7.1 High RDP inGroups+ Plugin rdp-ingroups Cross-Site Scripting No login needed ≤ 1.0.6 CVE-2025-23546 Patchstack
7.1 High FOMO Pay Chinese Payment Solution Plugin fomo-payment-gateway-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.4 CVE-2025-23543 Patchstack
7.1 High RDP Linkedin Login Plugin rdp-linkedin-login Cross-Site Scripting No login needed ≤ 1.7.0 CVE-2025-23542 Patchstack
7.1 High Site Editor Google Map Plugin site-editor-google-map Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23466 Patchstack
7.1 High RWS Enquiry And Lead Follow-up Plugin rws-enquiry Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23460 Patchstack
7.1 High NS Simple Intro Loader Plugin ns-simple-intro-loader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.3 CVE-2025-23459 Patchstack
7.1 High GetSocial Plugin getsocial Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-22283 Patchstack
7.2 High Product Import Export for WooCommerce Plugin product-import-export-for-woo PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.5.0 CVE-2025-1913 Wordfence
7.6 High Product Import Export for WooCommerce Plugin product-import-export-for-woo Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.5.0 CVE-2025-1912 Wordfence
7.2 High WordPress Importer Plugin wordpress-importer PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 0.8.3 CVE-2024-13889 Wordfence
8.8 High WP Compress Plugin wp-compress-image-optimizer Broken Access Control Authenticated (Subscriber+) Missing Authorization via Multiple Functions ≤ 6.30.15 CVE-2025-2110 Wordfence
7.3 High Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Broken Access Control Unauthenticated Arbitrary Filter Call No login needed ≤ 1.0.6.7 CVE-2025-1514 Wordfence
8.1 High BWL Advanced FAQ Manager Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update ≤ 2.1.4 CVE-2024-13801 Wordfence
7.2 High Newsletters Plugin newsletters-lite Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.9.9.7 CVE-2025-2009 Wordfence
7.2 High Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid Plugin boldgrid-backup Remote Code Execution WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command Injection ≤ 1.16.10 CVE-2025-2257 Wordfence
8.8 High Booknetic Plugin Cross-Site Request Forgery Staff Creation via CSRF No login needed < 4.1.5 Fixed in 4.1.5 CVE-2024-13146 WPScan
7.5 High WP01 Plugin wp01 Path Traversal Arbitrary File Download No login needed ≤ 2.6.2 CVE-2025-30567 Patchstack
8.8 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed 4.11.13 – 5.25.08 CVE-2025-2319 Wordfence
7.2 High WP Church Donation Plugin wp-church-donation Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.7 CVE-2024-13690 Wordfence
7.1 High Stylish Google Sheet Reader Plugin stylish-google-sheet-reader Cross-Site Scripting Reflected XSS No login needed < 4.1 Fixed in 4.1 CVE-2024-13863 WPScan
7.2 High Downloable by American Osteopathic Association Plugin Server-Side Request Forgery Unauthenticated SSRF No login needed ≤ 0.1.0 CVE-2024-13618 WPScan
8.6 High Downloable by American Osteopathic Association Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 0.1.0 CVE-2024-13617 WPScan
7.1 High Translator Plugin translator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3 CVE-2025-30621 Patchstack
7.1 High WP Odoo Form Integrator Plugin wp-odoo-form-integrator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30620 Patchstack
7.1 High Replace Default Words Plugin replace-default-words Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.3 CVE-2025-30612 Patchstack
7.1 High WordPress SQL Backup Plugin wordpress-sql-backup Cross-Site Request Forgery No login needed ≤ 3.5.2 CVE-2025-30608 Patchstack
7.6 High JiangQie Official Website Mini Program Plugin jiangqie-official-website-mini-program SQL Injection ≤ 1.8.2 CVE-2025-30604 Patchstack
7.1 High CopyLink Plugin copy-link Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-30603 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only