WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 5,801–5,850 of 17,767 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 117 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed ≤ 2.7.0 CVE-2025-13378 Wordfence
5.3 Medium QODE Wishlist for WooCommerce Plugin qode-wishlist-for-woocommerce Broken Access Control Unauthenticated Insecure Direct Object Reference to Wishlist Update No login needed ≤ 1.2.7 CVE-2025-13157 Wordfence
5.3 Medium Hide Category by User Role for WooCommerce Plugin hide-category-by-user-role-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Cache Flushing No login needed ≤ 2.3.1 CVE-2025-13441 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence
6.1 Medium WP Directory Kit Plugin wpdirectorykit Cross-Site Scripting Reflected Cross-Site Scripting via 'order_by' Parameter No login needed ≤ 1.4.5 CVE-2025-13525 Wordfence
4.4 Medium StaffList Plugin stafflist Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.2.6 CVE-2025-12185 Wordfence
6.1 Medium Customer Reviews Collector for WooCommerce Plugin customer-reviews-collector-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.6.1 CVE-2025-12123 Wordfence
6.4 Medium Simple Folio Plugin simple-folio Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2025-12151 Wordfence
6.4 Medium Soundslides Plugin soundslides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundslides Shortcode ≤ 1.4.2 CVE-2025-12713 Wordfence
6.4 Medium wp-twitpic Plugin wp-twitpic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-12670 Wordfence
6.4 Medium SortTable Post Plugin sorttable-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.2 CVE-2025-12649 Wordfence
6.4 Medium Shouty Plugin shouty Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shouty Shortcode Attributes ≤ 0.2.1 CVE-2025-12712 Wordfence
5.3 Medium Reuters Direct Plugin reuters-direct Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 3.0.0 CVE-2025-12579 Wordfence
6.4 Medium Google Drive upload and download link Plugin google-drive-upload-and-download-link Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-12666 Wordfence
4.3 Medium Reuters Direct Plugin reuters-direct Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 3.0.0 CVE-2025-12578 Wordfence
6.1 Medium Houzez Theme Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 4.1.6 CVE-2025-9163 Wordfence
6.3 Medium Houzez Theme PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via Saved Search ≤ 4.1.6 CVE-2025-9191 Wordfence
4.9 Medium Bookme Plugin bookme-free-appointment-booking-system SQL Injection Authenticated (Admin+) SQL Injection via 'filter[status]' Parameter ≤ 4.2 CVE-2025-13385 Wordfence
4.3 Medium Refund Request for WooCommerce Plugin refund-request-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Refund Status Update ≤ 1.0 CVE-2025-12634 Wordfence
4.3 Medium Peer Publish Plugin peer-publish Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-12587 Wordfence
4.9 Medium ProjectList Plugin projectlist SQL Injection Authenticated (Editor+) SQL Injection via 'id' Parameter ≤ 0.3.0 CVE-2025-13370 Wordfence
4.4 Medium Just Highlight Plugin just-highlight Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Highlight Color' Setting ≤ 1.0.3 CVE-2025-13311 Wordfence
5.3 Medium Ace Post Type Builder Plugin ace-post-type-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Custom Taxonomy Deletion via 'taxonomy' Parameter No login needed ≤ 1.9 CVE-2025-13405 Wordfence
6.4 Medium Inline frame – Iframe Plugin inline-frame-iframe Cross-Site Scripting Iframe <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.1 CVE-2025-12645 Wordfence
4.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming ≤ 23.4 CVE-2025-13382 Wordfence
6.5 Medium AI Engine for WordPress: ChatGPT, GPT Content Generator Plugin liquid-chatgpt Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.0.1 CVE-2025-13380 Wordfence
5.3 Medium atec Duplicate Page & Post Plugin atec-duplicate-page-post Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication and Data Exposure No login needed ≤ 1.2.20 CVE-2025-13404 Wordfence
4.4 Medium YouTube Subscribe Plugin easy-youtube-subscribe Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Title and Channel ID ≤ 3.0.0 CVE-2025-12025 Wordfence
5.3 Medium Social Images Widget Plugin social-images-widget Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 2.1 CVE-2025-13386 Wordfence
5.3 Medium Locker Content Plugin locker-content Information Disclosure Unauthenticated Information Exposure No login needed ≤ 1.0.0 CVE-2025-12525 Wordfence
5.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 14 CVE-2025-13389 Wordfence
6.5 Medium Wishlist for WooCommerce Plugin th-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 1.1.3 CVE-2025-12040 Wordfence
4.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages ≤ 14 CVE-2025-13452 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
5.3 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control Missing Authorization to Unauthenticated Business Information Export No login needed ≤ 3.3.11 CVE-2025-13414 Wordfence
6.1 Medium Job Board by BestWebSoft Plugin job-board Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage No login needed ≤ 1.2.1 CVE-2025-13383 Wordfence
4.4 Medium ZWeb - Social Mobile Plugin zweb-social-mobile Cross-Site Scripting Social Mobile <= 1.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-12032 Wordfence
5.3 Medium Autochat Automatic Conversation Plugin auyautochat-for-wp Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.1.9 CVE-2025-12043 Wordfence
5.4 Medium Blog2Social Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing ≤ 8.7.0 CVE-2025-13558 Wordfence
4.3 Medium Search Exclude Plugin search-exclude Broken Access Control Missing Authorization to Authenticated (Contributor+) Search Settings Modification via REST API ≤ 2.5.7 CVE-2025-10646 Wordfence
6.5 Medium Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.6.2 CVE-2025-10144 Wordfence
6.3 Medium WP 2FA Plugin wp-2fa Other Second Factor Bypass < 3.0.0 Fixed in 3.0.0 CVE-2025-12628 WPScan
4.7 Medium WP Front User Submit Plugin Open Redirect No login needed < 5.0.0 Fixed in 5.0.0 CVE-2025-12569 WPScan
5.9 Medium Backup Migration Plugin backup-backup Information Disclosure Unauthenticated Backup Download No login needed < 2.0.0 Fixed in 2.0.0 CVE-2025-12394 WPScan
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.4.5 CVE-2025-12800 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter No login needed ≤ 1.2.60 CVE-2025-13318 Wordfence
4.3 Medium GSheetConnector For Ninja Forms Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) System Information Exposure ≤ 2.0.1 CVE-2025-13136 Wordfence
5.3 Medium IDonate – Blood Donation, Request And Donor Management System Plugin idonate Broken Access Control Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 2.1.14 CVE-2025-12877 Wordfence
5.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Other Unauthenticated Fake Payment Creation No login needed ≤ 1.1.7 CVE-2025-12752 Wordfence
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter No login needed ≤ 1.3.96 CVE-2025-13317 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only