WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,851–5,900 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 118 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Related Posts via Categories Plugin related-posts-via-categories Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.2 CVE-2025-30602 Patchstack
8.5 High Flickr set slideshows Plugin flickr-set-slideshows SQL Injection ≤ 0.9 CVE-2025-30590 Patchstack
7.1 High Map Contact Plugin map-contact Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0.4 CVE-2025-30588 Patchstack
7.1 High LH OGP Meta Plugin lh-ogp-meta-tags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.73 CVE-2025-30587 Patchstack
7.1 High cTabs Plugin ctabs Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-30586 Patchstack
7.1 High AlphaOmega Captcha & Anti-Spam Filter Plugin alphaomega-captcha-anti-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3 CVE-2025-30584 Patchstack
7.1 High Pro Rank Tracker Plugin proranktracker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30583 Patchstack
7.1 High AdSense Privacy Policy Plugin adsense-privacy-policy Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30578 Patchstack
7.1 High Browser Address Bar Color Plugin browser-address-bar-color Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.3 Fixed in 3.4 CVE-2025-30577 Patchstack
7.1 High Simple Rating Plugin simple-rating Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-30572 Patchstack
7.6 High STEdb Forms Plugin stedb-forms SQL Injection ≤ 1.0.4 CVE-2025-30571 Patchstack
7.6 High دکمه، شبکه اجتماعی خرید Plugin dokme SQL Injection ≤ 2.0.6 CVE-2025-30570 Patchstack
8.5 High WP Featured Entries Plugin wp-featured-entries SQL Injection WordPress WP Featured Entries plugin <= - 1.0 SQL Injection ≤ 1.0 CVE-2025-30569 Patchstack
7.1 High banner-manager Plugin banner-manager Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 16.04.19 CVE-2025-30565 Patchstack
7.1 High Custom Script Integration Plugin custom-script-integration Cross-Site Request Forgery WordPress Custom Script Integration plugin <= - 2.1 Cross Site Request Forgery (CSRF) No login needed ≤ 2.1 CVE-2025-30564 Patchstack
7.1 High CAS Maestro Plugin cas-maestro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.3 CVE-2025-30561 Patchstack
7.1 High jQuery Dropdown Menu Plugin jquery-drop-down-menu-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 CVE-2025-30560 Patchstack
7.1 High ANAC XML Render Plugin anac-xml-render Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5.7 CVE-2025-30558 Patchstack
7.1 High WordPres 同步微博 Plugin wp2wb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.0 CVE-2025-30555 Patchstack
7.1 High WordPress Admin Bar Improved Plugin wordpress-admin-bar-improved Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.3.5 CVE-2025-30552 Patchstack
7.1 High CallPhone'r Plugin callphoner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-30550 Patchstack
7.6 High WP Profitshare Plugin wp-profitshare SQL Injection ≤ 1.4.9 CVE-2025-30525 Patchstack
7.6 High Super Simple Subscriptions Plugin super-simple-subscriptions SQL Injection ≤ 1.1.0 CVE-2025-30523 Patchstack
7.1 High Contact Form 7 Material Design Plugin cf7-material-design Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.0 CVE-2025-30522 Patchstack
7.5 High Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation By FunnelKit Plugin wp-marketing-automations SQL Injection Unauthenticated SQL Injection via 'automationId' No login needed ≤ 3.5.1 CVE-2025-2186 Wordfence
7.6 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.2 CVE-2025-1970 Wordfence
7.2 High Export and Import Users and Customers Plugin users-customers-import-export-for-wp-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.2 CVE-2025-1971 Wordfence
8.8 High Block Logic Plugin block-logic Remote Code Execution Authenticated (Contributor+) Remote Code Execution ≤ 1.0.8 CVE-2025-2303 Wordfence
8.8 High ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities PHP Object Injection User Profiles, Groups and Communities <= 5.9.4.5 - Authenticated (Subscriber+) PHP Object Injection ≤ 5.9.4.5 CVE-2025-0724 Wordfence
7.2 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce PHP Object Injection Authenticated (Admin+) PHP Object Injection via form_data Parameter ≤ 2.6.0 CVE-2024-13921 Wordfence
7.5 High File Away Plugin file-away Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read No login needed ≤ 3.9.9.0.1 CVE-2025-2539 Wordfence
7.5 High NP Quote Request for WooCommerce Plugin woo-rfq-for-woocommerce Broken Access Control Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure No login needed ≤ 1.9.179 CVE-2024-13558 Wordfence
7.6 High Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery via validate_file Function ≤ 2.6.0 CVE-2024-13923 Wordfence
7.1 High LinkMyPosts Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13881 WPScan
7.1 High My Quota Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.8 CVE-2024-13880 WPScan
7.1 High SpotBot Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.1.8 CVE-2024-13878 WPScan
7.1 High Passbeemedia Web Push Notifications Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13877 WPScan
7.1 High Meintopf Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.2.1 CVE-2024-13876 WPScan
7.1 High WP Programmmanager Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.2 CVE-2024-13875 WPScan
8.8 High Event Manager, Events Calendar, Tickets, Registrations – Eventin Plugin wp-event-solution Local File Inclusion Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion ≤ 4.0.24 CVE-2025-1770 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Broken Access Control Missing Authorization in Multiple Functions ≤ 4.7 CVE-2024-12920 Wordfence
8.8 High FoodBakery | Delivery Restaurant Directory Theme Cross-Site Request Forgery Cross-Site Request Forgery in Multiple Functions No login needed ≤ 4.7 CVE-2024-13933 Wordfence
7.5 High CozyStay Theme Broken Access Control Missing Authorization to Arbitrary Action Execution in ajax_handler No login needed ≤ 1.7.0 CVE-2024-13412 Wordfence
8.8 High Site Reviews Plugin site-reviews Cross-Site Scripting Unauthenticated Stored XSS No login needed < 7.2.5 Fixed in 7.2.5 CVE-2025-1232 WPScan
8.8 High BoomBox Theme Extensions Plugin Privilege Escalation Authenticated (Subscriber+) Privilege Escalation via Password Reset/Account Takeover in boombox_ajax_reset_password ≤ 1.8.0 CVE-2024-12295 Wordfence
8.8 High s2Member Pro Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion to Remote Code Execution via Shortcode ≤ 250214 CVE-2024-12563 Wordfence
7.3 High Logo Slider Plugin gs-logo-slider Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.7.3 CVE-2025-2262 Wordfence
8.5 High All In Menu Plugin all-in-menu SQL Injection ≤ 1.1.5 CVE-2025-27281 Patchstack
8.5 High FS Poster Plugin fs-poster SQL Injection ≤ 6.5.8 Fixed in 6.5.9 CVE-2025-26978 Patchstack
8.5 High PrivateContent Plugin private-content SQL Injection ≤ 8.11.4 CVE-2025-26976 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only