WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,901–5,950 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 119 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High PrivateContent Plugin private-content Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 8.11.5 CVE-2025-26972 Patchstack
8.3 High PrivateContent Plugin private-content Broken Access Control Subscriber+ Site Wide Broken Access Control ≤ 8.11.5 CVE-2025-26969 Patchstack
8.6 High Fresh Framework Plugin fresh-framework Broken Access Control Unauthenticated Broken Access Control No login needed ≤ 1.70.0 CVE-2025-26961 Patchstack
8.8 High Booking and Rental Manager Plugin booking-and-rental-manager-for-woocommerce PHP Object Injection ≤ 2.2.6 Fixed in 2.2.7 CVE-2025-26921 Patchstack
7.6 High PublishPress Authors Plugin publishpress-authors SQL Injection ≤ 4.7.3 Fixed in 4.7.4 CVE-2025-26886 Patchstack
7.1 High WP AntiDDOS Plugin wpantiddos Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-26556 Patchstack
7.1 High Debug-Bar-Extender Plugin debug-bar-extender Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.5 CVE-2025-26555 Patchstack
7.1 High WP Discord Post Plugin wp-discord-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.0 CVE-2025-26554 Patchstack
7.1 High Pre Order Addon for WooCommerce – Advance Order/Backorder Plugin wc-pre-order Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-26553 Patchstack
7.1 High Random Image Selector Plugin random-image-selector Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.4 CVE-2025-26548 Patchstack
7.1 High Random Posts, Mp3 Player + ShareButton Plugin random-posts-mp3-player-sharebutton Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23744 Patchstack
7.2 High WP Test Email Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2025-2325 Wordfence
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
8.8 High School Management System – WPSchoolPress Plugin wpschoolpress Broken Access Control WPSchoolPress <= 2.2.16 - Missing Authorization to Privilege Escalation via Account Takeover ≤ 2.2.16 CVE-2025-1667 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Privilege Escalation uListing <= 2.2.0 - Authenticated (Subscriber+) Privilege Escalation ≤ 2.2.0 CVE-2025-1653 Wordfence
8.8 High Directory Listings WordPress plugin – uListing Plugin ulisting Broken Access Control uListing <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Update and PHP Object Injection ≤ 2.2.0 CVE-2025-1657 Wordfence
7.3 High Civi - Job Board & Freelance Marketplace Theme Information Disclosure Job Board & Freelance Marketplace WordPress Theme <= 2.1.4 - Sensitive Information Exposure No login needed ≤ 2.1.4 CVE-2024-13773 Wordfence
8.8 High JobCareer | Job Board Responsive Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Multiple Administrative Actions ≤ 7.1 CVE-2024-12810 Wordfence
7.5 High AnalyticsWP Plugin SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.0.0 CVE-2024-13321 Wordfence
7.5 High WPCOM Member Plugin wpcom-member SQL Injection Unauthenticated Time-Based SQL Injection No login needed ≤ 1.7.6 CVE-2025-2221 Wordfence
8.8 High SoundRise Music Plugin Broken Access Control Authenticated (Subscriber+) Arbitrary Options Update ≤ 1.6.11 CVE-2025-2103 Wordfence
8.8 High InstaWP Connect – 1-click WP Staging & Migration Plugin instawp-connect Cross-Site Request Forgery Cross-Site Request Forgery to Local File Inclusion No login needed ≤ 0.1.0.83 CVE-2024-13913 Wordfence
8.1 High Eco Nature - Environment & Ecology Theme Broken Access Control Environment & Ecology WordPress Theme <= 2.0.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update ≤ 2.0.4 CVE-2025-0952 Wordfence
8.8 High Industrial Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 1.7.8 CVE-2024-13376 Wordfence
7.5 High LoginPress Plugin loginpress Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Options Update No login needed ≤ 3.3.1 CVE-2025-1764 Wordfence
7.5 High WP Ghost Plugin hide-my-wp Path Traversal Unauthenticated Limited File Read No login needed ≤ 5.4.01 CVE-2025-2056 Wordfence
7.5 High WP JobHunt Plugin Authentication Bypass Authentication Bypass to Candidate No login needed ≤ 7.1 CVE-2024-11283 Wordfence
7.5 High All in One WP Migration Plugin all-in-one-wp-migration PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 7.89 CVE-2024-10942 Wordfence
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
7.1 High WoWPth Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2025-1487 WPScan
7.1 High WoWPth Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0 CVE-2025-1486 WPScan
7.1 High Limit Bio Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 1.0 CVE-2025-1436 WPScan
7.1 High WP Click Info Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.7.4 CVE-2025-1401 WPScan
7.1 High Schedule Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0.0 CVE-2024-13891 WPScan
7.1 High WP E Customers Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 0.0.1 CVE-2024-13885 WPScan
7.1 High Limit Bio Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13884 WPScan
7.2 High AppPresser – Mobile App Framework Plugin apppresser Cross-Site Scripting Mobile App Framework <= 4.4.10 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.4.10 CVE-2025-1561 Wordfence
7.5 High Arielbrailovsky-Viralad Plugin arielbrailovsky-viralad SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.8 CVE-2025-2107 Wordfence
7.5 High Arielbrailovsky-Viralad Plugin arielbrailovsky-viralad SQL Injection Unauthenticated SQL Injection No login needed ≤ 1.0.8 CVE-2025-2106 Wordfence
8.8 High Review Schema Plugin review-schema Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Meta ≤ 2.2.4 CVE-2025-1707 Wordfence
7.1 High MaxA/B Plugin maxab Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.2.2 CVE-2025-28933 Patchstack
7.1 High Insert Code Plugin insert-code Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.4 CVE-2025-28932 Patchstack
7.1 High Hashtags Plugin wp-hashtags Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.3.2 CVE-2025-28931 Patchstack
7.1 High WATI Chat and Notification Plugin wati-chat-and-notification Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.1.2 Fixed in 1.1.5 CVE-2025-28925 Patchstack
7.1 High No Disposable Email Plugin no-disposable-email Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.5.1 CVE-2025-28923 Patchstack
7.1 High Go To Top Plugin go-to-top Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.0.8 CVE-2025-28922 Patchstack
7.1 High Featured Posts Grid Plugin featured-posts-grid Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.7 CVE-2025-28905 Patchstack
7.1 High Members page only for logged in users Plugin members-page-only-for-logged-in-users Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.2 CVE-2025-28901 Patchstack
7.1 High TabGarb Pro Plugin tabgarb Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.6 CVE-2025-28900 Patchstack
7.1 High Domain Plugin domain-theme Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3 CVE-2025-28897 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only