WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,901–5,950 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 119 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Information Disclosure AI Chatbot for WordPress <= 2.5.5 - Unauthenticated Information Exposure No login needed ≤ 2.5.5 CVE-2025-12585 Wordfence
4.9 Medium FluentCart A New Era of eCommerce Plugin fluent-cart SQL Injection Authenticated (Administrator+) SQL Injection via 'groupKey' Parameter ≤ 1.3.1 CVE-2025-13495 Wordfence
6.4 Medium CSSIgniter Shortcodes Plugin cssigniter-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'element' Shortcode Attribute ≤ 2.4.1 CVE-2025-13448 Wordfence
4.9 Medium Upload.am File Hosting VPN Plugin Information Disclosure Contributor+ Arbitrary Option Disclosure < 1.0.1 Fixed in 1.0.1 CVE-2025-12630 WPScan
6.4 Medium Nexter Extension Plugin nexter-extension Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.4.1 CVE-2025-13731 Wordfence
4.9 Medium WP Directory Kit Plugin wpdirectorykit SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.4.6 CVE-2025-13090 Wordfence
6.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Privilege Escalation Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action ≤ 3.3.2 CVE-2025-13534 Wordfence
4.3 Medium Beaver Builder – WordPress Page Builder Plugin beaver-builder-lite-version Broken Access Control WordPress Page Builder <= 2.9.4 - Missing Authorization to Authenticated (Contributor+) Global Preset Modification ≤ 2.9.4 CVE-2025-11726 Wordfence
5.3 Medium Zigaform Plugin zigaform-calculator-cost-estimation-form-builder-lite Information Disclosure Unauthenticated Form Submission Data Disclosure in rocket_front_payment_seesummary AJAX Endpoint No login needed ≤ 7.6.5 CVE-2025-13696 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
6.5 Medium Visualizer: Tables and Charts Manager Plugin visualizer SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.11.12 CVE-2025-12483 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.1 Medium WP Social Ninja – Embed Social Feeds, User Reviews & Chat Widgets Plugin wp-social-reviews Cross-Site Scripting Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and More) <= 3.20.3 - Unauthenticated Stored Cross-Site Scripting via External Content Import No login needed ≤ 3.20.3 CVE-2025-13007 Wordfence
4.1 Medium Donation Plugin SQL Injection Admin+ SQLi ≤ 1.0 CVE-2025-13001 WPScan
6.5 Medium Export All Posts, Products, Orders, Refunds & Users Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed ≤ 2.19 CVE-2025-13606 Wordfence
6.4 Medium BlockArt Blocks – Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library Plugin blockart-blocks Cross-Site Scripting Gutenberg Blocks, Page Builder Blocks ,WordPress Block Plugin, Sections & Template Library <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via `timestamp` Attribute ≤ 2.2.13 CVE-2025-13697 Wordfence
6.5 Medium Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting ≤ 2.1.20 CVE-2025-13835 Patchstack
4.3 Medium Nextend Social Login and Register Plugin nextend-facebook-connect Cross-Site Request Forgery Cross-Site Request Forgery to Unlink User Social Login No login needed ≤ 3.1.21 CVE-2025-13737 Wordfence
4.3 Medium Folders Plugin folders Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Folder Content Manipulation ≤ 3.1.5 CVE-2025-12971 Wordfence
4.3 Medium WP Fastest Cache Plugin wp-fastest-cache Broken Access Control Missing Authorization to Authenticated (Subscriber+) DB Cleanup Actions ≤ 1.4.0 CVE-2025-10476 Wordfence
5.3 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Broken Access Control Missing Authorization to Unauthenticated Media File Uploads No login needed ≤ 2.7.0 CVE-2025-13381 Wordfence
5.3 Medium Quick View for WooCommerce Plugin woo-quickview Information Disclosure Unauthenticated Private Product Disclosure No login needed ≤ 2.2.17 CVE-2025-12584 Wordfence
6.5 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed ≤ 2.7.0 CVE-2025-13378 Wordfence
5.3 Medium QODE Wishlist for WooCommerce Plugin qode-wishlist-for-woocommerce Broken Access Control Unauthenticated Insecure Direct Object Reference to Wishlist Update No login needed ≤ 1.2.7 CVE-2025-13157 Wordfence
5.3 Medium Hide Category by User Role for WooCommerce Plugin hide-category-by-user-role-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Cache Flushing No login needed ≤ 2.3.1 CVE-2025-13441 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence
6.1 Medium WP Directory Kit Plugin wpdirectorykit Cross-Site Scripting Reflected Cross-Site Scripting via 'order_by' Parameter No login needed ≤ 1.4.5 CVE-2025-13525 Wordfence
4.4 Medium StaffList Plugin stafflist Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.2.6 CVE-2025-12185 Wordfence
6.1 Medium Customer Reviews Collector for WooCommerce Plugin customer-reviews-collector-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 4.6.1 CVE-2025-12123 Wordfence
6.4 Medium Simple Folio Plugin simple-folio Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2025-12151 Wordfence
6.4 Medium Soundslides Plugin soundslides Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundslides Shortcode ≤ 1.4.2 CVE-2025-12713 Wordfence
6.4 Medium wp-twitpic Plugin wp-twitpic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-12670 Wordfence
6.4 Medium SortTable Post Plugin sorttable-post Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.2 CVE-2025-12649 Wordfence
6.4 Medium Shouty Plugin shouty Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shouty Shortcode Attributes ≤ 0.2.1 CVE-2025-12712 Wordfence
5.3 Medium Reuters Direct Plugin reuters-direct Broken Access Control Missing Authorization to Unauthenticated Settings Reset No login needed ≤ 3.0.0 CVE-2025-12579 Wordfence
6.4 Medium Google Drive upload and download link Plugin google-drive-upload-and-download-link Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-12666 Wordfence
4.3 Medium Reuters Direct Plugin reuters-direct Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 3.0.0 CVE-2025-12578 Wordfence
6.1 Medium Houzez Theme Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 4.1.6 CVE-2025-9163 Wordfence
6.3 Medium Houzez Theme PHP Object Injection Authenticated (Subscriber+) PHP Object Injection via Saved Search ≤ 4.1.6 CVE-2025-9191 Wordfence
4.9 Medium Bookme Plugin bookme-free-appointment-booking-system SQL Injection Authenticated (Admin+) SQL Injection via 'filter[status]' Parameter ≤ 4.2 CVE-2025-13385 Wordfence
4.3 Medium Refund Request for WooCommerce Plugin refund-request-for-woocommerce Broken Access Control Missing Authorization to Authenticated (Subscriber+) Refund Status Update ≤ 1.0 CVE-2025-12634 Wordfence
4.3 Medium Peer Publish Plugin peer-publish Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-12587 Wordfence
4.9 Medium ProjectList Plugin projectlist SQL Injection Authenticated (Editor+) SQL Injection via 'id' Parameter ≤ 0.3.0 CVE-2025-13370 Wordfence
4.4 Medium Just Highlight Plugin just-highlight Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'Highlight Color' Setting ≤ 1.0.3 CVE-2025-13311 Wordfence
5.3 Medium Ace Post Type Builder Plugin ace-post-type-builder Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Custom Taxonomy Deletion via 'taxonomy' Parameter No login needed ≤ 1.9 CVE-2025-13405 Wordfence
6.4 Medium Inline frame – Iframe Plugin inline-frame-iframe Cross-Site Scripting Iframe <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.1 CVE-2025-12645 Wordfence
4.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary File Renaming ≤ 23.4 CVE-2025-13382 Wordfence
6.5 Medium AI Engine for WordPress: ChatGPT, GPT Content Generator Plugin liquid-chatgpt Path Traversal Authenticated (Contributor+) Arbitrary File Read ≤ 1.0.1 CVE-2025-13380 Wordfence
5.3 Medium atec Duplicate Page & Post Plugin atec-duplicate-page-post Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary Post Duplication and Data Exposure No login needed ≤ 1.2.20 CVE-2025-13404 Wordfence
4.4 Medium YouTube Subscribe Plugin easy-youtube-subscribe Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting via Title and Channel ID ≤ 3.0.0 CVE-2025-12025 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only