WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 551–600 of 2,392 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.3 Medium | WP DB Booster | Cross-Site Request Forgery Cross-Site Request Forgery to Database Cleanup No login needed |
≤ 1.0.1 |
CVE-2025-14168 |
Wordfence | |
| 5.4 Medium | Amazon affiliate lite | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-14734 |
Wordfence | |
| 4.3 Medium | Quran Gateway | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.5 |
CVE-2025-14164 |
Wordfence | |
| 7.2 High | HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player | Server-Side Request Forgery The Ultimate No-Code Podcast, MP3 & Audio Player 2.4.0 - 2.5.1 - Unauthenticated Server-Side Request Forgery No login needed |
2.4.0 – 2.5.1 |
CVE-2025-13999 |
Wordfence | |
| 4.3 Medium | Prime Slider – Addons for Elementor | Server-Side Request Forgery Addons for Elementor <= 4.0.9 - Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 4.0.9 |
CVE-2025-14277 |
Wordfence | |
| 4.3 Medium | Download Plugins and Themes from Dashboard | Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Plugin/Theme Archival No login needed |
≤ 1.9.6 |
CVE-2025-14399 |
Wordfence | |
| 4.9 Medium | Zephyr Project Manager | Path Traversal Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery |
≤ 3.3.203 |
CVE-2025-12496 |
Wordfence | |
| 6.5 Medium | Fancy Product Designer | WooCommerce | Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via Race Condition No login needed |
≤ 6.4.8 |
CVE-2025-13231 |
Wordfence | |
| 5.4 Medium | Meks Quick Plugin Disabler | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-68083 |
Patchstack | |
| 5.4 Medium | Semrush Content Toolkit | Cross-Site Request Forgery No login needed |
≤ 1.1.32 Fixed in 1.1.33 |
CVE-2025-68082 |
Patchstack | |
| 5.4 Medium | Kerge | Server-Side Request Forgery No login needed |
≤ 4.1.3 Fixed in 4.1.4 |
CVE-2025-67989 |
Patchstack | |
| 4.3 Medium | Freshchat | Cross-Site Request Forgery No login needed |
≤ 2.3.4 |
CVE-2025-64240 |
Patchstack | |
| 4.3 Medium | RTL Tester | Cross-Site Request Forgery No login needed |
≤ 1.2 |
CVE-2025-64239 |
Patchstack | |
| 4.3 Medium | Quick Interest Slider | Cross-Site Request Forgery No login needed |
≤ 3.1.5 Fixed in 3.1.6 |
CVE-2025-64237 |
Patchstack | |
| 4.3 Medium | Listify | Cross-Site Request Forgery No login needed |
≤ 3.2.5 |
CVE-2025-59009 |
Patchstack | |
| 4.3 Medium | WP Attractive Donations System - Easy Stripe & Paypal donations | Cross-Site Request Forgery Easy Stripe & Paypal donations plugin <= 1.25 - Cross Site Request Forgery (CSRF) No login needed |
≤ 1.25 |
CVE-2025-58999 |
Patchstack | |
| 4.3 Medium | Popover Windows | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Popover Configuration Update No login needed |
≤ 1.2 |
CVE-2025-14394 |
Wordfence | |
| 4.3 Medium | Lucky Draw Contests | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 4.2 |
CVE-2025-14462 |
Wordfence | |
| 4.4 Medium | Emplibot – AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated | Server-Side Request Forgery AI Content Writer with Keyword Research, Infographics, and Linking | SEO Optimized | Fully Automated <= 1.0.9 - Authenticated (Admin+) Server-Side Request Forgery |
≤ 1.0.9 |
CVE-2025-11970 |
Wordfence | |
| 4.3 Medium | Image Slider by Ays- Responsive Slider and Carousel | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Slider Deletion No login needed |
≤ 2.7.0 |
CVE-2025-14454 |
Wordfence | |
| 4.3 Medium | Events Manager – Calendar, Bookings, Tickets, and more! | Cross-Site Request Forgery Calendar, Bookings, Tickets, and more! <= 7.2.2.2 - Cross-Site Request Forgery to Location Deletion No login needed |
≤ 7.2.2.2 |
CVE-2025-12407 |
Wordfence | |
| 4.3 Medium | Secure Copy Content Protection and Content Locking | Cross-Site Request Forgery Cross-Site Request Forgery to Data Export No login needed |
≤ 4.9.2 |
CVE-2025-14159 |
Wordfence | |
| 3.5 Low | WP Fastest Cache Premium | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Blind Server-Side Request Forgery |
≤ 1.7.4 |
CVE-2025-10583 |
Wordfence | |
| 4.3 Medium | Simple Theme Changer | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Theme Switcher Configuration Update No login needed |
≤ 1.0 |
CVE-2025-14391 |
Wordfence | |
| 4.3 Medium | Rabbit Hole | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed |
≤ 1.1 |
CVE-2025-13366 |
Wordfence | |
| 4.3 Medium | Upcoming for Calendly | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.4 |
CVE-2025-14160 |
Wordfence | |
| 4.3 Medium | Purchase and Expense Manager | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Purchase Record Deletion No login needed |
≤ 1.1.2 |
CVE-2025-13987 |
Wordfence | |
| 4.3 Medium | Animated Pixel Marquee Creator | Cross-Site Request Forgery Cross-Site Request Forgery via 'marquee' Parameter No login needed |
≤ 1.0.0 |
CVE-2025-14062 |
Wordfence | |
| 4.3 Medium | Truefy Embed | Cross-Site Request Forgery Cross-Site Request Forgery to 'truefy_embed_options_update' Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-14161 |
Wordfence | |
| 4.3 Medium | Resource Library for Logged In Users | Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed |
≤ 1.5 |
CVE-2025-14354 |
Wordfence | |
| 4.3 Medium | Kirim.Email WooCommerce Integration | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.2.9 |
CVE-2025-14165 |
Wordfence | |
| 4.3 Medium | IMAQ Core | Cross-Site Request Forgery Cross-Site Request Forgery to URL Structure Update No login needed |
≤ 1.2.1 |
CVE-2025-13363 |
Wordfence | |
| 4.3 Medium | Coding Blocks | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-14158 |
Wordfence | |
| 4.3 Medium | Foxtool All-in-One: Contact chat button, Custom login, Media optimize images | Cross-Site Request Forgery Cross-Site Request Forgery to Google OAuth Connection No login needed |
≤ 2.5.2 |
CVE-2025-13408 |
Wordfence | |
| 4.3 Medium | BMLT | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Creation and Deletion No login needed |
≤ 3.11.4 |
CVE-2025-14162 |
Wordfence | |
| 5.8 Medium | RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator | Server-Side Request Forgery Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator <= 5.1.1 - Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 5.1.1 |
CVE-2025-11467 |
Wordfence | |
| 8.8 High | Video Merchant | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed |
≤ 5.0.4 |
CVE-2025-14390 |
Wordfence | |
| 4.3 Medium | Advanced Product Fields (Product Addons) for WooCommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Product Field Group Duplication and Publication No login needed |
≤ 1.6.17 |
CVE-2025-13924 |
Wordfence | |
| 4.3 Medium | WP Fast Cache | Cross-Site Request Forgery No login needed |
≤ 1.5 |
CVE-2023-22675 |
Patchstack | |
| 5.4 Medium | GiveWP | Cross-Site Request Forgery No login needed |
≤ 4.13.1 Fixed in 4.13.2 |
CVE-2025-67467 |
Patchstack | |
| 4.3 Medium | KALLYAS | Cross-Site Request Forgery No login needed |
≤ 4.25.0 Fixed in 4.25.0 |
CVE-2025-63060 |
Patchstack | |
| 7.1 High | New User Approve | Cross-Site Request Forgery No login needed |
≤ 3.2.3 Fixed in 3.2.4 |
CVE-2025-63030 |
Patchstack | |
| 4.3 Medium | WP Hotel Booking | Cross-Site Request Forgery No login needed |
≤ 2.2.8 Fixed in 2.2.9 |
CVE-2025-63012 |
Patchstack | |
| 4.9 Medium | Hercules Core | Server-Side Request Forgery |
≤ 7.4 |
CVE-2025-63010 |
Patchstack | |
| 4.3 Medium | WP Flashy Marketing Automation | Cross-Site Request Forgery No login needed |
≤ 2.0.8 Fixed in 2.0.9 |
CVE-2025-62873 |
Patchstack | |
| 4.3 Medium | Social Photo Fetcher | Cross-Site Request Forgery No login needed |
≤ 3.0.4 |
CVE-2025-62872 |
Patchstack | |
| 4.3 Medium | Just TinyMCE Custom Styles | Cross-Site Request Forgery No login needed |
≤ 1.2.1 |
CVE-2025-62871 |
Patchstack | |
| 4.3 Medium | Auto Alt Text | Cross-Site Request Forgery No login needed |
≤ 2.5.2 Fixed in 2.5.3 |
CVE-2025-62866 |
Patchstack | |
| 4.3 Medium | SMTP Mail | Cross-Site Request Forgery No login needed |
≤ 1.3.51 |
CVE-2025-62762 |
Patchstack | |
| 6.5 Medium | Add Custom Codes | Cross-Site Request Forgery No login needed |
≤ 4.80 Fixed in 5.0 |
CVE-2025-62739 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.