WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 551–600 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 12 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Depicter Plugin depicter Cross-Site Request Forgery No login needed ≤ 4.0.4 CVE-2025-8383 Wordfence
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
4.3 Medium Stockie Extra Plugin stockie-extra Cross-Site Request Forgery No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64226 Patchstack
4.3 Medium PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.13.12 Fixed in 11.14 CVE-2025-64201 Patchstack
4.3 Medium Super Store Finder Plugin superstorefinder-wp Cross-Site Request Forgery No login needed ≤ 7.5 CVE-2025-58939 Patchstack
5.3 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2025-57931 Patchstack
4.3 Medium Entrada Theme entrada Cross-Site Request Forgery No login needed ≤ 5.7.7 CVE-2025-58918 Patchstack
4.9 Medium Slider Templates Plugin slider-templates Server-Side Request Forgery ≤ 1.0.3 CVE-2025-62988 Patchstack
4.3 Medium Raychat Plugin raychat Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-62975 Patchstack
4.3 Medium Simple Content Templates for Blog Posts & Pages Plugin simple-post-template Cross-Site Request Forgery No login needed ≤ 2.2.61 CVE-2025-62958 Patchstack
4.3 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Request Forgery No login needed ≤ 0.5.8.5 Fixed in 0.5.9 CVE-2025-62891 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Cross-Site Request Forgery WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation No login needed ≤ 1.1.23.0 CVE-2025-11976 Wordfence
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery Cross-Site Request Forgery to Settings Manipulation No login needed ≤ 3.1.6 CVE-2025-11497 Wordfence
6.8 Medium Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint ≤ 5.2.4 CVE-2025-12136 Wordfence
4.3 Medium Disable Content Editor For Specific Template Plugin disable-contect-editor-for-specific-template Cross-Site Request Forgery Cross-Site Request Forgery to Template Configuration Update No login needed ≤ 2.0 CVE-2025-12072 Wordfence
6.1 Medium Multi Item Responsive Slider Plugin mislider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-11992 Wordfence
5.5 Medium Orbit Fox Plugin Server-Side Request Forgery Author+ Server-Side Request Forgery < 3.0.2 Fixed in 3.0.2 CVE-2025-10874 WPScan
5.0 Medium Feedzy RSS Feeds Lite Plugin feedzy-rss-feeds Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 5.1.0 CVE-2025-11128 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.4.6 CVE-2025-10705 Wordfence
4.3 Medium Product Catalog Simple Plugin post-type-x Cross-Site Request Forgery No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-62061 Patchstack
4.3 Medium UPC/EAN/GTIN Code Generator Plugin upc-ean-barcode-generator Cross-Site Request Forgery No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-62009 Patchstack
4.3 Medium WP Media Categories Plugin wp-media-categories Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-60134 Patchstack
4.4 Medium Icegram Express Pro Plugin email-subscribers-premium Server-Side Request Forgery ≤ 5.9.5 Fixed in 5.9.6 CVE-2025-49917 Patchstack
5.4 Medium Captcha.eu Plugin captcha-eu Server-Side Request Forgery No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2025-49374 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Request Forgery No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-49373 Patchstack
4.7 Medium Search & Filter Plugin search-filter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Open Redirect No login needed ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-48099 Patchstack
4.3 Medium PixelYourSite Plugin pixelyoursite Cross-Site Request Forgery Cross-Site Request Forgery to GDPR Options Modification No login needed ≤ 11.1.2 CVE-2025-10588 Wordfence
5.0 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery ≤ 8.2.5 CVE-2025-11536 Wordfence
6.4 Medium Essential Blocks Plugin essential-blocks Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 5.7.1 CVE-2025-11361 Wordfence
4.3 Medium Ally - Web Accessibility & Usability Plugin Cross-Site Request Forgery Web Accessibility & Usability <= 3.8.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.8.0 CVE-2025-10700 Wordfence
4.4 Medium Task Scheduler Plugin task-scheduler Server-Side Request Forgery Authenticated (Admin+) Blind Server-Side Request Forgery ≤ 1.6.3 CVE-2025-10056 Wordfence
4.3 Medium Theme Importer Plugin theme-importer Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-10312 Wordfence
4.3 Medium TopBar Plugin topbar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-10300 Wordfence
4.3 Medium FunKItools Plugin funkitools Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.2 CVE-2025-10301 Wordfence
4.3 Medium Course Redirects for Learndash Plugin course-redirects-for-learndash Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-10376 Wordfence
4.3 Medium Web Accessibility By accessiBe Plugin accessibe Cross-Site Request Forgery No login needed ≤ 2.10 CVE-2025-10375 Wordfence
4.3 Medium Page Blocks Plugin page-blocks Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-9626 Wordfence
6.8 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 5.8.1 CVE-2025-9975 Wordfence
4.3 Medium WidgetPack Comment System Plugin widgetpack-comment-system Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-9621 Wordfence
5.4 Medium WP Go Maps (formerly WP Google Maps) Plugin wp-google-maps Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 9.0.46 CVE-2025-11166 Wordfence
4.3 Medium Trinity Audio Plugin trinity-audio Cross-Site Request Forgery No login needed ≤ 5.20.2 CVE-2025-9886 Wordfence
4.3 Medium Ultimate Viral Quiz Plugin ultimate-viral-quiz Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2025-10302 Wordfence
4.3 Medium AP Background Plugin ap-background Cross-Site Request Forgery No login needed ≤ 3.8.2 CVE-2025-9897 Wordfence
4.3 Medium Notification Bar Plugin simple-bar Cross-Site Request Forgery No login needed ≤ 2.2 CVE-2025-9895 Wordfence
4.3 Medium ContentMX Content Publisher Plugin contentmx-content-publisher Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-9889 Wordfence
4.3 Medium WP SinoType Plugin wp-sinotype Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9630 Wordfence
4.3 Medium Customify Theme customify Cross-Site Request Forgery No login needed ≤ 0.4.11 CVE-2025-8669 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only