WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.
Showing 551–600 of 1,492 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | GDPR Cookie Consent | Cross-Site Request Forgery Bulk Delete via CSRF No login needed |
< 2.6.1 Fixed in 2.6.1 |
CVE-2024-8286 |
WPScan | |
| 4.3 Medium | GamiPress - Reset User | Cross-Site Request Forgery Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF No login needed |
< 1.0.1 Fixed in 1.0.1 |
CVE-2024-8245 |
WPScan | |
| 6.1 Medium | BabelZ – Google Translate Widget | Cross-Site Request Forgery Google Translate Widget <= 1.1.5 - CSRF to Stored XSS No login needed |
≤ 1.1.5 |
CVE-2024-8095 |
WPScan | |
| 6.5 Medium | Ntz Antispam | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 2.0e |
CVE-2024-8094 |
WPScan | |
| 6.1 Medium | JavaScript Logic | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 0.1 |
CVE-2024-8090 |
WPScan | |
| 6.1 Medium | PeoplePond | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.1.9 |
CVE-2024-8085 |
WPScan | |
| 4.3 Medium | Widgets Reset | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 0.1 |
CVE-2024-8082 |
WPScan | |
| 4.3 Medium | Custom Author Base | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 1.1.1 |
CVE-2024-8050 |
WPScan | |
| 6.1 Medium | Smooth Gallery Replacement | Cross-Site Request Forgery CSRF to Stored XSS No login needed |
≤ 1.0 |
CVE-2024-8032 |
WPScan | |
| 4.3 Medium | Joy Of Text Lite – SMS messaging | Cross-Site Request Forgery SMS messaging for WordPress <= 2.3.1 - Settings Update via CSRF No login needed |
≤ 2.3.1 |
CVE-2024-7984 |
WPScan | |
| 6.1 Medium | MapFig Studio | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 0.2.1 |
CVE-2024-6712 |
WPScan | |
| 4.3 Medium | Competition Form | Cross-Site Request Forgery Competition Deletion via CSRF No login needed |
≤ 2.0 |
CVE-2024-12750 |
WPScan | |
| 6.5 Medium | JSP Store Locator | Cross-Site Request Forgery Deletion via Missing CSRF No login needed |
≤ 1.0 |
CVE-2024-12301 |
WPScan | |
| 6.1 Medium | WordPress连接微博 | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 2.5.6 |
CVE-2024-12282 |
WPScan | |
| 6.1 Medium | tarteaucitron.js | Cross-Site Scripting Stored XSS via CSRF No login needed |
< 0.3.0 Fixed in 0.3.0 |
CVE-2024-11719 |
WPScan | |
| 4.3 Medium | Connexion Logs | Cross-Site Request Forgery Log Deletion via CSRF No login needed |
≤ 3.0.2 |
CVE-2024-11373 |
WPScan | |
| 4.3 Medium | BTEV | Cross-Site Request Forgery Settings Update via CSRF No login needed |
≤ 2.0.2 |
CVE-2024-10677 |
WPScan | |
| 4.3 Medium | Nokaut Offers Box | Cross-Site Request Forgery Plugin Reset via CSRF No login needed |
≤ 1.4.0 |
CVE-2024-10634 |
WPScan | |
| 5.4 Medium | ARForms Builder | Cross-Site Scripting Unauthenticated Stored XSS |
< 1.7.1 Fixed in 1.7.1 |
CVE-2024-10504 |
WPScan | |
| 5.4 Medium | Smaily for WP | Cross-Site Request Forgery No login needed |
≤ 3.1.7 |
CVE-2025-47684 |
Patchstack | |
| 4.3 Medium | Web Accessibility with Max Access | Cross-Site Request Forgery No login needed |
≤ 2.0.9 Fixed in 2.1.0 |
CVE-2025-47681 |
Patchstack | |
| 4.3 Medium | Credova_Financial | Cross-Site Request Forgery No login needed |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2025-47674 |
Patchstack | |
| 5.4 Medium | LiveAgent | Cross-Site Request Forgery No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2025-47667 |
Patchstack | |
| 4.4 Medium | WP Pipes | Server-Side Request Forgery |
≤ 1.4.2 |
CVE-2025-47664 |
Patchstack | |
| 5.4 Medium | 워드프레스 결제 심플페이 | Cross-Site Request Forgery No login needed |
≤ 5.2.11 Fixed in 5.3.3 |
CVE-2025-47661 |
Patchstack | |
| 4.3 Medium | Sidebar Manager Light | Cross-Site Request Forgery No login needed |
≤ 1.18 |
CVE-2025-47647 |
Patchstack | |
| 5.5 Medium | WebinarPress | Server-Side Request Forgery |
≤ 1.33.28 |
CVE-2025-47635 |
Patchstack | |
| 4.3 Medium | Awin – Advertiser Tracking for WooCommerce | Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed |
≤ 2.0.0 Fixed in 2.0.1 |
CVE-2025-47633 |
Patchstack | |
| 4.3 Medium | DoFollow Case by Case | Cross-Site Request Forgery No login needed |
≤ 3.5.1 Fixed in 3.6.0 |
CVE-2025-47624 |
Patchstack | |
| 4.3 Medium | LessButtons Social Sharing and Statistics | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.6.1 |
CVE-2025-47614 |
Patchstack | |
| 4.3 Medium | EasyMe Connect | Cross-Site Request Forgery No login needed |
≤ 3.0.3 Fixed in 3.0.4 |
CVE-2025-47609 |
Patchstack | |
| 4.3 Medium | Simple Giveaways | Cross-Site Request Forgery No login needed |
≤ 2.49.0 |
CVE-2025-47606 |
Patchstack | |
| 4.3 Medium | WP Podcasts Manager | Cross-Site Request Forgery No login needed |
≤ 1.3 Fixed in 1.4 |
CVE-2025-47597 |
Patchstack | |
| 4.3 Medium | Beacon Lead Magnets and Lead Capture | Cross-Site Request Forgery No login needed |
≤ 1.5.8 Fixed in 1.5.9 |
CVE-2025-47596 |
Patchstack | |
| 4.3 Medium | Soccer Live Scores | Cross-Site Request Forgery No login needed |
≤ 1.0.5 |
CVE-2025-47594 |
Patchstack | |
| 4.3 Medium | WPSpeed | Cross-Site Request Forgery No login needed |
≤ 2.6.5 Fixed in 2.6.6 |
CVE-2025-47590 |
Patchstack | |
| 4.3 Medium | Wiki Embed | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed |
≤ 1.4.6 Fixed in 1.4.7 |
CVE-2025-47551 |
Patchstack | |
| 5.4 Medium | Wbcom Designs - Activity Link Preview For BuddyPress | Server-Side Request Forgery Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) No login needed |
≤ 1.4.4 Fixed in 1.6.0 |
CVE-2025-47548 |
Patchstack | |
| 4.3 Medium | TrueBooker | Cross-Site Request Forgery No login needed |
≤ 1.0.7 Fixed in 1.0.8 |
CVE-2025-47543 |
Patchstack | |
| 4.3 Medium | Simple calendar for Elementor | Cross-Site Request Forgery No login needed |
≤ 1.6.5 Fixed in 1.6.6 |
CVE-2025-47542 |
Patchstack | |
| 4.3 Medium | Seznam Webmaster | Cross-Site Request Forgery No login needed |
≤ 1.4.7 Fixed in 1.4.8 |
CVE-2025-47523 |
Patchstack | |
| 4.3 Medium | Easy PayPal Events | Cross-Site Request Forgery No login needed |
≤ 1.2.2 Fixed in 1.3 |
CVE-2025-47519 |
Patchstack | |
| 6.4 Medium | Display Remote Posts Block | Server-Side Request Forgery |
≤ 1.1.0 Fixed in 1.1.1 |
CVE-2025-47484 |
Patchstack | |
| 4.9 Medium | Easy Replace Image | Server-Side Request Forgery |
≤ 3.5.0 Fixed in 3.5.1 |
CVE-2025-47483 |
Patchstack | |
| 5.4 Medium | PW WooCommerce Bulk Edit | Cross-Site Request Forgery No login needed |
≤ 2.134 Fixed in 2.135 |
CVE-2025-47473 |
Patchstack | |
| 4.3 Medium | GPT3 AI Content Writer | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Prompt Generation No login needed |
≤ 1.9.14 Fixed in 1.9.15 |
CVE-2025-47470 |
Patchstack | |
| 4.3 Medium | Hash Form | Cross-Site Request Forgery No login needed |
≤ 1.2.8 Fixed in 1.2.9 |
CVE-2025-47468 |
Patchstack | |
| 5.4 Medium | Ultimate WP Mail | Cross-Site Request Forgery No login needed |
≤ 1.3.4 Fixed in 1.3.5 |
CVE-2025-47466 |
Patchstack | |
| 4.9 Medium | Solace Extra | Server-Side Request Forgery |
≤ 1.3.1 Fixed in 1.3.2 |
CVE-2025-47464 |
Patchstack | |
| 4.3 Medium | FundEngine | Cross-Site Request Forgery No login needed |
≤ 1.7.3 Fixed in 1.7.4 |
CVE-2025-47459 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.