WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 5,951–6,000 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 120 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Custom top bar Plugin custom-top-bar Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-28895 Patchstack
7.1 High List of Posts from each Category Plugin list-posts-by-category Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-28894 Patchstack
7.1 High FTP Sync Plugin ftp-sync Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.6 CVE-2025-28892 Patchstack
7.1 High price-calc Plugin price-calc Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.6.3 CVE-2025-28891 Patchstack
7.1 High WP Compare Tables Plugin wp-compare-tables Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.5 CVE-2025-28883 Patchstack
7.1 High WP jQuery Persian Datepicker Plugin wpjqp-datepicker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.1.0 CVE-2025-28861 Patchstack
7.1 High Google News Editors Picks Feed Generator Plugin google-news-editors-picks-news-feeds Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1 CVE-2025-28860 Patchstack
7.1 High Rankchecker.io Integration Plugin rankchecker-io-integration Cross-Site Request Forgery CSRF to Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.9 CVE-2025-28857 Patchstack
7.1 High Countdown Timer Plugin widget-countdown Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13864 WPScan
7.1 High S3Bubble Media Streaming Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 8.0 CVE-2024-13862 WPScan
7.1 High WP Login Control Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 2.0.0 CVE-2024-13836 WPScan
7.1 High XV Random Quotes Plugin xv-random-quotes Cross-Site Scripting Reflected XSS No login needed ≤ 1.40 CVE-2024-13574 WPScan
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
7.5 High WC Place Order Without Payment Plugin wc-place-order-without-payment Local File Inclusion No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-26933 Patchstack
7.1 High WPBookit Plugin wpbookit Cross-Site Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.2 CVE-2025-26910 Patchstack
8.8 High Gtbabel Plugin gtbabel Privilege Escalation Unauthenticated Admin Account Takeover No login needed < 6.6.9 Fixed in 6.6.9 CVE-2024-11638 WPScan
8.8 High VikRentCar Car Rental Management System Plugin vikrentcar Cross-Site Request Forgery Cross-Site Request Forgery to Authenticated (Subscriber+) Arbitrary File Upload No login needed ≤ 1.4.2 CVE-2024-11640 Wordfence
7.5 High WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall SQL Injection Registration, Profile, Commerce & More <= 16.26.10 - Unauthenticated SQL Injection No login needed ≤ 16.26.10 CVE-2025-1323 Wordfence
8.1 High Product Input Fields for WooCommerce Plugin product-input-fields-for-woocommerce Arbitrary File Upload Unauthenticated Limited File Upload No login needed ≤ 1.12.0 CVE-2024-13359 Wordfence
8.8 High Aiomatic - AI Content Writer, Editor, ChatBot & AI Toolkit Plugin Broken Access Control AI Content Writer, Editor, ChatBot & AI Toolkit <= 2.3.8 - Missing Authorization to Authenticated (Contributor+) Arbitrary File Upload ≤ 2.3.8 CVE-2024-13882 Wordfence
8.1 High miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon Plugin Authentication Bypass No login needed ≤ 200.3.9 CVE-2024-11087 Wordfence
7.2 High SMTP by BestWebSoft Plugin bws-smtp Arbitrary File Upload Authenticated (Administrator+) Arbitrary File Upload ≤ 1.1.9 CVE-2024-13908 Wordfence
7.2 High Post Meta Data Manager Plugin post-meta-data-manager Privilege Escalation Authentciated (Admin+) Multisite Privilege Escalation ≤ 1.4.4 CVE-2024-13835 Wordfence
7.2 High Allow PHP Execute Plugin allow-php-execute Remote Code Execution Authenticated (Editor+) PHP Code Injection ≤ 1.0 CVE-2024-13890 Wordfence
7.1 High WordPress Activity O Meter Plugin Cross-Site Scripting Reflected XSS No login needed ≤ 1.0 CVE-2024-13668 WPScan
8.8 High Eventer - WordPress Event & Booking Manager Plugin SQL Injection WordPress Event & Booking Manager Plugin <= 3.9.9.2 - Authenticated (Subscriber+) SQL Injection via reg_id ≤ 3.9.9.2 CVE-2025-0959 Wordfence
8.8 High School Management System Plugin wpschoolpress Privilege Escalation Authenticated (Student+) Account Takeover and Privilege Escalation ≤ 93.0.0 CVE-2024-9658 Wordfence
7.5 High CS Framework Plugin Path Traversal Authenticated (Subscriber+) Arbitrary File Read No login needed ≤ 7.1 CVE-2024-12036 Wordfence
7.5 High Ultimate Video Player Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 10.0 CVE-2024-10804 Wordfence
8.8 High CS Framework Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 7.0 CVE-2024-12035 Wordfence
7.2 High Gallery by BestWebSoft – Customizable Image and Photo Galleries Plugin gallery-plugin PHP Object Injection Customizable Image and Photo Galleries for WordPress <= 4.7.3 - Authenticated (Administrator+) PHP Object Injection ≤ 4.7.3 CVE-2024-13906 Wordfence
8.8 High UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.5.04 CVE-2025-1309 Wordfence
7.5 High CURCY - WooCommerce Multi Currency - Currency Switcher Plugin SQL Injection WooCommerce Multi Currency - Currency Switcher <= 2.3.6 - Unauthenticated SQL Injection No login needed ≤ 2.3.6 CVE-2024-13320 Wordfence
8.1 High Flex Mag - Responsive WordPress News Theme Broken Access Control Responsive WordPress News Theme <= 3.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Deletion ≤ 3.5.2 CVE-2024-13655 Wordfence
8.1 High Homey Theme Authentication Bypass Limited Authentication Bypass due to Missing Empty Value Check No login needed ≤ 2.4.3 CVE-2025-0749 Wordfence
7.5 High Ultimate Member Plugin ultimate-member SQL Injection Unauthenticated SQL Injection via search Parameter No login needed ≤ 2.10.0 CVE-2025-1702 Wordfence
7.5 High DesignThemes Core Features Plugin Broken Access Control Missing Authorization to Unauthenticated Arbitrary File Read via dt_process_imported_file No login needed ≤ 4.7 CVE-2024-13471 Wordfence
8.8 High WordPress Awesome Import & Export Plugin - Import & Export WordPress Data Plugin Broken Access Control Import & Export WordPress Data <= 4.1.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary SQL Execution/Privilege Escalation ≤ 4.1.1 CVE-2024-13232 Wordfence
8.1 High ZoomSounds - WordPress Wave Audio Player with Playlist Plugin PHP Object Injection WordPress Wave Audio Player with Playlist <= 6.91 - Unauthenticated PHP Object Injection No login needed ≤ 6.91 CVE-2024-13777 Wordfence
8.1 High WooCommerce Recover Abandoned Cart Plugin PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 24.4.0 CVE-2025-0956 Wordfence
8.8 High Newscrunch Theme newscrunch Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 1.8.4 CVE-2025-1306 Wordfence
8.8 High Animation Addons for Elementor Pro Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation ≤ 1.6 CVE-2025-1639 Wordfence
7.1 High Zigaform – Price Calculator & Cost Estimation Form Builder Lite Plugin zigaform-calculator-cost-estimation-form-builder-lite Cross-Site Scripting Price Calculator & Cost Estimation Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26994 Patchstack
7.1 High Zigaform Plugin zigaform-form-builder-lite Cross-Site Scripting Form Builder Lite plugin <= 7.4.2 - Cross Site Scripting (XSS) No login needed ≤ 7.4.2 Fixed in 7.4.3 CVE-2025-26989 Patchstack
7.1 High SMS Alert Order Notifications Plugin sms-alert Cross-Site Scripting WooCommerce plugin <= 3.7.8 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.7.8 Fixed in 3.7.9 CVE-2025-26984 Patchstack
8.8 High Events Calendar for GeoDirectory Plugin events-for-geodirectory PHP Object Injection ≤ 2.3.14 Fixed in 2.3.15 CVE-2025-26967 Patchstack
7.1 High Small Package Quotes – Unishippers Edition Plugin small-package-quotes-unishippers-edition Cross-Site Scripting Unishippers Edition plugin <= 2.4.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.9 Fixed in 2.4.10 CVE-2025-26918 Patchstack
7.1 High WP Templata Plugin wptemplata Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-26917 Patchstack
7.1 High Variable Inspector Plugin variable-inspector Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 Fixed in 2.6.3 CVE-2025-26914 Patchstack
7.2 High WordPress Assistant Plugin assistant PHP Object Injection ≤ 1.5.1 Fixed in 1.5.1.1 CVE-2025-26885 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only