WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 5,951–6,000 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 120 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Social Images Widget Plugin social-images-widget Broken Access Control Missing Authorization to Unauthenticated Arbitrary Plugin Settings Deletion No login needed ≤ 2.1 CVE-2025-13386 Wordfence
5.3 Medium Locker Content Plugin locker-content Information Disclosure Unauthenticated Information Exposure No login needed ≤ 1.0.0 CVE-2025-12525 Wordfence
5.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Information Disclosure No login needed ≤ 14 CVE-2025-13389 Wordfence
6.5 Medium Wishlist for WooCommerce Plugin th-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 1.1.3 CVE-2025-12040 Wordfence
4.3 Medium Admin and Customer Messages After Order for WooCommerce: OrderConvo Plugin admin-and-client-message-after-order-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated User Impersonation in Order Messages ≤ 14 CVE-2025-13452 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
5.3 Medium Chamber Dashboard Business Directory Plugin chamber-dashboard-business-directory Broken Access Control Missing Authorization to Unauthenticated Business Information Export No login needed ≤ 3.3.11 CVE-2025-13414 Wordfence
6.1 Medium Job Board by BestWebSoft Plugin job-board Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage No login needed ≤ 1.2.1 CVE-2025-13383 Wordfence
4.4 Medium ZWeb - Social Mobile Plugin zweb-social-mobile Cross-Site Scripting Social Mobile <= 1.0.0 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-12032 Wordfence
5.3 Medium Autochat Automatic Conversation Plugin auyautochat-for-wp Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.1.9 CVE-2025-12043 Wordfence
5.4 Medium Blog2Social Plugin blog2social Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing ≤ 8.7.0 CVE-2025-13558 Wordfence
4.3 Medium Search Exclude Plugin search-exclude Broken Access Control Missing Authorization to Authenticated (Contributor+) Search Settings Modification via REST API ≤ 2.5.7 CVE-2025-10646 Wordfence
6.5 Medium Perfect Brands for WooCommerce Plugin perfect-woocommerce-brands SQL Injection Authenticated (Contributor+) SQL Injection ≤ 3.6.2 CVE-2025-10144 Wordfence
6.3 Medium WP 2FA Plugin wp-2fa Other Second Factor Bypass < 3.0.0 Fixed in 3.0.0 CVE-2025-12628 WPScan
4.7 Medium WP Front User Submit Plugin Open Redirect No login needed < 5.0.0 Fixed in 5.0.0 CVE-2025-12569 WPScan
5.9 Medium Backup Migration Plugin backup-backup Information Disclosure Unauthenticated Backup Download No login needed < 2.0.0 Fixed in 2.0.0 CVE-2025-12394 WPScan
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.4.5 CVE-2025-12800 Wordfence
5.3 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Broken Access Control Missing Authorization to Unauthenticated Arbitrary Booking Confirmation via 'dex_bccf_ipn' Parameter No login needed ≤ 1.2.60 CVE-2025-13318 Wordfence
4.3 Medium GSheetConnector For Ninja Forms Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) System Information Exposure ≤ 2.0.1 CVE-2025-13136 Wordfence
5.3 Medium IDonate – Blood Donation, Request And Donor Management System Plugin idonate Broken Access Control Blood Donation, Request And Donor Management System <= 2.1.15 - Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 2.1.14 CVE-2025-12877 Wordfence
5.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Other Unauthenticated Fake Payment Creation No login needed ≤ 1.1.7 CVE-2025-12752 Wordfence
5.3 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control Missing Authorization to Arbitrary Booking Confirmation via 'cpabc_ipncheck' Parameter No login needed ≤ 1.3.96 CVE-2025-13317 Wordfence
6.4 Medium Cookie Notice & Compliance for GDPR / CCPA Plugin cookie-notice Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.5.8 CVE-2025-11186 Wordfence
5.3 Medium Tainacan Plugin tainacan Information Disclosure Unauthenticated Information Exposure No login needed ≤ 1.0.0 CVE-2025-12747 Wordfence
6.6 Medium Easy Invoice Plugin easy-invoice Local File Inclusion ≤ 2.1.4 Fixed in 2.1.5 CVE-2025-66115 Patchstack
5.3 Medium Show Variations as Single Products Woocommerce Plugin woo-show-single-variations-shop-category Broken Access Control No login needed ≤ 2.0 Fixed in 3.0 CVE-2025-66114 Patchstack
5.3 Medium Better Chat Support for Messenger Plugin better-chat-support Broken Access Control No login needed ≤ 1.2.18 Fixed in 1.2.19 CVE-2025-66113 Patchstack
4.3 Medium Accessibility Toolkit by WebYes Plugin accessibility-plus Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66112 Patchstack
6.5 Medium Nelio Popups Plugin nelio-popups Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-66111 Patchstack
5.3 Medium Tiktok Feed Plugin b-tiktok-feed Broken Access Control No login needed ≤ 1.0.23 Fixed in 1.0.24 CVE-2025-66110 Patchstack
5.3 Medium Cart Weight for WooCommerce Plugin woo-cart-weight Broken Access Control No login needed ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66109 Patchstack
4.3 Medium TNC Toolbox: Web Performance Plugin tnc-toolbox Broken Access Control ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-66108 Patchstack
5.3 Medium Subscriptions & Memberships for PayPal Plugin subscriptions-memberships-for-paypal Broken Access Control No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-66107 Patchstack
4.3 Medium Featured Post Creative Plugin featured-post-creative Broken Access Control ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-66106 Patchstack
4.3 Medium CBX Bookmark & Favorite Plugin cbxwpbookmark Broken Access Control ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-66101 Patchstack
5.3 Medium Chat Help Plugin chat-help Broken Access Control No login needed ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-66099 Patchstack
6.5 Medium Travelers' Map Plugin travelers-map Cross-Site Scripting ≤ 2.3.2 Fixed in 2.3.3 CVE-2025-66098 Patchstack
4.3 Medium I Order Terms Plugin i-order-terms Cross-Site Request Forgery No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-66097 Patchstack
4.3 Medium Table Block by Tableberg Plugin tableberg Broken Access Control ≤ 0.6.9 Fixed in 0.6.10 CVE-2025-66096 Patchstack
6.5 Medium Extensions for Leaflet Map Plugin extensions-leaflet-map Cross-Site Scripting ≤ 4.8 Fixed in 4.9 CVE-2025-66093 Patchstack
6.5 Medium Accordion Slider Plugin accordion-slider Cross-Site Scripting ≤ 1.9.13 Fixed in 1.9.14 CVE-2025-66092 Patchstack
6.5 Medium Stylish Cost Calculator Plugin stylish-cost-calculator Cross-Site Scripting ≤ 8.1.5 Fixed in 8.1.6 CVE-2025-66091 Patchstack
6.5 Medium SKT Skill Bar Plugin skt-skill-bar Cross-Site Scripting ≤ 2.5 Fixed in 2.6 CVE-2025-66090 Patchstack
4.3 Medium Product Feed for WooCommerce Plugin webtoffee-product-feed Broken Access Control ≤ 2.3.1 Fixed in 2.3.2 CVE-2025-66089 Patchstack
4.3 Medium PropertyHive Plugin propertyhive Broken Access Control ≤ 2.1.12 Fixed in 2.1.13 CVE-2025-66087 Patchstack
5.3 Medium SMS Alert Order Notifications Plugin sms-alert Broken Access Control No login needed ≤ 3.8.8 Fixed in 3.8.9 CVE-2025-66086 Patchstack
4.3 Medium Arconix Shortcodes Plugin arconix-shortcodes Broken Access Control ≤ 2.1.18 Fixed in 2.1.19 CVE-2025-66085 Patchstack
4.3 Medium FluentCommunity Plugin fluent-community Broken Access Control ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-66084 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66083 Patchstack
5.3 Medium WpEvently Plugin mage-eventpress Broken Access Control No login needed ≤ 5.0.4 Fixed in 5.0.5 CVE-2025-66082 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only