WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,001–6,050 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 121 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High s2Member Plugin s2member Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 241216 Fixed in 250214 CVE-2025-26879 Patchstack
7.1 High Flashfader Plugin flashfader Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.1 CVE-2025-27279 Patchstack
7.1 High AcuGIS Leaflet Maps Plugin mapfig-premium-leaflet-map-maker Cross-Site Scripting Multiple Cross Site Scripting (XSS) vulnerabilities No login needed ≤ 5.1.1.0 CVE-2025-27278 Patchstack
7.1 High WOO Codice Fiscale Plugin woo-codice-fiscale Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6.3 CVE-2025-27275 Patchstack
7.1 High DB Tables Import/Export Plugin db-tables-importexport Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-27271 Patchstack
7.1 High .htaccess Login block Plugin htaccess-login-block Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9a CVE-2025-27269 Patchstack
7.5 High Doctor Appointment Booking Plugin doctor-appointment-booking Local File Inclusion ≤ 1.0.0 CVE-2025-27264 Patchstack
8.5 High Doctor Appointment Booking Plugin doctor-appointment-booking SQL Injection ≤ 1.0.0 CVE-2025-27263 Patchstack
7.1 High IE CSS3 Support Plugin ie-css3-support Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.1 CVE-2025-26589 Patchstack
7.1 High TTT Crop Plugin ttt-crop Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-26588 Patchstack
7.1 High sidebarTabs Plugin sidebartabs Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.1 CVE-2025-26587 Patchstack
7.1 High Events Planner Plugin events-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.10 CVE-2025-26586 Patchstack
7.1 High DL Leadback Plugin dl-leadback Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-26585 Patchstack
7.1 High Mobile Plugin rocket-wp-mobile Cross-Site Scripting No login needed ≤ 1.3.3 CVE-2025-26563 Patchstack
7.1 High ViperBar Plugin viperbar Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-26557 Patchstack
7.7 High Helloprint Plugin helloprint Arbitrary File Deletion ≤ 2.0.7 Fixed in 2.1.0 CVE-2025-26540 Patchstack
8.6 High Helloprint Plugin helloprint Arbitrary File Deletion No login needed ≤ 2.0.7 Fixed in 2.1.0 CVE-2025-26534 Patchstack
7.1 High Migrate Posts Plugin migrate-post Cross-Site Scripting Post Based Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-25170 Patchstack
7.1 High Authors Autocomplete Meta Box Plugin authors-autocomplete-meta-box Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-25169 Patchstack
7.1 High Staff Directory Plugin: Company Directory Plugin staff-directory-pro Cross-Site Scripting No login needed ≤ 4.3 CVE-2025-25165 Patchstack
7.1 High Meta Accelerator Plugin meta-accelerator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.4 CVE-2025-25164 Patchstack
7.1 High Sports Rankings and Lists Plugin sports-rankings-lists Path Traversal Arbitrary File Download No login needed ≤ 1.0.2 CVE-2025-25162 Patchstack
7.1 High WP Find Your Nearest Plugin wp-find-your-nearest Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.3.1 CVE-2025-25161 Patchstack
7.1 High Uncomplicated SEO Plugin uncomplicated-seo Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-25158 Patchstack
7.1 High WP Church Center Plugin wp-church-center Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.3 CVE-2025-25157 Patchstack
7.1 High WP Less Compiler Plugin wp-less-compiler Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2025-25142 Patchstack
7.1 High WP Frontend Submit Plugin wp-frontend-submit Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.0 CVE-2025-25133 Patchstack
7.1 High Visitor Details Plugin visitors-details Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-25132 Patchstack
7.5 High Delete Comments By Status Plugin delete-comments-by-status Local File Inclusion No login needed ≤ 2.1.1 CVE-2025-25130 Patchstack
7.1 High Callback Request Plugin callback-request Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4 CVE-2025-25129 Patchstack
7.1 High Contact Us By Lord Linus Plugin contact-us-by-lord-linus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6 CVE-2025-25127 Patchstack
7.1 High Status Updater Plugin fb-status-updater Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.9.2 CVE-2025-25124 Patchstack
8.1 High WizShop Plugin wizshop Local File Inclusion No login needed ≤ 3.0.2 CVE-2025-25122 Patchstack
7.1 High Woocommerce osCommerce Sync Plugin woo-oscommerce-sync Cross-Site Scripting No login needed ≤ 2.0.20 CVE-2025-25119 Patchstack
7.1 High Top Bar – PopUps – by WPOptin Plugin wpoptin Cross-Site Scripting No login needed ≤ 2.0.8 CVE-2025-25118 Patchstack
7.1 High User Role Plugin user-roles Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-25114 Patchstack
7.1 High Implied Cookie Consent Plugin implied-cookie-consent Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-25113 Patchstack
7.6 High Social Links Plugin social-links SQL Injection ≤ 1.2 CVE-2025-25112 Patchstack
8.1 High WP Vehicle Manager Plugin js-vehicle-manager Local File Inclusion No login needed ≤ 3.1 CVE-2025-25109 Patchstack
7.1 High SW Plus Plugin shalom-world-media-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1 CVE-2025-25108 Patchstack
7.1 High Yahoo BOSS Plugin yahoo-boss Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7 CVE-2025-25102 Patchstack
7.1 High Appointment Buddy Widget Plugin appointment-buddy-online-appointment-booking-by-accrete Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-25099 Patchstack
7.1 High All push notification for WP Plugin all-push-notification Cross-Site Scripting No login needed ≤ 1.5.3 CVE-2025-25092 Patchstack
7.1 High Dreamstime Stock Photos Plugin dreamstime-stock-photos Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1 Fixed in 4.2 CVE-2025-25090 Patchstack
7.1 High Image Rotator Plugin appten-image-rotator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0 CVE-2025-25089 Patchstack
7.1 High seekXL Snapr Plugin seekxl-snapr Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.6 CVE-2025-25087 Patchstack
7.1 High EP4 More Embeds Plugin ep4-more-embeds Cross-Site Scripting Stored Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-25083 Patchstack
7.1 High Album Reviewer Plugin albumreviewer Cross-Site Scripting No login needed ≤ 2.0.2 CVE-2025-25070 Patchstack
7.1 High CM Map Locations Plugin cm-map-locations Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-24758 Patchstack
7.1 High CM Pop-Up banners Plugin cm-pop-up-banners Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.6 Fixed in 1.7.7 CVE-2025-24694 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only