WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,001–6,050 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 5.9 Medium | Head Meta Data | Cross-Site Scripting |
≤ 20250327 Fixed in 20251118 |
CVE-2025-66081 |
Patchstack | |
| 6.5 Medium | Gutenverse Form | Broken Access Control |
≤ 2.2.0 Fixed in 2.3.0 |
CVE-2025-66079 |
Patchstack | |
| 5.3 Medium | Legal Pages | Broken Access Control No login needed |
≤ 1.4.6 Fixed in 1.4.7 |
CVE-2025-66077 |
Patchstack | |
| 4.3 Medium | WP Cookie Notice for GDPR, CCPA & ePrivacy Consent | Broken Access Control |
≤ 4.0.3 Fixed in 4.0.4 |
CVE-2025-66075 |
Patchstack | |
| 5.3 Medium | UsersWP | Broken Access Control No login needed |
≤ 1.2.47 Fixed in 1.2.48 |
CVE-2025-66072 |
Patchstack | |
| 5.3 Medium | Custom Order Numbers for WooCommerce | Broken Access Control No login needed |
≤ 1.11.0 Fixed in 1.11.1 |
CVE-2025-66071 |
Patchstack | |
| 4.3 Medium | PPOM for WooCommerce | Broken Access Control |
≤ 33.0.16 Fixed in 33.0.17 |
CVE-2025-66069 |
Patchstack | |
| 6.5 Medium | Funnel Builder by FunnelKit | Cross-Site Scripting |
≤ 3.13.1.2 Fixed in 3.13.1.3 |
CVE-2025-66067 |
Patchstack | |
| 6.5 Medium | Envo Extra | Cross-Site Scripting |
≤ 1.9.11 Fixed in 1.9.12 |
CVE-2025-66066 |
Patchstack | |
| 6.5 Medium | Gutenverse | Broken Access Control |
≤ 3.2.1 Fixed in 3.3.0 |
CVE-2025-66065 |
Patchstack | |
| 4.3 Medium | Giveaways and Contests by RafflePress | Cross-Site Request Forgery No login needed |
≤ 1.12.20 Fixed in 1.12.21 |
CVE-2025-66064 |
Patchstack | |
| 5.4 Medium | WP Google Review Slider | Broken Access Control |
≤ 17.4 Fixed in 17.6 |
CVE-2025-66063 |
Patchstack | |
| 4.3 Medium | Seriously Simple Podcasting | Cross-Site Request Forgery No login needed |
≤ 3.13.0 Fixed in 3.14.0 |
CVE-2025-66061 |
Patchstack | |
| 5.3 Medium | Seriously Simple Podcasting | Broken Access Control No login needed |
≤ 3.13.0 Fixed in 3.14.0 |
CVE-2025-66060 |
Patchstack | |
| 5.3 Medium | Seriously Simple Podcasting | Information Disclosure Sensitive Data Exposure No login needed |
≤ 3.13.0 Fixed in 3.14.0 |
CVE-2025-66059 |
Patchstack | |
| 6.5 Medium | Bold Page Builder | Cross-Site Scripting |
≤ 5.5.2 Fixed in 5.5.3 |
CVE-2025-66057 |
Patchstack | |
| 4.3 Medium | Uncanny Automator | Information Disclosure Sensitive Data Exposure |
≤ 6.10.0 Fixed in 6.10.0 |
CVE-2025-66056 |
Patchstack | |
| 6.5 Medium | Enfold | Cross-Site Scripting |
≤ 7.1.2 Fixed in 7.1.3 |
CVE-2025-66053 |
Patchstack | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client' |
≤ 3.2.9 |
CVE-2025-10039 |
Wordfence | |
| 6.4 Medium | FluentCRM - Marketing Automation | Cross-Site Scripting Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode |
≤ 2.9.84 |
CVE-2025-12935 |
Wordfence | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Role Removal |
≤ 3.3.1 |
CVE-2025-10054 |
Wordfence | |
| 4.9 Medium | Groundhogg | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 4.2.6.1 |
CVE-2025-12750 |
Wordfence | |
| 6.4 Medium | Magical Products Display | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via MPD Pricing Table Widget |
≤ 1.1.29 |
CVE-2025-12964 |
Wordfence | |
| 4.4 Medium | WP Delete Post Copies | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 6.0.2 |
CVE-2025-12066 |
Wordfence | |
| 6.4 Medium | Shortcode for Google Street View | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 0.5.7 |
CVE-2025-11808 |
Wordfence | |
| 4.3 Medium | Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories | Broken Access Control Authenticated (Author+) Missing Authorization to Post/Page Status Modification |
≤ 4.9.1 |
CVE-2025-13149 |
Wordfence | |
| 6.4 Medium | HT Mega – Absolute Addons For Elementor | Cross-Site Scripting Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection |
≤ 3.0.0 |
CVE-2025-13141 |
Wordfence | |
| 4.9 Medium | 简数采集器 | Path Traversal Authenticated (Admin+) Arbitrary File Read |
≤ 2.6.3 |
CVE-2025-11973 |
Wordfence | |
| 6.4 Medium | WP Company Info | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.9.0 |
CVE-2025-11826 |
Wordfence | |
| 5.3 Medium | BigBuy Dropshipping Connector for WooCommerce | Information Disclosure Unauthenticated IP Spoofing to phpinfo() Exposure No login needed |
≤ 2.0.5 |
CVE-2025-12039 |
Wordfence | |
| 6.4 Medium | WPSite Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2 |
CVE-2025-11803 |
Wordfence | |
| 6.4 Medium | Bulma Shortcodes | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11802 |
Wordfence | |
| 6.4 Medium | Surbma | MiniCRM Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0 |
CVE-2025-11800 |
Wordfence | |
| 4.3 Medium | Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contract Address Update |
≤ 2.4.7 |
CVE-2025-11773 |
Wordfence | |
| 6.4 Medium | Display Pages Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-11763 |
Wordfence | |
| 6.4 Medium | HotelRunner Booking Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.2.4 |
CVE-2025-13135 |
Wordfence | |
| 6.4 Medium | Shortcodes Bootstrap | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-11764 |
Wordfence | |
| 5.3 Medium | Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO | Broken Access Control Missing Authentication to Unauthenticated Presale Update No login needed |
≤ 2.4.7 |
CVE-2025-11771 |
Wordfence | |
| 6.4 Medium | UiPress lite | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.5.09 |
CVE-2025-11003 |
Wordfence | |
| 6.5 Medium | UiPress lite | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure |
≤ 3.5.09 |
CVE-2025-10938 |
Wordfence | |
| 6.4 Medium | Affiliate AI Lite | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.1 |
CVE-2025-11799 |
Wordfence | |
| 5.4 Medium | Return Refund and Exchange For WooCommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read |
≤ 4.5.5 |
CVE-2025-12881 |
Wordfence | |
| 6.1 Medium | AuthorSure | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.3 |
CVE-2025-13134 |
Wordfence | |
| 4.3 Medium | UiPress lite | Effortless custom dashboards, admin themes and pages | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update |
≤ 3.5.08 |
CVE-2025-11815 |
Wordfence | |
| 6.1 Medium | EchBay Admin Security | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.3.0 |
CVE-2025-11885 |
Wordfence | |
| 4.3 Medium | Custom Post Type | Cross-Site Request Forgery Cross-Site Request Forgery to Custom Post Type Deletion No login needed |
≤ 1.0 |
CVE-2025-13142 |
Wordfence | |
| 6.4 Medium | Islamic Phrases | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.12.2015 |
CVE-2025-11768 |
Wordfence | |
| 5.3 Medium | Import WP – Export and Import CSV and XML files to | Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure No login needed |
≤ 2.14.17 |
CVE-2025-12894 |
Wordfence | |
| 6.4 Medium | BrightTALK WordPress Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.4.0 |
CVE-2025-11770 |
Wordfence | |
| 6.4 Medium | Tips Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.2.1 |
CVE-2025-11767 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.