WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,001–6,050 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 121 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Head Meta Data Plugin head-meta-data Cross-Site Scripting ≤ 20250327 Fixed in 20251118 CVE-2025-66081 Patchstack
6.5 Medium Gutenverse Form Plugin gutenverse-form Broken Access Control ≤ 2.2.0 Fixed in 2.3.0 CVE-2025-66079 Patchstack
5.3 Medium Legal Pages Plugin legal-pages Broken Access Control No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-66077 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Broken Access Control ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-66075 Patchstack
5.3 Medium UsersWP Plugin userswp Broken Access Control No login needed ≤ 1.2.47 Fixed in 1.2.48 CVE-2025-66072 Patchstack
5.3 Medium Custom Order Numbers for WooCommerce Plugin custom-order-numbers-for-woocommerce Broken Access Control No login needed ≤ 1.11.0 Fixed in 1.11.1 CVE-2025-66071 Patchstack
4.3 Medium PPOM for WooCommerce Plugin woocommerce-product-addon Broken Access Control ≤ 33.0.16 Fixed in 33.0.17 CVE-2025-66069 Patchstack
6.5 Medium Funnel Builder by FunnelKit Plugin funnel-builder Cross-Site Scripting ≤ 3.13.1.2 Fixed in 3.13.1.3 CVE-2025-66067 Patchstack
6.5 Medium Envo Extra Plugin envo-extra Cross-Site Scripting ≤ 1.9.11 Fixed in 1.9.12 CVE-2025-66066 Patchstack
6.5 Medium Gutenverse Plugin gutenverse Broken Access Control ≤ 3.2.1 Fixed in 3.3.0 CVE-2025-66065 Patchstack
4.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Cross-Site Request Forgery No login needed ≤ 1.12.20 Fixed in 1.12.21 CVE-2025-66064 Patchstack
5.4 Medium WP Google Review Slider Plugin wp-google-places-review-slider Broken Access Control ≤ 17.4 Fixed in 17.6 CVE-2025-66063 Patchstack
4.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Cross-Site Request Forgery No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66061 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Broken Access Control No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66060 Patchstack
5.3 Medium Seriously Simple Podcasting Plugin seriously-simple-podcasting Information Disclosure Sensitive Data Exposure No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-66059 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.5.2 Fixed in 5.5.3 CVE-2025-66057 Patchstack
4.3 Medium Uncanny Automator Plugin uncanny-automator Information Disclosure Sensitive Data Exposure ≤ 6.10.0 Fixed in 6.10.0 CVE-2025-66056 Patchstack
6.5 Medium Enfold Plugin enfold Cross-Site Scripting ≤ 7.1.2 Fixed in 7.1.3 CVE-2025-66053 Patchstack
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client' ≤ 3.2.9 CVE-2025-10039 Wordfence
6.4 Medium FluentCRM - Marketing Automation Plugin fluent-crm Cross-Site Scripting Marketing Automation For WordPress <= 2.9.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'fluentcrm_content' Shortcode ≤ 2.9.84 CVE-2025-12935 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Role Removal ≤ 3.3.1 CVE-2025-10054 Wordfence
4.9 Medium Groundhogg Plugin SQL Injection Authenticated (Admin+) SQL Injection ≤ 4.2.6.1 CVE-2025-12750 Wordfence
6.4 Medium Magical Products Display Plugin magical-products-display Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via MPD Pricing Table Widget ≤ 1.1.29 CVE-2025-12964 Wordfence
4.4 Medium WP Delete Post Copies Plugin Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 6.0.2 CVE-2025-12066 Wordfence
6.4 Medium Shortcode for Google Street View Plugin wp-google-street-view-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.5.7 CVE-2025-11808 Wordfence
4.3 Medium Schedule Post Changes With PublishPress Future: Unpublish, Delete, Change Status, Trash, Change Categories Plugin post-expirator Broken Access Control Authenticated (Author+) Missing Authorization to Post/Page Status Modification ≤ 4.9.1 CVE-2025-13149 Wordfence
6.4 Medium HT Mega – Absolute Addons For Elementor Plugin Cross-Site Scripting Absolute Addons For Elementor <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Tag Attribute Injection ≤ 3.0.0 CVE-2025-13141 Wordfence
4.9 Medium 简数采集器 Plugin keydatas Path Traversal Authenticated (Admin+) Arbitrary File Read ≤ 2.6.3 CVE-2025-11973 Wordfence
6.4 Medium WP Company Info Plugin wp-company-info Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.9.0 CVE-2025-11826 Wordfence
5.3 Medium BigBuy Dropshipping Connector for WooCommerce Plugin bigbuy-wc-dropshipping-connector Information Disclosure Unauthenticated IP Spoofing to phpinfo() Exposure No login needed ≤ 2.0.5 CVE-2025-12039 Wordfence
6.4 Medium WPSite Shortcode Plugin wpsite-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2025-11803 Wordfence
6.4 Medium Bulma Shortcodes Plugin bulma-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11802 Wordfence
6.4 Medium Surbma | MiniCRM Shortcode Plugin surbma-minicrm-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-11800 Wordfence
4.3 Medium Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO Plugin tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop Broken Access Control Missing Authorization to Authenticated (Subscriber+) Contract Address Update ≤ 2.4.7 CVE-2025-11773 Wordfence
6.4 Medium Display Pages Shortcode Plugin display-pages-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-11763 Wordfence
6.4 Medium HotelRunner Booking Widget Plugin hotelrunner Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.2.4 CVE-2025-13135 Wordfence
6.4 Medium Shortcodes Bootstrap Plugin shortcodes-bootstrap Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-11764 Wordfence
5.3 Medium Cryptocurrency (Token), Launchpad (Presale), ICO & IDO, Airdrop by TokenICO Plugin tokenico-cryptocurrency-token-launchpad-presale-ico-ido-airdrop Broken Access Control Missing Authentication to Unauthenticated Presale Update No login needed ≤ 2.4.7 CVE-2025-11771 Wordfence
6.4 Medium UiPress lite Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.5.09 CVE-2025-11003 Wordfence
6.5 Medium UiPress lite Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 3.5.09 CVE-2025-10938 Wordfence
6.4 Medium Affiliate AI Lite Plugin affiliate-ai-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2025-11799 Wordfence
5.4 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Order Message Read ≤ 4.5.5 CVE-2025-12881 Wordfence
6.1 Medium AuthorSure Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.3 CVE-2025-13134 Wordfence
4.3 Medium UiPress lite | Effortless custom dashboards, admin themes and pages Plugin uipress-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Settings Update ≤ 3.5.08 CVE-2025-11815 Wordfence
6.1 Medium EchBay Admin Security Plugin echbay-admin-security Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.3.0 CVE-2025-11885 Wordfence
4.3 Medium Custom Post Type Plugin custom-post-type Cross-Site Request Forgery Cross-Site Request Forgery to Custom Post Type Deletion No login needed ≤ 1.0 CVE-2025-13142 Wordfence
6.4 Medium Islamic Phrases Plugin islamic-phrases Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.12.2015 CVE-2025-11768 Wordfence
5.3 Medium Import WP – Export and Import CSV and XML files to Plugin Information Disclosure Export and Import CSV and XML files to WordPress <= 2.14.17 - Unauthenticated Information Exposure No login needed ≤ 2.14.17 CVE-2025-12894 Wordfence
6.4 Medium BrightTALK WordPress Shortcode Plugin brighttalk-wp-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.0 CVE-2025-11770 Wordfence
6.4 Medium Tips Shortcode Plugin tips-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2.1 CVE-2025-11767 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only