WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,051–6,100 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 122 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium AudioTube Plugin audiotube Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.0.3 CVE-2025-11801 Wordfence
5.3 Medium Checkbox Plugin Broken Access Control Missing Authorization to Unauthenticated Log Clearing No login needed ≤ 2.8.10 CVE-2025-12170 Wordfence
4.3 Medium Return Refund and Exchange For WooCommerce Plugin woo-refund-and-exchange-lite Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation ≤ 4.5.5 CVE-2025-12086 Wordfence
6.4 Medium Stock Tools Plugin stock-tools Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-11765 Wordfence
6.4 Medium Pollcaster Shortcode Plugin pollcaster-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12661 Wordfence
6.1 Medium Tainacan Plugin tainacan Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-12746 Wordfence
6.4 Medium Padlet Shortcode Plugin wallwisher-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3 CVE-2025-12660 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion ≤ 3.3.0 CVE-2025-12169 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Restore ≤ 3.3.1 CVE-2025-12022 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Empty ≤ 3.3.1 CVE-2025-12085 Wordfence
4.3 Medium ELEX WordPress HelpDesk & Customer Ticketing System Plugin elex-helpdesk-customer-support-ticket-system Broken Access Control Missing Authorization to Authenticated (Subscriber+) Ticket Restore ≤ 3.3.1 CVE-2025-12023 Wordfence
5.3 Medium LearnPress – WordPress LMS Plugin learnpress Broken Access Control WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure No login needed ≤ 4.2.9.4 CVE-2025-11368 Wordfence
6.4 Medium Multiple Plugins and Themes <= (Various Versions) Theme Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library ≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … CVE-2025-5092 Wordfence
6.8 Medium Attention Bar Plugin SQL Injection Admin+ SQLi ≤ 0.7.2.1 CVE-2025-12502 WPScan
5.3 Medium Ultimate Member Widgets for Elementor Plugin ultimate-member-widgets-for-elementor Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.3 CVE-2025-12778 Wordfence
4.3 Medium SiteSEO – SEO Simplified Plugin siteseo Broken Access Control SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosure ≤ 1.3.2 CVE-2025-13085 Wordfence
5.3 Medium SureForms Plugin sureforms Cross-Site Request Forgery Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution No login needed ≤ 1.13.1 CVE-2025-12535 Wordfence
4.3 Medium WP Login and Register using JWT Plugin login-register-using-jwt Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Key Exposure ≤ 3.0.0 CVE-2025-12822 Wordfence
5.3 Medium SiteSEO – SEO Simplified Plugin siteseo Broken Access Control SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset No login needed ≤ 1.3.2 CVE-2025-12814 Wordfence
5.4 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 2.5.3 CVE-2025-12359 Wordfence
6.5 Medium Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings Plugin directorist Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update No login needed ≤ 8.5.2 CVE-2025-12174 Wordfence
6.4 Medium FunnelKit – Funnel Builder for WooCommerce Checkout Plugin funnel-builder Cross-Site Scripting Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode ≤ 3.13.1.2 CVE-2025-12878 Wordfence
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.14.8 CVE-2025-13054 Wordfence
4.3 Medium WSChat – WordPress Live Chat Plugin wschat-live-chat Broken Access Control WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 3.1.6 CVE-2025-12751 Wordfence
6.4 Medium Pet-Manager – Petfinder Plugin tier-management-petfinder Cross-Site Scripting Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm-petfinder Shortcode ≤ 3.6.1 CVE-2025-12710 Wordfence
5.3 Medium Booking Plugin for WordPress Appointments – Time Slot Plugin timeslot Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed ≤ 1.4.7 CVE-2025-12842 Wordfence
5.3 Medium Quiz Maker Plugin quiz-maker Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 6.7.0.80 CVE-2025-12426 Wordfence
5.3 Medium Email Subscribers & Newsletters Plugin email-subscribers Denial of Service Missing Authentication to Unauthenticated Mailing Queue Trigger No login needed ≤ 5.9.10 CVE-2025-12349 Wordfence
5.3 Medium New User Approve Plugin new-user-approve Information Disclosure Unauthenticated Sensitive Information Disclosure via Type Juggling No login needed ≤ 3.0.9 CVE-2025-12770 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Broken Access Control Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename No login needed ≤ 4.10.0 CVE-2025-12427 Wordfence
6.4 Medium Royal Elementor Addons and Templates Plugin royal-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.7.1036 CVE-2025-6251 Wordfence
5.3 Medium YITH WooCommerce Wishlist Plugin yith-woocommerce-wishlist Information Disclosure Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion No login needed ≤ 4.10.0 CVE-2025-12777 Wordfence
5.3 Medium Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more Plugin woocommerce-google-adwords-conversion-tracking-tag Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed ≤ 1.49.2 CVE-2025-12545 Wordfence
6.4 Medium Icon List Block – Add Icon-Based Lists with Custom Styles Plugin icon-list-block Server-Side Request Forgery Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.2.1 CVE-2025-12376 Wordfence
6.8 Medium AI Engine Plugin ai-engine Server-Side Request Forgery Authenticated (Editor+) Server-Side Request Forgery ≤ 3.1.8 CVE-2025-8084 Wordfence
5.8 Medium WP Migrate Lite Plugin wp-migrate-db Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.7.6 CVE-2025-11427 Wordfence
6.4 Medium Enable SVG, WebP, and ICO Upload Plugin enable-svg-webp-ico-upload Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploads ≤ 1.1.2 CVE-2025-12457 Wordfence
5.3 Medium Restrictions for BuddyPress Plugin bp-restrict Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 1.5.2 CVE-2025-12391 Wordfence
6.4 Medium Photonic Gallery & Lightbox for Flickr, SmugMug & Others Plugin photonic Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Caption Attribute ≤ 3.21 CVE-2025-12691 Wordfence
4.3 Medium wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce Plugin catalog-mode-pricing-enquiry-forms-promotions Broken Access Control Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce <= 1.2.2 - Missing Authorization to Sensitive Information Disclosure ≤ 1.2.2 CVE-2025-12639 Wordfence
5.3 Medium Cryptocurrency Payment Gateway for WooCommerce Plugin triplea-cryptocurrency-payment-gateway-for-woocommerce Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed ≤ 2.0.25 CVE-2025-12392 Wordfence
4.3 Medium WP Duplicate Page Plugin wp-duplicate-page Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure ≤ 1.7 CVE-2025-12481 Wordfence
6.4 Medium Meta Display Block Plugin meta-display-block Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-12088 Wordfence
6.6 Medium Simple User Import Export Plugin a3-user-importer Content Injection Authenticated (Admin+) CSV Injection ≤ 1.1.7 CVE-2025-13133 Wordfence
6.1 Medium WP Twitter Auto Publish Plugin twitter-auto-publish Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed ≤ 1.7.4 CVE-2025-12079 Wordfence
5.4 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget ≤ 8.3.4 CVE-2025-13196 Wordfence
5.4 Medium Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links Plugin broken-link-checker-seo Broken Access Control Easily Fix/Monitor Internal and External links <= 1.2.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Trashing ≤ 1.2.5 CVE-2025-11734 Wordfence
6.4 Medium everviz Plugin everviz Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1 CVE-2025-11868 Wordfence
4.3 Medium Download Panel Plugin download-panel Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification ≤ 1.3.3 CVE-2025-12961 Wordfence
6.1 Medium Project Honey Pot Spam Trap Plugin project-honey-pot-spam-trap Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-12406 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only