WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,051–6,100 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | AudioTube | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.0.3 |
CVE-2025-11801 |
Wordfence | |
| 5.3 Medium | Checkbox | Broken Access Control Missing Authorization to Unauthenticated Log Clearing No login needed |
≤ 2.8.10 |
CVE-2025-12170 |
Wordfence | |
| 4.3 Medium | Return Refund and Exchange For WooCommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Refund Request Cancellation |
≤ 4.5.5 |
CVE-2025-12086 |
Wordfence | |
| 6.4 Medium | Stock Tools | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-11765 |
Wordfence | |
| 6.4 Medium | Pollcaster Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12661 |
Wordfence | |
| 6.1 Medium | Tainacan | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2025-12746 |
Wordfence | |
| 6.4 Medium | Padlet Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3 |
CVE-2025-12660 |
Wordfence | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion |
≤ 3.3.0 |
CVE-2025-12169 |
Wordfence | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Restore |
≤ 3.3.1 |
CVE-2025-12022 |
Wordfence | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Trash Empty |
≤ 3.3.1 |
CVE-2025-12085 |
Wordfence | |
| 4.3 Medium | ELEX WordPress HelpDesk & Customer Ticketing System | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Ticket Restore |
≤ 3.3.1 |
CVE-2025-12023 |
Wordfence | |
| 5.3 Medium | LearnPress – WordPress LMS | Broken Access Control WordPress LMS Plugin <= 4.2.9.4 - Missing Authorization to Unauthenticated Arbitrary Callback Execution to Information Exposure No login needed |
≤ 4.2.9.4 |
CVE-2025-11368 |
Wordfence | |
| 6.4 Medium | Multiple Plugins and Themes <= (Various Versions) | Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via lightGallery JavaScript Library |
≤ 1.0.5, ≤ 1.1.9, ≤ 1.2.5.1, … |
CVE-2025-5092 |
Wordfence | |
| 6.8 Medium | Attention Bar | SQL Injection Admin+ SQLi |
≤ 0.7.2.1 |
CVE-2025-12502 |
WPScan | |
| 5.3 Medium | Ultimate Member Widgets for Elementor | Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 2.3 |
CVE-2025-12778 |
Wordfence | |
| 4.3 Medium | SiteSEO – SEO Simplified | Broken Access Control SEO Simplified <= 1.3.2 - Insecure Direct Object Reference to Sensitive Post Meta Disclosure |
≤ 1.3.2 |
CVE-2025-13085 |
Wordfence | |
| 5.3 Medium | SureForms | Cross-Site Request Forgery Cross-Site Request Forgery Protection Bypass via Improper Nonce Distribution No login needed |
≤ 1.13.1 |
CVE-2025-12535 |
Wordfence | |
| 4.3 Medium | WP Login and Register using JWT | Broken Access Control Missing Authorization to Authenticated (Subscriber+) API Key Exposure |
≤ 3.0.0 |
CVE-2025-12822 |
Wordfence | |
| 5.3 Medium | SiteSEO – SEO Simplified | Broken Access Control SEO Simplified <= 1.3.2 - Improper Authorization to Authenticated Settings Reset No login needed |
≤ 1.3.2 |
CVE-2025-12814 |
Wordfence | |
| 5.4 Medium | Responsive Lightbox & Gallery | Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery |
≤ 2.5.3 |
CVE-2025-12359 |
Wordfence | |
| 6.5 Medium | Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Data Export and Slug Update No login needed |
≤ 8.5.2 |
CVE-2025-12174 |
Wordfence | |
| 6.4 Medium | FunnelKit – Funnel Builder for WooCommerce Checkout | Cross-Site Scripting Funnel Builder for WooCommerce Checkout <= 3.13.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via wfop_phone Shortcode |
≤ 3.13.1.2 |
CVE-2025-12878 |
Wordfence | |
| 6.4 Medium | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.14.8 |
CVE-2025-13054 |
Wordfence | |
| 4.3 Medium | WSChat – WordPress Live Chat | Broken Access Control WordPress Live Chat <= 3.1.6 - Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 3.1.6 |
CVE-2025-12751 |
Wordfence | |
| 6.4 Medium | Pet-Manager – Petfinder | Cross-Site Scripting Petfinder <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via kwm-petfinder Shortcode |
≤ 3.6.1 |
CVE-2025-12710 |
Wordfence | |
| 5.3 Medium | Booking Plugin for WordPress Appointments – Time Slot | Broken Access Control Time Slot <= 1.4.7 - Unauthenticated Arbitrary Email Sending No login needed |
≤ 1.4.7 |
CVE-2025-12842 |
Wordfence | |
| 5.3 Medium | Quiz Maker | Information Disclosure Unauthenticated Sensitive Information Exposure No login needed |
≤ 6.7.0.80 |
CVE-2025-12426 |
Wordfence | |
| 5.3 Medium | Email Subscribers & Newsletters | Denial of Service Missing Authentication to Unauthenticated Mailing Queue Trigger No login needed |
≤ 5.9.10 |
CVE-2025-12349 |
Wordfence | |
| 5.3 Medium | New User Approve | Information Disclosure Unauthenticated Sensitive Information Disclosure via Type Juggling No login needed |
≤ 3.0.9 |
CVE-2025-12770 |
Wordfence | |
| 5.3 Medium | YITH WooCommerce Wishlist | Broken Access Control Unauthenticated Insecure Direct Object Reference to Unauthenticated Wishlist Rename No login needed |
≤ 4.10.0 |
CVE-2025-12427 |
Wordfence | |
| 6.4 Medium | Royal Elementor Addons and Templates | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.1036 |
CVE-2025-6251 |
Wordfence | |
| 5.3 Medium | YITH WooCommerce Wishlist | Information Disclosure Unauthenticated Wishlist Token Disclosure to Wishlist Item Deletion No login needed |
≤ 4.10.0 |
CVE-2025-12777 |
Wordfence | |
| 5.3 Medium | Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more | Information Disclosure Track Conversions and Analytics, Google Ads, TikTok and more <= 1.49.2 - Unauthenticated Information Exposure No login needed |
≤ 1.49.2 |
CVE-2025-12545 |
Wordfence | |
| 6.4 Medium | Icon List Block – Add Icon-Based Lists with Custom Styles | Server-Side Request Forgery Add Icon-Based Lists with Custom Styles <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery |
≤ 1.2.1 |
CVE-2025-12376 |
Wordfence | |
| 6.8 Medium | AI Engine | Server-Side Request Forgery Authenticated (Editor+) Server-Side Request Forgery |
≤ 3.1.8 |
CVE-2025-8084 |
Wordfence | |
| 5.8 Medium | WP Migrate Lite | Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 2.7.6 |
CVE-2025-11427 |
Wordfence | |
| 6.4 Medium | Enable SVG, WebP, and ICO Upload | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploads |
≤ 1.1.2 |
CVE-2025-12457 |
Wordfence | |
| 5.3 Medium | Restrictions for BuddyPress | Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed |
≤ 1.5.2 |
CVE-2025-12391 |
Wordfence | |
| 6.4 Medium | Photonic Gallery & Lightbox for Flickr, SmugMug & Others | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Caption Attribute |
≤ 3.21 |
CVE-2025-12691 |
Wordfence | |
| 4.3 Medium | wModes – Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce | Broken Access Control Catalog Mode, Product Pricing, Enquiry Forms & Promotions | for WooCommerce <= 1.2.2 - Missing Authorization to Sensitive Information Disclosure |
≤ 1.2.2 |
CVE-2025-12639 |
Wordfence | |
| 5.3 Medium | Cryptocurrency Payment Gateway for WooCommerce | Broken Access Control Missing Authorization to Unauthenticated Tracking Status Update No login needed |
≤ 2.0.25 |
CVE-2025-12392 |
Wordfence | |
| 4.3 Medium | WP Duplicate Page | Broken Access Control Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure |
≤ 1.7 |
CVE-2025-12481 |
Wordfence | |
| 6.4 Medium | Meta Display Block | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-12088 |
Wordfence | |
| 6.6 Medium | Simple User Import Export | Content Injection Authenticated (Admin+) CSV Injection |
≤ 1.1.7 |
CVE-2025-13133 |
Wordfence | |
| 6.1 Medium | WP Twitter Auto Publish | Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed |
≤ 1.7.4 |
CVE-2025-12079 |
Wordfence | |
| 5.4 Medium | Element Pack Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map widget |
≤ 8.3.4 |
CVE-2025-13196 |
Wordfence | |
| 5.4 Medium | Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links | Broken Access Control Easily Fix/Monitor Internal and External links <= 1.2.5 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post Trashing |
≤ 1.2.5 |
CVE-2025-11734 |
Wordfence | |
| 6.4 Medium | everviz | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-11868 |
Wordfence | |
| 4.3 Medium | Download Panel | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Modification |
≤ 1.3.3 |
CVE-2025-12961 |
Wordfence | |
| 6.1 Medium | Project Honey Pot Spam Trap | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0.1 |
CVE-2025-12406 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.