WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,101–6,150 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 123 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium ArtiBot Free Chat Bot for WebSites Plugin artibot Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed ≤ 1.1.7 CVE-2025-12078 Wordfence
4.3 Medium The Permalinks Cascade Plugin the-permalinks-cascade Broken Access Control Missing Authorization To Authenticated (Subscriber+) Plugin Settings Update ≤ 2.2 CVE-2025-12372 Wordfence
6.4 Medium RTMKit Addons Plugin rometheme-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Accordion Repeater Block Attribute ≤ 1.6.5 CVE-2025-8609 Wordfence
6.5 Medium ACF Flexible Layouts Manager Plugin acf-flexible-layouts-manager Broken Access Control Missing Authorization to Unauthenticated Custom Field Update No login needed ≤ 1.1.6 CVE-2025-12937 Wordfence
4.3 Medium WP Admin Microblog Plugin wp-admin-microblog Cross-Site Request Forgery Cross-Site Request Forgery to Message Creation No login needed ≤ 3.1.1 CVE-2025-12173 Wordfence
4.3 Medium Top Friends Plugin top-friends Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 0.3 CVE-2025-12827 Wordfence
6.4 Medium Gutenify - Visual Site Builder Blocks & Site Templates Plugin gutenify Cross-Site Scripting Visual Site Builder Blocks & Site Templates <= 1.5.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Count Up block ≤ 1.5.9 CVE-2025-8605 Wordfence
6.4 Medium Local Syndication Plugin local-syndication Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery via Shortcode ≤ 1.5a CVE-2025-12962 Wordfence
6.4 Medium CSV to SortTable Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.2 CVE-2025-12823 Wordfence
6.1 Medium Like-it Plugin like-it Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.2 CVE-2025-12404 Wordfence
4.3 Medium Coil Web Monetization Plugin coil-web-monetization Cross-Site Request Forgery No login needed ≤ 2.0.2 CVE-2025-9625 Wordfence
6.4 Medium VK All in One Expansion Unit Plugin vk-all-in-one-expansion-unit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.112.1 CVE-2025-11265 Wordfence
6.4 Medium VK All in One Expansion Unit Plugin vk-all-in-one-expansion-unit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 9.112.1 CVE-2025-11267 Wordfence
5.4 Medium Post Type Switcher Plugin post-type-switcher Broken Access Control Insecure Direct Object Reference to Authenticated (Author+) Post Type Change ≤ 4.0.0 CVE-2025-12524 Wordfence
5.4 Medium Classified Listing – Classified ads & Business Directory Plugin classified-listing Arbitrary Shortcode Execution Classified ads & Business Directory Plugin <= 5.0.3 - Authenticated (Subscriber+) Arbitrary Shortcode Execution via Listing Description ≤ 5.0.3 CVE-2025-7711 Wordfence
5.3 Medium Contest Gallery Plugin contest-gallery Broken Access Control Missing Authorization No login needed ≤ 28.0.2 CVE-2025-12849 Wordfence
4.3 Medium Image Gallery – Photo Grid & Video Gallery Plugin modula-best-grid-gallery Arbitrary File Deletion Photo Grid & Video Gallery <= 2.12.28 - Improper Authorization to Authenticated (Author+) Arbitrary Image File Move ≤ 2.12.28 CVE-2025-12494 Wordfence
6.5 Medium WP Project Manager Plugin wedevs-project-manager SQL Injection Authenticated (Subscriber+) SQL Injection via 'completed_at_operator' ≤ 2.6.26 CVE-2025-8994 Wordfence
4.3 Medium All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic Plugin all-in-one-seo-pack Broken Access Control Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic <= 4.8.9 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Deletion ≤ 4.8.9 CVE-2025-12847 Wordfence
4.3 Medium Qi Blocks Plugin qi-blocks Broken Access Control Missing Authorization to Arbitrary Attachment Resize ≤ 1.4.3 CVE-2025-12182 Wordfence
4.9 Medium School Management System – WPSchoolPress Plugin wpschoolpress SQL Injection WPSchoolPress <= 2.2.23 - Authenticated (Administrator+) SQL Injection ≤ 2.2.23 CVE-2025-11981 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.12.0 - Missing Authorization to Authenticated (Author+) Multiple Gallery Actions ≤ 1.12.0 CVE-2025-12377 Wordfence
5.3 Medium JetFormBuilder Plugin jetformbuilder Broken Access Control No login needed ≤ 3.5.3 Fixed in 3.5.4 CVE-2025-64384 Patchstack
6.5 Medium Qi Blocks Plugin qi-blocks Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64383 Patchstack
4.3 Medium Order Export & Order Import for WooCommerce Plugin order-import-export-for-woocommerce Broken Access Control ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-64382 Patchstack
6.5 Medium Booking Calendar Plugin booking Cross-Site Scripting ≤ 10.14.7 Fixed in 10.14.8 CVE-2025-64381 Patchstack
6.5 Medium Booster for WooCommerce Plugin woocommerce-jetpack Cross-Site Scripting ≤ 7.3.2 Fixed in 7.4.0 CVE-2025-64380 Patchstack
4.3 Medium Booster for WooCommerce Plugin woocommerce-jetpack Broken Access Control ≤ 7.4.0 Fixed in 7.5.0 CVE-2025-64379 Patchstack
5.3 Medium YOP Poll Plugin yop-poll Broken Access Control No login needed ≤ 6.5.38 Fixed in 6.5.39 CVE-2025-64370 Patchstack
6.5 Medium Contact Form Email Plugin contact-form-to-email Broken Access Control ≤ 1.3.58 Fixed in 1.3.59 CVE-2025-64369 Patchstack
6.5 Medium Analytics Germanized for Google Analytics Plugin ga-germanized Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-64292 Patchstack
5.3 Medium ChatBot Plugin chatbot Broken Access Control No login needed ≤ 7.3.9 Fixed in 7.4.0 CVE-2025-64277 Patchstack
6.5 Medium Survey Maker Plugin survey-maker Broken Access Control ≤ 5.1.9.4 Fixed in 5.1.9.5 CVE-2025-64276 Patchstack
6.5 Medium Booking Manager Plugin booking-manager Cross-Site Scripting ≤ 2.1.17 Fixed in 2.1.18 CVE-2025-64275 Patchstack
4.3 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Broken Access Control ≤ 3.4.4 Fixed in 3.4.5 CVE-2025-64274 Patchstack
4.3 Medium WP Plugin Manager Plugin wp-plugin-manager Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-64271 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Broken Access Control ≤ 1.2.150 Fixed in 1.2.151 CVE-2025-64269 Patchstack
4.3 Medium WooCommerce Ultimate Points And Rewards Plugin woocommerce-ultimate-points-and-rewards Information Disclosure Sensitive Data Exposure ≤ 2.10.2 Fixed in 2.10.3 CVE-2025-64267 Patchstack
4.3 Medium Frontend File Manager Plugin nmedia-user-file-uploader Broken Access Control ≤ 23.2 Fixed in 23.3 CVE-2025-64265 Patchstack
5.9 Medium Popup addon for Ninja Forms Plugin popup-addon-for-ninja-forms Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-64264 Patchstack
5.4 Medium WP Content Pilot Plugin wp-content-pilot Broken Access Control ≤ 2.1.7 Fixed in 2.1.8 CVE-2025-64263 Patchstack
6.5 Medium Auto Prune Posts Plugin auto-prune-posts Cross-Site Request Forgery No login needed ≤ 3.0.0 Fixed in 3.1.0 CVE-2025-64262 Patchstack
5.4 Medium Appointment Booking Calendar Plugin appointment-booking-calendar Broken Access Control ≤ 1.3.95 Fixed in 1.3.96 CVE-2025-64261 Patchstack
5.3 Medium Theater Plugin theatre Broken Access Control No login needed ≤ 0.18.8 Fixed in 0.19 CVE-2025-64259 Patchstack
6.4 Medium WordPress Content Flipper Plugin wp-flipper Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11769 Wordfence
5.3 Medium WP Headless CMS Framework Plugin wp-rest-headless Other Unauthenticated Protection Mechanism Bypass No login needed ≤ 1.15 CVE-2025-11260 Wordfence
6.4 Medium Angel – Fashion Model Agency WordPress CMS Theme Cross-Site Scripting Fashion Model Agency WordPress CMS Theme <= 3.2.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.2.3 CVE-2025-10295 Wordfence
4.3 Medium Convert WebP & AVIF | Quicq | Best image optimizer and compression plugin | Improve your Google Pagespeed Plugin quicq Broken Access Control Missing Authorization to Authenticated (Subscriber+) Afosto Disconnect ≤ 2.0.0 CVE-2025-12015 Wordfence
6.4 Medium Save as PDF Button Plugin save-as-pdf Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via restpackpdfbutton Shortcode ≤ 1.9.2 CVE-2025-8397 Wordfence
5.3 Medium Comment Edit Core – Simple Comment Editing Plugin simple-comment-editing Information Disclosure Simple Comment Editing <= 3.1.0 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.1.0 CVE-2025-12681 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only