WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,151–6,200 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.9 Medium | Poll Maker – Versus Polls, Anonymous Polls, Image Polls | SQL Injection Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter |
≤ 6.0.7 |
CVE-2025-12620 |
Wordfence | |
| 5.3 Medium | Survey Maker | Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 5.1.9.4 |
CVE-2025-12891 |
Wordfence | |
| 5.3 Medium | SureForms | Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed |
≤ 1.13.1 |
CVE-2025-12536 |
Wordfence | |
| 5.3 Medium | Survey Maker | Broken Access Control Missing Authorization to Unauthenticated Limited Option Update No login needed |
≤ 5.1.9.4 |
CVE-2025-12892 |
Wordfence | |
| 5.3 Medium | Welcart e-Commerce | Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 2.11.24 |
CVE-2025-12979 |
Wordfence | |
| 4.3 Medium | Page Builder: Pagelayer – Drag and Drop website builder | Broken Access Control Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference |
≤ 2.0.5 |
CVE-2025-12366 |
Wordfence | |
| 6.5 Medium | Data Tables Generator by Supsystic | Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion |
≤ 1.10.45 |
CVE-2025-12089 |
Wordfence | |
| 6.5 Medium | Specific Content For Mobile – Customize the mobile version without redirections | SQL Injection Customize the mobile version without redirections <= 0.5.5 - Authenticated (Contributor+) SQL Injection |
≤ 0.5.5 |
CVE-2025-11454 |
Wordfence | |
| 4.3 Medium | WP Import – Ultimate CSV XML Importer | Broken Access Control Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure |
≤ 7.33 |
CVE-2025-12732 |
Wordfence | |
| 4.3 Medium | Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images | Broken Access Control Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion |
≤ 1.8.3 |
CVE-2025-12113 |
Wordfence | |
| 4.4 Medium | MembershipWorks | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 6.14 |
CVE-2025-12018 |
Wordfence | |
| 4.3 Medium | Asgaros Forum | Cross-Site Request Forgery Cross-Site Request Forgery to Subscription Settings Update No login needed |
≤ 3.2.1 |
CVE-2025-12901 |
Wordfence | |
| 4.3 Medium | GeoDirectory – WP Business Directory Plugin and Classified Listings Directory | Broken Access Control WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment |
≤ 2.8.139 |
CVE-2025-12833 |
Wordfence | |
| 4.3 Medium | Wishlist and Save for later for Woocommerce | Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion |
≤ 1.1.22 |
CVE-2025-12087 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed |
≤ 1.1.27 |
CVE-2025-12788 |
Wordfence | |
| 4.3 Medium | Classified Listing – AI-Powered Classified ads & Business Directory | Broken Access Control AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering |
≤ 5.2.0 |
CVE-2025-12953 |
Wordfence | |
| 5.3 Medium | Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings | Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed |
≤ 1.1.27 |
CVE-2025-12787 |
Wordfence | |
| 5.3 Medium | Make Email Customizer for WooCommerce | Broken Access Control Subscriber+ Arbitrary Options Update No login needed |
≤ 1.0.6 |
CVE-2025-11237 |
WPScan | |
| 6.4 Medium | GitHub Gist Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.2 |
CVE-2025-12667 |
Wordfence | |
| 6.4 Medium | Live Photos on | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 0.1 |
CVE-2025-12651 |
Wordfence | |
| 4.4 Medium | Featured Image | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.1 |
CVE-2025-12019 |
Wordfence | |
| 5.3 Medium | Add Multiple Marker | Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed |
≤ 1.2 |
CVE-2025-11999 |
Wordfence | |
| 6.4 Medium | Coon Google Maps | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12662 |
Wordfence | |
| 5.3 Medium | Crypto Tool | Information Disclosure Unauthenticated Information Exposure via Global Authentication State No login needed |
≤ 2.22 |
CVE-2025-11986 |
Wordfence | |
| 6.4 Medium | Include fussball.de Widgets | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'api' and 'type' |
≤ 4.0.0 |
CVE-2025-11129 |
Wordfence | |
| 5.4 Medium | The Total Book Project | Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Book Manipulation |
≤ 1.0 |
CVE-2025-12126 |
Wordfence | |
| 6.4 Medium | Jeba Cute forkit | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12663 |
Wordfence | |
| 6.4 Medium | Simple Donate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11882 |
Wordfence | |
| 6.4 Medium | Twitter Feed | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-11860 |
Wordfence | |
| 6.4 Medium | WP Count Down Timer | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.1 |
CVE-2025-12668 |
Wordfence | |
| 6.4 Medium | Preload Current Images | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.3 |
CVE-2025-12658 |
Wordfence | |
| 6.4 Medium | Woocommerce – Products By Custom Tax | Cross-Site Scripting Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 2.2 |
CVE-2025-11821 |
Wordfence | |
| 4.4 Medium | Squirrels Auto Inventory | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0.3 |
CVE-2025-12631 |
Wordfence | |
| 6.4 Medium | Paypal Donation Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1 |
CVE-2025-11859 |
Wordfence | |
| 5.3 Medium | Wisly | Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed |
≤ 1.0.0 |
CVE-2025-11532 |
Wordfence | |
| 6.4 Medium | WP-Iconics | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.0.4 |
CVE-2025-12671 |
Wordfence | |
| 4.3 Medium | Ninja Countdown | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Countdown Deletion |
≤ 1.5.0 |
CVE-2025-12665 |
Wordfence | |
| 4.3 Medium | Private Google Calendars | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset |
≤ 20250811 |
CVE-2025-12526 |
Wordfence | |
| 6.4 Medium | Precise Columns | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11869 |
Wordfence | |
| 6.4 Medium | Chart Expert | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.0 |
CVE-2025-12753 |
Wordfence | |
| 6.4 Medium | Magazine Companion | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.3 |
CVE-2025-11828 |
Wordfence | |
| 6.4 Medium | Share to Google Classroom | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via share_to_google Shortcode |
≤ 1.0 |
CVE-2025-12711 |
Wordfence | |
| 6.1 Medium | YSlider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-12590 |
Wordfence | |
| 6.4 Medium | Eventbee Ticketing Widget | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11856 |
Wordfence | |
| 4.3 Medium | USB Qr Code Scanner For Woocommerce | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.0 |
CVE-2025-12588 |
Wordfence | |
| 6.1 Medium | WP-OAuth | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 0.4.1 |
CVE-2025-12021 |
Wordfence | |
| 4.9 Medium | Double the Donation | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 3.0.0 |
CVE-2025-12020 |
Wordfence | |
| 6.4 Medium | Flickr Show | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.5 |
CVE-2025-12672 |
Wordfence | |
| 6.1 Medium | WP-Walla | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.5.3.5 |
CVE-2025-12589 |
Wordfence | |
| 4.3 Medium | WP Custom Admin Login Page Logo | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.4.8.4 |
CVE-2025-12132 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.