WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,151–6,200 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 124 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.9 Medium Poll Maker – Versus Polls, Anonymous Polls, Image Polls Plugin poll-maker SQL Injection Versus Polls, Anonymous Polls, Image Polls <= 6.0.7 - Authenticated (Administrator+) SQL Injection via `filterbyauthor` Parameter ≤ 6.0.7 CVE-2025-12620 Wordfence
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 5.1.9.4 CVE-2025-12891 Wordfence
5.3 Medium SureForms Plugin sureforms Broken Access Control Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.13.1 CVE-2025-12536 Wordfence
5.3 Medium Survey Maker Plugin survey-maker Broken Access Control Missing Authorization to Unauthenticated Limited Option Update No login needed ≤ 5.1.9.4 CVE-2025-12892 Wordfence
5.3 Medium Welcart e-Commerce Plugin usc-e-shop Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.11.24 CVE-2025-12979 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 2.0.5 - Authenticated (Author+) Insecure Direct Object Reference ≤ 2.0.5 CVE-2025-12366 Wordfence
6.5 Medium Data Tables Generator by Supsystic Plugin data-tables-generator-by-supsystic Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion ≤ 1.10.45 CVE-2025-12089 Wordfence
6.5 Medium Specific Content For Mobile – Customize the mobile version without redirections Plugin specific-content-for-mobile SQL Injection Customize the mobile version without redirections <= 0.5.5 - Authenticated (Contributor+) SQL Injection ≤ 0.5.5 CVE-2025-11454 Wordfence
4.3 Medium WP Import – Ultimate CSV XML Importer Plugin wp-ultimate-csv-importer Broken Access Control Ultimate CSV XML Importer for WordPress <= 7.33 - Missing Authorization to Authenticated (Author+) Sensitive Information Exposure ≤ 7.33 CVE-2025-12732 Wordfence
4.3 Medium Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images Plugin Broken Access Control Auto Generate & Bulk Update Alt Texts For Images <= 1.8.3 - Missing Authorization to Authenticated (Subscriber+) API Key Deletion ≤ 1.8.3 CVE-2025-12113 Wordfence
4.4 Medium MembershipWorks Plugin memberfindme Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 6.14 CVE-2025-12018 Wordfence
4.3 Medium Asgaros Forum Plugin asgaros-forum Cross-Site Request Forgery Cross-Site Request Forgery to Subscription Settings Update No login needed ≤ 3.2.1 CVE-2025-12901 Wordfence
4.3 Medium GeoDirectory – WP Business Directory Plugin and Classified Listings Directory Plugin geodirectory Broken Access Control WP Business Directory Plugin and Classified Listings Directory <= 2.8.139 - Missing Authorization to Authenticated (Author+) Arbitrary Image Attachment ≤ 2.8.139 CVE-2025-12833 Wordfence
4.3 Medium Wishlist and Save for later for Woocommerce Plugin aco-wishlist-for-woocommerce Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Wishlist Item Deletion ≤ 1.1.22 CVE-2025-12087 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Price Manipulation All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Missing Payment Verification to Unauthenticated Payment Bypass No login needed ≤ 1.1.27 CVE-2025-12788 Wordfence
4.3 Medium Classified Listing – AI-Powered Classified ads & Business Directory Plugin classified-listing Broken Access Control AI-Powered Classified ads & Business Directory Plugin <= 5.2.0 - Missing Authorization to Authenticated (Subscriber+) Listing Types Tampering ≤ 5.2.0 CVE-2025-12953 Wordfence
5.3 Medium Hydra Booking – All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings Plugin hydra-booking Broken Access Control All in One Appointment Booking System | Appointment Scheduling, Booking Calendar & WooCommerce Bookings <= 1.1.27 - Unauthenticated Arbitrary Booking Cancellation via Weak Hash Generation No login needed ≤ 1.1.27 CVE-2025-12787 Wordfence
5.3 Medium Make Email Customizer for WooCommerce Plugin Broken Access Control Subscriber+ Arbitrary Options Update No login needed ≤ 1.0.6 CVE-2025-11237 WPScan
6.4 Medium GitHub Gist Shortcode Plugin github-gist-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.2 CVE-2025-12667 Wordfence
6.4 Medium Live Photos on Plugin live-photos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 0.1 CVE-2025-12651 Wordfence
4.4 Medium Featured Image Plugin featured-image Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.1 CVE-2025-12019 Wordfence
5.3 Medium Add Multiple Marker Plugin add-multiple-marker Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 1.2 CVE-2025-11999 Wordfence
6.4 Medium Coon Google Maps Plugin coon-google-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12662 Wordfence
5.3 Medium Crypto Tool Plugin crypto Information Disclosure Unauthenticated Information Exposure via Global Authentication State No login needed ≤ 2.22 CVE-2025-11986 Wordfence
6.4 Medium Include fussball.de Widgets Plugin include-fussball-de-widgets Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'api' and 'type' ≤ 4.0.0 CVE-2025-11129 Wordfence
5.4 Medium The Total Book Project Plugin the-total-book-project Broken Access Control Insecure Direct Object Reference to Authenticated (Contributor+) Book Manipulation ≤ 1.0 CVE-2025-12126 Wordfence
6.4 Medium Jeba Cute forkit Plugin jeba-cute-forkit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12663 Wordfence
6.4 Medium Simple Donate Plugin simple-donate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11882 Wordfence
6.4 Medium Twitter Feed Plugin ot-twitter-feed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-11860 Wordfence
6.4 Medium WP Count Down Timer Plugin wp-count-down-timer Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.1 CVE-2025-12668 Wordfence
6.4 Medium Preload Current Images Plugin preload-current-images Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.3 CVE-2025-12658 Wordfence
6.4 Medium Woocommerce – Products By Custom Tax Plugin woocommerce-products-by-custom-tax Cross-Site Scripting Products By Custom Tax <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.2 CVE-2025-11821 Wordfence
4.4 Medium Squirrels Auto Inventory Plugin squirrels-auto-inventory Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2025-12631 Wordfence
6.4 Medium Paypal Donation Shortcode Plugin paypal-donation-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.1 CVE-2025-11859 Wordfence
5.3 Medium Wisly Plugin wisly Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 1.0.0 CVE-2025-11532 Wordfence
6.4 Medium WP-Iconics Plugin wp-iconics Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.0.4 CVE-2025-12671 Wordfence
4.3 Medium Ninja Countdown Plugin ninja-countdown Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Countdown Deletion ≤ 1.5.0 CVE-2025-12665 Wordfence
4.3 Medium Private Google Calendars Plugin private-google-calendars Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Reset ≤ 20250811 CVE-2025-12526 Wordfence
6.4 Medium Precise Columns Plugin precise-columns Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11869 Wordfence
6.4 Medium Chart Expert Plugin chart-expert Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0 CVE-2025-12753 Wordfence
6.4 Medium Magazine Companion Plugin bnm-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2025-11828 Wordfence
6.4 Medium Share to Google Classroom Plugin share-to-google-classroom Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via share_to_google Shortcode ≤ 1.0 CVE-2025-12711 Wordfence
6.1 Medium YSlider Plugin yslider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.1 CVE-2025-12590 Wordfence
6.4 Medium Eventbee Ticketing Widget Plugin eventbee-ticketing-widget Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-11856 Wordfence
4.3 Medium USB Qr Code Scanner For Woocommerce Plugin usb-qr-code-scanner-for-woocommerce Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-12588 Wordfence
6.1 Medium WP-OAuth Plugin wp-oauth Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 0.4.1 CVE-2025-12021 Wordfence
4.9 Medium Double the Donation Plugin double-the-donation Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.0.0 CVE-2025-12020 Wordfence
6.4 Medium Flickr Show Plugin wp-flickrshow Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5 CVE-2025-12672 Wordfence
6.1 Medium WP-Walla Plugin wp-walla Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.5.3.5 CVE-2025-12589 Wordfence
4.3 Medium WP Custom Admin Login Page Logo Plugin wp-custom-login-page-logo Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.4.8.4 CVE-2025-12132 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only