WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,201–6,250 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 125 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Auto Ad Inserter – Increase Google Adsense and Ad Manager Revenue Plugin revenueflex-easy-ads Broken Access Control Increase Google Adsense and Ad Manager Revenue Plugin <= 1.5 - Settings Change ≤ 1.5 Fixed in 1.5.1 CVE-2025-27296 Patchstack
7.1 High Add Linked Images To Gallery Plugin add-linked-images-to-gallery-v01 Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-27277 Patchstack
8.8 High Photo Gallery ( Responsive ) Plugin photo-gallery-pearlbells Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 4.0 CVE-2025-27276 Patchstack
7.5 High VG PostCarousel Plugin vg-postcarousel Local File Inclusion ≤ 1.1 CVE-2025-27272 Patchstack
7.1 High Eventer Plugin eventer Cross-Site Scripting WordPress Event & Booking Manager Plugin plugin < 3.9.9 - Reflected Cross Site Scripting (XSS) No login needed ≤ 3.9.9 Fixed in 3.9.9 CVE-2025-22635 Patchstack
7.1 High WooCommerce Pricing – Product Pricing Plugin woo-pricing-table Cross-Site Scripting Product Pricing plugin <= 1.0.9 - Cross Site Scripting (XSS) No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-22632 Patchstack
7.1 High Marketing Automation Plugin marketing-automation Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.6.8 Fixed in 1.2.6.9 CVE-2025-22631 Patchstack
7.1 High Responsive Modal Builder for High Conversion – Easy Popups Plugin easy-popups Cross-Site Scripting Easy Popups plugin <= 1.5.0 - Cross Site Scripting (XSS) No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-26774 Patchstack
7.5 High Calculator Builder Plugin calculator-builder Local File Inclusion No login needed ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-26760 Patchstack
7.5 High FULL Customer Plugin full-customer Local File Inclusion Cliente plugin <= 3.1.26 - Local File Inclusion No login needed ≤ 3.1.26 Fixed in 3.1.27 CVE-2025-26757 Patchstack
8.8 High A1POST.BG Shipping for Woo Plugin a1post-bg-shipping-for-woocommerce Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 1.5 Fixed in 1.5.1 CVE-2025-27012 Patchstack
7.1 High Magic the Gathering Card Tooltips Plugin magic-the-gathering-card-tooltips Cross-Site Scripting No login needed ≤ 3.5.0 Fixed in 3.6.0 CVE-2025-26756 Patchstack
7.2 High Vulnerability: SMTP for Amazon SES Plugin smtp-amazon-ses Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed ≤ 1.8 CVE-2025-0957 Wordfence
7.2 High SMTP for Sendinblue – YaySMTP Plugin smtp-sendinblue Cross-Site Scripting YaySMTP <= 1.2 - Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed ≤ 1.2 CVE-2025-0953 Wordfence
7.2 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid Cross-Site Scripting YaySMTP <= 1.4 - Unauthenticated Stored Cross-Site Scripting via Email Logs No login needed ≤ 1.4 CVE-2025-0918 Wordfence
7.2 High Migration, Backup, Staging – WPvivid Plugin wpvivid-backuprestore Arbitrary File Upload WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file ≤ 0.9.112 CVE-2024-13869 Wordfence
7.5 High IP2Location Country Blocker Plugin ip2location-country-blocker Broken Access Control Missing Authorization to Unauthenticated Information Exposure via admin_init Function No login needed ≤ 2.38.8 CVE-2025-1361 Wordfence
7.5 High LTL Freight Quotes – Purolator Edition Plugin ltl-freight-quotes-purolator-freight-edition SQL Injection Purolator Edition <= 2.2.3 - Unauthenticated SQL Injection No login needed ≤ 2.2.3 CVE-2024-13474 Wordfence
7.3 High Custom Post Type Date Archives Plugin custom-post-type-date-archives Broken Access Control Missing Authorization to Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.7.1 CVE-2025-1510 Wordfence
7.2 High Mambo Importer Plugin mambo-joomla-importer PHP Object Injection Authenticated (Administrator+) PHP Object Injection ≤ 1.0 CVE-2024-13899 Wordfence
7.3 High Show Me The Cookies Plugin show-me-the-cookies Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.0 CVE-2025-1509 Wordfence
8.8 High Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates Plugin responsive-addons-for-elementor Local File Inclusion Free Elementor Addons Plugin and Elementor Templates <= 1.6.4 - Authenticated (Contributor+) Local File Inclusion ≤ 1.6.4 CVE-2024-13353 Wordfence
7.5 High Events Manager – Calendar, Bookings, Tickets, and more! Plugin events-manager SQL Injection Calendar, Bookings, Tickets, and more! <= 6.6.3 - Unauthenticated SQL Injection via Event Status Parameter No login needed ≤ 6.6.3 CVE-2024-11260 Wordfence
7.2 High Lenix Elementor Leads addon Plugin lenix-elementor-leads-addon Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via URL Form Field No login needed ≤ 1.8.2 CVE-2025-1039 Wordfence
7.3 High WooCommerce Food - Restaurant Menu & Food ordering Plugin Arbitrary Shortcode Execution Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution via ids No login needed ≤ 3.3.2 CVE-2024-13792 Wordfence
7.5 High LTL Freight Quotes – GlobalTranz Edition Plugin ltl-freight-quotes-globaltranz-edition SQL Injection GlobalTranz Edition <= 2.3.11 - Unauthenticated SQL Injection No login needed ≤ 2.3.11 CVE-2024-13476 Wordfence
8.1 High Ultimate Classified Listings Plugin ultimate-classified-listings Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover No login needed ≤ 1.5 CVE-2024-13753 Wordfence
7.2 High WPMobile.App Plugin wpappninja Open Redirect Open Redirect via 'redirect' Parameter No login needed ≤ 11.56 CVE-2024-13888 Wordfence
7.5 High Small Package Quotes – Worldwide Express Edition Plugin small-package-quotes-wwe-edition SQL Injection Worldwide Express Edition <= 5.2.18 - Unauthenticated SQL Injection No login needed ≤ 5.2.18 CVE-2024-13534 Wordfence
7.5 High Small Package Quotes – USPS Edition Plugin small-package-quotes-usps-edition SQL Injection USPS Edition <= 1.3.5 - Unauthenticated SQL Injection No login needed ≤ 1.3.5 CVE-2024-13533 Wordfence
7.5 High Small Package Quotes – For Customers of FedEx Plugin small-package-quotes-fedex-edition SQL Injection For Customers of FedEx <= 4.3.1 - Unauthenticated SQL Injection No login needed ≤ 4.3.1 CVE-2024-13491 Wordfence
7.5 High LTL Freight Quotes – SAIA Edition Plugin ltl-freight-quotes-saia-edition SQL Injection SAIA Edition <= 2.2.10 - Unauthenticated SQL Injection No login needed ≤ 2.2.10 CVE-2024-13483 Wordfence
7.5 High LTL Freight Quotes – ABF Freight Edition Plugin ltl-freight-quotes-abf-freight-edition SQL Injection ABF Freight Edition <= 3.3.7 - Unauthenticated SQL Injection No login needed ≤ 3.3.7 CVE-2024-13485 Wordfence
7.5 High LTL Freight Quotes – R+L Carriers Edition Plugin ltl-freight-quotes-rl-edition SQL Injection R+L Carriers Edition <= 3.3.4 - Unauthenticated SQL Injection No login needed ≤ 3.3.4 CVE-2024-13481 Wordfence
7.5 High LTL Freight Quotes – SEFL Edition Plugin ltl-freight-quotes-sefl-edition SQL Injection SEFL Edition <= 3.2.4 - Unauthenticated SQL Injection No login needed ≤ 3.2.4 CVE-2024-13479 Wordfence
7.5 High LTL Freight Quotes – TForce Edition Plugin ltl-freight-quotes-ups-edition SQL Injection TForce Edition <= 3.6.4 - Unauthenticated SQL Injection No login needed ≤ 3.6.4 CVE-2024-13478 Wordfence
7.2 High YaySMTP Plugin yaysmtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed 2.4.9 – 2.6.2 CVE-2025-0916 Wordfence
7.5 High LTL Freight Quotes – Old Dominion Edition Plugin SQL Injection Old Dominion Edition <= 4.2.10 - Unauthenticated SQL Injection No login needed ≤ 4.2.10 CVE-2024-13489 Wordfence
7.5 High Team Builder For WPBakery Page Builder(Formerly Visual Composer) Plugin team-builder-for-wpbakery-page-builder Local File Inclusion Authenticated (Contributor+) Local File Inclusion ≤ 1.0 CVE-2024-13592 Wordfence
7.5 High Trash Duplicate and 301 Redirect Plugin trash-duplicate-and-301-redirect Broken Access Control Missing Authorization to Unauthenticated Arbitrary Post Deletion No login needed ≤ 1.9 CVE-2024-13468 Wordfence
7.2 High Subscribe2 – Form, Email Subscribers & Newsletters Plugin subscribe2 Cross-Site Scripting Form, Email Subscribers & Newsletters <= 10.43 - Unauthenticated Stored Cross-Site Scripting via IP Parameter No login needed ≤ 10.43 CVE-2024-11582 Wordfence
8.6 High Paid Videochat Turnkey Site Plugin ppv-live-webcams Arbitrary File Deletion No login needed ≤ 7.2.12 Fixed in 7.3 CVE-2025-22663 Patchstack
7.5 High Atarim Plugin atarim-visual-collaboration Broken Access Control Arbitrary Content Deletion No login needed ≤ 4.0.9 Fixed in 4.1.0 CVE-2025-22657 Patchstack
8.1 High Cookie Monster Plugin cookie-monster Local File Inclusion No login needed ≤ 1.2.2 CVE-2025-22656 Patchstack
8.5 High Distance Rate Shipping for WooCommerce Plugin distance-rate-shipping-for-woocommerce-pro SQL Injection ≤ 1.3.4 CVE-2025-22639 Patchstack
7.2 High FormCraft - Premium WordPress Form Builder Plugin Cross-Site Scripting Premium WordPress Form Builder <= 3.9.11 - Unauthenticated Stored Cross-Site Scripting via SVG File Upload No login needed ≤ 3.9.11 CVE-2025-0817 Wordfence
7.5 High Uncode Theme Path Traversal Unauthenticated Arbitrary File Read in uncode_admin_get_oembed No login needed ≤ 2.9.1.6 CVE-2024-13681 Wordfence
7.2 High Post SMTP Plugin post-smtp Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 3.0.2 CVE-2025-0521 Wordfence
7.3 High PressMart - Modern Elementor WooCommerce Theme Arbitrary Shortcode Execution Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.16 CVE-2024-13797 Wordfence
7.2 High Super Testimonials Plugin sola-testimonials Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting No login needed ≤ 4.0.1 CVE-2024-13704 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only