WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,201–6,250 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 125 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Document Pro Elementor – Documentation & Knowledge Base Plugin document-pro-elementor Information Disclosure Documentation & Knowledge Base <= 1.0.9 - Unauthenticated Information Exposure No login needed ≤ 1.0.9 CVE-2025-11997 Wordfence
6.4 Medium Geopost Plugin geopost Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2 CVE-2025-12754 Wordfence
6.5 Medium Authors List Plugin authors-list Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure via Limited Method Call in Plugin's Shortcode ≤ 2.0.6.1 CVE-2025-12010 Wordfence
6.4 Medium Skip to Timestamp Plugin skip-to-timestamp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.4.4 CVE-2025-11805 Wordfence
6.4 Medium Nonaki – Drag and Drop Email Template builder and Newsletter Plugin nonaki-email-template-customizer Cross-Site Scripting Drag and Drop Email Template builder and Newsletter plugin for WordPress <= 1.0.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Fields ≤ 1.0.11 CVE-2025-12644 Wordfence
4.3 Medium CTL Arcade Lite Plugin ctl-arcade-lite Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Activation and Deactivation No login needed ≤ 1.0 CVE-2025-11886 Wordfence
5.4 Medium Progress Bar Blocks for Gutenberg Plugin progressmatify-blocks Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG ≤ 1.0.0 CVE-2025-12880 Wordfence
5.5 Medium RandomQuotr Plugin randomquotr Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.4 CVE-2025-12632 Wordfence
4.4 Medium Fleet Manager Plugin fleet Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 2.5.1 CVE-2025-12538 Wordfence
5.3 Medium Find Unused Images Plugin find-unused-images Broken Access Control Missing Authorization to Unauthenticated Arbitrary Attachment Deletion No login needed ≤ 1.0.7 CVE-2025-11996 Wordfence
5.3 Medium Crypto Tool Plugin crypto Arbitrary File Deletion Missing Authentication to Unauthenticated Limited File Deletion No login needed ≤ 2.22 CVE-2025-11988 Wordfence
6.4 Medium My Geo Posts Free Plugin my-geo-posts-free Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2025-11863 Wordfence
6.4 Medium Ungapped Widgets Plugin ungapped-widgets Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1 CVE-2025-12652 Wordfence
6.4 Medium Five9 Live Chat Plugin five9 Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.2 CVE-2025-11829 Wordfence
5.4 Medium Slippy Slider – Responsive Touch Navigation Slider Plugin slippy-slider-responsive-touch-navigation-slider Cross-Site Scripting Responsive Touch Navigation Slider <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-11874 Wordfence
6.4 Medium WP BBCode Plugin wp-bbcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.8.1 CVE-2025-11873 Wordfence
5.3 Medium Shelf Planner Plugin shelf-planner Information Disclosure Unauthenticated Information Exposure via Log Files No login needed ≤ 2.8.1 CVE-2025-11891 Wordfence
6.4 Medium WP Bootstrap Tabs Plugin wp-bootstrap-tabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.4 CVE-2025-11822 Wordfence
5.3 Medium Shelf Planner Plugin shelf-planner Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 2.8.1 CVE-2025-11894 Wordfence
4.3 Medium Gallery Plugin for WordPress – Envira Photo Gallery Plugin envira-gallery-lite Broken Access Control Envira Photo Gallery <= 1.11.0 - Missing Authorization to Authenticated (Contributor+) Gallery Conversion ≤ 1.11.0 CVE-2025-11448 Wordfence
6.4 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Call To Action Widget ≤ 1.1.5 CVE-2025-12837 Wordfence
6.4 Medium Saphali LiqPay for donate Plugin saphali-liqpay-for-donate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.2 CVE-2025-12643 Wordfence
6.5 Medium CYAN Backup Plugin cyan-backup Arbitrary File Deletion Authenticated (Admin+) Arbitrary File Deletion ≤ 2.5.4 CVE-2025-12092 Wordfence
4.9 Medium Quick Featured Images Plugin quick-featured-images SQL Injection Authenticated (Editor+) SQL Injection via delete_orphaned ≤ 13.7.3 CVE-2025-11980 Wordfence
5.3 Medium Academy LMS Pro Plugin Information Disclosure Unauthenticated Sensitive Information Exposure via 'enqueue_social_login_script' No login needed ≤ 3.3.8 CVE-2025-12098 Wordfence
5.3 Medium Flexible Refund and Return Order for WooCommerce Plugin flexible-refund-and-return-order-for-woocommerce Broken Access Control Incorrect Authorization to Authenticated (Contributor+) Refund Status Update No login needed ≤ 1.0.42 CVE-2025-12621 Wordfence
4.3 Medium EventPrime – Events Calendar, Bookings and Tickets Plugin eventprime-event-calendar-management Broken Access Control Events Calendar, Bookings and Tickets <= 4.2.0.0 - Missing Authorization to Authenticated (Subscriber+) Booking Note Creation ≤ 4.2.0.0 CVE-2025-12498 Wordfence
4.4 Medium HTML Forms Plugin html-forms Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.5.5 CVE-2025-12125 Wordfence
6.4 Medium Insert Headers and Footers Code – HT Script Plugin insert-headers-and-footers-script Cross-Site Scripting HT Script <= 1.1.6 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 1.1.6 CVE-2025-12112 Wordfence
6.5 Medium WPFunnels Plugin wpfunnels Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal ≤ 3.6.2 CVE-2025-12000 Wordfence
4.3 Medium Groups Plugin groups Broken Access Control Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Group Join ≤ 3.7.0 CVE-2025-11748 Wordfence
6.1 Medium Mang Board WP Plugin Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.3.1 CVE-2025-12193 Wordfence
4.9 Medium Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI Plugin SQL Injection AI Autotagger with OpenAI <= 3.40.0 - Authenticated (Editor+) SQL Injection ≤ 3.40.0 CVE-2025-11972 Wordfence
5.3 Medium WPFunnels Plugin wpfunnels Broken Access Control Unauthorized User Registration No login needed ≤ 3.6.2 CVE-2025-12353 Wordfence
6.5 Medium Ovatheme Events Manager Plugin Broken Access Control Missing Authorization No login needed ≤ 1.8.6 CVE-2025-7663 Wordfence
6.1 Medium WP2Social Auto Publish Plugin facebook-auto-publish Cross-Site Scripting Reflected Cross-Site Scripting via PostMessage No login needed ≤ 2.4.7 CVE-2025-12064 Wordfence
5.3 Medium Course Booking System Plugin course-booking-system Broken Access Control Missing Authorization to Unauthenticated Booking Data Export No login needed ≤ 6.1.5 CVE-2025-12042 Wordfence
5.3 Medium Download Manager Plugin download-manager Broken Access Control Unauthenticated Cron Trigger due to Hardcoded Cron Key No login needed ≤ 3.3.30 CVE-2025-12177 Wordfence
4.3 Medium Contact Form 7 AWeber Extension Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Log Reset ≤ 0.1.42 CVE-2025-12167 Wordfence
6.4 Medium Simple Downloads List Plugin simple-downloads-list Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 1.4.3 CVE-2025-12583 Wordfence
4.3 Medium Page & Post Notes Plugin page-post-notes Broken Access Control Missing Authorization to Authenticated (Subscriber+) Note Update/Deletion ≤ 1.3.4 CVE-2025-12527 Wordfence
4.0 Medium WP Airbnb Review Slider Plugin wp-airbnb-review-slider Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 4.2 CVE-2025-12520 Wordfence
6.5 Medium IDonate Plugin idonate Broken Access Control Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary User Deletion via admin_post_donor_delete Function 2.0.0 – 2.1.9 CVE-2025-4522 Wordfence
4.3 Medium Contest Gallery Plugin contest-gallery Cross-Site Request Forgery No login needed ≤ 28.0.0 Fixed in 28.0.1 CVE-2025-62950 Patchstack
6.5 Medium Effect Maker Plugin effect-maker Broken Access Control ≤ 1.2.1 CVE-2025-62914 Patchstack
6.5 Medium UDesign Core Plugin u-design-core Cross-Site Scripting ≤ 4.14.1 Fixed in 4.14.2 CVE-2025-62051 Patchstack
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Broken Access Control No login needed ≤ 3.5.32 Fixed in 3.5.33 CVE-2025-62049 Patchstack
6.5 Medium TheGem Demo Import (for WPBakery) Plugin thegem-importer Broken Access Control Arbitrary Content Deletion ≤ 5.10.5 Fixed in 5.10.5.2 CVE-2025-62046 Patchstack
6.5 Medium TheGem Theme Elements (for WPBakery) Plugin thegem-elements Cross-Site Scripting ≤ 5.10.5.1 Fixed in 5.10.5.2 CVE-2025-62044 Patchstack
6.5 Medium MeetingHub Plugin meetinghub Information Disclosure Sensitive Data Exposure ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62038 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only