WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,251–6,300 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 126 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Togo Plugin togo Broken Access Control ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62037 Patchstack
6.5 Medium Togo Plugin togo Broken Access Control No login needed ≤ 1.0.4 Fixed in 1.0.4 CVE-2025-62033 Patchstack
6.5 Medium tagDiv Cloud Library Plugin td-cloud-library Cross-Site Scripting ≤ 3.9.2 Fixed in 3.9.2 CVE-2025-62032 Patchstack
6.5 Medium tagDiv Composer Plugin td-composer Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-62030 Patchstack
4.3 Medium Salient Plugin salient Broken Access Control ≤ 17.4.0 Fixed in 17.4.0 CVE-2025-62028 Patchstack
5.3 Medium KALLYAS Theme kallyas Broken Access Control No login needed ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62018 Patchstack
5.4 Medium KALLYAS Theme kallyas Broken Access Control ≤ 4.22.0 Fixed in 4.23.0 CVE-2025-62017 Patchstack
6.5 Medium TheGem (Elementor) Plugin thegem-elementor Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62012 Patchstack
6.5 Medium TheGem Plugin thegem Cross-Site Scripting ≤ 5.10.5 Fixed in 5.10.5.1 CVE-2025-62011 Patchstack
6.5 Medium Bux Woocommerce Plugin bux-woocommerce Broken Access Control No login needed ≤ 1.2.3 CVE-2025-60247 Patchstack
4.8 Medium Atarim Plugin atarim-visual-collaboration Arbitrary File Upload No login needed ≤ 4.2.1 Fixed in 4.2.2 CVE-2025-60187 Patchstack
6.5 Medium Jock On Air Now (JOAN) Plugin joan Broken Access Control ≤ 6.0.4 Fixed in 6.0.5 CVE-2025-58986 Patchstack
5.3 Medium All In One Login Plugin change-wp-admin-login Authentication Bypass Bypass Vulnerability No login needed ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-58595 Patchstack
5.3 Medium imEvent Plugin imevent Broken Access Control No login needed ≤ 3.4.0 CVE-2025-58243 Patchstack
5.3 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Broken Access Control No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2025-5803 Patchstack
6.5 Medium Backup and Move Plugin backup-and-move Broken Access Control ≤ 0.1 CVE-2025-53246 Patchstack
6.5 Medium Sertifier Certificate & Badge Maker Plugin sertifier-certificates-open-badges Broken Access Control ≤ 1.21 CVE-2025-53214 Patchstack
6.5 Medium Easy Appointments Plugin easy-appointments Content Injection No login needed ≤ 3.12.14 Fixed in 3.12.14.1 CVE-2025-49398 Patchstack
5.5 Medium Ajax Search Lite Plugin ajax-search-lite PHP Object Injection ≤ 4.13.3 Fixed in 4.13.4 CVE-2025-48086 Patchstack
4.3 Medium Advanced Google Maps Plugin wp-google-map-gold Broken Access Control ≤ 5.8.4 Fixed in 5.8.5 CVE-2025-39465 Patchstack
4.1 Medium Smush Image Compression and Optimization Plugin wp-smushit Path Traversal Directory Traversal ≤ 3.17.0 Fixed in 3.17.1 CVE-2025-22288 Patchstack
4.3 Medium Strong Testimonials Plugin strong-testimonials Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.16 CVE-2025-11268 Wordfence
4.3 Medium Better Find and Replace Plugin real-time-auto-find-and-replace Broken Access Control Missing Authorization ≤ 1.7.7 CVE-2025-12360 Wordfence
6.1 Medium Hubbub Lite Plugin social-pug Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.36.0 CVE-2025-12471 Wordfence
4.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery via post_url ≤ 8.6.0 CVE-2025-12560 Wordfence
5.3 Medium Easy Digital Download Plugin Other Insufficient Verification to Order Manipulation No login needed ≤ 3.5.2 CVE-2025-11271 Wordfence
4.3 Medium Blog2Social: Social Media Auto Post & Scheduler Plugin blog2social Broken Access Control Incorrect Authorization to Video File Upload ≤ 8.6.0 CVE-2025-12563 Wordfence
4.3 Medium Easy Email Subscription Plugin email-subscription-with-secure-captcha Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Subscriber Deletion No login needed ≤ 1.3 CVE-2025-10691 Wordfence
4.9 Medium Easy Email Subscription Plugin email-subscription-with-secure-captcha SQL Injection Authenticated (Admin+) SQL Injection via uid ≤ 1.3 CVE-2025-10683 Wordfence
6.4 Medium Ad Inserter Plugin ad-inserter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Field ≤ 2.8.7 CVE-2025-11745 Wordfence
4.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Broken Access Control Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Email Sending ≤ 3.6.4.1 CVE-2025-12469 Wordfence
5.3 Medium The Events Calendar Plugin the-events-calendar Information Disclosure Sysinfo Key Incorrect Comparison to Unauthenticated Sensitive Information Exposure No login needed ≤ 6.15.9 CVE-2025-12192 Wordfence
5.3 Medium FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce Plugin wp-marketing-automations Information Disclosure Email Marketing Automation and CRM for WordPress & WooCommerce <= 3.6.4.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 3.6.4.1 CVE-2025-12468 Wordfence
6.4 Medium Visual Link Preview Plugin visual-link-preview Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via visual-link-preview Shortcode ≤ 2.2.7 CVE-2025-11987 Wordfence
6.4 Medium Graphina – Elementor Charts and Graphs Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Elementor Charts and Graphs <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Widgets ≤ 3.1.8 CVE-2025-11820 Wordfence
5.3 Medium KiotViet Sync Plugin kiotvietsync Broken Access Control Use of Hard-coded Password to Authorization Bypass No login needed ≤ 1.8.5 CVE-2025-12676 Wordfence
4.3 Medium KiotViet Sync Plugin kiotvietsync Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.8.5 CVE-2025-12675 Wordfence
5.3 Medium KiotViet Sync Plugin kiotvietsync Information Disclosure Unauthenticated Webhook Key Exposure No login needed ≤ 1.8.5 CVE-2025-12677 Wordfence
6.4 Medium B Carousel Block – Responsive Image and Content Carousel Plugin b-carousel-block Broken Access Control Responsive Image and Content Carousel <= 1.1.5 - Missing Authorization to Authenticated (Subscriber+) Server-Side Request Forgery ≤ 1.1.5 CVE-2025-12388 Wordfence
4.3 Medium Depicter — Popup & Slider Builder Plugin depicter Broken Access Control Add Email collecting Popup, Popup Modal, Coupon Popup, Image Slider, Carousel Slider, Post Slider Carousel <= 4.0.4 - Missing Authorization to Authenticated (Contributor+) Safe File Type Upload ≤ 4.0.4 CVE-2025-11373 Wordfence
6.4 Medium WPeMatico RSS Feed Fetcher Plugin wpematico Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via wpematico_test_feed ≤ 2.8.11 CVE-2025-11917 Wordfence
5.3 Medium Download Counter Button Plugin Path Traversal Unauthenticated Arbitrary File Download No login needed ≤ 1.8.6.7 CVE-2025-11072 WPScan
6.3 Medium Ace User Management Plugin ace-user-management Authentication Bypass Subscriber+ Authentication Bypass via Password Rest ≤ 2.0.3 CVE-2025-6027 WPScan
5.3 Medium Elementinvader Addons for Elementor Plugin elementinvader-addons-for-elementor Broken Access Control Unauthenticated Arbitrary Email Sending No login needed < 1.4.1 Fixed in 1.4.1 CVE-2025-10873 WPScan
6.3 Medium FunnelKit Plugin funnel-builder Cross-Site Scripting Reflected XSS No login needed < 3.12.0.1 Fixed in 3.12.0.1 CVE-2025-10567 WPScan
6.4 Medium Spectra Plugin ultimate-addons-for-gutenberg Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Custom CSS ≤ 2.19.14 CVE-2025-11162 Wordfence
5.3 Medium Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction Plugin paid-member-subscriptions Broken Access Control Effortless Memberships, Recurring Payments & Content Restriction <= 2.16.4 - Missing Authorization to Unauthenticated Arbitrary Member Subscription Auto Renewal No login needed ≤ 2.16.4 CVE-2025-11835 Wordfence
6.1 Medium SMS Plugin sms4wp Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.1.8 CVE-2025-12580 Wordfence
4.3 Medium Features Plugin features Broken Access Control Missing Authorization to Authenticated (Subscriber+) Option Reset ≤ 0.0.2 CVE-2025-12582 Wordfence
5.6 Medium Everest Forms (Pro) Plugin PHP Object Injection Unauthenticated PHP Object Injection via PHAR Deserialization in Form Signature No login needed ≤ 1.9.7 CVE-2025-8871 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only