WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,301–6,350 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 4.4 Medium | MeetingList | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 0.11 |
CVE-2025-12184 |
Wordfence | |
| 6.4 Medium | Orbit Fox Companion | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Post Taxonomy |
≤ 3.0.2 |
CVE-2025-12045 |
Wordfence | |
| 4.4 Medium | Clubmember | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 0.2 |
CVE-2025-12396 |
Wordfence | |
| 6.1 Medium | Associados Amazon | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.8 |
CVE-2025-12403 |
Wordfence | |
| 6.4 Medium | Reuse Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.7 |
CVE-2025-11812 |
Wordfence | |
| 4.4 Medium | Multi-language Responsive Portfolio | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-11753 |
Wordfence | |
| 6.1 Medium | Visit Counter | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
1.0 |
CVE-2025-12452 |
Wordfence | |
| 4.3 Medium | Import Export For WooCommerce | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update |
≤ 1.6.2 |
CVE-2025-12389 |
Wordfence | |
| 4.4 Medium | Nari Accountant | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 1.0.12 |
CVE-2025-12371 |
Wordfence | |
| 4.4 Medium | WP Carticon | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-12065 |
Wordfence | |
| 6.1 Medium | MapMap | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update and Stored Cross-Site Scripting No login needed |
≤ 1.1 |
CVE-2025-12415 |
Wordfence | |
| 6.1 Medium | LinkedIn Resume | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.00 |
CVE-2025-12402 |
Wordfence | |
| 4.3 Medium | Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Post Creation |
2.0.7 – 2.2.6 |
CVE-2025-12156 |
Wordfence | |
| 6.1 Medium | Centangle Team Showcase | Cross-Site Request Forgery Cross-Site Request Forgery To Plugin's Settings Modification And Stored Cross-Site Scripting No login needed |
≤ 1.0.0 |
CVE-2025-12456 |
Wordfence | |
| 6.1 Medium | LMB^Box Smileys | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 3.2 |
CVE-2025-12400 |
Wordfence | |
| 6.4 Medium | Extensions for Leaflet Map | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.7 |
CVE-2025-12369 |
Wordfence | |
| 5.3 Medium | Simple User Capabilities | Broken Access Control Missing Authorization to Unauthenticated Capability Reset No login needed |
≤ 1.0 |
CVE-2025-12157 |
Wordfence | |
| 6.1 Medium | SH Contextual Help | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 3.2.1 |
CVE-2025-12410 |
Wordfence | |
| 6.5 Medium | All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier | Broken Access Control Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Authorization to Page Creation and Information Exposure No login needed |
≤ 2.0.3 |
CVE-2025-11758 |
Wordfence | |
| 5.4 Medium | Social Media WPCF7 Stop Words | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.1.3 |
CVE-2025-12413 |
Wordfence | |
| 4.4 Medium | Free Quotation | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 3.1.6 |
CVE-2025-12393 |
Wordfence | |
| 5.3 Medium | DominoKit | Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed |
≤ 1.1.0 |
CVE-2025-12350 |
Wordfence | |
| 6.1 Medium | Pagerank Tools | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.1.5 |
CVE-2025-12416 |
Wordfence | |
| 6.1 Medium | Top Bar Notification | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.12 |
CVE-2025-12412 |
Wordfence | |
| 4.3 Medium | Posts Navigation Links for Sections and Headings - Free by WP Masters | Cross-Site Request Forgery Free by WP Masters <= 1.0.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.1 |
CVE-2025-12188 |
Wordfence | |
| 4.3 Medium | WP Global Screen Options | Cross-Site Request Forgery Cross-Site Request Forgery to Screen Options Update No login needed |
≤ 0.2 |
CVE-2025-12069 |
Wordfence | |
| 6.1 Medium | Label Plugins | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.5 |
CVE-2025-12401 |
Wordfence | |
| 4.3 Medium | ViaAds | Cross-Site Request Forgery Cross-Site Request Forgery to API Key Update No login needed |
≤ 2.1.2 |
CVE-2025-12070 |
Wordfence | |
| 6.4 Medium | TablePress – Tables in WordPress made easy | Cross-Site Scripting Tables in WordPress made easy <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes |
≤ 3.2.4 |
CVE-2025-12324 |
Wordfence | |
| 6.4 Medium | Greenshift – animation and page builder blocks | Cross-Site Scripting animation and page builder blocks <= 12.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Chart Data Attributes |
≤ 12.2.7 |
CVE-2025-11841 |
Wordfence | |
| 5.3 Medium | WP Snow Effect | Broken Access Control No login needed |
≤ 1.1.19 |
CVE-2025-64294 |
Patchstack | |
| 6.4 Medium | Kallyas | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.23.0 |
CVE-2025-6988 |
Wordfence | |
| 4.9 Medium | Import WP – Export and Import CSV and XML files to | Path Traversal Export and Import CSV and XML files to WordPress <= 2.14.16 - Authenticated (Admin+) Arbitrary File Read |
≤ 2.14.16 |
CVE-2025-12137 |
Wordfence | |
| 6.5 Medium | wpForo Forum | SQL Injection Authenticated (Susbscriber+) SQL Injection |
≤ 2.4.9 |
CVE-2025-11740 |
Wordfence | |
| 6.4 Medium | Schema & Structured Data for WP & AMP | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.51 |
CVE-2025-11502 |
Wordfence | |
| 4.3 Medium | Folderly | Broken Access Control Incorrect Authorization to Authenticated (Author+) Term Deletion |
≤ 0.3 |
CVE-2025-12038 |
Wordfence | |
| 4.3 Medium | WP Discourse | Information Disclosure Authenticated (Author+) Information Exposure |
≤ 2.5.9 |
CVE-2025-11983 |
Wordfence | |
| 6.4 Medium | Employee Spotlight – Team Member Showcase & Meet the Team | Cross-Site Scripting Team Member Showcase & Meet the Team Plugin <= 5.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 5.1.2 |
CVE-2025-12090 |
Wordfence | |
| 4.3 Medium | Qi Blocks | Broken Access Control Missing Authorization to Authenticated (Contributor+) Plugin Settings Update |
≤ 1.4.3 |
CVE-2025-12180 |
Wordfence | |
| 4.4 Medium | Flying Images: Optimize and Lazy Load Images for Faster Page Speed | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.4.14 |
CVE-2025-11927 |
Wordfence | |
| 6.4 Medium | Schema Scalpel | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title in JSON-LD Schema |
≤ 1.6.1 |
CVE-2025-12118 |
Wordfence | |
| 4.3 Medium | List category posts | Information Disclosure Authenticated (Contributor+) Information Exposure |
≤ 0.92.0 |
CVE-2025-11377 |
Wordfence | |
| 4.3 Medium | SiteSEO – SEO Simplified | Broken Access Control SEO Simplified <= 1.3.1 - Missing Authorization to Authenticated (Author+) Plugin Settings Update |
≤ 1.3.1 |
CVE-2025-12367 |
Wordfence | |
| 4.4 Medium | CSS & JavaScript Toolbox | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 12.0.5 |
CVE-2025-11928 |
Wordfence | |
| 6.4 Medium | Inactive Logout | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting |
≤ 3.5.5 |
CVE-2025-11922 |
Wordfence | |
| 5.3 Medium | Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages | Broken Access Control Missing Authorization to Unauthenticated API Disconnect No login needed |
≤ 3.5.1 |
CVE-2025-11816 |
Wordfence | |
| 5.3 Medium | Document Library Lite | Broken Access Control Missing Authorization to Sensitive Information Exposure No login needed |
≤ 1.1.6 |
CVE-2025-11174 |
Wordfence | |
| 5.3 Medium | Analytify Pro | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 7.0.3 |
CVE-2025-12521 |
Wordfence | |
| 5.4 Medium | Bard | Cross-Site Request Forgery No login needed |
≤ 1.6 Fixed in 1.7 |
CVE-2025-64368 |
Patchstack | |
| 6.5 Medium | Groundhogg | Cross-Site Scripting |
≤ 4.2.6 Fixed in 4.2.6.1 |
CVE-2025-64367 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.