WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,351–6,400 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 128 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Ohio Extra Plugin ohio-extra Cross-Site Scripting ≤ 3.6.0 Fixed in 3.6.1 CVE-2025-64365 Patchstack
6.5 Medium K Elements Plugin k-elements Cross-Site Scripting ≤ 5.5.0 Fixed in 5.5.0 CVE-2025-64362 Patchstack
6.5 Medium Consulting Elementor Widgets Plugin consulting-elementor-widgets Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-64361 Patchstack
4.3 Medium Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control ≤ 2.2.3 Fixed in 2.2.4 CVE-2025-64358 Patchstack
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-64357 Patchstack
4.3 Medium Insert PHP Code Snippet Plugin insert-php-code-snippet Broken Access Control ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-64356 Patchstack
6.5 Medium Gutenberg Plugin gutenberg Cross-Site Scripting ≤ 21.8.2 Fixed in 21.9.0 CVE-2025-64354 Patchstack
4.3 Medium Rank Math SEO Plugin seo-by-rank-math Information Disclosure Sensitive Data Exposure ≤ 1.0.252.1 Fixed in 1.0.253 CVE-2025-64351 Patchstack
5.3 Medium ERI File Library Plugin eri-file-library Broken Access Control Missing Authorization to Unauthenticated Protected File Download No login needed ≤ 1.1.0 CVE-2025-12041 Wordfence
5.3 Medium OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) Plugin oopspam-anti-spam Other Unauthenticated IP Header Spoofing No login needed ≤ 1.2.53 CVE-2025-12094 Wordfence
4.3 Medium Depicter Plugin depicter Cross-Site Request Forgery No login needed ≤ 4.0.4 CVE-2025-8383 Wordfence
4.3 Medium The Events Calendar Plugin the-events-calendar Broken Access Control Missing Authorization to Authenticated (Subscriber+) Draft Event Title/QR Code Exposure ≤ 6.15.9 CVE-2025-12175 Wordfence
6.8 Medium Zombify Plugin Path Traversal Authenticated (Subscriber+) Path Traversal to Arbitrary File Read No login needed ≤ 1.7.5 CVE-2025-8385 Wordfence
5.3 Medium RealPress Plugin realpress Broken Access Control Unauthenticated Content Creation/Email Sending via REST No login needed < 1.1.0 Fixed in 1.1.0 CVE-2025-11191 WPScan
6.4 Medium Qzzr Shortcode Plugin qzzr-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.0.1 CVE-2025-11806 Wordfence
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Broken Access Control WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Missing Authorization to Authenticated (Subscriber+) Sync Rule Creation ≤ 1.1.23.0 CVE-2025-11975 Wordfence
5.3 Medium AppPresser – Mobile App Framework Plugin apppresser Broken Access Control Mobile App Framework <= 4.5.0 - Missing Authorization to Unauthenticated Limited Sensitive Information Exposure No login needed ≤ 4.5.0 CVE-2025-11881 Wordfence
6.5 Medium Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue Plugin site-checkup Denial of Service Unauthenticated Log File Poisoning No login needed ≤ 1.47 CVE-2025-11627 Wordfence
5.3 Medium Translate WordPress and go Multilingual – Weglot Plugin weglot Broken Access Control Weglot <= 5.1 - Missing Authorization to Unauthenticated Limited Transient Deletion No login needed ≤ 5.1 CVE-2025-10008 Wordfence
6.4 Medium Blocksy Companion Plugin blocksy-companion Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.14 CVE-2025-12475 Wordfence
4.3 Medium Call Now Button Plugin call-now-button Broken Access Control Authenticated (Subscriber+) Missing Authorization to Multiple Functions ≤ 1.5.4 CVE-2025-11632 Wordfence
4.3 Medium Call Now Button Plugin call-now-button Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Settings Update ≤ 1.5.3 CVE-2025-11587 Wordfence
6.1 Medium LiteSpeed Cache Plugin litespeed-cache Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 7.5.0.1 CVE-2025-12450 Wordfence
4.9 Medium Easy Testimonial Slider and Form Plugin easy-testimonial-rotator SQL Injection Authenticated (Admin+) SQL injection ≤ 1.0.2 CVE-2015-10147 Wordfence
4.9 Medium Thumbnail Slider With Lightbox Plugin wp-responsive-slider-with-lightbox SQL Injection Authenticated (Admin+) SQL Injection ≤ 1.0.4 CVE-2015-10146 Wordfence
5.9 Medium Premmerce User Roles Plugin premmerce-user-roles Cross-Site Scripting ≤ 1.0.13 Fixed in 1.0.14 CVE-2025-64291 Patchstack
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
5.9 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Scripting ≤ 2.2.7 CVE-2025-64289 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
5.4 Medium Premmerce Wholesale Pricing for WooCommerce Plugin premmerce-woocommerce-wholesale-pricing Broken Access Control ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-64285 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.6.7 Fixed in 1.6.8 CVE-2025-64283 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-64234 Patchstack
4.3 Medium Client Invoicing by Sprout Invoices Plugin sprout-invoices Broken Access Control ≤ 20.8.7 Fixed in 20.8.8 CVE-2025-64229 Patchstack
4.3 Medium SUMO Affiliates Pro Plugin affs Information Disclosure Sensitive Data Exposure ≤ 11.0.0 Fixed in 11.1.0 CVE-2025-64228 Patchstack
4.3 Medium Stockie Extra Plugin stockie-extra Cross-Site Request Forgery No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64226 Patchstack
6.5 Medium Rey Core Plugin rey-core Cross-Site Scripting ≤ 3.1.8 Fixed in 3.1.9 CVE-2025-64220 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Broken Access Control ≤ 6.4.18 Fixed in 6.4.19 CVE-2025-64219 Patchstack
5.4 Medium MasterStudy LMS Pro Plugin masterstudy-lms-learning-management-system-pro Broken Access Control ≤ 4.7.16 Fixed in 4.7.16 CVE-2025-64212 Patchstack
5.3 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control No login needed ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-64211 Patchstack
5.4 Medium Masterstudy Elementor Widgets Plugin masterstudy-elementor-widgets Broken Access Control ≤ 1.2.4 Fixed in 1.2.5 CVE-2025-64210 Patchstack
6.5 Medium Jannah - Extensions Plugin jannah-extensions Cross-Site Scripting Extensions plugin <= 1.1.4 - Cross Site Scripting (XSS) ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-64208 Patchstack
6.5 Medium SmartMag Theme smart-mag Cross-Site Scripting ≤ 10.3.1 Fixed in 10.3.2 CVE-2025-64204 Patchstack
6.5 Medium Sahifa Plugin sahifa Cross-Site Scripting ≤ 5.8.6 Fixed in 5.8.6 CVE-2025-64202 Patchstack
4.3 Medium PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.13.12 Fixed in 11.14 CVE-2025-64201 Patchstack
5.9 Medium Email Template Customizer for WooCommerce Plugin email-template-customizer-for-woo Cross-Site Scripting ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-64200 Patchstack
5.3 Medium wpresidence Theme wpresidence Broken Access Control No login needed ≤ 5.3.2 Fixed in 5.3.2.1 CVE-2025-64199 Patchstack
6.5 Medium Rehub Plugin rehub-theme Cross-Site Scripting ≤ 19.9.9.1 Fixed in 19.9.9.1 CVE-2025-64197 Patchstack
6.5 Medium Eduma Plugin eduma Cross-Site Scripting ≤ 5.7.6 Fixed in 5.7.7 CVE-2025-64194 Patchstack
4.3 Medium Super Store Finder Plugin superstorefinder-wp Cross-Site Request Forgery No login needed ≤ 7.5 CVE-2025-58939 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only