WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 601–650 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 29
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium BM Content Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting via ux_cb_page_options_save ≤ 3.16.2.1 CVE-2025-1777 Wordfence
6.4 Medium Profile Builder Plugin profile-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via user_meta and compare Shortcodes ≤ 3.13.8 CVE-2025-4671 Wordfence
5.6 Medium Ninja Tables – Easy Data Table Builder Plugin ninja-tables PHP Object Injection Easy Data Table Builder <= 5.0.18 - Unauthenticated PHP Object Injection to Limited Remote Code Execution No login needed ≤ 5.0.18 CVE-2025-2939 Wordfence
6.4 Medium Element Pack Addons for Elementor – Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder Plugin Cross-Site Scripting Best Elementor addons with Ready Templates, Blocks, Widgets and WooCommerce Builder <= 5.11.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 5.11.2 CVE-2025-5292 Wordfence
8.8 High Offsprout Page Builder Plugin offsprout-page-builder Privilege Escalation Authenticated (Contributor+) Privilege Escalation via permission_callback Function 2.2.1 – 2.15.2 CVE-2025-4672 Wordfence
6.5 Medium Woo Slider Pro - Drag Drop Slider Builder For WooCommerce Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Drag Drop Slider Builder For WooCommerce <= 1.12 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion ≤ 1.12 CVE-2025-4597 Wordfence
6.5 Medium Woo Slider Pro Plugin woo-slider-pro-drag-drop-slider-builder-for-woocommerce Broken Access Control Arbitrary Content Deletion ≤ 1.12 CVE-2025-48334 Patchstack
9.8 Critical Course Builder Plugin course-builder PHP Object Injection No login needed ≤ 3.6.6 Fixed in 3.6.6 CVE-2025-48336 Patchstack
6.4 Medium Bold Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via additional_settings Parameter ≤ 5.3.6 CVE-2025-5286 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Slider and Post Carousel Widgets ≤ 5.4.0 CVE-2025-4682 Wordfence
4.7 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Reflected Cross-Site Scripting via login_url Parameter No login needed ≤ 2.0.0 CVE-2025-4223 Wordfence
6.4 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Scripting Drag and Drop website builder <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Link ≤ 2.0.0 CVE-2024-13427 Wordfence
9.3 Critical Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder SQL Injection No login needed ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-31914 Patchstack
7.1 High Visual Builder Plugin visual-builder Broken Access Control No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-46488 Patchstack
8.8 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 3.1 Fixed in 3.2 CVE-2025-47690 Patchstack
9.8 Critical Smart Sections Theme Builder - WPBakery Page Builder Addon Plugin visucom-smart-sections PHP Object Injection WPBakery Page Builder Addon plugin <= 1.7.8 - PHP Object Injection No login needed ≤ 1.7.8 CVE-2025-39410 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Broken Access Control No login needed ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-39449 Patchstack
6.5 Medium Custom PC Builder Lite for WooCommerce Plugin custom-pc-builder-lite-for-woocommerce Broken Access Control Settings Change No login needed ≤ 1.0.1 CVE-2025-43838 Patchstack
5.9 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.74 Fixed in 3.5.0 CVE-2025-48277 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.11.0 Fixed in 45.12.0 CVE-2025-48276 Patchstack
6.5 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Cross-Site Scripting Lite plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48232 Patchstack
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-text' Parameter ≤ 5.3.5 CVE-2025-3715 Wordfence
4.3 Medium WP Ultimate Tours Builder Plugin wp_ultimatetoursbuilder Cross-Site Request Forgery No login needed ≤ 1.055 CVE-2025-31921 Patchstack
5.4 Medium Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-31915 Patchstack
6.1 Medium WooCommerce Checkout & Funnel Builder by FunnelKit Plugin SQL Injection Admin+ SQL Injection No login needed < 3.10.2 Fixed in 3.10.2 CVE-2025-2203 WPScan
7.2 High Taskbuilder Plugin taskbuilder SQL Injection Admin+ SQL Injection < 3.0.9 Fixed in 3.0.9 CVE-2024-9831 WPScan
4.8 Medium RegistrationMagic Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Stored XSS < 6.0.2.1 Fixed in 6.0.2.1 CVE-2024-9390 WPScan
4.8 Medium Page Builder: Pagelayer Plugin pagelayer Cross-Site Scripting Page Builder: Pagelayer < 1.9.0- Admin+ Stored XSS < 1.9.0 Fixed in 1.9.0 CVE-2024-8618 WPScan
4.8 Medium Profile Builder Plugin Cross-Site Scripting Admin+ Stored Cross Site Scripting < 3.12.2 Fixed in 3.12.2 CVE-2024-6708 WPScan
5.4 Medium ARForms Builder Plugin Cross-Site Scripting Unauthenticated Stored XSS < 1.7.1 Fixed in 1.7.1 CVE-2024-10504 WPScan
4.8 Medium Lead Form Builder Plugin Cross-Site Scripting Admin+ Stored XSS < 1.9.8 Fixed in 1.9.8 CVE-2024-10475 WPScan
2.7 Low ApplyOnline – Application Form Builder and Manager Plugin apply-online Broken Access Control Application Form Builder and Manager < 2.6.3 - Unauthenticated Application File Access < 2.6.3 Fixed in 2.6.3 CVE-2024-10098 WPScan
8.8 High WordPress Review Plugin: The Ultimate Solution for Building a Review Website Plugin wp-review Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Custom Fields ≤ 5.3.5 CVE-2025-2158 Wordfence
4.3 Medium Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode Plugin coming-soon Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure ≤ 6.18.15 CVE-2025-3949 Wordfence
6.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Remote Code Execution Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Limited Code Execution via get_table_records Function ≤ 8.9.1 CVE-2025-4208 Wordfence
6.4 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Cross-Site Scripting Ultimate Form Builder – Contact forms and much more <= 8.9.1 - Authenticated (Custom) Stored Cross-Site Scripting ≤ 8.9.1 CVE-2025-3468 Wordfence
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
5.9 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-47525 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.2 Fixed in 5.3.3 CVE-2025-47488 Patchstack
7.5 High Slider & Popup Builder by Depicter Plugin depicter SQL Injection Unauthenticated SQL Injection via 's' Parameter No login needed ≤ 3.6.1 CVE-2025-2011 Wordfence
6.4 Medium Team Members – Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder Plugin wps-team Cross-Site Scripting Best WordPress Team Plugin with Team Slider, Team Showcase & Team Builder <= 3.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.4.1 CVE-2025-3521 Wordfence
4.3 Medium Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor Plugin ultimate-store-kit Cross-Site Request Forgery Cross-Site Request Forgery to Limited User Meta Update No login needed ≤ 2.4.1 CVE-2025-2168 Wordfence
6.5 Medium tagDiv Opt-In Builder Plugin SQL Injection Authenticated (Subscriber+) SQL Injection via subscriptionCouponId Parameter ≤ 1.7 CVE-2025-2890 Wordfence
5.3 Medium WS Form LITE – Drag & Drop Contact Form Builder Plugin ws-form Broken Access Control Drag & Drop Contact Form Builder for WordPress <= 1.10.35 - Missing Authorization to Unauthenticated Sensitive Information Exposure No login needed ≤ 1.10.35 CVE-2025-3912 Wordfence
8.8 High BM Content Builder Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update ≤ 3.16.2.1 CVE-2025-1279 Wordfence
5.3 Medium Upsell Funnel Builder for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Other Unauthenticated Order Manipulation No login needed ≤ 3.0.0 CVE-2025-3743 Wordfence
6.5 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Server-Side Request Forgery WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.2 - Unauthenticated Server-Side Request Forgery via URL Parameter No login needed ≤ 3.1.2 CVE-2025-3775 Wordfence
6.5 Medium Image Hover Effects For WPBakery Page Builder Plugin image-hover-effects-for-visual-composer Cross-Site Scripting ≤ 2.0 CVE-2025-46484 Patchstack
7.5 High Popup Builder Plugin easy-notify-lite Local File Inclusion ≤ 1.1.35 Fixed in 1.1.37 CVE-2025-46230 Patchstack
6.5 Medium Visual Composer Website Builder Plugin visualcomposer Cross-Site Scripting ≤ 45.10.0 Fixed in 45.11.0 CVE-2025-46254 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only