WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 601–650 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Media Library Downloader Plugin media-library-downloader Cross-Site Request Forgery No login needed ≤ 1.4.0 CVE-2025-62734 Patchstack
4.3 Medium Custom Sidebars by ProteusThemes Plugin custom-sidebars-by-proteusthemes Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-62733 Patchstack
4.3 Medium Media Library File Download Plugin media-download Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62103 Patchstack
4.3 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Request Forgery No login needed ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-62102 Patchstack
4.3 Medium Duplicate Content Cure Plugin duplicate-content-cure Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-59132 Patchstack
7.1 High Create Posts & Terms Plugin create-posts-terms Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-49351 Patchstack
7.1 High WP sIFR Plugin wp-sifr Cross-Site Request Forgery No login needed ≤ 0.6.8.1 CVE-2025-49347 Patchstack
7.1 High PDF Creator Lite Plugin pdf-creator-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-49341 Patchstack
4.3 Medium SupportCandy Plugin supportcandy Cross-Site Request Forgery No login needed ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-67598 Patchstack
4.3 Medium Business Directory Plugin business-directory-plugin Cross-Site Request Forgery No login needed ≤ 6.4.19 Fixed in 6.4.20 CVE-2025-67596 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.82 Fixed in 6.7.0.83 CVE-2025-67595 Patchstack
4.3 Medium UsersWP Plugin userswp Cross-Site Request Forgery No login needed ≤ 1.2.48 Fixed in 1.2.49 CVE-2025-67593 Patchstack
4.3 Medium JNews Paywall Plugin jnews-paywall Cross-Site Request Forgery No login needed ≤ 12.0.1 Fixed in 12.0.1 CVE-2025-67591 Patchstack
4.3 Medium Ultimate FAQ Plugin ultimate-faqs Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-67590 Patchstack
7.1 High Rencontre Plugin rencontre Cross-Site Request Forgery No login needed ≤ 3.13.7 Fixed in 3.13.8 CVE-2025-67534 Patchstack
4.3 Medium CWW Companion Plugin cww-companion Cross-Site Request Forgery No login needed ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-67473 Patchstack
4.3 Medium Online Booking & Scheduling Calendar for WordPress by vcita Plugin meeting-scheduler-by-vcita Cross-Site Request Forgery No login needed ≤ 4.5.5 Fixed in 4.6.0 CVE-2025-67472 Patchstack
4.3 Medium Quick Contact Form Plugin quick-contact-form Cross-Site Request Forgery No login needed ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-67471 Patchstack
4.3 Medium PDF Thumbnail Generator Plugin pdf-thumbnail-generator Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-67469 Patchstack
4.3 Medium Simple Link Directory Plugin simple-link-directory Cross-Site Request Forgery No login needed ≤ 8.8.3 Fixed in 8.8.4 CVE-2025-67465 Patchstack
4.3 Medium Salon booking system Plugin salon-booking-system Cross-Site Request Forgery No login needed ≤ 10.30.3 Fixed in 10.30.4 CVE-2025-66531 Patchstack
4.3 Medium Chartify Plugin chart-builder Cross-Site Request Forgery No login needed ≤ 3.6.3 Fixed in 3.6.4 CVE-2025-66529 Patchstack
4.3 Medium Simple Folio Plugin simple-folio Cross-Site Request Forgery No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-64256 Patchstack
4.3 Medium WP Landing Page Plugin wp-landing-page Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Post Meta Update No login needed ≤ 0.9.3 CVE-2025-13629 Wordfence
8.8 High User Generator and Importer Plugin user-importer-and-generator Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Arbitrary Administrator Account Creation No login needed ≤ 1.2.2 CVE-2025-12879 Wordfence
4.3 Medium WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors Plugin wc-vendors Cross-Site Request Forgery WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors <= 2.6.4 - Cross-Site Request Forgery to Vendor Product Deletion No login needed ≤ 2.6.4 CVE-2025-12130 Wordfence
4.3 Medium ARK Related Posts Plugin ark-relatedpost Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.19 CVE-2025-13684 Wordfence
4.3 Medium Torod – The smart shipping and delivery portal for e-shops and retailers Plugin torod Cross-Site Request Forgery The smart shipping and delivery portal for e-shops and retailers <= 1.9 - Cross-Site Request Forgery To Plugin's Settings Modification No login needed ≤ 1.9 CVE-2025-12373 Wordfence
4.3 Medium Image Optimizer by wps.sk Plugin image-optimizer-wpssk Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Image Optimization No login needed ≤ 1.2.0 CVE-2025-12190 Wordfence
4.3 Medium Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents Plugin bread-butter Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 7.11.1374 CVE-2025-12189 Wordfence
4.3 Medium Hide Categories Or Products On Shop Page Plugin hide-categories-or-products-on-shop-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.7 CVE-2025-12128 Wordfence
4.3 Medium Time Sheets Plugin time-sheets Cross-Site Request Forgery No login needed ≤ 2.1.3 CVE-2025-10055 Wordfence
4.3 Medium Quantic Social Image Hover Plugin tw-image-hover-share Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.8 CVE-2025-13360 Wordfence
6.1 Medium dream gallery Plugin dream-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via 'dreampluginsmain' AJAX Action No login needed ≤ 1.0 CVE-2025-13621 Wordfence
4.3 Medium ContentStudio Plugin contentstudio Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.3.7 CVE-2025-13144 Wordfence
4.3 Medium Norby AI Plugin norby-ai Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.3 CVE-2025-13362 Wordfence
4.3 Medium Backup, Restore and Migrate your sites with XCloner Plugin xcloner-backup-and-restore Cross-Site Request Forgery Cross-Site Request Forgery in Xcloner_Remote_Storage:save() No login needed ≤ 4.8.2 CVE-2025-11759 Wordfence
4.3 Medium ShopEngine Plugin shopengine Cross-Site Request Forgery Cross-Site Request Forgery to Wishlist Manipulation No login needed ≤ 4.8.5 CVE-2025-12358 Wordfence
4.3 Medium SurveyJS: Drag & Drop WordPress Form Builder Plugin surveyjs Cross-Site Request Forgery Cross-Site Request Forgery to Survey Deletion No login needed ≤ 1.12.20 CVE-2025-13140 Wordfence
4.3 Medium Photo Gallery by Ays Plugin gallery-photo-gallery Cross-Site Request Forgery Cross-Site Request Forgery to Bulk Actions No login needed ≤ 6.4.8 CVE-2025-13685 Wordfence
6.5 Medium Export All Posts, Products, Orders, Refunds & Users Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Sensitive Information Exposure No login needed ≤ 2.19 CVE-2025-13606 Wordfence
4.3 Medium Nextend Social Login and Register Plugin nextend-facebook-connect Cross-Site Request Forgery Cross-Site Request Forgery to Unlink User Social Login No login needed ≤ 3.1.21 CVE-2025-13737 Wordfence
6.5 Medium AI ChatBot with ChatGPT and Content Generator by AYS Plugin ays-chatgpt-assistant Server-Side Request Forgery Unauthenticated Server-Side Request Forgery via 'pinecone_url' Parameter No login needed ≤ 2.7.0 CVE-2025-13378 Wordfence
4.3 Medium Poll, Survey & Quiz Maker Plugin by Opinion Stage Plugin social-polls-by-opinionstage Cross-Site Request Forgery Cross-Site Request Forgery to Account Disconnection No login needed ≤ 19.12.0 CVE-2025-13143 Wordfence
4.3 Medium Reuters Direct Plugin reuters-direct Cross-Site Request Forgery Cross-Site Request Forgery to Settings Reset No login needed ≤ 3.0.0 CVE-2025-12578 Wordfence
4.3 Medium Peer Publish Plugin peer-publish Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-12587 Wordfence
4.3 Medium Conditional Maintenance Mode Plugin maintenance-mode-based-on-user-roles Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-12586 Wordfence
6.1 Medium Job Board by BestWebSoft Plugin job-board Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting via $_GET Array Storage No login needed ≤ 1.2.1 CVE-2025-13383 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 7.4.5 CVE-2025-12800 Wordfence
8.8 High Zegen Core Plugin Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary File Upload No login needed ≤ 2.0.1 CVE-2025-11087 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only