WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 601–650 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 13 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Restrict User Registration Plugin restrict-user-registration Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.1 CVE-2025-9892 Wordfence
4.3 Medium PayPal Forms Plugin paypal-forms Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-10309 Wordfence
4.3 Medium Optimize More! – CSS Plugin optimize-more-css Cross-Site Request Forgery CSS <= 1.0.3 - Cross-Site Request Forgery to Plugin Settings Reset No login needed ≤ 1.0.3 CVE-2025-9945 Wordfence
6.1 Medium Mobile Site Redirect Plugin mobile-site-redirect Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-9884 Wordfence
4.3 Medium MPWizard – Create Mercado Pago Payment Links Plugin mpwizard Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2025-9885 Wordfence
4.3 Medium Comment Info Detector Plugin comment-info-detector Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.5 CVE-2025-10311 Wordfence
4.0 Medium Block For Mailchimp – Easy Mailchimp Form Integration Plugin block-for-mailchimp Server-Side Request Forgery Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.12 CVE-2025-10735 Wordfence
6.1 Medium LockerPress – WordPress Security Plugin lockerpress-wordpress-security Cross-Site Request Forgery WordPress Security Plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9946 Wordfence
4.3 Medium Chat by Chatwee Plugin chatwee Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.1.3 CVE-2025-9948 Wordfence
4.3 Medium VM Menu Reorder Plugin vm-menu-reorder Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-9893 Wordfence
4.3 Medium Professional Contact Form Plugin professional-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Test Email Sending No login needed ≤ 1.0.0 CVE-2025-9944 Wordfence
4.3 Medium cForms – Light speed fast Form Builder Plugin cforms-plugin Cross-Site Request Forgery Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-9898 Wordfence
6.1 Medium Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms Plugin trust-reviews Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9899 Wordfence
4.3 Medium Sync Feedly Plugin sync-feedly Cross-Site Request Forgery Cross-Site Request Forgery to Sync Trigger No login needed ≤ 1.0.1 CVE-2025-9894 Wordfence
4.3 Medium HidePost Plugin hidepost Cross-Site Request Forgery No login needed ≤ 2.3.8 CVE-2025-9896 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
5.4 Medium Silencesoft RSS Reader Plugin external-rss-reader Server-Side Request Forgery No login needed ≤ 0.6 CVE-2025-60181 Patchstack
5.4 Medium ZoloBlocks Plugin zoloblocks Server-Side Request Forgery No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-60161 Patchstack
4.3 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60145 Patchstack
4.3 Medium Sendle Shipping Plugin official-sendle-shipping-method Cross-Site Request Forgery No login needed ≤ 6.02 Fixed in 6.03 CVE-2025-60139 Patchstack
4.3 Medium Post Featured Video Plugin post-featured-video Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-60137 Patchstack
4.3 Medium Vehica Core Plugin vehica-core Cross-Site Request Forgery No login needed ≤ 1.0.100 Fixed in 1.0.101 CVE-2025-60117 Patchstack
4.3 Medium Instapage Plugin instapage Cross-Site Request Forgery No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2025-60115 Patchstack
4.3 Medium Groovy Menu Plugin groovy-menu-free Cross-Site Request Forgery No login needed ≤ 1.4.3 CVE-2025-60113 Patchstack
4.3 Medium Download Manager Plugin download-manager Cross-Site Request Forgery No login needed ≤ 3.3.24 Fixed in 3.3.25 CVE-2025-60093 Patchstack
4.3 Medium Di Themes Demo Site Importer Plugin di-themes-demo-site-importer Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Plugin Activation No login needed ≤ 1.2 CVE-2025-58914 Patchstack
5.4 Medium Snow Monkey Theme Server-Side Request Forgery Unauthenticated Blind Server-Side Request Forgery No login needed 29.1.5 CVE-2025-10137 Wordfence
4.3 Medium System Dashboard Plugin system-dashboard Cross-Site Request Forgery No login needed ≤ 2.8.20 CVE-2025-10377 Wordfence
4.3 Medium OAuth Single Sign On – SSO (OAuth Client) Plugin miniorange-login-with-eve-online-google-facebook Cross-Site Request Forgery SSO (OAuth Client) <= 6.26.12 - Cross-Site Request Forgery No login needed ≤ 6.26.12 CVE-2025-10752 Wordfence
6.4 Medium Publitio Plugin publitio Server-Side Request Forgery ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-58962 Patchstack
4.3 Medium Zoho Flow Plugin zoho-flow Cross-Site Request Forgery No login needed ≤ 2.14.1 Fixed in 2.14.2 CVE-2025-59568 Patchstack
5.4 Medium Mihdan: No External Links Plugin mihdan-no-external-links Cross-Site Request Forgery No login needed ≤ 5.1.6.2 Fixed in 5.1.7 CVE-2025-53451 Patchstack
4.3 Medium SEO Backlink Monitor Plugin seo-backlink-monitor Cross-Site Request Forgery No login needed ≤ 1.8.0 CVE-2025-53456 Patchstack
4.4 Medium SEO Backlink Monitor Plugin seo-backlink-monitor Server-Side Request Forgery ≤ 1.8.0 CVE-2025-53457 Patchstack
4.4 Medium Beaf Plugin image-compare-block Server-Side Request Forgery ≤ 1.6.2 CVE-2025-53461 Patchstack
6.5 Medium RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Plugin ris-version-switcher Cross-Site Request Forgery Downgrade or Upgrade WP Versions Easily Plugin <= 1.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.0 CVE-2025-57902 Patchstack
4.3 Medium AgreeMe Checkboxes For WooCommerce Plugin agreeme-checkboxes-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-57905 Patchstack
4.3 Medium TOCHAT.BE Plugin tochat-be Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-57915 Patchstack
4.3 Medium Deliver via Shipos for WooCommerce Plugin wc-shipos-delivery Cross-Site Request Forgery No login needed ≤ 3.0.2 Fixed in 3.1.0 CVE-2025-57914 Patchstack
4.3 Medium Developer Plugin developer Cross-Site Request Forgery No login needed ≤ 1.2.6 CVE-2025-57924 Patchstack
4.3 Medium Dashboard Notepad Plugin dashboard-notepad Cross-Site Request Forgery No login needed ≤ 1.42 CVE-2025-57927 Patchstack
4.3 Medium Double the Donation Plugin double-the-donation Cross-Site Request Forgery No login needed ≤ 2.0.0 Fixed in 3.0.0 CVE-2025-57930 Patchstack
4.3 Medium Piotnet Forms Plugin piotnetforms Cross-Site Request Forgery No login needed ≤ 1.0.30 CVE-2025-57933 Patchstack
4.3 Medium LWS Affiliation Plugin lws-affiliation Cross-Site Request Forgery No login needed ≤ 2.3.6 CVE-2025-57934 Patchstack
4.3 Medium Emergency Password Reset Plugin emergency-password-reset Cross-Site Request Forgery No login needed ≤ 9.3 Fixed in 9.4 CVE-2025-57942 Patchstack
4.4 Medium Skimlinks Affiliate Marketing Tool Plugin skimlinks Server-Side Request Forgery ≤ 1.3.1 CVE-2025-57943 Patchstack
5.4 Medium payOS Plugin payos Cross-Site Request Forgery No login needed ≤ 1.0.73 CVE-2025-57946 Patchstack
4.3 Medium Travel Map Plugin travelmap-blog Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-57960 Patchstack
4.3 Medium SALESmanago & Leadoo Plugin salesmanago Cross-Site Request Forgery No login needed ≤ 3.8.1 Fixed in 3.8.2 CVE-2025-57970 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only