WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,451–6,500 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 130 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium WP Virtual Assistant Plugin virtualassistant Broken Access Control No login needed ≤ 3.0 CVE-2025-60155 Patchstack
5.9 Medium MWW Disclaimer Buttons Plugin mww-disclaimer-buttons Cross-Site Scripting ≤ 3.41 Fixed in 3.5 CVE-2025-60154 Patchstack
7.5 High Subscribe To Unlock Plugin subscribe-to-unlock Local File Inclusion ≤ 1.1.5 CVE-2025-60153 Patchstack
4.3 Medium Subscribe To Unlock Plugin subscribe-to-unlock Broken Access Control ≤ 1.1.5 CVE-2025-60152 Patchstack
7.5 High Subscribe to Download Plugin subscribe-to-download Local File Inclusion ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60150 Patchstack
5.9 Medium Notely Plugin notely Cross-Site Scripting ≤ 1.8.0 Fixed in 1.9.0 CVE-2025-60149 Patchstack
4.3 Medium Subscribe to Download Plugin subscribe-to-download Broken Access Control ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60148 Patchstack
6.5 Medium HT Feed Plugin ht-instagram Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-60147 Patchstack
5.9 Medium Map Categories to Pages Plugin map-categories-to-pages Cross-Site Scripting ≤ 1.3.2 CVE-2025-60146 Patchstack
4.3 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60145 Patchstack
5.9 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Scripting ≤ 1.2 CVE-2025-60144 Patchstack
4.3 Medium Netgsm Plugin netgsm Broken Access Control ≤ 2.9.69 CVE-2025-60143 Patchstack
6.5 Medium Simple Meta Tags Plugin simple-meta-tags Cross-Site Scripting ≤ 1.5 CVE-2025-60142 Patchstack
5.9 Medium The Tribal Plugin the-tech-tribe Cross-Site Scripting ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-60141 Patchstack
5.3 Medium The Tribal Plugin the-tech-tribe Information Disclosure Sensitive Data Exposure No login needed ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-60140 Patchstack
4.3 Medium Sendle Shipping Plugin official-sendle-shipping-method Cross-Site Request Forgery No login needed ≤ 6.02 Fixed in 6.03 CVE-2025-60139 Patchstack
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting ≤ 2.6 CVE-2025-60138 Patchstack
4.3 Medium Post Featured Video Plugin post-featured-video Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-60137 Patchstack
5.9 Medium User Notes Plugin user-notes Cross-Site Scripting ≤ 1.0.2 Fixed in 1.0.3 CVE-2025-60136 Patchstack
5.9 Medium PE Easy Slider Plugin pe-easy-slider Cross-Site Scripting ≤ 1.1.0 CVE-2025-60133 Patchstack
5.3 Medium WEDOS Global Plugin wgpwpp Broken Access Control No login needed ≤ 1.2.2 CVE-2025-60130 Patchstack
5.3 Medium Yext Plugin yext Broken Access Control No login needed ≤ 1.1.3 CVE-2025-60129 Patchstack
4.3 Medium Delisho Plugin dr-widgets-blocks Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60128 Patchstack
5.4 Medium CopySafe Web Protection Plugin wp-copysafe-web Broken Access Control ≤ 5.1 Fixed in 5.2 CVE-2025-60127 Patchstack
8.8 High Testimonial Slider Plugin testimonial-add Local File Inclusion ≤ 3.5.8.6 CVE-2025-60126 Patchstack
5.3 Medium FoodBook Plugin foodbook Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.6 Fixed in 4.7.7 CVE-2025-60125 Patchstack
6.5 Medium Simple Colorbox Plugin simple-colorbox Cross-Site Scripting ≤ 1.6.1 CVE-2025-60124 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-60123 Patchstack
4.3 Medium HivePress Claim Listings Plugin hivepress-claim-listings Broken Access Control ≤ 1.1.4 CVE-2025-60122 Patchstack
5.3 Medium WooEvents Plugin woo-events Broken Access Control No login needed ≤ 4.1.7 Fixed in 4.1.8 CVE-2025-60121 Patchstack
5.3 Medium CoSchedule Plugin coschedule-by-todaymade Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.11 Fixed in 3.4.0 CVE-2025-60119 Patchstack
5.3 Medium WP Directory Kit Plugin wpdirectorykit Broken Access Control No login needed ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-60120 Patchstack
8.5 High PGS Core Plugin pgs-core SQL Injection ≤ 5.9.0 CVE-2025-60118 Patchstack
4.3 Medium Vehica Core Plugin vehica-core Cross-Site Request Forgery No login needed ≤ 1.0.100 Fixed in 1.0.101 CVE-2025-60117 Patchstack
5.4 Medium Grand Conference Theme Custom Post Type Plugin grandconference-custom-post Broken Access Control ≤ 2.6.4 Fixed in 2.6.4 CVE-2025-60116 Patchstack
4.3 Medium Instapage Plugin instapage Cross-Site Request Forgery No login needed ≤ 3.7.0 Fixed in 3.7.1 CVE-2025-60115 Patchstack
6.6 Medium YayCurrency Plugin yaycurrency Remote Code Execution ≤ 3.3.1 Fixed in 3.3.2 CVE-2025-60114 Patchstack
4.3 Medium Groovy Menu Plugin groovy-menu-free Cross-Site Request Forgery No login needed ≤ 1.4.3 CVE-2025-60113 Patchstack
6.5 Medium aThemes Addons for Elementor Plugin athemes-addons-for-elementor-lite Cross-Site Scripting ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-60112 Patchstack
8.8 High Javo Core Plugin javo-core Cross-Site Request Forgery No login needed ≤ 3.0.0.266 CVE-2025-60111 Patchstack
8.5 High AllInOne - Banner Rotator Plugin all-in-one-bannerrotator SQL Injection Banner Rotator Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60110 Patchstack
8.5 High LambertGroup - AllInOne - Content Slider Plugin all-in-one-contentslider SQL Injection AllInOne - Content Slider Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60109 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Thumbnails Plugin all-in-one-thumbnailsbanner SQL Injection AllInOne - Banner with Thumbnails Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60108 Patchstack
8.5 High LambertGroup - AllInOne - Banner with Playlist Plugin all-in-one-bannerwithplaylist SQL Injection AllInOne - Banner with Playlist Plugin <= 3.8 - SQL Injection ≤ 3.8 CVE-2025-60107 Patchstack
4.9 Medium EmailKit Plugin emailkit Broken Access Control Arbitrary Content Deletion ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-60106 Patchstack
6.5 Medium Ditty Plugin ditty-news-ticker Cross-Site Scripting ≤ 3.1.58 Fixed in 3.1.59 CVE-2025-60105 Patchstack
5.9 Medium Gallery Custom Links Plugin gallery-custom-links Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-60104 Patchstack
5.4 Medium ListingPro Plugin listingpro-plugin Broken Access Control ≤ 2.9.8 CVE-2025-60103 Patchstack
6.5 Medium WPFront User Role Editor Plugin wpfront-user-role-editor Cross-Site Scripting ≤ 4.2.3 Fixed in 4.2.4 CVE-2025-60102 Patchstack
6.5 Medium Embed Any Document Plugin embed-any-document Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-60099 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only