WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,501–6,550 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 131 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium SpendeOnline.org Plugin spendeonline Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.0.1 CVE-2025-11875 Wordfence
5.3 Medium Social Feed Gallery Plugin insta-gallery Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 4.9.2 CVE-2025-10637 Wordfence
6.3 Medium Discussion Board – WordPress Forum Plugin Arbitrary Shortcode Execution WordPress Forum Plugin <= 2.5.5 - Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 2.5.5 CVE-2025-8483 Wordfence
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery Cross-Site Request Forgery to Settings Manipulation No login needed ≤ 3.1.6 CVE-2025-11497 Wordfence
4.3 Medium Password Policy Manager | Password Manager Plugin Broken Access Control Missing Authorization to Authenticated (Subscriber+) Configuration Log Out ≤ 2.0.5 CVE-2025-11255 Wordfence
6.4 Medium Widget Options – The #1 WordPress Widget & Block Control Plugin Cross-Site Scripting The #1 WordPress Widget & Block Control Plugin <= 4.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.1.2 CVE-2025-10580 Wordfence
6.5 Medium Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More Plugin charitable SQL Injection Donation Plugin for WordPress – Fundraising with Recurring Donations & More <= 1.8.8.4 - Authenticated (Subscriber+) SQL Injection ≤ 1.8.8.4 CVE-2025-11893 Wordfence
4.4 Medium Fast Velocity Minify Plugin fast-velocity-minify Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 3.5.1 CVE-2025-12034 Wordfence
4.3 Medium WP VR – 360 Panorama and Free Virtual Tour Builder Plugin wpvr Broken Access Control Improper Authorization to Authenticated (Contributor+) Plugin Settings Update ≤ 8.5.41 CVE-2025-12005 Wordfence
5.3 Medium User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds Plugin userfeedback-lite Broken Access Control Create Interactive Feedback Form, User Surveys, and Polls in Seconds <= 1.8.0 - Missing Authorization to Information Disclosure No login needed ≤ 1.8.0 CVE-2025-10694 Wordfence
5.4 Medium Tutor LMS Pro – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.8.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to View/Edit Other Assignments ≤ 3.8.3 CVE-2025-6639 Wordfence
6.5 Medium GenerateBlocks Plugin generateblocks Information Disclosure Improper Authorization to Authenticated (Contributor+) Arbitrary Options Disclosure ≤ 2.1.1 CVE-2025-11879 Wordfence
6.4 Medium Open Source Genesis Framework Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Shortcodes ≤ 3.6.0 CVE-2025-10737 Wordfence
6.4 Medium Gutenberg Blocks – PublishPress Blocks Controls, Visibility, Reusable Blocks Plugin advanced-gutenberg Cross-Site Scripting PublishPress Blocks Controls, Visibility, Reusable Blocks <= 3.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.3.4 CVE-2025-8588 Wordfence
5.3 Medium Tutor LMS – eLearning and online course solution Plugin tutor Broken Access Control eLearning and online course solution <= 3.8.3 - Missing Authorization to Unauthenticated Payment Status Update No login needed ≤ 3.8.3 CVE-2025-11564 Wordfence
6.4 Medium Testimonial Carousel For Elementor Plugin testimonials-carousel-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 11.6.2 CVE-2025-8666 Wordfence
6.4 Medium Listeo Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via soundcloud Shortcode ≤ 2.0.8 CVE-2025-8413 Wordfence
4.3 Medium Tutor LMS Plugin tutor Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 3.8.3 CVE-2025-6680 Wordfence
5.3 Medium Product Filter by WBW Plugin Broken Access Control Missing Authorization to Unauthenticated Settings Update No login needed ≤ 3.0.0 CVE-2025-11269 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.2.4 CVE-2025-11823 Wordfence
5.3 Medium BackWPup Plugin backwpup Broken Access Control Missing Authorization to Sensitive Information Exposure ≤ 5.5.0 CVE-2025-10579 Wordfence
5.3 Medium eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams Plugin eroom-zoom-meetings-webinar Information Disclosure Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information Exposure No login needed ≤ 1.5.6 CVE-2025-11760 Wordfence
4.3 Medium AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant Plugin chatbot-ai-free-models Content Injection Customer Support, Live Chat, Virtual Assistant <= 1.6.5 - Unauthenticated CSV Injection No login needed ≤ 1.6.5 CVE-2025-11576 Wordfence
5.3 Medium ZoloBlocks Plugin zoloblocks Broken Access Control Missing Authorization to Unauthenticated Popup Enable/Disable No login needed ≤ 2.3.11 CVE-2025-12134 Wordfence
6.8 Medium Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint ≤ 5.2.4 CVE-2025-12136 Wordfence
6.1 Medium VNPAY for Woocommerce Plugin vnpay-for-woocommerce Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-12017 Wordfence
5.4 Medium Microsoft Azure Storage Plugin windows-azure-storage Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Media Deletion ≤ 4.5.1 CVE-2025-10749 Wordfence
4.3 Medium Check Plagiarism Plugin check-plagiarism Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 2.0 CVE-2025-11172 Wordfence
4.3 Medium Originality.ai AI Checker Plugin originality-ai Broken Access Control Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'ai_get_table' ≤ 1.0.16 CVE-2025-10901 Wordfence
4.3 Medium Originality.ai AI Checker Plugin originality-ai Broken Access Control Missing Authorization to Authenticated (Subscriber+) Scan Log Deletion via ' ai_scan_result_remove' ≤ 1.0.15 CVE-2025-10902 Wordfence
4.3 Medium NGINX Cache Optimizer Plugin nginx-cache-optimizer Broken Access Control Missing Authorization to Authenticated (Subscriber+) Dynamic Caching Exclusion Update ≤ 1.1 CVE-2025-12014 Wordfence
4.3 Medium LLM Hubspot Blog Import Plugin llm-hubspot-blog-import Broken Access Control Missing Authorization to Authenticated (Subscriber+) Hubspot Import ≤ 1.0.1 CVE-2025-11257 Wordfence
6.4 Medium Simple Excel Pricelist for WooCommerce Plugin simple-excel-pricelist-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.13 CVE-2025-12096 Wordfence
6.5 Medium RapidResult Plugin rapidresult SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.2 CVE-2025-10748 Wordfence
6.4 Medium Time Clock – A WordPress Employee & Volunteer Time Clock Plugin time-clock Cross-Site Scripting A WordPress Employee & Volunteer Time Clock Plugin <= 1.3.1 - Authenticated (Custom+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-10701 Wordfence
4.3 Medium Supervisor Plugin supervisor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.3.2 CVE-2025-11887 Wordfence
6.3 Medium URL Shortener Plugin exact-links Broken Access Control Missing Authorization to Authenticated (Subscriber+) Link Manipulation ≤ 3.0.7 CVE-2025-10740 Wordfence
4.3 Medium Disable Content Editor For Specific Template Plugin disable-contect-editor-for-specific-template Cross-Site Request Forgery Cross-Site Request Forgery to Template Configuration Update No login needed ≤ 2.0 CVE-2025-12072 Wordfence
6.1 Medium Multi Item Responsive Slider Plugin mislider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-11992 Wordfence
4.4 Medium qnotsquiz Plugin qnotsquiz Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-12016 Wordfence
5.5 Medium Orbit Fox Plugin Server-Side Request Forgery Author+ Server-Side Request Forgery < 3.0.2 Fixed in 3.0.2 CVE-2025-10874 WPScan
6.8 Medium Jeg Elementor Kit Plugin Cross-Site Scripting Author+ Stored XSS < 2.7.0 Fixed in 2.7.0 CVE-2025-9978 WPScan
6.4 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via `percentage` Parameter ≤ 5.4.5 CVE-2025-7730 Wordfence
5.0 Medium Feedzy RSS Feeds Lite Plugin feedzy-rss-feeds Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 5.1.0 CVE-2025-11128 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.4.6 CVE-2025-10705 Wordfence
6.4 Medium Beaver Builder Plugin (Starter Version) Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'auto_play' ≤ 2.9.2.1 CVE-2025-8427 Wordfence
4.3 Medium MeetingHub Plugin meetinghub Broken Access Control ≤ 1.23.9 Fixed in 1.23.10 CVE-2025-62073 Patchstack
4.3 Medium Front End Users Plugin front-end-only-users Broken Access Control ≤ 3.2.33 Fixed in 3.2.34 CVE-2025-62072 Patchstack
4.3 Medium Social proof testimonials and reviews by Repuso Plugin social-testimonials-and-reviews-widget Broken Access Control ≤ 5.29 Fixed in 5.30 CVE-2025-62071 Patchstack
4.3 Medium WowRevenue Plugin revenue Broken Access Control ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62070 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only