WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,601–6,650 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 133 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Flexible Blogtitle Plugin flexible-blogtitle Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1 CVE-2025-23846 Patchstack
7.1 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.1 CVE-2025-23812 Patchstack
7.1 High InFunding Plugin infunding Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-23768 Patchstack
7.1 High CMC MIGRATE Plugin cmc-migrate Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.0.3 CVE-2025-23746 Patchstack
7.1 High Formatted post Plugin formatted-post Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.01 CVE-2025-23709 Patchstack
7.1 High ReadMe Creator Plugin readme-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23643 Patchstack
7.1 High WP IMAP Auth Plugin wp-imap-authentication Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.0.1 CVE-2025-23506 Patchstack
7.1 High History timeline Plugin history-timeline Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.7.2 CVE-2025-23475 Patchstack
7.1 High FWD Slider Plugin fwd-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23462 Patchstack
7.1 High Simple shortcode buttons Plugin simple-shortcode-buttons Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3.2 CVE-2025-23449 Patchstack
7.1 High Mapbox for WP Advanced Plugin mapbox-for-wp-advanced Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-22772 Patchstack
7.1 High a Gateway for Pasargad Bank on WooCommerce Plugin a-gateway-for-pasargad-bank-on-woocommerce Cross-Site Scripting No login needed ≤ 2.5.2 CVE-2025-23966 Patchstack
7.1 High Good Old Gallery Plugin good-old-gallery Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.2 CVE-2025-23959 Patchstack
8.1 High Improved Sale Badges – Free Version Plugin improved-sale-badges-free-version Local File Inclusion Free Version Plugin <= 1.0.1 - Local File Inclusion No login needed ≤ 1.0.1 CVE-2025-23949 Patchstack
8.1 High Background animation blocks Plugin background-animation-blocks Local File Inclusion No login needed ≤ 2.1.5 CVE-2025-23948 Patchstack
8.8 High WOOEXIM Plugin wooexim PHP Object Injection ≤ 5.0.0 CVE-2025-23944 Patchstack
7.5 High Image Gallery Box by CRUDLab Plugin image-gallery-box-by-crudlab Local File Inclusion ≤ 1.0.3 CVE-2025-23938 Patchstack
8.5 High Menus Plus+ Plugin menus-plus SQL Injection ≤ 1.9.6 CVE-2025-23910 Patchstack
7.1 High WP Block Pack Plugin wp-block-pack Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1.6 CVE-2025-23874 Patchstack
7.1 High WordPress File Search Plugin wpfilesearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23867 Patchstack
7.1 High EU DSGVO Helper Plugin dsgvo Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.6.1 CVE-2025-23866 Patchstack
7.1 High WP2APP Plugin wp2appir Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.2 CVE-2025-23811 Patchstack
7.1 High Ultimate Subscribe Plugin ultimate-subscribe Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-23806 Patchstack
7.1 High Snippy Plugin snippy Cross-Site Request Forgery CSRF to Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23803 Patchstack
7.1 High Mass Messaging in BuddyPress Plugin mass-messaging-in-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.2.1 CVE-2025-23798 Patchstack
7.6 High Contact Form 7 Round Robin Lead Distribution Plugin contact-form-7-round-robin-lead-distribution SQL Injection ≤ 1.2.1 CVE-2025-23784 Patchstack
7.5 High WM Options Import Export Plugin wm-options-import-export Information Disclosure Sensitive Data Exposure No login needed ≤ 1.0.1 CVE-2025-23781 Patchstack
7.5 High WPDB to Sql Plugin wpdb-to-sql Information Disclosure Sensitive Data Exposure No login needed ≤ 1.2 CVE-2025-23774 Patchstack
7.1 High Fast Tube Plugin fast-tube Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.3.1 CVE-2025-23770 Patchstack
7.1 High Content Mirror Plugin content-mirror Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23769 Patchstack
7.1 High Pootle button Plugin pootle-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.0 CVE-2025-23758 Patchstack
7.1 High Easy Filtering Plugin easy-filtering Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.5.0 CVE-2025-23732 Patchstack
7.1 High Jet Skinner for BuddyPress Plugin jet-skinner-for-buddypress Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.5 CVE-2025-23706 Patchstack
7.1 High Lime Developer Login Plugin lime-developer-login Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.0 CVE-2025-23701 Patchstack
7.1 High yCyclista Plugin ycyclista Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2.3 CVE-2025-23700 Patchstack
7.1 High Podčlánková inzerce Plugin podclankova-inzerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.4.0 CVE-2025-23697 Patchstack
7.1 High Staging CDN Plugin staging-cdn Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23696 Patchstack
7.1 High CtyGrid Hyp3rL0cal Search Plugin hyp3rl0cal-city-search Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.1.1.1 CVE-2025-23695 Patchstack
7.1 High Admin Menu Organizer Plugin admin-menu-organizer Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23686 Patchstack
7.1 High MACME Plugin macme Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23683 Patchstack
7.1 High Preloader Quotes Plugin preloader-quotes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23682 Patchstack
7.1 High REDIRECTION PLUS Plugin redirection-plus Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23681 Patchstack
7.1 High FP RSS Category Excluder Plugin fp-rss-category-excluder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-23679 Patchstack
7.1 High LocalGrid Plugin localgrid Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.1 CVE-2025-23678 Patchstack
7.1 High LH Email Plugin lh-email Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.12 CVE-2025-23676 Patchstack
7.1 High Bit.ly linker Plugin bitly-linker Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23674 Patchstack
7.1 High Instant Appointment Plugin instant-appointment Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.2 CVE-2025-23672 Patchstack
7.1 High Content Planner Plugin content-planner Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-23631 Patchstack
7.1 High Cyber Slider Plugin cyber-new-slider Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.1 CVE-2025-23630 Patchstack
7.1 High Unique UX Plugin unique-ux Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 0.9.2 CVE-2025-23625 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only