WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,211 vulnerabilities, 1,526 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 7, 2026.

Showing 6,701–6,750 of 9,010 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 135 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.5 High Standard Box Sizes – for WooCommerce Plugin standard-box-sizes Broken Access Control No login needed ≤ 1.6.13 Fixed in 1.6.14 CVE-2025-22318 Patchstack
7.5 High Private Messages for UserPro Plugin userpro-messaging Local File Inclusion No login needed ≤ 4.10.0 CVE-2025-22311 Patchstack
7.1 High ARPrice Plugin arprice Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 4.1.3 Fixed in 4.2 CVE-2024-49700 Patchstack
8.8 High ARPrice Plugin arprice PHP Object Injection ≤ 4.1.3 Fixed in 4.2 CVE-2024-49699 Patchstack
8.5 High ARPrice Plugin arprice SQL Injection ≤ 4.1.3 Fixed in 4.2 CVE-2024-49666 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49333 Patchstack
8.5 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu SQL Injection ≤ 1.16.5 CVE-2024-49303 Patchstack
7.1 High Hero Mega Menu - Responsive WordPress Menu Plugin hmenu Cross-Site Scripting No login needed ≤ 1.16.5 CVE-2024-49300 Patchstack
8.8 High String Locator Plugin string-locator PHP Object Injection Unauthenticated PHP Object Injection No login needed ≤ 2.6.6 CVE-2024-10936 Wordfence
7.5 High The Ultimate WordPress Toolkit – WP Extended Plugin wpextended SQL Injection WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module No login needed ≤ 3.0.12 CVE-2024-13184 Wordfence
7.5 High Ultimate Member Plugin ultimate-member SQL Injection Unauthenticated SQL Injection No login needed ≤ 2.9.1 CVE-2025-0308 Wordfence
7.2 High GravityForms Plugin Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'alt' parameter No login needed ≤ 2.9.1.3 CVE-2024-13377 Wordfence
7.5 High Advanced File Manager Plugin file-manager-advanced Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload 5.2.12 – 5.2.13 CVE-2024-13333 Wordfence
7.1 High root Cookie Plugin root-cookie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.6 CVE-2025-23815 Patchstack
7.1 High Auto FTP Plugin auto-ftp Cross-Site Request Forgery CSRF to Stored Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-23793 Patchstack
7.1 High Chatter Plugin chatter Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23760 Patchstack
7.5 High FAT Event Lite Plugin fat-event-lite Local File Inclusion Authenticated Non-Arbitrary Local File Inclusion ≤ 1.1 CVE-2025-23915 Patchstack
8.5 High WordPress Custom Sidebar Plugin wordpress-custom-sidebar SQL Injection ≤ 2.3 CVE-2025-23912 Patchstack
7.1 High GravatarLocalCache Plugin gravatarlocalcache Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.2 CVE-2025-23901 Patchstack
8.5 High WordPress Google Map Professional Plugin google-map-professional SQL Injection ≤ 1.0 CVE-2025-23913 Patchstack
8.5 High Solidres – Hotel booking Plugin solidres SQL Injection Hotel booking plugin for WordPress Plugin <= 0.9.4 - SQL Injection ≤ 0.9.4 CVE-2025-23911 Patchstack
7.1 High Genki Announcement Plugin genki-announcement Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23900 Patchstack
7.1 High Error Notification Plugin error-notification Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.2.7 CVE-2025-23902 Patchstack
7.1 High Apply with LinkedIn buttons Plugin apply-with-linkedin-buttons Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.3 CVE-2025-23898 Patchstack
7.1 High Annie Plugin annie Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.1 CVE-2025-23884 Patchstack
7.1 High Add RSS Plugin add-rss Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.5 CVE-2025-23895 Patchstack
7.1 High Better Protected Pages Plugin better-protected-pages Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-23875 Patchstack
7.1 High amr personalise Plugin amr-personalise Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.10 CVE-2025-23880 Patchstack
7.1 High PayForm Plugin payform Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.0 CVE-2025-23872 Patchstack
7.1 High LSD Google Maps Embedder Plugin lsd-google-maps-embedder Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23871 Patchstack
7.1 High Copyright Safeguard Footer Notice Plugin copyright-safeguard-footer-notice Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 3.0 CVE-2025-23870 Patchstack
7.1 High CJ Custom Content Plugin cj-custom-content Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 2.0 CVE-2025-23869 Patchstack
7.1 High Debt Calculator Plugin debt-calculator Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23861 Patchstack
7.1 High Hotspots Analytics Plugin hotspots Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.0.12 CVE-2025-23848 Patchstack
7.1 High Gallery Plugin wordpress-gallery-plugin Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4 CVE-2025-23842 Patchstack
7.1 High Custom Widget Classes Plugin custom-widget-classes Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1 CVE-2025-23844 Patchstack
7.1 High WordPress Data Guard Plugin wordpress-data-guards Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 8 CVE-2025-23828 Patchstack
7.1 High Stop Comment Spam Plugin stop-comment-spam Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.5.3 Fixed in 0.5.4 CVE-2025-23826 Patchstack
7.1 High CNZZ&51LA Plugin cnzz51la-for-wordpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 CVE-2025-23823 Patchstack
7.1 High WP Cookies Alert Plugin wp-cookies-alert Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.1.1 CVE-2025-23821 Patchstack
7.1 High Admin Cleanup Plugin admin-cleanup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.2 CVE-2025-23832 Patchstack
7.1 High Strx Magic Floating Sidebar Maker Plugin strx-magic-floating-sidebar-maker Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.1 CVE-2025-23827 Patchstack
7.1 High Content Security Policy Pro Plugin content-security-policy-pro Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.5 CVE-2025-23820 Patchstack
7.1 High More Link Modifier Plugin more-link-modifier Cross-Site Request Forgery CSRF to Cross-Site Scripting No login needed ≤ 1.0.3 CVE-2025-23818 Patchstack
7.1 High Category Custom Fields Plugin categorycustomfields Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-23822 Patchstack
7.1 High Custom List Table Example Plugin custom-list-table-example Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 1.4.1 CVE-2025-23808 Patchstack
7.1 High MHR-Custom-Anti-Copy Plugin mhr-custom-anti-copy Cross-Site Request Forgery CSRF to Stored Cross Site Request Forgery (CSRF) No login needed ≤ 2.0 CVE-2025-23817 Patchstack
7.1 High SEOReseller Partner Plugin sr-partner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.3.15 CVE-2025-23805 Patchstack
7.1 High Len Slider Plugin len-slider Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.11 CVE-2025-23810 Patchstack
7.1 High WP Service Payment Form With Authorize.net Plugin wp-service-payment-form-with-authorizenet Cross-Site Request Forgery CSRF to Reflected Cross Site Scripting (XSS) No login needed ≤ 2.6.0 CVE-2025-23804 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only