WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,701–6,750 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | WPBakery Page Builder | Cross-Site Scripting Stored Cross-Site Scripting via Custom JS Module |
≤ 8.6.1 |
CVE-2025-11160 |
Wordfence | |
| 5.5 Medium | BlindMatrix e-Commerce | Local File Inclusion Contributor+ LFI |
< 3.1 Fixed in 3.1 |
CVE-2025-10406 |
WPScan | |
| 6.4 Medium | Ova Advent | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.1.7 |
CVE-2025-8561 |
Wordfence | |
| 4.3 Medium | Quick Featured Images | Broken Access Control Insecure Direct Object Reference to Image Manipulation |
≤ 13.7.2 |
CVE-2025-11176 |
Wordfence | |
| 6.1 Medium | Simple SEO | Cross-Site Scripting Contributor+ Stored XSS No login needed |
< 2.0.32 Fixed in 2.0.32 |
CVE-2025-10357 |
WPScan | |
| 4.3 Medium | SureForms – Drag and Drop Form Builder | Broken Access Control Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure |
≤ 1.12.1 |
CVE-2025-10732 |
Wordfence | |
| 6.8 Medium | The Plus Addons for Elementor | Cross-Site Scripting Author+ Stored XSS |
< 6.3.16 Fixed in 6.3.16 |
CVE-2025-9698 |
WPScan | |
| 4.3 Medium | Course Redirects for Learndash | Cross-Site Request Forgery No login needed |
≤ 0.4 |
CVE-2025-10376 |
Wordfence | |
| 4.3 Medium | Web Accessibility By accessiBe | Cross-Site Request Forgery No login needed |
≤ 2.10 |
CVE-2025-10375 |
Wordfence | |
| 6.4 Medium | WordPress Live Webcam Widget & Shortcode | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2 |
CVE-2025-10129 |
Wordfence | |
| 4.9 Medium | Custom 404 Pro | SQL Injection Authenticated (Administrator+) SQL Injection via `path` Parameter |
≤ 3.12.0 |
CVE-2025-9947 |
Wordfence | |
| 6.5 Medium | WP Links Page | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 4.9.6 |
CVE-2025-10175 |
Wordfence | |
| 5.3 Medium | Code Quality Control Tool | Information Disclosure Unauthenticated Information Exposure via Log Files No login needed |
≤ 2.1 |
CVE-2025-8484 |
Wordfence | |
| 4.9 Medium | Error Log Viewer by BestWebSoft | Path Traversal Authenticated (Administrator+) Arbitrary File Read |
≤ 1.1.6 |
CVE-2025-9950 |
Wordfence | |
| 4.3 Medium | Newsup | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Installation |
≤ 5.0.10 |
CVE-2025-8682 |
Wordfence | |
| 6.4 Medium | WP Easy Toggles | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.9.0 |
CVE-2025-10190 |
Wordfence | |
| 4.3 Medium | Page Blocks | Cross-Site Request Forgery No login needed |
≤ 1.1.0 |
CVE-2025-9626 |
Wordfence | |
| 6.8 Medium | WP Scraper | Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery |
≤ 5.8.1 |
CVE-2025-9975 |
Wordfence | |
| 6.4 Medium | Easy Plugin Stats | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.1 |
CVE-2025-7652 |
Wordfence | |
| 6.4 Medium | Stock History & Reports Manager for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.2 |
CVE-2025-10167 |
Wordfence | |
| 4.3 Medium | WidgetPack Comment System | Cross-Site Request Forgery No login needed |
≤ 1.6.1 |
CVE-2025-9621 |
Wordfence | |
| 4.7 Medium | CM Registration – Tailored tool for seamless login and invitation-based registrations | Open Redirect Tailored tool for seamless login and invitation-based registrations <= 2.5.6 - Open Redirect No login needed |
≤ 2.5.6 |
CVE-2025-11167 |
Wordfence | |
| 5.3 Medium | WPC Smart Wishlist for WooCommerce | Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed |
≤ 5.0.3 |
CVE-2025-11518 |
Wordfence | |
| 4.3 Medium | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe | Content Injection Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection No login needed |
≤ 27.0.3 |
CVE-2025-11254 |
Wordfence | |
| 4.9 Medium | NEX-Forms – Ultimate Forms | SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection |
≤ 9.1.6 |
CVE-2025-10185 |
Wordfence | |
| 4.9 Medium | My Auctions Allegro | SQL Injection Authenticated (Admin+) SQL Injection |
≤ 3.6.31 |
CVE-2025-10048 |
Wordfence | |
| 5.3 Medium | Trinity Audio | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 5.21.0 |
CVE-2025-9196 |
Wordfence | |
| 6.4 Medium | Draft List | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.6.1 |
CVE-2025-11197 |
Wordfence | |
| 6.4 Medium | Enable Media Replace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode |
≤ 4.1.6 |
CVE-2025-9496 |
Wordfence | |
| 5.9 Medium | Everest Backup | Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed |
≤ 2.3.5 |
CVE-2025-11380 |
Wordfence | |
| 6.4 Medium | Colibri Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode |
≤ 1.0.334 |
CVE-2025-9560 |
Wordfence | |
| 5.4 Medium | WP JobHunt | Broken Access Control WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass |
≤ 7.6 |
CVE-2025-7374 |
Wordfence | |
| 6.4 Medium | WP JobHunt | Cross-Site Scripting Authenticated (Candidate+) Stored Cross-Site Scripting via ‘cs_job_title’ |
≤ 7.6 |
CVE-2025-7781 |
Wordfence | |
| 4.5 Medium | Booking Manager | Broken Access Control Contributor+ Booking Deletion |
< 2.1.15 Fixed in 2.1.15 |
CVE-2025-10124 |
WPScan | |
| 6.5 Medium | Slider Revolution | Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Read |
≤ 6.7.37 |
CVE-2025-10249 |
Wordfence | |
| 6.4 Medium | Betheme | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_title' |
≤ 28.1.6 |
CVE-2025-9371 |
Wordfence | |
| 5.4 Medium | WP Go Maps (formerly WP Google Maps) | Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed |
≤ 9.0.46 |
CVE-2025-11166 |
Wordfence | |
| 6.5 Medium | Welcart e-Commerce | SQL Injection Authenticated (Author+) SQL Injection via Cookie |
≤ 2.11.21 |
CVE-2025-10649 |
Wordfence | |
| 5.3 Medium | Chartify – WordPress Chart | Authentication Bypass WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function No login needed |
≤ 3.5.9 |
CVE-2025-11171 |
Wordfence | |
| 5.3 Medium | WP Reset | Information Disclosure Unauthenticated Sensitive Information Exposure via wf-licensing.log No login needed |
≤ 2.05 |
CVE-2025-10645 |
Wordfence | |
| 6.4 Medium | Featured Image from URL (FIFU) | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields |
≤ 5.2.7 |
CVE-2025-7400 |
Wordfence | |
| 6.3 Medium | Responsive Lightbox & Gallery | Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed |
< 2.5.3 Fixed in 2.5.3 |
CVE-2025-9710 |
WPScan | |
| 4.3 Medium | Ultimate Addons for Elementor Lite | Cross-Site Scripting Author+ Stored XSS |
< 2.5.0 Fixed in 2.5.0 |
CVE-2025-9703 |
WPScan | |
| 4.3 Medium | Trinity Audio | Cross-Site Request Forgery No login needed |
≤ 5.20.2 |
CVE-2025-9886 |
Wordfence | |
| 6.4 Medium | Contest Gallery – Upload, Vote & Sell with PayPal and Stripe | Cross-Site Scripting Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 27.0.2 |
CVE-2025-10383 |
Wordfence | |
| 6.1 Medium | Trinity Audio | Cross-Site Scripting Reflected Cross-Site Scripting No login needed |
≤ 5.20.2 |
CVE-2025-9952 |
Wordfence | |
| 4.3 Medium | WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder | Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function |
≤ 1.2.16 |
CVE-2025-9029 |
Wordfence | |
| 5.3 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association No login needed |
≤ 4.10.0 |
CVE-2025-11228 |
Wordfence | |
| 5.4 Medium | Majestic Before After Image | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.2 |
CVE-2025-9030 |
Wordfence | |
| 6.5 Medium | Integrate Dynamics 365 CRM | Broken Access Control Missing Authorization No login needed |
≤ 1.0.9 |
CVE-2025-10746 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.