WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,701–6,750 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 135 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Stored Cross-Site Scripting via Custom JS Module ≤ 8.6.1 CVE-2025-11160 Wordfence
5.5 Medium BlindMatrix e-Commerce Plugin window-blinds-solution Local File Inclusion Contributor+ LFI < 3.1 Fixed in 3.1 CVE-2025-10406 WPScan
6.4 Medium Ova Advent Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.1.7 CVE-2025-8561 Wordfence
4.3 Medium Quick Featured Images Plugin quick-featured-images Broken Access Control Insecure Direct Object Reference to Image Manipulation ≤ 13.7.2 CVE-2025-11176 Wordfence
6.1 Medium Simple SEO Plugin cds-simple-seo Cross-Site Scripting Contributor+ Stored XSS No login needed < 2.0.32 Fixed in 2.0.32 CVE-2025-10357 WPScan
4.3 Medium SureForms – Drag and Drop Form Builder Plugin sureforms Broken Access Control Drag and Drop Form Builder for WordPress <= 1.12.1 - Missing Authorization to Authenticated (Contributor+) Information Disclosure ≤ 1.12.1 CVE-2025-10732 Wordfence
6.8 Medium The Plus Addons for Elementor Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Author+ Stored XSS < 6.3.16 Fixed in 6.3.16 CVE-2025-9698 WPScan
4.3 Medium Course Redirects for Learndash Plugin course-redirects-for-learndash Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-10376 Wordfence
4.3 Medium Web Accessibility By accessiBe Plugin accessibe Cross-Site Request Forgery No login needed ≤ 2.10 CVE-2025-10375 Wordfence
6.4 Medium WordPress Live Webcam Widget & Shortcode Plugin wp-webcam-widget-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2 CVE-2025-10129 Wordfence
4.9 Medium Custom 404 Pro Plugin custom-404-pro SQL Injection Authenticated (Administrator+) SQL Injection via `path` Parameter ≤ 3.12.0 CVE-2025-9947 Wordfence
6.5 Medium WP Links Page Plugin wp-links-page SQL Injection Authenticated (Subscriber+) SQL Injection ≤ 4.9.6 CVE-2025-10175 Wordfence
5.3 Medium Code Quality Control Tool Plugin code-quality-control-tool Information Disclosure Unauthenticated Information Exposure via Log Files No login needed ≤ 2.1 CVE-2025-8484 Wordfence
4.9 Medium Error Log Viewer by BestWebSoft Plugin error-log-viewer Path Traversal Authenticated (Administrator+) Arbitrary File Read ≤ 1.1.6 CVE-2025-9950 Wordfence
4.3 Medium Newsup Theme newsup Broken Access Control Missing Authorization to Authenticated (Subscriber+) Plugin Installation ≤ 5.0.10 CVE-2025-8682 Wordfence
6.4 Medium WP Easy Toggles Plugin wp-easy-toggles Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9.0 CVE-2025-10190 Wordfence
4.3 Medium Page Blocks Plugin page-blocks Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-9626 Wordfence
6.8 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 5.8.1 CVE-2025-9975 Wordfence
6.4 Medium Easy Plugin Stats Plugin easy-plugin-stats Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.1 CVE-2025-7652 Wordfence
6.4 Medium Stock History & Reports Manager for WooCommerce Plugin stock-snapshot-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.2 CVE-2025-10167 Wordfence
4.3 Medium WidgetPack Comment System Plugin widgetpack-comment-system Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-9621 Wordfence
4.7 Medium CM Registration – Tailored tool for seamless login and invitation-based registrations Plugin cm-invitation-codes Open Redirect Tailored tool for seamless login and invitation-based registrations <= 2.5.6 - Open Redirect No login needed ≤ 2.5.6 CVE-2025-11167 Wordfence
5.3 Medium WPC Smart Wishlist for WooCommerce Plugin woo-smart-wishlist Broken Access Control Insecure Direct Object Reference to Unauthenticated Wishlist Manipulation No login needed ≤ 5.0.3 CVE-2025-11518 Wordfence
4.3 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Content Injection Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection No login needed ≤ 27.0.3 CVE-2025-11254 Wordfence
4.9 Medium NEX-Forms – Ultimate Forms Plugin nex-forms-express-wp-form-builder SQL Injection Ultimate Forms Plugin for WordPress <= 9.1.6 - Authenticated (Admin+) SQL Injection ≤ 9.1.6 CVE-2025-10185 Wordfence
4.9 Medium My Auctions Allegro Plugin my-auctions-allegro-free-edition SQL Injection Authenticated (Admin+) SQL Injection ≤ 3.6.31 CVE-2025-10048 Wordfence
5.3 Medium Trinity Audio Plugin trinity-audio Information Disclosure Unauthenticated Information Exposure No login needed ≤ 5.21.0 CVE-2025-9196 Wordfence
6.4 Medium Draft List Plugin simple-draft-list Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.6.1 CVE-2025-11197 Wordfence
6.4 Medium Enable Media Replace Plugin enable-media-replace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via file_modified Shortcode ≤ 4.1.6 CVE-2025-9496 Wordfence
5.9 Medium Everest Backup Plugin everest-backup Broken Access Control Missing Authorization to Unauthenticated Information Exposure No login needed ≤ 2.3.5 CVE-2025-11380 Wordfence
6.4 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via colibri_newsletter Shortcode ≤ 1.0.334 CVE-2025-9560 Wordfence
5.4 Medium WP JobHunt Plugin Broken Access Control WP JobHunt <= 7.6 Authenticated (Custom+) Authorization Bypass ≤ 7.6 CVE-2025-7374 Wordfence
6.4 Medium WP JobHunt Plugin Cross-Site Scripting Authenticated (Candidate+) Stored Cross-Site Scripting via ‘cs_job_title’ ≤ 7.6 CVE-2025-7781 Wordfence
4.5 Medium Booking Manager Plugin booking-manager Broken Access Control Contributor+ Booking Deletion < 2.1.15 Fixed in 2.1.15 CVE-2025-10124 WPScan
6.5 Medium Slider Revolution Plugin Broken Access Control Missing Authorization to Authenticated (Contributor+) Arbitrary File Read ≤ 6.7.37 CVE-2025-10249 Wordfence
6.4 Medium Betheme Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_title' ≤ 28.1.6 CVE-2025-9371 Wordfence
5.4 Medium WP Go Maps (formerly WP Google Maps) Plugin wp-google-maps Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 9.0.46 CVE-2025-11166 Wordfence
6.5 Medium Welcart e-Commerce Plugin usc-e-shop SQL Injection Authenticated (Author+) SQL Injection via Cookie ≤ 2.11.21 CVE-2025-10649 Wordfence
5.3 Medium Chartify – WordPress Chart Plugin chart-builder Authentication Bypass WordPress Chart Plugin <= 3.5.9 - Missing Authentication for Administrative Function No login needed ≤ 3.5.9 CVE-2025-11171 Wordfence
5.3 Medium WP Reset Plugin wp-reset Information Disclosure Unauthenticated Sensitive Information Exposure via wf-licensing.log No login needed ≤ 2.05 CVE-2025-10645 Wordfence
6.4 Medium Featured Image from URL (FIFU) Plugin featured-image-from-url Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Featured Image Custom Fields ≤ 5.2.7 CVE-2025-7400 Wordfence
6.3 Medium Responsive Lightbox & Gallery Plugin responsive-lightbox Cross-Site Scripting Unauthenticated Stored-XSS via Comments No login needed < 2.5.3 Fixed in 2.5.3 CVE-2025-9710 WPScan
4.3 Medium Ultimate Addons for Elementor Lite Plugin Cross-Site Scripting Author+ Stored XSS < 2.5.0 Fixed in 2.5.0 CVE-2025-9703 WPScan
4.3 Medium Trinity Audio Plugin trinity-audio Cross-Site Request Forgery No login needed ≤ 5.20.2 CVE-2025-9886 Wordfence
6.4 Medium Contest Gallery – Upload, Vote & Sell with PayPal and Stripe Plugin contest-gallery Cross-Site Scripting Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 27.0.2 CVE-2025-10383 Wordfence
6.1 Medium Trinity Audio Plugin trinity-audio Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 5.20.2 CVE-2025-9952 Wordfence
4.3 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin wdesignkit Broken Access Control Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.16 - Missing Authentication via wdkit_handle_review_submission Function ≤ 1.2.16 CVE-2025-9029 Wordfence
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms-Campaign Association No login needed ≤ 4.10.0 CVE-2025-11228 Wordfence
5.4 Medium Majestic Before After Image Plugin majestic-before-after-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.2 CVE-2025-9030 Wordfence
6.5 Medium Integrate Dynamics 365 CRM Plugin integrate-dynamics-365-crm Broken Access Control Missing Authorization No login needed ≤ 1.0.9 CVE-2025-10746 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only