WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 6,751–6,800 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.5 Medium | GiveWP – Donation Plugin and Fundraising Platform | Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure No login needed |
≤ 4.10.0 |
CVE-2025-11227 |
Wordfence | |
| 5.4 Medium | WP Photo Album Plus | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload |
≤ 9.0.11.006 |
CVE-2025-8726 |
Wordfence | |
| 4.3 Medium | Ultimate Viral Quiz | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0 |
CVE-2025-10302 |
Wordfence | |
| 6.4 Medium | AP Background | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.8.2 |
CVE-2025-10165 |
Wordfence | |
| 4.3 Medium | AP Background | Cross-Site Request Forgery No login needed |
≤ 3.8.2 |
CVE-2025-9897 |
Wordfence | |
| 4.3 Medium | Constructor | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Theme Clean |
≤ 1.6.5 |
CVE-2025-9194 |
Wordfence | |
| 6.4 Medium | X Addons for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field |
≤ 1.0.16 |
CVE-2025-9204 |
Wordfence | |
| 6.4 Medium | Flexi | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode |
≤ 4.28 |
CVE-2025-9129 |
Wordfence | |
| 6.3 Medium | Schema Plugin For Divi, Gutenberg & Shortcodes | PHP Object Injection Authenticated (Contributor+) Object Instantiation |
≤ 4.3.2 |
CVE-2025-7825 |
Wordfence | |
| 4.3 Medium | Notification Bar | Cross-Site Request Forgery No login needed |
≤ 2.2 |
CVE-2025-9895 |
Wordfence | |
| 6.4 Medium | Auto Bulb Finder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.8.0 |
CVE-2025-9858 |
Wordfence | |
| 4.3 Medium | ContentMX Content Publisher | Cross-Site Request Forgery No login needed |
≤ 1.0.6 |
CVE-2025-9889 |
Wordfence | |
| 4.3 Medium | WP SinoType | Cross-Site Request Forgery No login needed |
≤ 1.0 |
CVE-2025-9630 |
Wordfence | |
| 6.4 Medium | Fintelligence Calculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.3 |
CVE-2025-9859 |
Wordfence | |
| 4.3 Medium | Customify | Cross-Site Request Forgery No login needed |
≤ 0.4.11 |
CVE-2025-8669 |
Wordfence | |
| 5.5 Medium | Ultimate Multi Design Video Carousel | Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting |
≤ 1.4 |
CVE-2025-9372 |
Wordfence | |
| 6.4 Medium | Epic Bootstrap Buttons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via icol Parameter |
≤ 1.0 |
CVE-2025-8776 |
Wordfence | |
| 5.3 Medium | Restrict User Registration | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.1 |
CVE-2025-9892 |
Wordfence | |
| 6.5 Medium | Woo superb slideshow transition gallery with random effect | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 9.1 |
CVE-2025-9199 |
Wordfence | |
| 4.3 Medium | PayPal Forms | Cross-Site Request Forgery No login needed |
≤ 1.0.3 |
CVE-2025-10309 |
Wordfence | |
| 4.4 Medium | TableGen – Data Table Generator | Cross-Site Scripting Data Table Generator <= 1.3.1 - Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.3.1 |
CVE-2025-10053 |
Wordfence | |
| 6.4 Medium | Meks Easy Maps | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.1.4 |
CVE-2025-9206 |
Wordfence | |
| 6.4 Medium | A Simple Multilanguage | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0 |
CVE-2025-9854 |
Wordfence | |
| 6.4 Medium | Generic Elements | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.2.8 |
CVE-2025-9080 |
Wordfence | |
| 6.4 Medium | WP Photo Effects | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 1.2.4 |
CVE-2025-10192 |
Wordfence | |
| 4.3 Medium | Optimize More! – CSS | Cross-Site Request Forgery CSS <= 1.0.3 - Cross-Site Request Forgery to Plugin Settings Reset No login needed |
≤ 1.0.3 |
CVE-2025-9945 |
Wordfence | |
| 6.1 Medium | Mobile Site Redirect | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.2.1 |
CVE-2025-9884 |
Wordfence | |
| 6.4 Medium | Ultra Addons Lite for Elementor | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Field |
≤ 1.1.9 |
CVE-2025-9077 |
Wordfence | |
| 6.4 Medium | Ird Slider | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-9876 |
Wordfence | |
| 5.5 Medium | Interactive Medical Drawing of Human Body | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 2.6 |
CVE-2025-9332 |
Wordfence | |
| 6.4 Medium | Event Tickets, RSVPs, Calendar | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.2 |
CVE-2025-9875 |
Wordfence | |
| 6.5 Medium | Wp cycle text announcement | SQL Injection Authenticated (Contributor+) SQL Injection |
≤ 8.1 |
CVE-2025-9198 |
Wordfence | |
| 4.3 Medium | MPWizard – Create Mercado Pago Payment Links | Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed |
≤ 1.2.1 |
CVE-2025-9885 |
Wordfence | |
| 5.5 Medium | Smart Docs | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 1.1.1 |
CVE-2025-9333 |
Wordfence | |
| 6.4 Medium | Unify | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via unify_checkout Shortcode |
≤ 3.4.7 |
CVE-2025-9130 |
Wordfence | |
| 4.3 Medium | Comment Info Detector | Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed |
≤ 1.0.5 |
CVE-2025-10311 |
Wordfence | |
| 5.3 Medium | SiteAlert (Formerly WP Health) | Broken Access Control Missing Authorization to Unauthenticated Site Health Information Exposure No login needed |
≤ 1.9.8 |
CVE-2025-10212 |
Wordfence | |
| 6.4 Medium | Easy Elementor Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.2.9 |
CVE-2025-9045 |
Wordfence | |
| 6.4 Medium | Yoast SEO Premium | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
25.7 – 25.9 |
CVE-2025-11241 |
Wordfence | |
| 6.1 Medium | Schema & Structured Data for WP & AMP | Cross-Site Scripting Unauthenticated Stored-XSS No login needed |
< 1.50 Fixed in 1.50 |
CVE-2025-9512 |
WPScan | |
| 4.0 Medium | Block For Mailchimp – Easy Mailchimp Form Integration | Server-Side Request Forgery Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery No login needed |
≤ 1.1.12 |
CVE-2025-10735 |
Wordfence | |
| 6.4 Medium | ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns | Cross-Site Scripting Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.3.10 |
CVE-2025-9075 |
Wordfence | |
| 5.9 Medium | File Manager, Code editor, backup by Managefy | Information Disclosure Unauthenticated Information Exposure No login needed |
≤ 1.6.1 |
CVE-2025-10744 |
Wordfence | |
| 4.3 Medium | SmartCrawl SEO checker, analyzer & optimizer | Broken Access Control Missing Authorization to Plugin Settings Update |
≤ 3.14.3 |
CVE-2025-11163 |
Wordfence | |
| 6.4 Medium | LatePoint | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 5.1.94 |
CVE-2025-6941 |
Wordfence | |
| 5.5 Medium | LatePoint | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 5.1.94 |
CVE-2025-6815 |
Wordfence | |
| 6.4 Medium | planetcalc | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via language Parameter |
≤ 2.2 |
CVE-2025-8777 |
Wordfence | |
| 6.4 Medium | SurveyAnyplace | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.0 |
CVE-2025-10196 |
Wordfence | |
| 6.1 Medium | LockerPress – WordPress Security | Cross-Site Request Forgery WordPress Security Plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0 |
CVE-2025-9946 |
Wordfence | |
| 6.4 Medium | Eulerpool Research Systems | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 4.0.1 |
CVE-2025-10128 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.