WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,751–6,800 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 136 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.10.0 - Missing Authorization to Unauthenticated Forms and Campaigns Disclosure No login needed ≤ 4.10.0 CVE-2025-11227 Wordfence
5.4 Medium WP Photo Album Plus Plugin wp-photo-album-plus Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload ≤ 9.0.11.006 CVE-2025-8726 Wordfence
4.3 Medium Ultimate Viral Quiz Plugin ultimate-viral-quiz Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2025-10302 Wordfence
6.4 Medium AP Background Plugin ap-background Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.8.2 CVE-2025-10165 Wordfence
4.3 Medium AP Background Plugin ap-background Cross-Site Request Forgery No login needed ≤ 3.8.2 CVE-2025-9897 Wordfence
4.3 Medium Constructor Theme constructor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Theme Clean ≤ 1.6.5 CVE-2025-9194 Wordfence
6.4 Medium X Addons for Elementor Plugin x-addons-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Youtube Video ID Field ≤ 1.0.16 CVE-2025-9204 Wordfence
6.4 Medium Flexi Plugin flexi Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via flexi-form-tag Shortcode ≤ 4.28 CVE-2025-9129 Wordfence
6.3 Medium Schema Plugin For Divi, Gutenberg & Shortcodes Plugin wp-structured-data-schema PHP Object Injection Authenticated (Contributor+) Object Instantiation ≤ 4.3.2 CVE-2025-7825 Wordfence
4.3 Medium Notification Bar Plugin simple-bar Cross-Site Request Forgery No login needed ≤ 2.2 CVE-2025-9895 Wordfence
6.4 Medium Auto Bulb Finder Plugin auto-bulb-finder-for-wp-wc Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.8.0 CVE-2025-9858 Wordfence
4.3 Medium ContentMX Content Publisher Plugin contentmx-content-publisher Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-9889 Wordfence
4.3 Medium WP SinoType Plugin wp-sinotype Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9630 Wordfence
6.4 Medium Fintelligence Calculator Plugin fintelligence-calculator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.3 CVE-2025-9859 Wordfence
4.3 Medium Customify Theme customify Cross-Site Request Forgery No login needed ≤ 0.4.11 CVE-2025-8669 Wordfence
5.5 Medium Ultimate Multi Design Video Carousel Plugin ultimate-multi-design-video-carousel Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 1.4 CVE-2025-9372 Wordfence
6.4 Medium Epic Bootstrap Buttons Plugin epic-bootstrap-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via icol Parameter ≤ 1.0 CVE-2025-8776 Wordfence
5.3 Medium Restrict User Registration Plugin restrict-user-registration Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.1 CVE-2025-9892 Wordfence
6.5 Medium Woo superb slideshow transition gallery with random effect Plugin woo-superb-slideshow-transition-gallery-with-random-effect SQL Injection Authenticated (Contributor+) SQL Injection ≤ 9.1 CVE-2025-9199 Wordfence
4.3 Medium PayPal Forms Plugin paypal-forms Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-10309 Wordfence
4.4 Medium TableGen – Data Table Generator Plugin table-creator Cross-Site Scripting Data Table Generator <= 1.3.1 - Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.3.1 CVE-2025-10053 Wordfence
6.4 Medium Meks Easy Maps Plugin meks-easy-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.4 CVE-2025-9206 Wordfence
6.4 Medium A Simple Multilanguage Plugin a-simple-multilanguage Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-9854 Wordfence
6.4 Medium Generic Elements Plugin generic-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.8 CVE-2025-9080 Wordfence
6.4 Medium WP Photo Effects Plugin wp-photo-effects Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.2.4 CVE-2025-10192 Wordfence
4.3 Medium Optimize More! – CSS Plugin optimize-more-css Cross-Site Request Forgery CSS <= 1.0.3 - Cross-Site Request Forgery to Plugin Settings Reset No login needed ≤ 1.0.3 CVE-2025-9945 Wordfence
6.1 Medium Mobile Site Redirect Plugin mobile-site-redirect Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-9884 Wordfence
6.4 Medium Ultra Addons Lite for Elementor Plugin ut-elementor-addons-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text Field ≤ 1.1.9 CVE-2025-9077 Wordfence
6.4 Medium Ird Slider Plugin ird-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-9876 Wordfence
5.5 Medium Interactive Medical Drawing of Human Body Plugin interactive-medical-drawing-of-human-body Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 2.6 CVE-2025-9332 Wordfence
6.4 Medium Event Tickets, RSVPs, Calendar Plugin ticket-spot Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-9875 Wordfence
6.5 Medium Wp cycle text announcement Plugin wp-cycle-text-announcement SQL Injection Authenticated (Contributor+) SQL Injection ≤ 8.1 CVE-2025-9198 Wordfence
4.3 Medium MPWizard – Create Mercado Pago Payment Links Plugin mpwizard Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2025-9885 Wordfence
5.5 Medium Smart Docs Plugin smart-docs Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting ≤ 1.1.1 CVE-2025-9333 Wordfence
6.4 Medium Unify Plugin unify Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via unify_checkout Shortcode ≤ 3.4.7 CVE-2025-9130 Wordfence
4.3 Medium Comment Info Detector Plugin comment-info-detector Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.5 CVE-2025-10311 Wordfence
5.3 Medium SiteAlert (Formerly WP Health) Plugin my-wp-health-check Broken Access Control Missing Authorization to Unauthenticated Site Health Information Exposure No login needed ≤ 1.9.8 CVE-2025-10212 Wordfence
6.4 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.9 CVE-2025-9045 Wordfence
6.4 Medium Yoast SEO Premium Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting 25.7 – 25.9 CVE-2025-11241 Wordfence
6.1 Medium Schema & Structured Data for WP & AMP Plugin schema-and-structured-data-for-wp Cross-Site Scripting Unauthenticated Stored-XSS No login needed < 1.50 Fixed in 1.50 CVE-2025-9512 WPScan
4.0 Medium Block For Mailchimp – Easy Mailchimp Form Integration Plugin block-for-mailchimp Server-Side Request Forgery Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.12 CVE-2025-10735 Wordfence
6.4 Medium ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns Plugin zoloblocks Cross-Site Scripting Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns <= 2.3.10 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3.10 CVE-2025-9075 Wordfence
5.9 Medium File Manager, Code editor, backup by Managefy Plugin softdiscover-db-file-manager Information Disclosure Unauthenticated Information Exposure No login needed ≤ 1.6.1 CVE-2025-10744 Wordfence
4.3 Medium SmartCrawl SEO checker, analyzer & optimizer Plugin smartcrawl-seo Broken Access Control Missing Authorization to Plugin Settings Update ≤ 3.14.3 CVE-2025-11163 Wordfence
6.4 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 5.1.94 CVE-2025-6941 Wordfence
5.5 Medium LatePoint Plugin latepoint Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 5.1.94 CVE-2025-6815 Wordfence
6.4 Medium planetcalc Plugin planetcalc Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via language Parameter ≤ 2.2 CVE-2025-8777 Wordfence
6.4 Medium SurveyAnyplace Plugin surveyanyplace Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-10196 Wordfence
6.1 Medium LockerPress – WordPress Security Plugin lockerpress-wordpress-security Cross-Site Request Forgery WordPress Security Plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9946 Wordfence
6.4 Medium Eulerpool Research Systems Plugin alleaktien-quantitativ Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 4.0.1 CVE-2025-10128 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only