WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,801–6,850 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 137 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Mihdan: Elementor Yandex Maps Plugin mihdan-elementor-yandex-maps Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Marker Pins ≤ 1.6.11 CVE-2025-8608 Wordfence
6.4 Medium The Pack Elementor addon Plugin the-pack-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Typing Letter Widget ≤ 2.1.5 CVE-2025-8214 Wordfence
6.4 Medium BP Direct Menus Plugin bp-direct-menus Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-10189 Wordfence
6.4 Medium Any News Ticker Plugin any-news-ticker Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.1 CVE-2025-10168 Wordfence
6.4 Medium dbview Plugin dbview Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.5.5 CVE-2025-10182 Wordfence
4.3 Medium Chat by Chatwee Plugin chatwee Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.1.3 CVE-2025-9948 Wordfence
6.4 Medium Nexa Blocks Plugin nexa-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps Widget ≤ 1.1.0 CVE-2025-8624 Wordfence
6.5 Medium All in One Music Player Plugin all-in-one-music-player Path Traversal Authenticated (Contributor+) Path Traversal via theme Parameter ≤ 1.3.1 CVE-2025-8559 Wordfence
6.4 Medium Big Post Shipping for WooCommerce Plugin woo-bigpost-shipping Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.2 CVE-2025-10191 Wordfence
6.4 Medium WeedMaps Menu Plugin weedmaps-menu-embed Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via weedmaps_menu Shortcode ≤ 1.2.0 CVE-2025-8623 Wordfence
6.4 Medium All Social Share Options Plugin all-social-share-options Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-10131 Wordfence
6.4 Medium Yoga Schedule Momoyoga Plugin momoyoga-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.9.0 CVE-2025-9852 Wordfence
6.4 Medium Qyrr – simply and modern QR-Code creation Plugin qyrr-code Arbitrary File Upload simply and modern QR-Code creation <= 2.0.7 - Authenticated (Contributor+) Arbitrary File Upload ≤ 2.0.7 CVE-2025-10000 Wordfence
6.4 Medium FancyTabs Plugin fancytabs Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter ≤ 1.1.0 CVE-2025-8560 Wordfence
6.4 Medium Layers Plugin layers Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 0.5 CVE-2025-10130 Wordfence
6.4 Medium My AskAI Plugin my-askai Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.0 CVE-2025-10179 Wordfence
6.4 Medium GutenBee – Gutenberg Blocks Plugin gutenbee Cross-Site Scripting Gutenberg Blocks <= 2.18.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.18.0 CVE-2025-8566 Wordfence
4.8 Medium Postie Plugin postie Cross-Site Scripting Admin+ Stored XSS < 1.9.71 Fixed in 1.9.71 CVE-2024-5200 WPScan
4.3 Medium VM Menu Reorder Plugin vm-menu-reorder Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-9893 Wordfence
4.3 Medium Professional Contact Form Plugin professional-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Test Email Sending No login needed ≤ 1.0.0 CVE-2025-9944 Wordfence
4.3 Medium cForms – Light speed fast Form Builder Plugin cforms-plugin Cross-Site Request Forgery Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-9898 Wordfence
6.1 Medium Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms Plugin trust-reviews Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9899 Wordfence
4.3 Medium Sync Feedly Plugin sync-feedly Cross-Site Request Forgery Cross-Site Request Forgery to Sync Trigger No login needed ≤ 1.0.1 CVE-2025-9894 Wordfence
4.3 Medium HidePost Plugin hidepost Cross-Site Request Forgery No login needed ≤ 2.3.8 CVE-2025-9896 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
6.4 Medium Team Members Plugin team-members Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.5 CVE-2025-8440 Wordfence
5.9 Medium Google+ Comments Plugin google-plus-comments Cross-Site Scripting ≤ 1.0 CVE-2025-60186 Patchstack
5.9 Medium kontur Admin Style Plugin kontur-admin-style Cross-Site Scripting ≤ 1.0.4 Fixed in 1.0.5 CVE-2025-60185 Patchstack
5.9 Medium SEO Search Permalink Plugin seo-search-permalink Cross-Site Scripting ≤ 1.0.3 CVE-2025-60184 Patchstack
5.4 Medium Silencesoft RSS Reader Plugin external-rss-reader Server-Side Request Forgery No login needed ≤ 0.6 CVE-2025-60181 Patchstack
5.9 Medium Click & Tweet Plugin click-tweet Cross-Site Scripting ≤ 0.8.9 CVE-2025-60179 Patchstack
5.9 Medium Recaptcha – wp Plugin recaptcha-wp Cross-Site Scripting wp Plugin <= 0.2.6 - Cross Site Scripting (XSS) ≤ 0.2.6 CVE-2025-60177 Patchstack
4.3 Medium Page Manager for Elementor Plugin page-manager-for-elementor Information Disclosure Sensitive Data Exposure ≤ 2.0.5 CVE-2025-60167 Patchstack
4.3 Medium WP Subscription Forms PRO Plugin wp-subscription-forms-pro Broken Access Control Arbitrary Content Deletion ≤ 2.0.5 CVE-2025-60166 Patchstack
4.3 Medium Frames Plugin frames Broken Access Control ≤ 1.5.7 CVE-2025-60165 Patchstack
6.5 Medium bbp topic count Plugin bbp-topic-count Cross-Site Scripting ≤ 3.2 CVE-2025-60163 Patchstack
6.5 Medium Job Board Manager Plugin job-board-manager Cross-Site Scripting ≤ 2.1.61 CVE-2025-60162 Patchstack
5.4 Medium ZoloBlocks Plugin zoloblocks Server-Side Request Forgery No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-60161 Patchstack
5.9 Medium Smart Related Products Plugin ai-related-products Cross-Site Scripting ≤ 2.0.8 CVE-2025-60160 Patchstack
4.3 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Broken Access Control ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60159 Patchstack
5.9 Medium Nota Fiscal Eletrônica WooCommerce Plugin nota-fiscal-eletronica-woocommerce Cross-Site Scripting ≤ 3.4.0.9 Fixed in 3.4.1.0 CVE-2025-60158 Patchstack
6.5 Medium WP Ticket Customer Service Software & Support Ticket System Plugin wp-ticket Cross-Site Scripting ≤ 6.0.2 Fixed in 6.0.3 CVE-2025-60157 Patchstack
5.3 Medium WP Virtual Assistant Plugin virtualassistant Broken Access Control No login needed ≤ 3.0 CVE-2025-60155 Patchstack
5.9 Medium MWW Disclaimer Buttons Plugin mww-disclaimer-buttons Cross-Site Scripting ≤ 3.41 Fixed in 3.5 CVE-2025-60154 Patchstack
4.3 Medium Subscribe To Unlock Plugin subscribe-to-unlock Broken Access Control ≤ 1.1.5 CVE-2025-60152 Patchstack
5.9 Medium Notely Plugin notely Cross-Site Scripting ≤ 1.8.0 Fixed in 1.9.0 CVE-2025-60149 Patchstack
4.3 Medium Subscribe to Download Plugin subscribe-to-download Broken Access Control ≤ 2.0.9 Fixed in 2.1.0 CVE-2025-60148 Patchstack
6.5 Medium HT Feed Plugin ht-instagram Cross-Site Scripting ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-60147 Patchstack
5.9 Medium Map Categories to Pages Plugin map-categories-to-pages Cross-Site Scripting ≤ 1.3.2 CVE-2025-60146 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only