WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 651–700 of 1,414 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 14 of 29
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 2.0 - Cross Site Scripting (XSS) ≤ 2.0 Fixed in 2.1 CVE-2025-46235 Patchstack
8.8 High Greenshift Plugin greenshift-animation-and-page-builder-blocks Arbitrary File Upload Authenticated (Subscriber+) Arbitrary File Upload 11.4 – 11.4.5 CVE-2025-3616 Wordfence
7.1 High Rebuild Permalinks Plugin rebuild-permalinks Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.6 CVE-2025-27346 Patchstack
7.1 High Listings for Buildium Plugin listings-for-buildium Cross-Site Request Forgery No login needed ≤ 0.1.5 Fixed in 0.1.6 CVE-2025-32606 Patchstack
8.5 High Taskbuilder Plugin taskbuilder SQL Injection ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-39569 Patchstack
9.3 Critical Cost Calculator Builder Plugin cost-calculator-builder SQL Injection No login needed ≤ 3.2.65 Fixed in 3.2.68 CVE-2025-39587 Patchstack
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.13.6 CVE-2025-2314 Wordfence
6.5 Medium SKT Blocks Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.9 CVE-2025-26998 Patchstack
6.4 Medium SKT Blocks – Gutenberg based Page Builder Plugin skt-blocks Cross-Site Scripting Gutenberg based Page Builder <= 1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.9 CVE-2025-3276 Wordfence
9.8 Critical Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder Plugin everest-forms PHP Object Injection Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress <= 3.1.1 - Unauthenticated PHP Object Injection No login needed ≤ 3.1.1 CVE-2025-3439 Wordfence
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder SQL Injection Authenticated (Subscriber+) SQL Injection via order_ids Parameter ≤ 3.2.67 CVE-2025-2128 Wordfence
7.1 High WP Table Builder Plugin wp-table-builder Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-32598 Patchstack
9.8 Critical Build App Online Plugin build-app-online Local File Inclusion No login needed ≤ 1.0.23 CVE-2025-32577 Patchstack
6.5 Medium Contact Form Builder by vcita Plugin contact-form-with-a-meeting-scheduler-by-vcita Cross-Site Scripting ≤ 4.10.2 Fixed in 4.10.5 CVE-2025-32199 Patchstack
4.3 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.8.4 Fixed in 1.2.8.5 CVE-2025-32201 Patchstack
6.5 Medium Colibri Page Builder Plugin colibri-page-builder Cross-Site Scripting ≤ 1.0.329 Fixed in 1.0.332 CVE-2025-32185 Patchstack
7.6 High Easy Query – WP Query Builder Plugin easy-query SQL Injection WP Query Builder plugin <= 2.0.4 - SQL Injection ≤ 2.0.4 CVE-2025-32120 Patchstack
8.1 High Countdown, Coming Soon, Maintenance – Countdown & Clock Plugin countdown-builder Local File Inclusion Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion No login needed ≤ 2.8.9.1 CVE-2025-2270 Wordfence
6.4 Medium RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login Plugin custom-registration-form-builder-with-submission-manager Cross-Site Scripting Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 6.0.4.3 CVE-2025-2836 Wordfence
7.1 High Team Builder Plugin team-display Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.3 CVE-2025-31907 Patchstack
9.9 Critical Countdown & Clock Plugin countdown-builder Remote Code Execution ≤ 2.8.8 Fixed in 2.8.9 CVE-2025-30841 Patchstack
5.4 Medium Pearl Plugin pearl-header-builder Broken Access Control ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-31881 Patchstack
4.3 Medium Pearl Plugin pearl-header-builder Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-31880 Patchstack
6.5 Medium PDF Generator Addon for Elementor Page Builder Plugin pdf-generator-addon-for-elementor-page-builder Cross-Site Scripting ≤ 2.1.0 Fixed in 2.2.0 CVE-2025-31850 Patchstack
6.5 Medium Team Members for Elementor Page Builder Plugin team-members-for-elementor Cross-Site Scripting ≤ 1.0.4 CVE-2025-31771 Patchstack
6.5 Medium HMH Footer Builder For Elementor Plugin hmh-footer-builder-for-elementor Cross-Site Scripting ≤ 1.0 CVE-2025-31749 Patchstack
6.4 Medium WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder Plugin Cross-Site Scripting Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder <= 1.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.3 CVE-2024-12189 Wordfence
6.4 Medium Avada Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.11.14 CVE-2025-1665 Wordfence
6.5 Medium Cost Calculator Builder Plugin cost-calculator-builder Cross-Site Scripting ≤ 3.2.65 Fixed in 3.2.66 CVE-2025-31414 Patchstack
7.5 High JetWooBuilder Plugin jet-woo-builder Local File Inclusion ≤ 2.1.18 Fixed in 2.1.18.1 CVE-2025-31016 Patchstack
9.8 Critical Kubio AI Page Builder Plugin kubio Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 2.5.1 CVE-2025-2294 Wordfence
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.9 Medium Chartify Plugin chart-builder Cross-Site Scripting ≤ 3.1.7 Fixed in 3.1.9 CVE-2025-30904 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 11.0.2 Fixed in 11.1 CVE-2025-30873 Patchstack
8.5 High Lead Form Data Collection to CRM Plugin wp-leads-builder-any-crm SQL Injection ≤ 3.0.1 Fixed in 3.1 CVE-2025-30810 Patchstack
5.4 Medium Live Forms Plugin liveforms Broken Access Control Live Forms plugin <= 4.8.4 - Settings Change ≤ 4.8.4 Fixed in 4.8.5 CVE-2025-30809 Patchstack
6.5 Medium Build Theme build Cross-Site Scripting ≤ 1.0.3 CVE-2025-26869 Patchstack
6.4 Medium Amazing service box Addons For WPBakery Page Builder Plugin amazing-service-box-visual-composer-addons Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload ≤ 2.0.0 CVE-2025-2573 Wordfence
5.3 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform Other Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder <= 5.2.12 - IP-Spoofing No login needed ≤ 5.2.12 CVE-2024-13666 Wordfence
6.4 Medium Make Builder Plugin make-builder Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery via make_builder_ajax_subscribe Function ≤ 1.1.10 CVE-2024-13856 Wordfence
7.2 High WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto Plugin tripetto Cross-Site Scripting Tripetto <= 8.0.9 - Unauthenticated Stored Cross-Site Scripting No login needed ≤ 8.0.9 CVE-2024-13497 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Broken Access Control Drag and Drop website builder <= 1.9.9 - Missing Authorization to Authenticated (Contributor+) Post Publication ≤ 1.9.8 CVE-2025-2104 Wordfence
6.4 Medium ShopLentor – WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) Plugin woolentor-addons Cross-Site Scripting WooCommerce Builder for Elementor & Gutenberg +20 Modules – All in One Solution (formerly WooLentor) <= 3.1.0 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Flash Sale Countdown Module ≤ 3.1.0 CVE-2025-1527 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 CVE-2024-13430 Wordfence
5.5 Medium Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin uncanny-automator Server-Side Request Forgery Easy Automation, Integration, Webhooks & Workflow Builder Plugin <= 6.2 - Authenticated (Admin+) Server-Side Request Forgery via Webhook ≤ 6.2 CVE-2024-13838 Wordfence
5.3 Medium NEX-Forms – Ultimate Form Builder – Contact forms and much more Plugin nex-forms-express-wp-form-builder Information Disclosure Ultimate Form Builder – Contact forms and much more <= 8.8.1 - Unauthenticated Sensitive Information Exposure No login needed ≤ 8.8.1 CVE-2024-13498 Wordfence
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.4 Medium Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Plugin essential-blocks Cross-Site Scripting Page Builder Gutenberg Blocks, Patterns & Templates <= 5.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 5.3.1 CVE-2025-1664 Wordfence
6.4 Medium The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 6.2.2 CVE-2025-1287 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only