WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 6,951–7,000 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 140 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium WP Notification Bell Plugin wp-notification-bell Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-58821 Patchstack
5.9 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58820 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-58819 Patchstack
5.4 Medium Developer Tools Blocker Plugin swiftninjapro-inspect-element-console-blocker Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-58818 Patchstack
4.3 Medium SoftMe Plugin softme Broken Access Control ≤ 1.1.27 CVE-2025-58817 Patchstack
3.5 Low Product Carousel Slider for Elementor Plugin ecommerce-product-carousel-slider-for-elementor Broken Access Control ≤ 2.1.3 CVE-2025-58816 Patchstack
7.2 High Aitasi Coming Soon Plugin aitasi-coming-soon PHP Object Injection Deserialization of untrusted data ≤ 2.0.2 CVE-2025-58815 Patchstack
6.5 Medium Stagtools Plugin stagtools Cross-Site Scripting ≤ 2.3.8 CVE-2025-58814 Patchstack
4.3 Medium Consultstreet Plugin consultstreet Broken Access Control ≤ 3.0.0 CVE-2025-58813 Patchstack
6.5 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Cross-Site Scripting ≤ 1.4.3 CVE-2025-58812 Patchstack
5.9 Medium Ultimate Client Dash Plugin ulimate-client-dash Cross-Site Scripting ≤ 4.7 CVE-2025-58811 Patchstack
5.9 Medium Simple Link List Widget Plugin simple-link-list-widget Cross-Site Scripting ≤ 0.3.2 CVE-2025-58810 Patchstack
7.1 High To Lead For Salesforce Plugin salesforce-wordpress-to-lead Cross-Site Request Forgery No login needed ≤ 2.7.3.9 CVE-2025-58809 Patchstack
6.5 Medium prettyPhoto Plugin prettyphoto Cross-Site Scripting ≤ 1.2.5 CVE-2025-58808 Patchstack
7.1 High Purge Varnish Cache Plugin purge-varnish Cross-Site Request Forgery No login needed ≤ 2.6 CVE-2025-58807 Patchstack
7.1 High WordPress Error Monitoring by Bugsnag Plugin bugsnag Cross-Site Request Forgery No login needed ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-58806 Patchstack
5.9 Medium Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Scripting ≤ 3.0 CVE-2025-58805 Patchstack
4.3 Medium WooCommerce Single Page Checkout Plugin woo-single-page-checkout Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-58804 Patchstack
4.3 Medium TrustMate.io – WooCommerce integration Plugin trustmate-io-integration-for-woocommerce Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.16.0 CVE-2025-58802 Patchstack
5.4 Medium Responder Plugin responder Cross-Site Request Forgery No login needed ≤ 4.3.8 Fixed in 4.4.0 CVE-2025-58801 Patchstack
4.3 Medium WP Email Template Plugin wp-email-template Cross-Site Request Forgery No login needed ≤ 2.8.5 CVE-2025-58800 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-58799 Patchstack
4.3 Medium BCM Duplicate Menu Plugin bcm-duplicate-menu Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-58798 Patchstack
5.3 Medium Ninja Charts Plugin ninja-charts Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-58797 Patchstack
6.5 Medium Elementor Element Condition Plugin ele-conditions Cross-Site Scripting ≤ 1.0.5 CVE-2025-58796 Patchstack
4.3 Medium Payoneer Checkout Plugin payoneer-checkout Content Injection Content Spoofing No login needed ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-58795 Patchstack
4.3 Medium Notification for Telegram Plugin notification-for-telegram Cross-Site Request Forgery No login needed ≤ 3.5 CVE-2025-58794 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.7 CVE-2025-58793 Patchstack
4.3 Medium Authors List Plugin authors-list Cross-Site Request Forgery No login needed ≤ 2.0.6.2 CVE-2025-58792 Patchstack
5.9 Medium SEO Auto Linker Plugin wpa-seo-auto-linker Cross-Site Scripting ≤ 1.5.3 CVE-2025-58791 Patchstack
6.5 Medium Kiwi Plugin kiwi-social-share Cross-Site Scripting ≤ 2.1.8 CVE-2025-58790 Patchstack
7.6 High WP Full Stripe Free Plugin wp-full-stripe-free SQL Injection ≤ 8.2.5 Fixed in 8.2.6 CVE-2025-58789 Patchstack
7.6 High License Manager for WooCommerce Plugin license-manager-for-woocommerce SQL Injection ≤ 3.0.12 Fixed in 3.0.13 CVE-2025-58788 Patchstack
6.5 Medium Themify Popup Plugin themify-popup Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-58787 Patchstack
6.5 Medium Ibtana – Ecommerce Product Addons Plugin ibtana-ecommerce-product-addons Cross-Site Scripting Ecommerce Product Addons plugin <= 0.4.7.6 - Cross Site Scripting (XSS) ≤ 0.4.7.6 CVE-2025-58786 Patchstack
5.4 Medium Ray Enterprise Translation Plugin lingotek-translation Broken Access Control ≤ 1.7.2 CVE-2025-58785 Patchstack
6.5 Medium ARI Fancy Lightbox Plugin ari-fancy-lightbox Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58784 Patchstack
4.3 Medium Gutentor Plugin gutentor Broken Access Control ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-58783 Patchstack
8.1 High WordPress Helpdesk Integration Plugin wp-helpdesk-integration Local File Inclusion Unauthenticated Local File Inclusion No login needed ≤ 5.8.10 CVE-2025-9990 Wordfence
7.2 High LTL Freight Quotes - TQL Edition Plugin ltl-freight-quotes-tql-edition PHP Object Injection TQL Edition Plugin <= 1.2.6 - PHP Object Injection ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58644 Patchstack
7.2 High LTL Freight Quotes – Daylight Edition Plugin ltl-freight-quotes-daylight-edition PHP Object Injection Daylight Edition Plugin <= 2.2.7 - PHP Object Injection ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-58643 Patchstack
7.2 High LTL Freight Quotes – Day & Ross Edition Plugin ltl-freight-quotes-day-ross-edition PHP Object Injection Day & Ross Edition Plugin <= 2.1.11 - PHP Object Injection ≤ 2.1.11 Fixed in 2.1.12 CVE-2025-58642 Patchstack
5.4 Medium Exit Intent Popup Plugin exitintentpopup Server-Side Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.3 CVE-2025-58641 Patchstack
6.5 Medium Document Engine Plugin document-engine Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2025-58640 Patchstack
5.4 Medium Contact Form By Mega Forms Plugin mega-forms Broken Access Control ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-58639 Patchstack
7.5 High immonex Kickstart Plugin immonex-kickstart Local File Inclusion ≤ 1.11.6 Fixed in 1.11.13 CVE-2025-58637 Patchstack
5.3 Medium Support Genix Plugin support-genix-lite Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2025-58635 Patchstack
5.3 Medium PeachPay Payments Plugin peachpay-for-woocommerce Broken Access Control No login needed ≤ 1.117.4 Fixed in 1.117.5 CVE-2025-58634 Patchstack
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.21 Fixed in 1.1.22 CVE-2025-58633 Patchstack
6.5 Medium Dadevarzan WordPress Common Plugin dadevarzan-common Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-58632 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only