WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,051–7,100 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 142 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.4 Medium MakeStories (for Google Web Stories) Plugin makestories-helper Server-Side Request Forgery ≤ 3.0.4 CVE-2025-57984 Patchstack
6.5 Medium WP Subtitle Plugin wp-subtitle Cross-Site Scripting ≤ 3.4.1 Fixed in 3.4.2 CVE-2025-57986 Patchstack
5.3 Medium WP Events Manager Plugin wp-events-manager Broken Access Control No login needed ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-57987 Patchstack
6.5 Medium Uncanny Toolkit for LearnDash Plugin uncanny-learndash-toolkit Cross-Site Scripting ≤ 3.7.0.3 Fixed in 3.7.0.4 CVE-2025-57988 Patchstack
6.5 Medium WordPress Widgets Shortcode Plugin wp-widgets-shortcode Cross-Site Scripting ≤ 1.0.3 CVE-2025-57989 Patchstack
5.4 Medium Clariti Plugin clariti Broken Access Control ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-57991 Patchstack
5.4 Medium Blog Designer Plugin blog-designer Broken Access Control ≤ 3.1.8 CVE-2025-57990 Patchstack
4.3 Medium Mail Baby SMTP Plugin mail-baby-smtp Cross-Site Request Forgery No login needed ≤ 2.8 Fixed in 3.2.12 CVE-2025-57992 Patchstack
5.4 Medium Upcoming Events Lists Plugin upcoming-events-lists Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.4.0 CVE-2025-57994 Patchstack
6.5 Medium Geolocation IP Detection Plugin geoip-detect Cross-Site Scripting ≤ 5.5.0 Fixed in 5.6.0 CVE-2025-57993 Patchstack
4.3 Medium DethemeKit For Elementor Plugin dethemekit-for-elementor Broken Access Control ≤ 2.1.10 CVE-2025-57995 Patchstack
6.5 Medium Buckets Plugin buckets Cross-Site Scripting ≤ 0.3.9 CVE-2025-57996 Patchstack
5.9 Medium E-namad & Shamed Logo Manager Plugin e-namad-shamed-logo-manager Cross-Site Scripting ≤ 2.2 CVE-2025-57998 Patchstack
4.3 Medium Trustpilot Reviews Plugin trustpilot-reviews Broken Access Control ≤ 2.5.925 Fixed in 3.6.0 CVE-2025-57997 Patchstack
6.5 Medium WPKoi Templates for Elementor Plugin wpkoi-templates-for-elementor Cross-Site Scripting ≤ 3.4.3 Fixed in 3.4.4 CVE-2025-57999 Patchstack
6.5 Medium Compact Archives Plugin compact-archives Cross-Site Scripting ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-58001 Patchstack
5.3 Medium Memberful - Membership Plugin memberful-wp Broken Access Control No login needed ≤ 1.75.0 Fixed in 1.76.0 CVE-2025-58000 Patchstack
6.5 Medium GD bbPress Tools Plugin gd-bbpress-tools Cross-Site Scripting ≤ 3.5.3 CVE-2025-58002 Patchstack
5.3 Medium DriCub Plugin dricub-driving-school Broken Access Control No login needed ≤ 2.9 CVE-2025-58004 Patchstack
5.3 Medium Javo Core Plugin javo-core Broken Access Control No login needed ≤ 3.0.0.266 CVE-2025-58003 Patchstack
5.4 Medium DriCub Plugin dricub-driving-school Server-Side Request Forgery No login needed ≤ 2.9 CVE-2025-58005 Patchstack
4.7 Medium WP Gravity Forms Keap/Infusionsoft Plugin gf-infusionsoft Open Redirect No login needed ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58006 Patchstack
6.5 Medium Participants Database Plugin participants-database Cross-Site Scripting ≤ 2.7.6.3 Fixed in 2.7.7 CVE-2025-58008 Patchstack
4.3 Medium Hubbub Lite Plugin social-pug Information Disclosure Sensitive Data Exposure ≤ 1.35.2 Fixed in 1.36.0 CVE-2025-58007 Patchstack
6.4 Medium Content Mask Plugin content-mask Server-Side Request Forgery ≤ 1.8.5.2 Fixed in 1.8.5.3 CVE-2025-58011 Patchstack
4.3 Medium SV Proven Expert Plugin sv-provenexpert Cross-Site Request Forgery No login needed ≤ 2.0.06 CVE-2025-58010 Patchstack
5.3 Medium Quiz Maker Plugin quiz-maker Information Disclosure Sensitive Data Exposure No login needed ≤ 6.7.0.65 Fixed in 6.7.0.66 CVE-2025-58015 Patchstack
4.3 Medium Quiz Maker Plugin quiz-maker Cross-Site Request Forgery No login needed ≤ 6.7.0.64 Fixed in 6.7.0.65 CVE-2025-58014 Patchstack
4.3 Medium CF7 Submissions Plugin cf7-submissions Broken Access Control ≤ 0.26 CVE-2025-58016 Patchstack
6.5 Medium Ultimate Store Kit Elementor Addons Plugin ultimate-store-kit Cross-Site Scripting ≤ 2.8.6 Fixed in 2.8.7 CVE-2025-58017 Patchstack
6.5 Medium Search Atlas SEO Plugin metasync Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-58019 Patchstack
6.5 Medium Mail Subscribe List Plugin mail-subscribe-list Cross-Site Scripting ≤ 2.1.10 CVE-2025-58018 Patchstack
6.5 Medium Theater Plugin theatre Cross-Site Scripting ≤ 0.18.8 Fixed in 0.19 CVE-2025-58020 Patchstack
6.5 Medium ShortCode Plugin shortcode Cross-Site Scripting ≤ 0.8.1 CVE-2025-58022 Patchstack
6.5 Medium List Child Pages Shortcode Plugin list-child-pages-shortcode Cross-Site Scripting ≤ 1.3.1 Fixed in 1.4.0 CVE-2025-58021 Patchstack
6.5 Medium Genealogical Tree Plugin genealogical-tree Cross-Site Scripting ≤ 2.2.7 CVE-2025-58023 Patchstack
6.5 Medium Termageddon: Cookie Consent & Privacy Compliance Plugin termageddon-usercentrics Cross-Site Scripting ≤ 1.8.1 Fixed in 1.8.2 CVE-2025-58026 Patchstack
6.5 Medium Master Slider Plugin master-slider Cross-Site Scripting ≤ 3.11.0 CVE-2025-58025 Patchstack
6.5 Medium NGG Smart Image Search Plugin ngg-smart-image-search Cross-Site Scripting ≤ 3.4.3 CVE-2025-58027 Patchstack
6.5 Medium Designil PDPA Thailand Plugin pdpa-thailand Cross-Site Scripting ≤ 2.0.1 CVE-2025-58028 Patchstack
6.5 Medium Page-list Plugin page-list Cross-Site Scripting ≤ 5.8 Fixed in 5.9 CVE-2025-58030 Patchstack
5.3 Medium Classic Widgets with Block-based Widgets Plugin classic-widgets-with-block-based-widgets Broken Access Control No login needed ≤ 1.0.1 CVE-2025-58029 Patchstack
6.5 Medium Nextend Facebook Connect Plugin nextend-facebook-connect Cross-Site Scripting ≤ 3.1.19 Fixed in 3.1.20 CVE-2025-58031 Patchstack
5.9 Medium Draft Plugin website-builder Cross-Site Scripting ≤ 3.0.9 CVE-2025-58033 Patchstack
4.3 Medium WP Compiler Plugin wp-compiler Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-58032 Patchstack
4.3 Medium Fastly Plugin fastly Cross-Site Request Forgery No login needed ≤ 1.2.28 Fixed in 1.2.29 CVE-2025-58199 Patchstack
4.3 Medium Flexible FAQ Plugin flexible-faq Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-58200 Patchstack
6.5 Medium Card Elements for WPBakery Plugin card-elements-for-wpbakery Cross-Site Scripting ≤ 1.0.8 CVE-2025-58220 Patchstack
4.3 Medium Show Pages List Plugin show-pages-list Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-58219 Patchstack
4.3 Medium PilotPress Plugin pilotpress Broken Access Control ≤ 2.0.36 CVE-2025-58221 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only