WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,101–7,150 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 143 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Kento Splash Screen Plugin kento-splash-screen Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.4 CVE-2025-48351 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Broken Access Control ≤ 2.2.7 CVE-2025-48350 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
4.3 Medium Site Offline Plugin site-offline Broken Access Control ≤ 1.5.7 CVE-2025-48348 Patchstack
6.5 Medium bxSlider integration Plugin bxslider-integration Cross-Site Scripting ≤ 1.7.2 CVE-2025-48347 Patchstack
7.1 High WPMU Ldap Authentication Plugin wpmuldap Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 5.0.1 Fixed in 5.1 CVE-2025-48343 Patchstack
5.3 Medium WP Mailgun SMTP Plugin wp-mailgun-smtp Broken Access Control No login needed ≤ 1.0.7 CVE-2025-48327 Patchstack
7.1 High WP Admin Plugin wp-admin-theme Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48325 Patchstack
5.9 Medium tli.tl auto Twitter poster Plugin tlitl-auto-twitter-poster Cross-Site Scripting ≤ 3.4 CVE-2025-48324 Patchstack
5.9 Medium Advance Food Menu Plugin advance-food-menu Cross-Site Scripting ≤ 1.0 CVE-2025-48323 Patchstack
6.5 Medium Statify Widget Plugin statify-widget Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-48322 Patchstack
7.1 High Ultimate twitter profile widget Plugin ultimate-twitter-profile-widget Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0 CVE-2025-48321 Patchstack
7.1 High 百度分享按钮 Plugin baidushare-wp Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.6 CVE-2025-48320 Patchstack
5.9 Medium Mesa Mesa Reservation Widget Plugin mesa-mesa-reservation-widget Cross-Site Scripting ≤ 1.0.0 CVE-2025-48319 Patchstack
4.3 Medium 多说社会化评论框 Plugin duoshuo Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-48318 Patchstack
6.5 Medium Responsive Mobile-Friendly Tooltip Plugin responsive-mobile-friendly-tooltip Cross-Site Scripting ≤ 1.6.6 CVE-2025-48316 Patchstack
6.5 Medium WordPress HTML Plugin custom-html-bodyhead Cross-Site Scripting ≤ 0.51 CVE-2025-48315 Patchstack
5.9 Medium Add Code To Head Plugin add-code-to-head Cross-Site Scripting ≤ 1.17 CVE-2025-48314 Patchstack
5.9 Medium Tripadvisor Shortcode Plugin tripadvisor-shortcode Cross-Site Scripting ≤ 2.2 CVE-2025-48313 Patchstack
6.5 Medium WPAvatar Plugin wpavatar Cross-Site Scripting ≤ 1.9.4 CVE-2025-48312 Patchstack
7.1 High Invisible Optin Plugin invisible-optin Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0 CVE-2025-48311 Patchstack
4.3 Medium Table Editor Plugin wp-table-editor Cross-Site Request Forgery No login needed ≤ 1.6.4 CVE-2025-48310 Patchstack
7.1 High BetPress Plugin betpress Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.0.1 Lite CVE-2025-48309 Patchstack
7.1 High Newsletter subscription optin module Plugin newsletter-subscription-widget-for-sendblaster Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.9 CVE-2025-48308 Patchstack
7.1 High SEO For Images Plugin seo-for-images Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.0 CVE-2025-48307 Patchstack
7.1 High Savyour Affiliate Partner Plugin savyour-affiliate-partner Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 2.1.4 CVE-2025-48306 Patchstack
5.9 Medium Goal Tracker for Patreon Plugin goal-tracker-for-patreon Cross-Site Scripting ≤ 0.4.6 CVE-2025-48305 Patchstack
7.1 High Google XML News Sitemap Plugin gn-xml-sitemap Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 0.02 CVE-2025-48304 Patchstack
6.5 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-48110 Patchstack
7.1 High XM-Backup Plugin xm-backup Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 0.9.1 CVE-2025-48109 Patchstack
9.1 Critical bidorbuy Store Integrator Plugin bidorbuystoreintegrator Remote Code Execution ≤ 2.12.0 CVE-2025-48100 Patchstack
9.3 Critical WooBeWoo Product Filter Pro Plugin woofilter-pro SQL Injection No login needed < 2.9.6 Fixed in 2.9.6 CVE-2025-39496 Patchstack
7.2 High Small Package Quotes – USPS Edition Plugin small-package-quotes-usps-edition PHP Object Injection USPS Edition Plugin <= 1.3.9 - PHP Object Injection ≤ 1.3.9 Fixed in 1.3.10 CVE-2025-58218 Patchstack
7.1 High Instant Breaking News Plugin instant-breaking-news Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.0.1 CVE-2025-58217 Patchstack
5.9 Medium WP Thumbtack Review Slider Plugin wp-thumbtack-review-slider Cross-Site Scripting ≤ 2.6 Fixed in 2.7 CVE-2025-58216 Patchstack
6.5 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting ≤ 1.0.14 Fixed in 1.0.15 CVE-2025-58213 Patchstack
6.5 Medium Epeken All Kurir Plugin epeken-all-kurir Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-58212 Patchstack
6.5 Medium Chatbox Manager Plugin wa-chatbox-manager Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58211 Patchstack
6.5 Medium Transcoder Plugin transcoder Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58209 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Cross-Site Scripting ≤ 6.2.0 Fixed in 6.3.0 CVE-2025-58208 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58205 Patchstack
4.7 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Open Redirect No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-58204 Patchstack
4.4 Medium Solace Extra Plugin solace-extra Server-Side Request Forgery ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-58203 Patchstack
4.3 Medium Simple Page Access Restriction Plugin simple-page-access-restriction Cross-Site Request Forgery No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2025-58202 Patchstack
5.3 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Broken Access Control No login needed ≤ 1.17.17 Fixed in 1.17.18 CVE-2025-58201 Patchstack
6.5 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.9 Fixed in 1.2.10 CVE-2025-58198 Patchstack
6.5 Medium Simple Download Monitor Plugin simple-download-monitor Cross-Site Scripting ≤ 3.9.34 Fixed in 3.9.35 CVE-2025-58197 Patchstack
6.5 Medium UiCore Elements Plugin uicore-elements Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-58196 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.17 Fixed in 1.4.18 CVE-2025-58195 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-58194 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only