WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,101–7,150 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 143 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.3 Medium Team Manager Plugin wp-team-manager Broken Access Control No login needed ≤ 2.6.8 CVE-2025-58222 Patchstack
5.4 Medium Printeers Print & Ship Plugin invition-print-ship Cross-Site Request Forgery No login needed ≤ 1.17.0 CVE-2025-58224 Patchstack
5.9 Medium VoucherPress Plugin voucherpress Cross-Site Scripting ≤ 1.5.7 CVE-2025-58223 Patchstack
5.3 Medium 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery Plugin interactive-3d-flipbook-powered-physics-engine Information Disclosure PDF Flipbook Viewer, Flipbook Image Gallery Plugin <= 1.16.16 - Sensitive Data Exposure No login needed ≤ 1.16.16 Fixed in 1.16.17 CVE-2025-58226 Patchstack
6.5 Medium Quick View for WooCommerce Plugin woo-quickview Cross-Site Scripting ≤ 2.2.16 Fixed in 2.2.17 CVE-2025-58228 Patchstack
6.5 Medium Podlove Subscribe button Plugin podlove-subscribe-button Cross-Site Scripting ≤ 1.3.11 Fixed in 1.3.12 CVE-2025-58227 Patchstack
6.5 Medium Sitekit Plugin sitekit Cross-Site Scripting ≤ 2.0 CVE-2025-58229 Patchstack
6.5 Medium ZoloBlocks Plugin zoloblocks Cross-Site Scripting ≤ 2.3.12 Fixed in 2.3.13 CVE-2025-58230 Patchstack
6.5 Medium Bitly Plugin wp-bitly Cross-Site Scripting ≤ 2.8.0 CVE-2025-58231 Patchstack
6.5 Medium SQL Chart Builder Plugin sql-chart-builder Cross-Site Scripting ≤ 2.3.7.2 CVE-2025-58233 Patchstack
6.5 Medium Image Editor by Pixo Plugin image-editor-by-pixo Cross-Site Scripting ≤ 2.3.8 CVE-2025-58232 Patchstack
6.5 Medium JS Job Manager Plugin js-jobs Cross-Site Scripting ≤ 2.0.2 CVE-2025-58234 Patchstack
4.3 Medium Force Update Translations Plugin force-update-translations Cross-Site Request Forgery No login needed ≤ 0.5 Fixed in 0.6.0 CVE-2025-58236 Patchstack
6.5 Medium Front End Users Plugin front-end-only-users Cross-Site Scripting ≤ 3.2.35 CVE-2025-58235 Patchstack
6.5 Medium LC Wizard Plugin ghl-wizard Cross-Site Scripting ≤ 2.2.4 CVE-2025-58237 Patchstack
6.5 Medium WP Category Dropdown Plugin wp-category-dropdown Cross-Site Scripting ≤ 1.9 CVE-2025-58239 Patchstack
6.5 Medium PilotPress Plugin pilotpress Cross-Site Scripting ≤ 2.0.36 CVE-2025-58238 Patchstack
6.5 Medium xili-tidy-tags Plugin xili-tidy-tags Cross-Site Scripting ≤ 1.12.06 CVE-2025-58240 Patchstack
6.5 Medium SnapWidget Social Photo Feed Widget Plugin snapwidget-wp-instagram-widget Cross-Site Scripting ≤ 1.1.0 CVE-2025-58241 Patchstack
6.5 Medium Bg Church Memos Plugin bg-church-memos Cross-Site Scripting ≤ 1.1 CVE-2025-58242 Patchstack
5.9 Medium Portfolio Plugin portfolio Cross-Site Scripting ≤ 2.58 CVE-2025-58245 Patchstack
5.3 Medium TI WooCommerce Wishlist Plugin ti-woocommerce-wishlist Broken Access Control No login needed ≤ 2.10.0 Fixed in 2.11.0 CVE-2025-58247 Patchstack
4.3 Medium Qubely Plugin qubely Information Disclosure Sensitive Data Exposure ≤ 1.8.14 CVE-2025-58249 Patchstack
6.5 Medium Pinterest Pinboard Widget Plugin pinterest-pinboard-widget Cross-Site Scripting ≤ 1.0.7 CVE-2025-58248 Patchstack
4.3 Medium Sticky Header Effects for Elementor Plugin sticky-header-effects-for-elementor Broken Access Control ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-58251 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Scripting ≤ 7.3 CVE-2025-58253 Patchstack
4.3 Medium Getwid Plugin getwid Information Disclosure Sensitive Data Exposure ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-58252 Patchstack
6.5 Medium StylePress for Elementor Plugin full-site-builder-for-elementor Cross-Site Scripting ≤ 1.2.1 CVE-2025-58254 Patchstack
6.5 Medium Verowa Connect Plugin verowa-connect Cross-Site Scripting ≤ 3.2.3 Fixed in 3.3.0 CVE-2025-58257 Patchstack
5.9 Medium DOAJ Export Plugin doaj-export Cross-Site Scripting ≤ 1.0.4 CVE-2025-58256 Patchstack
4.3 Medium Lazy Blocks Plugin lazy-blocks Broken Access Control ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-58258 Patchstack
6.5 Medium Highlight and Share Plugin highlight-and-share Cross-Site Scripting Social Text and Image Sharing plugin <= 5.1.1 - Cross Site Scripting (XSS) ≤ 5.1.1 Fixed in 5.2.0 CVE-2025-58260 Patchstack
6.5 Medium JupiterX Core Plugin jupiterx-core Cross-Site Scripting ≤ 4.11.0 Fixed in 4.11.1 CVE-2025-58264 Patchstack
6.5 Medium BuddyPress Notification Widget Plugin buddypress-notifications-widget Cross-Site Scripting ≤ 1.3.3 CVE-2025-58263 Patchstack
6.5 Medium Events Manager – OpenStreetMaps Plugin stonehenge-em-osm Cross-Site Scripting OpenStreetMaps Plugin <= 4.2.1 - Cross Site Scripting (XSS) ≤ 4.2.1 CVE-2025-58265 Patchstack
5.9 Medium Gianism Plugin gianism Cross-Site Scripting ≤ 6.0.0 CVE-2025-58266 Patchstack
5.3 Medium WP Project Manager Plugin wedevs-project-manager Information Disclosure Sensitive Data Exposure No login needed ≤ 2.6.25 Fixed in 2.6.26 CVE-2025-58269 Patchstack
5.9 Medium AnyClip Luminous Studio Plugin anyclip-media Cross-Site Scripting ≤ 1.3.3 CVE-2025-58271 Patchstack
5.9 Medium Gravitate Automated Tester Plugin gravitate-automated-tester Cross-Site Scripting ≤ 1.4.5 CVE-2025-58645 Patchstack
5.9 Medium Simple Restaurant Menu Plugin simple-restaurant-menu Cross-Site Scripting ≤ 1.2 CVE-2025-58647 Patchstack
5.9 Medium Mobi2Go Plugin mobi2go Cross-Site Scripting ≤ 1.0.0 CVE-2025-58646 Patchstack
6.5 Medium Simple JWT Login Plugin simple-jwt-login Cross-Site Scripting ≤ 3.6.4 Fixed in 3.6.5 CVE-2025-58648 Patchstack
4.3 Medium All In One SEO Pack Plugin all-in-one-seo-pack Information Disclosure Sensitive Data Exposure ≤ 4.8.7.1 Fixed in 4.8.7.2 CVE-2025-58649 Patchstack
6.5 Medium PlayerJS Plugin playerjs Cross-Site Scripting ≤ 2.24 CVE-2025-58651 Patchstack
5.4 Medium All In One SEO Pack Plugin all-in-one-seo-pack Broken Access Control ≤ 4.8.7.1 Fixed in 4.8.7.2 CVE-2025-58650 Patchstack
6.5 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58652 Patchstack
6.5 Medium xili-language Plugin xili-language Cross-Site Scripting ≤ 2.21.3 CVE-2025-58654 Patchstack
6.5 Medium JSM file_get_contents() Shortcode Plugin wp-file-get-contents Cross-Site Scripting ≤ 2.7.1 CVE-2025-58653 Patchstack
5.9 Medium Category Featured Images Plugin category-featured-images Cross-Site Scripting ≤ 1.1.8 CVE-2025-58655 Patchstack
5.3 Medium Estonian Shipping Methods for WooCommerce Plugin estonian-shipping-methods-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.7.2 CVE-2025-58656 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only