WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,151–7,200 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 144 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Uncanny Automator Plugin uncanny-automator Broken Access Control ≤ 6.7.0.1 Fixed in 6.8.0 CVE-2025-58193 Patchstack
4.3 Medium WP Bulk Delete Plugin wp-bulk-delete Broken Access Control ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58192 Patchstack
5.3 Medium Printeers Print & Ship Plugin invition-print-ship Path Traversal Directory Traversal No login needed ≤ 1.17.0 CVE-2025-48081 Patchstack
5.9 Medium Admin Menu Groups Plugin admin-menu-groups Cross-Site Scripting ≤ 0.1.2 CVE-2025-49035 Patchstack
5.9 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-49039 Patchstack
4.3 Medium Backup Bolt Plugin backup-bolt Cross-Site Request Forgery No login needed ≤ 1.5.0 CVE-2025-49040 Patchstack
6.5 Medium School Management Plugin school-management Broken Access Control ≤ 93.2.0 CVE-2025-48108 Patchstack
4.7 Medium Automatic Plugin - AI content generator and auto poster Plugin Cross-Site Request Forgery AI content generator and auto poster plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.118.0 CVE-2025-6247 Wordfence
4.3 Medium Post Type Converter Plugin post-type-converter Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-48303 Patchstack
4.3 Medium Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Plugin sertifier-certificates-open-badges Cross-Site Request Forgery Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update No login needed ≤ 1.19 Fixed in 1.20 CVE-2025-7841 Wordfence
5.3 Medium Church Admin Plugin church-admin Broken Access Control No login needed ≤ 5.0.26 Fixed in 5.0.27 CVE-2025-57896 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-57895 Patchstack
4.3 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.19.8 Fixed in 3.19.8.1 CVE-2025-57894 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.79.270 Fixed in 1.79.274 CVE-2025-57893 Patchstack
4.3 Medium Simple Statistics for Feeds Plugin simple-feed-stats Cross-Site Request Forgery No login needed ≤ 20250322 Fixed in 20250820 CVE-2025-57892 Patchstack
5.9 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-57891 Patchstack
5.9 Medium Sessions Plugin sessions Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-57890 Patchstack
5.3 Medium Jobmonster Theme noo-jobmonster Information Disclosure Sensitive Data Exposure No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57888 Patchstack
6.5 Medium Jobmonster Theme noo-jobmonster Cross-Site Scripting ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57887 Patchstack
5.4 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.30.0 Fixed in 1.30.1 CVE-2025-57886 Patchstack
4.3 Medium Fluent Support Plugin fluent-support Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-57885 Patchstack
4.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 12.1.1 Fixed in 12.1.2 CVE-2025-57884 Patchstack
9.9 Critical Pin WP Theme pin-wp Arbitrary File Upload ≤ 7.2 Fixed in 7.2 CVE-2025-53251 Patchstack
5.3 Medium ProveSource Social Proof Plugin provesource Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.2 Fixed in 4.0.0 CVE-2025-48355 Patchstack
9.6 Critical ads.txt Guru Connect Plugin adstxt-guru-connect Cross-Site Request Forgery No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-49381 Patchstack
6.5 Medium Notice Bar Plugin notice-bar Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-49389 Patchstack
8.8 High JobZilla - Job Board Theme jobzilla Cross-Site Request Forgery Job Board WordPress Theme Theme <= 2.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2025-49382 Patchstack
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery No login needed ≤ 2.3.3 Fixed in 2.3.3.1 CVE-2025-49391 Patchstack
6.5 Medium Themify Icons Plugin themify-icons Cross-Site Scripting ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-49395 Patchstack
5.9 Medium Themify Audio Dock Plugin themify-audio-dock Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-49392 Patchstack
6.5 Medium Colorbox Lightbox Plugin wp-colorbox Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-49397 Patchstack
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control ≤ 7.6.7 Fixed in 7.6.8 CVE-2025-49396 Patchstack
8.8 High NEX-Forms Plugin nex-forms-express-wp-form-builder Cross-Site Request Forgery No login needed ≤ 9.1.3 Fixed in 9.1.4 CVE-2025-49399 Patchstack
8.5 High Houzez Theme houzez Broken Access Control ≤ 4.1.1 Fixed in 4.1.4 CVE-2025-49406 Patchstack
9.8 Critical WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting No login needed ≤ 8.2 Fixed in 8.3 CVE-2025-49400 Patchstack
10.0 Critical Templately Plugin templately Information Disclosure Sensitive Data Exposure No login needed ≤ 3.2.7 Fixed in 3.2.8 CVE-2025-49408 Patchstack
7.1 High WP Pipes Plugin wp-pipes Cross-Site Scripting No login needed ≤ 1.4.3 CVE-2025-28977 Patchstack
6.5 Medium Infility Global Plugin infility-global Path Traversal Arbitrary File Download ≤ 2.15.06 CVE-2025-47650 Patchstack
7.5 High Add Custom Codes Plugin add-custom-codes Remote Code Execution Arbitrary Code Execution ≤ 4.80 Fixed in 5.0 CVE-2025-30975 Patchstack
9.8 Critical SensorPress Plugin sensorpress-uptime-monitoring Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-49409 Patchstack
7.1 High iFrame Block Plugin iframe-block Cross-Site Scripting No login needed ≤ 0.1.1 CVE-2025-49411 Patchstack
10.0 Critical TC Testimonials Plugin tc-testimonial Cross-Site Scripting No login needed ≤ 1.1.1 CVE-2025-49410 Patchstack
7.1 High Super Store Finder Plugin superstorefinder-wp Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 7.6 Fixed in 7.7 CVE-2025-49413 Patchstack
5.9 Medium Page Transition Plugin page-transition Cross-Site Scripting ≤ 1.3 CVE-2025-49412 Patchstack
9.8 Critical Support Ticket Plugin support-ticket Privilege Escalation No login needed ≤ 1.9 CVE-2025-49422 Patchstack
7.1 High Ultra Portfolio Plugin ultra-portfolio Cross-Site Scripting WordPress Plugin <= 6.7 - Cross Site Scripting (XSS) No login needed ≤ 6.7 CVE-2025-49420 Patchstack
7.1 High Support Ticket Plugin support-ticket Cross-Site Scripting No login needed ≤ 1.9 CVE-2025-49424 Patchstack
7.5 High Cookie Warning Plugin cookie-warning Cross-Site Scripting ≤ 1.3 CVE-2025-49428 Patchstack
8.1 High Kitring Plugin kitring Local File Inclusion No login needed ≤ 2.8 CVE-2025-49426 Patchstack
9.8 Critical Cars4Rent Theme cars4rent PHP Object Injection No login needed ≤ 1.4.2 CVE-2025-49434 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only