WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,251–7,300 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 146 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium CatFolders – Tame Your WordPress Media Library by Category Plugin catfolders SQL Injection Tame Your WordPress Media Library by Category <= 2.5.2 - Authenticated (Author+) SQL Injection via CSV Import ≤ 2.5.2 CVE-2025-9776 Wordfence
4.9 Medium PagBank / PagSeguro Connect para WooCommerce Plugin pagbank-connect SQL Injection Authenticated (Shop Manager+) SQL Injection ≤ 4.44.3 CVE-2025-10142 Wordfence
6.4 Medium Heateor Login – Social Login Plugin heateor-login Cross-Site Scripting Social Login Plugin <= 1.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.9 CVE-2025-9857 Wordfence
6.4 Medium MyBrain Utilities Plugin mybrain-utilities Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.8 CVE-2025-10126 Wordfence
4.3 Medium Maspik Plugin contact-forms-anti-spam Cross-Site Request Forgery No login needed ≤ 2.5.6 CVE-2025-9888 Wordfence
4.3 Medium WP Blast | SEO & Performance Booster Plugin wpblast Cross-Site Request Forgery Cross-Site Request Forgery to Cache Clearing No login needed ≤ 1.8.6 CVE-2025-9622 Wordfence
6.4 Medium Auto Save Remote Images (Drafts) Plugin auto-save-remote-images-drafts Server-Side Request Forgery Authenticated (Contributor+) Server-Side Request Forgery ≤ 1.0.9 CVE-2025-7843 Wordfence
6.5 Medium Testimonial Plugin indianic-testimonial SQL Injection Authenticated (Contributor+) SQL Injection ≤ 2.3 CVE-2025-7826 Wordfence
4.3 Medium Maspik Plugin contact-forms-anti-spam Broken Access Control Authenticated (Subscriber+) Missing Authorization to Spam Log Export ≤ 2.5.6 CVE-2025-9979 Wordfence
5.5 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting Authenticated (Editor+) Stored Cross-Site Scripting ≤ 2.11.20 CVE-2025-9367 Wordfence
4.3 Medium NitroPack Plugin nitropack Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update via nitropack_set_compression_ajax Function ≤ 1.18.4 CVE-2025-8778 Wordfence
6.5 Medium Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net Plugin peachpay-for-woocommerce SQL Injection Authenticated (Contributor+) SQL Injection via order_by Parameter ≤ 1.117.5 CVE-2025-9463 Wordfence
6.5 Medium Duplicate Page and Post Plugin duplicate-wp-page-post SQL Injection Authenticated (Contributor+) SQL Injection via meta_key Parameter ≤ 2.9.5 CVE-2025-6189 Wordfence
6.4 Medium PowerPack Lite for Elementor Plugin powerpack-lite-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting Via 'cursor_url' ≤ 2.9.4 CVE-2025-8388 Wordfence
4.3 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control ≤ 1.31.0 Fixed in 1.31.1 CVE-2025-58976 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.1.1 Fixed in 3.2.0 CVE-2025-58975 Patchstack
5.3 Medium PDF Generator Plugin pdf-generator-for-wp Broken Access Control No login needed ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-58978 Patchstack
4.9 Medium WP eBay Product Feeds Plugin ebay-feeds-for-wordpress Server-Side Request Forgery ≤ 3.4.8 Fixed in 3.4.9 CVE-2025-58977 Patchstack
5.3 Medium BerqWP Plugin searchpro Broken Access Control No login needed ≤ 2.2.53 Fixed in 2.2.54 CVE-2025-58979 Patchstack
5.4 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control ≤ 1.31.0 Fixed in 1.31.1 CVE-2025-58981 Patchstack
5.3 Medium Export WP Page to Static HTML/CSS Plugin export-wp-page-to-static-html Broken Access Control No login needed ≤ 4.1.0 Fixed in 4.2.0 CVE-2025-58980 Patchstack
5.9 Medium Pixeline's Email Protector Plugin pixelines-email-protector Cross-Site Scripting ≤ 1.3.8 Fixed in 1.4.0 CVE-2025-58982 Patchstack
5.9 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting ≤ 2.11.20 Fixed in 2.11.21 CVE-2025-58984 Patchstack
5.9 Medium Include Me Plugin include-me Cross-Site Scripting ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-58983 Patchstack
6.5 Medium Additional Custom Product Tabs for WooCommerce Plugin product-tabs-for-woocommerce Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-58985 Patchstack
6.5 Medium Football Pool Plugin football-pool Cross-Site Scripting ≤ 2.12.6 Fixed in 2.13.0 CVE-2025-58987 Patchstack
6.5 Medium My Tickets Plugin my-tickets Cross-Site Scripting ≤ 2.0.22 Fixed in 2.0.23 CVE-2025-58988 Patchstack
6.5 Medium Dynamic Text Field For Contact Form 7 Plugin dynamic-text-field-for-contact-form-7 Cross-Site Scripting ≤ 1.0 Fixed in 1.1 CVE-2025-58989 Patchstack
6.5 Medium ShopLentor Plugin woolentor-addons Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-58990 Patchstack
5.9 Medium WP Weixin Plugin wp-weixin Cross-Site Scripting ≤ 1.3.16 Fixed in 1.3.17 CVE-2025-30875 Patchstack
5.3 Medium Awesome Support Plugin awesome-support Information Disclosure Sensitive Data Exposure No login needed ≤ 6.3.6 Fixed in 6.3.7 CVE-2025-53340 Patchstack
5.4 Medium Spreadconnect Plugin wc-spod Broken Access Control ≤ 2.1.5 CVE-2025-53291 Patchstack
5.3 Medium Kalium Theme kalium Broken Access Control No login needed ≤ 3.18.3 Fixed in 3.19 CVE-2025-53348 Patchstack
5.4 Medium Target Video Easy Publish Plugin brid-video-easy-publish Remote Code Execution Arbitrary Code Execution ≤ 3.8.9 CVE-2025-32688 Patchstack
6.5 Medium WP Simple Booking Calendar Plugin wp-simple-booking-calendar Broken Access Control ≤ 2.0.13 Fixed in 2.0.14 CVE-2025-39541 Patchstack
4.7 Medium GoodBarber Plugin goodbarber Open Redirect No login needed ≤ 1.0.26 Fixed in 1.0.27 CVE-2025-39523 Patchstack
4.3 Medium Church Admin Plugin church-admin Information Disclosure Sensitive Data Exposure ≤ 5.0.9 Fixed in 5.0.10 CVE-2025-39553 Patchstack
6.4 Medium LiteSpeed Cache Plugin litespeed-cache Server-Side Request Forgery ≤ 7.0.1 Fixed in 7.1 CVE-2025-47437 Patchstack
5.3 Medium Majestic Support Plugin majestic-support Broken Access Control No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-49860 Patchstack
4.3 Medium Categorify Plugin categorify Broken Access Control ≤ 1.0.7.5 CVE-2025-59005 Patchstack
5.4 Medium AutomatorWP Plugin automatorwp Broken Access Control Authenticated (Subscriber+) Missing Authorization to Multiple Functions ≤ 5.3.7 CVE-2025-9542 Wordfence
6.4 Medium Mikado Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 1.5.2 CVE-2025-9058 Wordfence
6.4 Medium Wilmer Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.4.5 CVE-2025-9061 Wordfence
5.0 Medium WP-Members Membership Plugin wp-members Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution via Profile Names ≤ 3.5.4.2 CVE-2025-9489 Wordfence
4.9 Medium ELEX WooCommerce Google Shopping (Google Product Feed) Plugin elex-woocommerce-google-product-feed-plugin-basic SQL Injection Authenticated (Admin+) SQL Inejction ≤ 1.4.3 CVE-2025-10046 Wordfence
6.4 Medium Recent Posts Widget Extended Plugin recent-posts-widget-extended Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via rpwe Shortcode ≤ 2.0.2 CVE-2025-6757 Wordfence
6.4 Medium SKT Addons for Elementor Plugin skt-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 3.7 CVE-2025-8564 Wordfence
6.4 Medium aThemes Addons for Elementor Lite Plugin athemes-addons-for-elementor-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.1.2 CVE-2025-8149 Wordfence
6.4 Medium Admin Menu Editor Plugin admin-menu-editor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder Parameter ≤ 1.14 CVE-2025-9493 Wordfence
6.5 Medium Cloud SAML SSO Plugin cloud-sso-single-sign-on Broken Access Control Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action No login needed ≤ 1.0.19 CVE-2025-7045 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only