WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,301–7,350 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 147 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium StreamWeasels Kick Integration Plugin streamweasels-kick-integration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via vodsChannel Parameter ≤ 1.1.5 CVE-2025-9442 Wordfence
6.4 Medium Smart Table Builder Plugin smart-table-builder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.0.1 CVE-2025-9126 Wordfence
6.4 Medium Content Views Plugin content-views-query-and-display-post-page Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Grid and List Widgets ≤ 4.1 CVE-2025-8722 Wordfence
6.5 Medium UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP Plugin userswp SQL Injection Front-end login form, User Registration, User Profile & Members Directory plugin for WP <= 1.2.44 - Authenticated (Subscriber+) SQL Injection ≤ 1.2.44 CVE-2025-10003 Wordfence
6.4 Medium Optio Dentistry Plugin optio-dentistry Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2 CVE-2025-9853 Wordfence
4.9 Medium User Registration & Membership Plugin user-registration SQL Injection Authenticated (Admin+) SQL Injection ≤ 4.3.0 CVE-2025-9085 Wordfence
6.4 Medium LA-Studio Element Kit for Elementor Plugin lastudio-element-kit Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 1.5.5.1 CVE-2025-8360 Wordfence
6.4 Medium Easy Social Feed – Social Photos Gallery – Post Feed – Like Box Plugin easy-facebook-likebox Cross-Site Scripting Social Photos Gallery – Post Feed – Like Box <= 6.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.6.7 CVE-2025-6067 Wordfence
6.4 Medium Html Social share buttons Plugin html-social-share-buttons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.1.16 CVE-2025-9849 Wordfence
5.3 Medium Rehub Theme Information Disclosure Unauthenticated Password Protected Post Disclosure No login needed ≤ 19.9.7 CVE-2025-7368 Wordfence
6.4 Medium Biagiotti Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.1.3 CVE-2025-9057 Wordfence
4.3 Medium Quick Paypal Payments Plugin quick-paypal-payments Cross-Site Request Forgery No login needed ≤ 5.7.46 Fixed in 5.7.47 CVE-2025-27003 Patchstack
6.5 Medium HAPPY Plugin happy-helpdesk-support-ticket-system Broken Access Control ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-53571 Patchstack
5.9 Medium GoUrl Bitcoin Payment Gateway & Paid Downloads & Membership Plugin gourl-bitcoin-payment-gateway-paid-downloads-membership Cross-Site Scripting ≤ 1.6.6 CVE-2025-48102 Patchstack
6.5 Medium Today's Date Inserter Plugin todays-date-inserter Cross-Site Scripting ≤ 1.2.1 CVE-2025-48103 Patchstack
6.5 Medium Easy Flash Embed Plugin easy-flash-embed Cross-Site Scripting ≤ 1.0 CVE-2025-48105 Patchstack
6.5 Medium MasterStudy LMS Plugin masterstudy-lms-learning-management-system Broken Access Control ≤ 3.6.15 Fixed in 3.6.16 CVE-2025-54744 Patchstack
6.5 Medium Course Booking Platform Plugin course-booking-platform Cross-Site Scripting ≤ 1.0.0 CVE-2025-58887 Patchstack
5.9 Medium Instant Locations Plugin instant-locations Cross-Site Scripting ≤ 1.0 CVE-2025-58886 Patchstack
5.9 Medium vipdrv Plugin vipdrv-vip-test-drive Cross-Site Scripting ≤ 1.0.3 CVE-2025-58884 Patchstack
5.9 Medium Search Cloud One Plugin search-cloud-one Cross-Site Scripting ≤ 2.2.5 CVE-2025-58883 Patchstack
6.5 Medium Simple Text Slider Plugin simple-text-slider Cross-Site Scripting ≤ 1.0.5 CVE-2025-58882 Patchstack
6.5 Medium Translate This gTranslate Shortcode Plugin translate-this-google-translate-web-element-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-58880 Patchstack
6.5 Medium Woocommerce Gifts Product Plugin woo-gift-product Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-58878 Patchstack
6.5 Medium Aparat Video Shortcode Plugin aparat-shortcode Cross-Site Scripting ≤ 0.2.4 CVE-2025-58876 Patchstack
6.5 Medium WP Github Gist Plugin wp-github-gist Cross-Site Scripting ≤ 0.5 CVE-2025-58875 Patchstack
6.5 Medium StoryMap Plugin wp-storymap Cross-Site Scripting ≤ 2.1 CVE-2025-58874 Patchstack
5.9 Medium Pushe Web Push Notification Plugin pushe-webpush Cross-Site Scripting ≤ 0.5.0 CVE-2025-58873 Patchstack
6.5 Medium Simple Price Calculator Plugin simple-price-calculator-basic Broken Access Control ≤ 1.3 CVE-2025-58872 Patchstack
6.5 Medium Master Paper Collapse Toggle Plugin master-paper-collapse-toggle Cross-Site Scripting ≤ 1.1 CVE-2025-58871 Patchstack
6.5 Medium WP-GraphViz Plugin wp-graphviz Cross-Site Scripting ≤ 1.5.1 CVE-2025-58870 Patchstack
6.5 Medium SimaCookie Plugin simasicher-dsgvo-cookie Cross-Site Request Forgery ≤ 1.3.2 CVE-2025-58869 Patchstack
6.5 Medium SimaCookie Plugin simasicher-dsgvo-cookie Cross-Site Scripting ≤ 1.3.2 CVE-2025-58868 Patchstack
6.5 Medium Easy Download Media Counter Plugin easy-download-media-counter Cross-Site Scripting ≤ 1.2 CVE-2025-58867 Patchstack
4.3 Medium Compact Admin Plugin compact-admin Cross-Site Request Forgery No login needed ≤ 1.3.3 CVE-2025-58865 Patchstack
6.5 Medium 金数据 Plugin jinshuju Cross-Site Scripting ≤ 1.0 CVE-2025-58864 Patchstack
6.5 Medium Zoomify embed for WP Plugin zoom-image-shortcode Cross-Site Scripting ≤ 1.5.2 CVE-2025-58863 Patchstack
6.5 Medium WordPress Events Calendar Plugin – connectDaily Plugin connect-daily-web-calendar Cross-Site Scripting connectDaily Plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 CVE-2025-58862 Patchstack
6.5 Medium WPB Image Widget Plugin wpb-image-widget Cross-Site Scripting ≤ 1.1 CVE-2025-58858 Patchstack
6.5 Medium Woocommerce Notify Updated Product Plugin woocommerce-notify-updated-product Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-58856 Patchstack
6.5 Medium Boxed Content Plugin boxed-content Cross-Site Scripting ≤ 1.0 CVE-2025-58851 Patchstack
6.5 Medium Showpass WordPress Extension Plugin showpass Cross-Site Scripting ≤ 4.0.3 Fixed in 4.0.4 CVE-2025-58850 Patchstack
6.5 Medium Donation Forms WP by Givecloud Plugin donation-forms-by-givecloud Cross-Site Scripting ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-58842 Patchstack
5.5 Medium Media Author Plugin media-author Broken Access Control ≤ 1.0.4 CVE-2025-58841 Patchstack
6.5 Medium Custom Team Manager Plugin custom-team-manager Cross-Site Scripting ≤ 2.4.2 CVE-2025-58840 Patchstack
6.5 Medium Smooth Accordion Plugin smooth-accordion Cross-Site Scripting ≤ 2.1 CVE-2025-58838 Patchstack
6.5 Medium SS Font Awesome Icon Plugin ss-font-awesome-icon Cross-Site Scripting ≤ 4.1.3 CVE-2025-58837 Patchstack
6.5 Medium FW Anker Plugin fw-anker Cross-Site Scripting ≤ 1.2.6 CVE-2025-58836 Patchstack
5.3 Medium Bonus for Woo Plugin bonus-for-woo Other Other vulnerability Type No login needed ≤ 7.6.6 Fixed in 7.6.7 CVE-2025-58835 Patchstack
6.5 Medium short.io Plugin wp-shortcm Cross-Site Scripting ≤ 2.4.2 CVE-2025-58834 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only