WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,351–7,400 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 148 of 358
Severity Component Vulnerability Affected versions Published CVE Source
5.9 Medium Search by Google Plugin search-google Cross-Site Scripting ≤ 1.9 CVE-2025-58832 Patchstack
4.3 Medium Parallax Scrolling Enllax.js Plugin parallax-scrolling-enllax-js Cross-Site Request Forgery No login needed ≤ 0.0.6 CVE-2025-58831 Patchstack
6.5 Medium Parallax Scrolling Enllax.js Plugin parallax-scrolling-enllax-js Cross-Site Scripting ≤ 0.0.6 CVE-2025-58830 Patchstack
4.9 Medium Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One Plugin ai-auto-tool Server-Side Request Forgery ≤ 2.3.3 CVE-2025-58829 Patchstack
6.5 Medium 코드엠샵 소셜톡 Plugin mshop-naver-talktalk Cross-Site Scripting ≤ 1.2.2 CVE-2025-58828 Patchstack
6.5 Medium WP Publication Archive Plugin wp-publication-archive Cross-Site Scripting ≤ 3.0.1 CVE-2025-58826 Patchstack
5.9 Medium Comment Form WP – Customize Default Comment Form Plugin comment-form-wp Cross-Site Scripting Customize Default Comment Form plugin <= 2.0.1 - Cross Site Scripting (XSS) ≤ 2.0.1 CVE-2025-58825 Patchstack
4.3 Medium Shk Corporate Plugin shk-corporate Broken Access Control ≤ 2.4.1.1 CVE-2025-58824 Patchstack
6.5 Medium Get Cash Plugin get-cash Cross-Site Scripting ≤ 3.2.3 CVE-2025-58823 Patchstack
6.5 Medium WP Mail Plugin wp-mail Cross-Site Scripting ≤ 1.3 CVE-2025-58822 Patchstack
5.9 Medium WP Notification Bell Plugin wp-notification-bell Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-58821 Patchstack
5.9 Medium Carousel Ultimate Plugin carousel Cross-Site Scripting ≤ 1.8 CVE-2025-58820 Patchstack
5.4 Medium Developer Tools Blocker Plugin swiftninjapro-inspect-element-console-blocker Cross-Site Request Forgery No login needed ≤ 3.2.1 CVE-2025-58818 Patchstack
4.3 Medium SoftMe Plugin softme Broken Access Control ≤ 1.1.27 CVE-2025-58817 Patchstack
6.5 Medium Stagtools Plugin stagtools Cross-Site Scripting ≤ 2.3.8 CVE-2025-58814 Patchstack
4.3 Medium Consultstreet Plugin consultstreet Broken Access Control ≤ 3.0.0 CVE-2025-58813 Patchstack
6.5 Medium Best Restaurant Menu by PriceListo Plugin best-restaurant-menu-by-pricelisto Cross-Site Scripting ≤ 1.4.3 CVE-2025-58812 Patchstack
5.9 Medium Ultimate Client Dash Plugin ulimate-client-dash Cross-Site Scripting ≤ 4.7 CVE-2025-58811 Patchstack
5.9 Medium Simple Link List Widget Plugin simple-link-list-widget Cross-Site Scripting ≤ 0.3.2 CVE-2025-58810 Patchstack
6.5 Medium prettyPhoto Plugin prettyphoto Cross-Site Scripting ≤ 1.2.5 CVE-2025-58808 Patchstack
5.9 Medium Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Scripting ≤ 3.0 CVE-2025-58805 Patchstack
4.3 Medium WooCommerce Single Page Checkout Plugin woo-single-page-checkout Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-58804 Patchstack
4.3 Medium TrustMate.io – WooCommerce integration Plugin trustmate-io-integration-for-woocommerce Cross-Site Request Forgery WooCommerce integration plugin <= 1.16.0 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.16.0 CVE-2025-58802 Patchstack
5.4 Medium Responder Plugin responder Cross-Site Request Forgery No login needed ≤ 4.3.8 Fixed in 4.4.0 CVE-2025-58801 Patchstack
4.3 Medium WP Email Template Plugin wp-email-template Cross-Site Request Forgery No login needed ≤ 2.8.5 CVE-2025-58800 Patchstack
4.3 Medium Custom WooCommerce Checkout Fields Editor Plugin add-fields-to-checkout-page-woocommerce Cross-Site Request Forgery No login needed ≤ 1.3.4 CVE-2025-58799 Patchstack
4.3 Medium BCM Duplicate Menu Plugin bcm-duplicate-menu Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-58798 Patchstack
5.3 Medium Ninja Charts Plugin ninja-charts Information Disclosure Sensitive Data Exposure No login needed ≤ 3.3.5 Fixed in 3.3.6 CVE-2025-58797 Patchstack
6.5 Medium Elementor Element Condition Plugin ele-conditions Cross-Site Scripting ≤ 1.0.5 CVE-2025-58796 Patchstack
4.3 Medium Payoneer Checkout Plugin payoneer-checkout Content Injection Content Spoofing No login needed ≤ 3.4.0 Fixed in 3.5.0 CVE-2025-58795 Patchstack
4.3 Medium Notification for Telegram Plugin notification-for-telegram Cross-Site Request Forgery No login needed ≤ 3.5 CVE-2025-58794 Patchstack
6.5 Medium WPB Elementor Addons Plugin wpb-elementor-addons Cross-Site Scripting ≤ 1.7 CVE-2025-58793 Patchstack
4.3 Medium Authors List Plugin authors-list Cross-Site Request Forgery No login needed ≤ 2.0.6.2 CVE-2025-58792 Patchstack
5.9 Medium SEO Auto Linker Plugin wpa-seo-auto-linker Cross-Site Scripting ≤ 1.5.3 CVE-2025-58791 Patchstack
6.5 Medium Kiwi Plugin kiwi-social-share Cross-Site Scripting ≤ 2.1.8 CVE-2025-58790 Patchstack
6.5 Medium Themify Popup Plugin themify-popup Cross-Site Scripting ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-58787 Patchstack
6.5 Medium Ibtana – Ecommerce Product Addons Plugin ibtana-ecommerce-product-addons Cross-Site Scripting Ecommerce Product Addons plugin <= 0.4.7.6 - Cross Site Scripting (XSS) ≤ 0.4.7.6 CVE-2025-58786 Patchstack
5.4 Medium Ray Enterprise Translation Plugin lingotek-translation Broken Access Control ≤ 1.7.2 CVE-2025-58785 Patchstack
6.5 Medium ARI Fancy Lightbox Plugin ari-fancy-lightbox Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58784 Patchstack
4.3 Medium Gutentor Plugin gutentor Broken Access Control ≤ 3.5.5 Fixed in 3.5.6 CVE-2025-58783 Patchstack
4.3 Medium OceanWP Theme oceanwp Broken Access Control Subscriber+ Limited Option Update < 4.1.2 Fixed in 4.1.2 CVE-2025-8944 WPScan
6.4 Medium Flatsome Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.20.0 CVE-2025-8684 Wordfence
5.3 Medium PopAd Plugin popad Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.4 CVE-2025-9616 Wordfence
4.9 Medium atec Debug Plugin atec-debug Path Traversal Authenticated (Administrator+) Arbitrary File Read ≤ 1.2.22 CVE-2025-9516 Wordfence
6.5 Medium Ai Engine Plugin ai-engine Broken Access Control Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion No login needed ≤ 2.9.5 CVE-2025-8268 Wordfence
5.4 Medium Exit Intent Popup Plugin exitintentpopup Server-Side Request Forgery No login needed ≤ 1.0.1 Fixed in 1.0.3 CVE-2025-58641 Patchstack
6.5 Medium Document Engine Plugin document-engine Cross-Site Scripting ≤ 1.2 Fixed in 1.3 CVE-2025-58640 Patchstack
5.4 Medium Contact Form By Mega Forms Plugin mega-forms Broken Access Control ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-58639 Patchstack
5.3 Medium Support Genix Plugin support-genix-lite Broken Access Control No login needed ≤ 1.4.23 Fixed in 1.4.24 CVE-2025-58635 Patchstack
5.3 Medium PeachPay Payments Plugin peachpay-for-woocommerce Broken Access Control No login needed ≤ 1.117.4 Fixed in 1.117.5 CVE-2025-58634 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only