WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,401–7,450 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 149 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Booking Ultra Pro Plugin booking-ultra-pro Cross-Site Scripting ≤ 1.1.21 Fixed in 1.1.22 CVE-2025-58633 Patchstack
6.5 Medium Dadevarzan WordPress Common Plugin dadevarzan-common Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-58632 Patchstack
5.9 Medium IssueM Plugin issuem Cross-Site Scripting ≤ 2.9.0 Fixed in 2.9.1 CVE-2025-58631 Patchstack
5.9 Medium Simple Matomo Tracking Code Plugin simple-matomo-tracking-code Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-58630 Patchstack
6.5 Medium RumbleTalk Live Group Chat Plugin rumbletalk-chat-a-chat-with-themes Cross-Site Scripting ≤ 6.3.5 Fixed in 6.3.6 CVE-2025-58626 Patchstack
5.9 Medium WP Flow Plus Plugin wp-imageflow2 Cross-Site Scripting ≤ 5.2.5 Fixed in 5.2.6 CVE-2025-58625 Patchstack
6.5 Medium Exchange Rates Plugin exchange-rates Cross-Site Scripting ≤ 1.2.5 Fixed in 1.3.0 CVE-2025-58624 Patchstack
6.5 Medium Event Feed for Eventbrite Plugin event-feed-for-eventbrite Cross-Site Scripting ≤ 1.3.2 Fixed in 1.4.0 CVE-2025-58623 Patchstack
4.3 Medium Mobile Contact Line Plugin mobile-contact-line Broken Access Control ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-58622 Patchstack
6.5 Medium PuzzleMe Plugin puzzleme Cross-Site Scripting ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-58621 Patchstack
6.5 Medium PDF for WPForms Plugin pdf-for-wpforms Cross-Site Scripting ≤ 6.2.1 Fixed in 6.3.0 CVE-2025-58620 Patchstack
6.5 Medium Pie Calendar Plugin pie-calendar Cross-Site Scripting ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-58618 Patchstack
4.3 Medium F4 Media Taxonomies Plugin f4-media-taxonomies Broken Access Control ≤ 1.1.4 Fixed in 1.1.5 CVE-2025-58617 Patchstack
6.5 Medium Frisbii Pay Plugin reepay-checkout-gateway Broken Access Control ≤ 1.8.2.1 Fixed in 1.8.3 CVE-2025-58616 Patchstack
4.4 Medium WP Bannerize Pro Plugin wp-bannerize-pro Server-Side Request Forgery ≤ 1.10.0 Fixed in 1.11.0 CVE-2025-58615 Patchstack
6.5 Medium Tooltipy Plugin bluet-keywords-tooltip-generator Cross-Site Scripting ≤ 5.5.6 Fixed in 5.5.9 CVE-2025-58614 Patchstack
5.3 Medium Posts Table with Search & Sort Plugin posts-data-table Broken Access Control No login needed ≤ 1.4.10 Fixed in 1.4.11 CVE-2025-58613 Patchstack
6.5 Medium PropertyHive Plugin propertyhive Cross-Site Scripting ≤ 2.1.5 Fixed in 2.1.6 CVE-2025-58612 Patchstack
4.3 Medium Tickera Plugin tickera-event-ticketing-system Cross-Site Request Forgery No login needed ≤ 3.5.5.6 Fixed in 3.5.5.8 CVE-2025-58611 Patchstack
6.5 Medium Gallery PhotoBlocks Plugin photoblocks-grid-gallery Cross-Site Scripting ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-58610 Patchstack
6.5 Medium Latest Post Shortcode Plugin latest-post-shortcode Cross-Site Scripting ≤ 14.0.3 Fixed in 14.10 CVE-2025-58609 Patchstack
6.5 Medium Cookie Notice & Consent Banner for GDPR & CCPA Compliance Plugin cookie-notice-and-consent-banner Cross-Site Scripting ≤ 1.7.11 Fixed in 1.7.12 CVE-2025-58607 Patchstack
5.0 Medium SaasLauncher Plugin saaslauncher Broken Access Control ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-58606 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting ≤ 1.8.7 Fixed in 1.8.8 CVE-2025-58605 Patchstack
5.3 Medium Surfer Plugin surferseo Broken Access Control No login needed ≤ 1.6.4.574 Fixed in 1.6.5.584 CVE-2025-58603 Patchstack
6.5 Medium If-So Dynamic Content Personalization Plugin if-so Cross-Site Scripting ≤ 1.9.4 Fixed in 1.9.4.1 CVE-2025-58602 Patchstack
4.3 Medium Classified Listing Plugin classified-listing Broken Access Control ≤ 5.0.6 Fixed in 5.0.7 CVE-2025-58601 Patchstack
5.3 Medium Paid Member Subscriptions Plugin paid-member-subscriptions Broken Access Control No login needed ≤ 2.15.9 Fixed in 2.16.0 CVE-2025-58600 Patchstack
4.3 Medium Order Delivery Date for WooCommerce Plugin order-delivery-date-for-woocommerce Broken Access Control ≤ 4.1.0 Fixed in 4.2.0 CVE-2025-58599 Patchstack
6.6 Medium Klarna Order Management for WooCommerce Plugin klarna-order-management-for-woocommerce Information Disclosure Sensitive Data Exposure ≤ 1.9.8 Fixed in 1.9.9 CVE-2025-58598 Patchstack
4.3 Medium wpForo Forum Plugin wpforo Broken Access Control Insecure Direct Object References (IDOR) ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-58597 Patchstack
5.9 Medium MailOptin Plugin mailoptin Cross-Site Scripting ≤ 1.2.75.0 Fixed in 1.2.75.1 CVE-2025-58596 Patchstack
4.3 Medium Brizy Plugin brizy Broken Access Control ≤ 2.7.12 Fixed in 2.7.13 CVE-2025-58594 Patchstack
6.5 Medium Orbit Fox by ThemeIsle Plugin themeisle-companion Cross-Site Scripting ≤ 3.0.0 Fixed in 3.0.1 CVE-2025-58593 Patchstack
4.3 Medium Malcure Malware Scanner Plugin wp-malware-removal Broken Access Control ≤ 16.8 Fixed in 16.9 CVE-2025-3701 Patchstack
4.3 Medium Post SMTP Plugin post-smtp Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Option Update ≤ 3.4.1 CVE-2025-9219 Wordfence
5.3 Medium Makeaholic Plugin makeaholic Broken Access Control No login needed ≤ 1.8.5 Fixed in 1.8.7 CVE-2025-58210 Patchstack
6.4 Medium Vayu Blocks Plugin vayu-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Block Attributes ≤ 1.3.9 CVE-2025-9378 Wordfence
6.5 Medium Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder Plugin fluentform PHP Object Injection Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 5.1.16 - 6.1.1 - Authenticated (Subscriber+) PHP Object Injection To Arbitrary File Read 5.1.16 – 6.1.1 CVE-2025-9260 Wordfence
5.5 Medium Amministrazione Trasparente Plugin amministrazione-trasparente Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via print_r Function ≤ 9.0 CVE-2025-5083 Wordfence
6.4 Medium TablePress Plugin tablepress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode_debug Parameter ≤ 3.2 CVE-2025-9500 Wordfence
6.4 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via oceanwp_library Shortcode ≤ 2.4.9 CVE-2025-9499 Wordfence
4.3 Medium Pro Bulk Watermark Plugin pro-watermark Path Traversal ≤ 2.0 CVE-2025-4956 Patchstack
4.3 Medium Related Posts Lite Plugin related-posts-lite Cross-Site Request Forgery No login needed ≤ 1.12 CVE-2025-9618 Wordfence
6.5 Medium Slider Revolution Plugin Path Traversal Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' ≤ 6.7.36 CVE-2025-9217 Wordfence
6.4 Medium Events Addon for Elementor Plugin events-addon-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Typewriter and Countdown Widgets ≤ 2.2.9 CVE-2025-8150 Wordfence
6.5 Medium iATS Online Forms Plugin iats-online-forms SQL Injection Authenticated (Contributor+) SQL Injection via order Parameter ≤ 1.2 CVE-2025-9441 Wordfence
6.4 Medium OSM Map Widget for Elementor Plugin osm-map-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-8619 Wordfence
6.4 Medium List Subpages Plugin list-sub-pages Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-8290 Wordfence
4.3 Medium Ultimate Tag Warrior Importer Plugin utw-importer Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-9374 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only