WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 701–750 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery No login needed ≤ 3.1.6 Fixed in 3.1.7 CVE-2025-64357 Patchstack
4.3 Medium Depicter Plugin depicter Cross-Site Request Forgery No login needed ≤ 4.0.4 CVE-2025-8383 Wordfence
4.3 Medium Premmerce Product Search for WooCommerce Plugin premmerce-search Cross-Site Request Forgery No login needed ≤ 2.2.4 Fixed in 2.2.5 CVE-2025-64290 Patchstack
4.3 Medium Premmerce Plugin premmerce Cross-Site Request Forgery No login needed ≤ 1.3.19 Fixed in 1.3.20 CVE-2025-64288 Patchstack
4.3 Medium WP Rentals Plugin wprentals Cross-Site Request Forgery No login needed ≤ 3.13.1 CVE-2025-64286 Patchstack
4.3 Medium Stockie Extra Plugin stockie-extra Cross-Site Request Forgery No login needed ≤ 1.2.11 Fixed in 1.2.12 CVE-2025-64226 Patchstack
4.3 Medium PowerPress Podcasting Plugin powerpress Cross-Site Request Forgery No login needed ≤ 11.13.12 Fixed in 11.14 CVE-2025-64201 Patchstack
7.1 High hpb seo Plugin hpbseo Cross-Site Request Forgery No login needed ≤ 3.0.1 CVE-2025-60075 Patchstack
4.3 Medium Super Store Finder Plugin superstorefinder-wp Cross-Site Request Forgery No login needed ≤ 7.5 CVE-2025-58939 Patchstack
5.3 Medium Popup box Plugin ays-popup-box Cross-Site Request Forgery No login needed ≤ 5.5.4 Fixed in 5.5.5 CVE-2025-57931 Patchstack
4.3 Medium Entrada Theme entrada Cross-Site Request Forgery No login needed ≤ 5.7.7 CVE-2025-58918 Patchstack
4.9 Medium Slider Templates Plugin slider-templates Server-Side Request Forgery ≤ 1.0.3 CVE-2025-62988 Patchstack
7.1 High FanBridge signup Plugin fanbridge-signup Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-62986 Patchstack
4.3 Medium Raychat Plugin raychat Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-62975 Patchstack
7.1 High CloudSearch Plugin cloud-search Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-62962 Patchstack
4.3 Medium Simple Content Templates for Blog Posts & Pages Plugin simple-post-template Cross-Site Request Forgery No login needed ≤ 2.2.61 CVE-2025-62958 Patchstack
7.1 High NikanWP WooCommerce Reporting Plugin wc-reports-lite Cross-Site Request Forgery No login needed ≤ 1.0.0 Fixed in 3.0.0 CVE-2025-62957 Patchstack
7.1 High Reloadly Plugin reloadly-topup-widget Cross-Site Request Forgery No login needed ≤ 2.0.1 CVE-2025-62956 Patchstack
7.1 High Did Prestashop Display Plugin did-prestashop-display Cross-Site Request Forgery No login needed ≤ 1.0.30 CVE-2025-62945 Patchstack
7.1 High WP Business Hours Plugin wp-business-hours Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-62934 Patchstack
7.1 High Awesome Testimonials Plugin awesome-testimonials Cross-Site Request Forgery No login needed ≤ 2.2.1 CVE-2025-62933 Patchstack
7.1 High Multilang Contact Form Plugin multilang-contact-form Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-62896 Patchstack
4.3 Medium Off-Canvas Sidebars & Menus (Slidebars) Plugin off-canvas-sidebars Cross-Site Request Forgery No login needed ≤ 0.5.8.5 Fixed in 0.5.9 CVE-2025-62891 Patchstack
4.3 Medium Premmerce Brands for WooCommerce Plugin premmerce-woocommerce-brands Cross-Site Request Forgery No login needed ≤ 1.2.13 Fixed in 1.2.14 CVE-2025-62890 Patchstack
7.1 High Pricing Table builder Plugin wpdevart-pricing-table Cross-Site Request Forgery No login needed ≤ 1.5.3 CVE-2025-62886 Patchstack
4.3 Medium FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) Plugin fusewp Cross-Site Request Forgery WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.) <= 1.1.23.0 - Cross-Site Request Forgery to Sync Rule Creation No login needed ≤ 1.1.23.0 CVE-2025-11976 Wordfence
4.3 Medium Advanced Database Cleaner Plugin advanced-database-cleaner Cross-Site Request Forgery Cross-Site Request Forgery to Settings Manipulation No login needed ≤ 3.1.6 CVE-2025-11497 Wordfence
8.8 High Simple Registration for WooCommerce Plugin woocommerce-simple-registration Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Role Request Approval No login needed ≤ 1.5.8 CVE-2025-12095 Wordfence
7.5 High Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers Plugin popup-builder-block Server-Side Request Forgery Unauthenticated Server-Side Request Forgery No login needed ≤ 2.1.4 CVE-2025-10861 Wordfence
6.8 Medium Real Cookie Banner: GDPR & ePrivacy Cookie Consent Plugin real-cookie-banner Server-Side Request Forgery Authenticated (Admin+) Server-Side Request Forgery via scan-without-login Endpoint ≤ 5.2.4 CVE-2025-12136 Wordfence
8.8 High IndieAuth Plugin indieauth Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover via Stolen OAuth Tokens No login needed ≤ 4.5.4 CVE-2025-12028 Wordfence
4.3 Medium Disable Content Editor For Specific Template Plugin disable-contect-editor-for-specific-template Cross-Site Request Forgery Cross-Site Request Forgery to Template Configuration Update No login needed ≤ 2.0 CVE-2025-12072 Wordfence
6.1 Medium Multi Item Responsive Slider Plugin mislider Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-11992 Wordfence
5.5 Medium Orbit Fox Plugin Server-Side Request Forgery Author+ Server-Side Request Forgery < 3.0.2 Fixed in 3.0.2 CVE-2025-10874 WPScan
5.0 Medium Feedzy RSS Feeds Lite Plugin feedzy-rss-feeds Server-Side Request Forgery Authenticated (Subscriber+) Server-Side Request Forgery ≤ 5.1.0 CVE-2025-11128 Wordfence
5.3 Medium MxChat – AI Chatbot Plugin mxchat-basic Server-Side Request Forgery AI Chatbot for WordPress <= 2.4.6 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 2.4.6 CVE-2025-10705 Wordfence
4.3 Medium Product Catalog Simple Plugin post-type-x Cross-Site Request Forgery No login needed ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-62061 Patchstack
4.3 Medium UPC/EAN/GTIN Code Generator Plugin upc-ean-barcode-generator Cross-Site Request Forgery No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-62009 Patchstack
7.1 High SUMO Memberships for WooCommerce Plugin sumomemberships Cross-Site Request Forgery No login needed ≤ 7.8.0 Fixed in 7.8.0 CVE-2025-62005 Patchstack
8.8 High Advanced Custom Fields : CPT Options Pages Plugin acf-cpt-options-pages Cross-Site Request Forgery No login needed ≤ 2.0.9 CVE-2025-60208 Patchstack
7.1 High HotelRunner Booking Widget Plugin hotelrunner Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-60168 Patchstack
4.3 Medium WP Media Categories Plugin wp-media-categories Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-60134 Patchstack
7.1 High Video Blogster Lite Plugin video-blogster-lite Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60132 Patchstack
4.4 Medium Icegram Express Pro Plugin email-subscribers-premium Server-Side Request Forgery ≤ 5.9.5 Fixed in 5.9.6 CVE-2025-49917 Patchstack
5.4 Medium Captcha.eu Plugin captcha-eu Server-Side Request Forgery No login needed ≤ 1.0.61 Fixed in 1.0.62 CVE-2025-49374 Patchstack
4.3 Medium Evergreen Content Poster Plugin evergreen-content-poster Cross-Site Request Forgery No login needed ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-49373 Patchstack
4.7 Medium Search & Filter Plugin search-filter Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Open Redirect No login needed ≤ 1.2.17 Fixed in 1.2.18 CVE-2025-48099 Patchstack
4.3 Medium PixelYourSite Plugin pixelyoursite Cross-Site Request Forgery Cross-Site Request Forgery to GDPR Options Modification No login needed ≤ 11.1.2 CVE-2025-10588 Wordfence
5.0 Medium Element Pack Addons for Elementor Plugin bdthemes-element-pack-lite Server-Side Request Forgery Authenticated (Subscriber+) Blind Server-Side Request Forgery ≤ 8.2.5 CVE-2025-11536 Wordfence
8.8 High Theme Editor Plugin theme-editor Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed ≤ 3.0 CVE-2025-9890 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only