WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 701–750 of 2,544 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium ClipLink Plugin cliplink Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49964 Patchstack
4.3 Medium Oganro Travel Portal Search Widget for HotelBeds APITUDE API Plugin oganro-travel-portal-search-widget-for-hotelbeds-apitude-api Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49966 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium XML Travel Portal Widget Plugin oganro-reservation-widget Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-49968 Patchstack
4.3 Medium Live Sports Streamthunder Plugin live-sports-streamthunder Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-49967 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-49975 Patchstack
4.3 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Request Forgery No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-49977 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.13.11 Fixed in 11.13.12 CVE-2025-49984 Patchstack
4.9 Medium WPThumb Plugin wp-thumb Server-Side Request Forgery ≤ 0.10 CVE-2025-49983 Patchstack
4.9 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery ≤ 3.3.2 CVE-2025-49985 Patchstack
5.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.12.18 Fixed in 1.12.19 CVE-2025-49997 Patchstack
6.5 Medium Mailing Group Listserv Plugin wp-mailing-group Cross-Site Request Forgery No login needed ≤ 3.0.5 CVE-2025-50036 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-50044 Patchstack
7.1 High Virtual Moderator Plugin virtual-moderator Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52772 Patchstack
7.1 High TinyNav Plugin tinynav Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-52781 Patchstack
7.1 High Logo Manager For Samandehi Plugin samandehi-logo-manager Cross-Site Request Forgery No login needed ≤ 0.5 CVE-2025-52780 Patchstack
7.1 High Change Cart button Colors WooCommerce Plugin wc-style Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-52783 Patchstack
7.1 High Lewe ChordPress Plugin chordpress Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 4.0.1 CVE-2025-52789 Patchstack
7.1 High Bluff Post Plugin bluff-post Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-52784 Patchstack
7.1 High Knowledge Base – Knowledge Base Maker Plugin knowledge-base-maker Cross-Site Request Forgery Knowledge Base Maker plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.1.8 CVE-2025-52791 Patchstack
7.1 High WP-DownloadCounter Plugin wp-downloadcounter Cross-Site Request Forgery No login needed ≤ 1.01 CVE-2025-52790 Patchstack
7.1 High Esselink.nu Settings Plugin esselinknu-settings Cross-Site Request Forgery No login needed ≤ 4.5 CVE-2025-52793 Patchstack
7.1 High WP User Stylesheet Switcher Plugin wp-user-stylesheet-switcher Cross-Site Request Forgery No login needed ≤ v2.2.0 CVE-2025-52792 Patchstack
7.1 High WP Front User Submit / Front Editor Plugin front-editor Cross-Site Request Forgery No login needed ≤ 5.0.6 CVE-2025-52795 Patchstack
7.1 High Creative Contact Form Plugin sexy-contact-form Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-52794 Patchstack
8.8 High Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-52825 Patchstack
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
4.3 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-49856 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-49865 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
7.1 High Civi Framework Plugin civi-framework Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to User Deactivation No login needed ≤ 2.1.6 Fixed in 2.1.6.4 CVE-2025-49511 Patchstack
7.1 High Konami Easter Egg Plugin konami-easter-egg Cross-Site Request Forgery No login needed ≤ v0.4 CVE-2025-49425 Patchstack
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium Wp Easy Allopass Plugin wordpress-easy-allopass Cross-Site Request Forgery No login needed ≤ 4.1.1 CVE-2025-49435 Patchstack
4.3 Medium WP Security Master Plugin wp-security-master Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-49440 Patchstack
4.3 Medium Admin Notes Plugin admin-note Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49446 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
7.1 High BP Profile as Homepage Plugin bp-profile-as-homepage Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1 CVE-2025-49453 Patchstack
5.4 Medium Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Request Forgery No login needed ≤ 1.0.4 CVE-2025-24772 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
4.3 Medium WP Media File Type Manager Plugin wp-media-file-type-manager Cross-Site Request Forgery No login needed ≤ 2.3.1 CVE-2025-27359 Patchstack
7.1 High Post Author Plugin post-author Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28950 Patchstack
7.1 High Mediabay - WordPress Media Library Folders Plugin mediabay Cross-Site Request Forgery WordPress Media Library Folders plugin <= 1.4 - CSRF to Reflected XSS No login needed ≤ 1.4 CVE-2025-28948 Patchstack
4.3 Medium Quick Event Calendar Plugin quick-event-calendar Cross-Site Request Forgery No login needed ≤ 1.4.9 CVE-2025-27360 Patchstack
7.4 High Backwp Plugin backwp Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.0.2 CVE-2025-28954 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only