WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 701–750 of 1,492 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 15 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Cache control by Cacholong Plugin cache-control-by-cacholong Cross-Site Request Forgery No login needed ≤ 5.4.1 CVE-2025-31763 Patchstack
4.3 Medium TZ PlusGallery Plugin tz-plus-gallery Cross-Site Request Forgery No login needed ≤ 1.5.5 CVE-2025-31756 Patchstack
6.5 Medium Breaking News WP Plugin breaking-news-wp Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.3 CVE-2025-31751 Patchstack
4.3 Medium Apimo Connector Plugin apimo Cross-Site Request Forgery No login needed ≤ 2.6.5.1 CVE-2025-31602 Patchstack
6.5 Medium Appointy Appointment Scheduler Plugin appointy-appointment-scheduler Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 4.2.1 CVE-2025-31601 Patchstack
4.3 Medium DesignO Plugin designo Cross-Site Request Forgery No login needed ≤ 2.6.0 CVE-2025-31600 Patchstack
5.4 Medium Elfsight Testimonials Slider Plugin elfsight-testimonials-slider Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.1 CVE-2025-31588 Patchstack
4.3 Medium Multi Days Events and Multi Events in One Day Calendar Plugin dragon-calendar-free-version Cross-Site Request Forgery No login needed ≤ 1.1.3 CVE-2025-31572 Patchstack
6.4 Medium WP Link Preview Plugin wp-link-preview Server-Side Request Forgery ≤ 1.4.1 CVE-2025-31527 Patchstack
4.3 Medium WP Church Donation Plugin wp-church-donation Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31410 Patchstack
4.3 Medium SimplyRETS Real Estate IDX Plugin simply-rets Cross-Site Request Forgery CSRF to Multiple Admin Actions ≤ 3.0.5 Fixed in 3.1.0 CVE-2025-31010 Patchstack
4.3 Medium WP Supersized Plugin wp-supersized Cross-Site Request Forgery No login needed ≤ 3.1.6 CVE-2025-31438 Patchstack
5.4 Medium Browser Caching with .htaccess Plugin browser-caching-with-htaccess Cross-Site Request Forgery No login needed 1.2.1 CVE-2025-31439 Patchstack
5.4 Medium Simple Trackback Disabler Plugin simple-trackback-disabler Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-31448 Patchstack
5.4 Medium NertWorks All in One Social Share Tools Plugin nertworks-all-in-one-social-share-tools Cross-Site Request Forgery No login needed ≤ 1.26 CVE-2025-31447 Patchstack
4.3 Medium Ultimate Security Checker Plugin ultimate-security-checker Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Security Rescan No login needed ≤ 4.2 CVE-2025-31456 Patchstack
5.4 Medium LWS SMS Plugin lws-sms Cross-Site Request Forgery No login needed ≤ 2.4.1 CVE-2025-31457 Patchstack
4.3 Medium WP Database Optimizer Plugin wp-database-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.1.3 CVE-2025-31474 Patchstack
4.9 Medium WP Compress for MainWP Plugin wp-compress-mainwp Server-Side Request Forgery ≤ 6.30.03 Fixed in 6.30.06 CVE-2025-31076 Patchstack
4.3 Medium Usermaven Plugin usermaven Cross-Site Request Forgery No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-31079 Patchstack
4.3 Medium Event Tickets with Ticket Scanner Plugin event-tickets-with-ticket-scanner Cross-Site Request Forgery Arbitrary Tickets Deletion via CSRF No login needed < 2.5.4 Fixed in 2.5.4 CVE-2025-1762 WPScan
5.4 Medium Easy Booked – Appointment Booking and Scheduling Management System Plugin easy-booked Cross-Site Request Forgery No login needed ≤ 2.4.5 Fixed in 2.4.6 CVE-2025-22634 Patchstack
4.3 Medium Print PDF Generator and Publisher Plugin nopeamedia Cross-Site Request Forgery No login needed ≤ 1.2.0 Fixed in 1.2.1 CVE-2025-22637 Patchstack
4.3 Medium AIO Performance Profiler, Monitor, Optimize, Compress & Debug Plugin all-in-one-performance-accelerator Broken Access Control ≤ 1.2 Fixed in 1.3 CVE-2025-22647 Patchstack
4.3 Medium Awesome Event Booking Plugin awesome-event-booking Cross-Site Request Forgery No login needed ≤ 2.7.5 Fixed in 2.8.0 CVE-2025-22669 Patchstack
6.5 Medium VikBooking Hotel Booking Engine & PMS Plugin vikbooking Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.7.2 Fixed in 1.7.3 CVE-2025-22670 Patchstack
4.9 Medium Video & Photo Gallery for Ultimate Member Plugin gallery-for-ultimate-member Server-Side Request Forgery ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-22672 Patchstack
4.3 Medium Gift Message for WooCommerce Plugin gift-message-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.7.8 Fixed in 1.7.9 CVE-2025-30923 Patchstack
4.4 Medium Metform Plugin metform Server-Side Request Forgery ≤ 3.9.2 Fixed in 3.9.3 CVE-2025-30914 Patchstack
5.4 Medium Float menu Plugin float-menu Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.2 Fixed in 6.1.3 CVE-2025-30912 Patchstack
4.3 Medium Custom Fields Account Registration For Woocommerce Plugin custom-fields-account-registration-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.1 Fixed in 1.2 CVE-2025-30888 Patchstack
4.3 Medium Product Author for WooCommerce Plugin wc-product-author Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-30872 Patchstack
4.3 Medium 3DPrint Lite Plugin 3dprint-lite Cross-Site Request Forgery No login needed ≤ 2.1.3.5 Fixed in 2.1.3.6 CVE-2025-30865 Patchstack
4.3 Medium Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms Plugin integration-for-contact-form-7-and-google-sheets Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-30863 Patchstack
4.3 Medium reCAPTCHA for all Plugin recaptcha-for-all Cross-Site Request Forgery No login needed ≤ 2.22 Fixed in 2.23 CVE-2025-30862 Patchstack
4.3 Medium Custom Field For WP Job Manager Plugin custom-field-for-wp-job-manager Cross-Site Request Forgery No login needed ≤ 1.4 Fixed in 1.5 CVE-2025-30856 Patchstack
4.3 Medium Serial Codes Generator and Validator with WooCommerce Support Plugin serial-codes-generator-and-validator Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 2.7.8 CVE-2025-30854 Patchstack
4.3 Medium Christmas Panda Plugin christmas-panda Cross-Site Request Forgery No login needed ≤ 1.0.4 Fixed in 1.1.0 CVE-2025-30842 Patchstack
4.3 Medium Verge3D Plugin verge3d Cross-Site Request Forgery No login needed ≤ 4.8.2 Fixed in 4.8.3 CVE-2025-30833 Patchstack
4.3 Medium Anthologize Plugin anthologize Cross-Site Request Forgery No login needed ≤ 0.8.2 Fixed in 0.8.3 CVE-2025-30823 Patchstack
4.3 Medium Custom Login Logo Plugin ideal-wp-login-logo-changer Cross-Site Request Forgery No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-30822 Patchstack
4.3 Medium publish post email notification Plugin publish-post-email-notification Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.2.3 Fixed in 1.0.2.4 CVE-2025-30816 Patchstack
4.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.1.8 Fixed in 2.2.0 CVE-2025-30815 Patchstack
4.3 Medium ValidateCertify Plugin validar-certificados-de-cursos Cross-Site Request Forgery No login needed ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-30811 Patchstack
4.3 Medium Flexible Cookies Plugin flexible-cookies Cross-Site Request Forgery No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-30805 Patchstack
4.3 Medium wpShopGermany IT-RECHT KANZLEI Plugin wpshopgermany-it-recht-kanzlei Cross-Site Request Forgery No login needed ≤ 2.0 Fixed in 2.1 CVE-2025-30804 Patchstack
4.3 Medium TWB Woocommerce Reviews Plugin twb-woocommerce-reviews Cross-Site Request Forgery No login needed ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-30801 Patchstack
4.3 Medium Football Pool Plugin football-pool Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.12.2 Fixed in 2.12.3 CVE-2025-30764 Patchstack
4.3 Medium IP Based Login Plugin ip-based-login Cross-Site Request Forgery Log Deletion via CSRF No login needed < 2.4.1 Fixed in 2.4.1 CVE-2024-13118 WPScan
5.4 Medium SpeakPipe Plugin speakpipe-voicemail-for-websites Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-30619 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only