WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,451–7,500 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 150 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium LWSCache Plugin lwscache Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activation via lwscache_activatePlugin Function ≤ 2.8.5 CVE-2025-8147 Wordfence
5.8 Medium B Slider Plugin b-slider Broken Access Control No login needed ≤ 1.1.30 Fixed in 2.0.0 CVE-2025-54734 Patchstack
6.5 Medium All Bootstrap Blocks Plugin all-bootstrap-blocks Broken Access Control No login needed ≤ 1.3.28 Fixed in 1.3.29 CVE-2025-54733 Patchstack
5.4 Medium LifePress Plugin lifepress Broken Access Control ≤ 2.1.3 Fixed in 2.2 CVE-2025-53337 Patchstack
6.4 Medium Chartbeat Plugin chartbeat Server-Side Request Forgery ≤ 2.0.7 CVE-2025-53250 Patchstack
4.3 Medium Houzez Theme houzez Local File Inclusion < 4.1.4 Fixed in 4.1.4 CVE-2025-49405 Patchstack
5.9 Medium Custom Comment Plugin customcomment Cross-Site Scripting ≤ 2.1.6 CVE-2025-48365 Patchstack
4.9 Medium rajce Plugin rajce Server-Side Request Forgery ≤ 0.4.2 CVE-2025-48364 Patchstack
4.3 Medium Popup for CF7 with Sweet Alert Plugin cf7-sweet-alert-popup Cross-Site Request Forgery No login needed ≤ 1.6.5 CVE-2025-48363 Patchstack
5.4 Medium Hesabfa Accounting Plugin hesabfa-accounting Cross-Site Request Forgery No login needed ≤ 2.2.5 CVE-2025-48362 Patchstack
5.3 Medium Hesabfa Accounting Plugin hesabfa-accounting Information Disclosure Sensitive Data Exposure via Log File No login needed ≤ 2.2.5 CVE-2025-48361 Patchstack
5.9 Medium Varnish/Nginx Proxy Caching Plugin vcaching Cross-Site Scripting ≤ 1.8.3 CVE-2025-48360 Patchstack
5.9 Medium Risk Free Cash On Delivery (COD) – WooCommerce Plugin risk-free-cash-on-delivery-cod-woocommerce Cross-Site Scripting WooCommerce plugin <= 1.0.4 - Cross Site Scripting (XSS) ≤ 1.0.4 CVE-2025-48358 Patchstack
5.4 Medium Century ToolKit Plugin century-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Arbitrary Plugin Activation No login needed ≤ 1.2.1 CVE-2025-48357 Patchstack
6.5 Medium Kanpress Plugin kanpress Cross-Site Scripting ≤ 1.1 CVE-2025-48356 Patchstack
6.5 Medium Better Post & Filter Widgets for Elementor Plugin better-post-filter-widgets-for-elementor Cross-Site Scripting ≤ 1.6.1 Fixed in 1.6.2 CVE-2025-48354 Patchstack
5.9 Medium Yandex Site search pinger Plugin yandex-pinger Cross-Site Scripting ≤ 1.5 CVE-2025-48352 Patchstack
4.3 Medium AutoWP Plugin autowp-ai-content-writer-rewriter Broken Access Control ≤ 2.2.7 CVE-2025-48350 Patchstack
6.5 Medium Video Gallery – Vimeo and YouTube Gallery Plugin smart-grid-gallery Cross-Site Scripting Vimeo and YouTube Gallery plugin <= 1.1.7 - Cross Site Scripting (XSS) ≤ 1.1.7 CVE-2025-48349 Patchstack
4.3 Medium Site Offline Plugin site-offline Broken Access Control ≤ 1.5.7 CVE-2025-48348 Patchstack
6.5 Medium bxSlider integration Plugin bxslider-integration Cross-Site Scripting ≤ 1.7.2 CVE-2025-48347 Patchstack
5.3 Medium WP Mailgun SMTP Plugin wp-mailgun-smtp Broken Access Control No login needed ≤ 1.0.7 CVE-2025-48327 Patchstack
5.9 Medium tli.tl auto Twitter poster Plugin tlitl-auto-twitter-poster Cross-Site Scripting ≤ 3.4 CVE-2025-48324 Patchstack
5.9 Medium Advance Food Menu Plugin advance-food-menu Cross-Site Scripting ≤ 1.0 CVE-2025-48323 Patchstack
6.5 Medium Statify Widget Plugin statify-widget Cross-Site Scripting ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-48322 Patchstack
5.9 Medium Mesa Mesa Reservation Widget Plugin mesa-mesa-reservation-widget Cross-Site Scripting ≤ 1.0.0 CVE-2025-48319 Patchstack
4.3 Medium 多说社会化评论框 Plugin duoshuo Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-48318 Patchstack
6.5 Medium Responsive Mobile-Friendly Tooltip Plugin responsive-mobile-friendly-tooltip Cross-Site Scripting ≤ 1.6.6 CVE-2025-48316 Patchstack
6.5 Medium WordPress HTML Plugin custom-html-bodyhead Cross-Site Scripting ≤ 0.51 CVE-2025-48315 Patchstack
5.9 Medium Add Code To Head Plugin add-code-to-head Cross-Site Scripting ≤ 1.17 CVE-2025-48314 Patchstack
5.9 Medium Tripadvisor Shortcode Plugin tripadvisor-shortcode Cross-Site Scripting ≤ 2.2 CVE-2025-48313 Patchstack
6.5 Medium WPAvatar Plugin wpavatar Cross-Site Scripting ≤ 1.9.4 CVE-2025-48312 Patchstack
4.3 Medium Table Editor Plugin wp-table-editor Cross-Site Request Forgery No login needed ≤ 1.6.4 CVE-2025-48310 Patchstack
5.9 Medium Goal Tracker for Patreon Plugin goal-tracker-for-patreon Cross-Site Scripting ≤ 0.4.6 CVE-2025-48305 Patchstack
6.5 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-48110 Patchstack
6.5 Medium Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection Plugin stopbadbots Broken Access Control Insufficient Authorization to Unauthenticated Blocklist Bypass No login needed ≤ 11.58 CVE-2025-9376 Wordfence
6.4 Medium Dynamic AJAX Product Filters for WooCommerce Plugin dynamic-ajax-product-filters-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter ≤ 1.3.7 CVE-2025-6255 Wordfence
6.4 Medium Dynamic AJAX Product Filters for WooCommerce Plugin dynamic-ajax-product-filters-for-woocommerce Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter ≤ 1.3.7 CVE-2025-8073 Wordfence
5.3 Medium Ajax Search Lite Plugin ajax-search-lite Broken Access Control Missing Authorization to Unauthenticated Basic Information Exposure via ASL_Query in AJAX Search Handler No login needed ≤ 4.13.1 CVE-2025-7956 Wordfence
6.5 Medium Simple Download Monitor Plugin simple-download-monitor SQL Injection Simple Download Monitor <= 3.9.33 – Authenticated (Contributor+) SQL Injection via order parameter in Log Export functionality ≤ 3.9.33 CVE-2025-8977 Wordfence
4.9 Medium File Manager, Code Editor, and Backup by Managefy Plugin softdiscover-db-file-manager Path Traversal Authenticated (Admin+) Path Traversal to Arbitrary File Download ≤ 1.4.8 CVE-2025-9345 Wordfence
6.4 Medium Booking Calendar Plugin booking Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 10.14.1 Fixed in 10.14.3 CVE-2025-9346 Wordfence
6.4 Medium Unlimited Elements For Elementor Plugin unlimited-elements-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.5.148 Fixed in 2.0.21 CVE-2025-8603 Wordfence
6.1 Medium WP ULike Pro Plugin Arbitrary File Upload Unauthenticated Limited Arbitrary File Upload No login needed ≤ 1.9.3 CVE-2024-9648 Wordfence
4.3 Medium LiquidThemes Themes <= Various Versions Theme Broken Access Control Missing Authorization to Authenticated (Subscriber+) All Plugins Deactivated Not stated CVE-2025-0951 Wordfence
6.4 Medium UsersWP Plugin userswp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.42 CVE-2025-9344 Wordfence
6.1 Medium Beaver Builder Plugin (Lite Version) Plugin beaver-builder-lite-version Cross-Site Scripting Reflected Cross-Site Scripting No login needed ≤ 2.9.2.1 Fixed in 2.9.3.1 CVE-2025-8897 Wordfence
5.4 Medium Pronamic Google Maps Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.4.1 CVE-2025-9352 Wordfence
5.9 Medium WP Thumbtack Review Slider Plugin wp-thumbtack-review-slider Cross-Site Scripting ≤ 2.6 Fixed in 2.7 CVE-2025-58216 Patchstack
6.5 Medium Booking System Trafft Plugin booking-system-trafft Cross-Site Scripting ≤ 1.0.14 Fixed in 1.0.15 CVE-2025-58213 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only