WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,501–7,550 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 151 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Contact Form 7 Editor Button Plugin cf7-editor-button Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-48345 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-49319 Patchstack
7.6 High Funnel Builder by FunnelKit Plugin funnel-builder SQL Injection ≤ 3.10.2 Fixed in 3.11.0 CVE-2025-49034 Patchstack
6.5 Medium Internal Linking of Related Contents Plugin internal-linking-of-related-contents Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-49884 Patchstack
8.5 High ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities SQL Injection ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49876 Patchstack
6.5 Medium Ultimate Push Notifications Plugin ultimate-push-notifications Broken Access Control No login needed ≤ 1.2.0 CVE-2025-50028 Patchstack
7.1 High PW WooCommerce On Sale! Plugin pw-woocommerce-on-sale Broken Access Control ≤ 1.39 Fixed in 1.40 CVE-2025-49888 Patchstack
7.1 High Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Scripting No login needed ≤ 1.0.4 CVE-2025-52777 Patchstack
9.3 Critical Traveler Plugin traveler SQL Injection No login needed ≤ 3.2.2 Fixed in 3.2.2 CVE-2025-52714 Patchstack
7.1 High Media Folder Plugin media-folder Cross-Site Scripting No login needed ≤ 1.0.0 CVE-2025-52786 Patchstack
7.1 High Dot html,php,xml etc pages Plugin dot-htmlphpxml-etc-pages Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-52779 Patchstack
7.5 High Sala Theme sala Broken Access Control No login needed ≤ 1.1.3 CVE-2025-52803 Patchstack
7.1 High Tennis Court Bookings Plugin tennis-court-bookings Cross-Site Scripting No login needed ≤ 1.2.7 CVE-2025-52787 Patchstack
8.5 High Pakke Envíos Plugin pakke SQL Injection ≤ 1.0.2 CVE-2025-52819 Patchstack
7.5 High Nuss Plugin nuss Broken Access Control No login needed ≤ 1.3.7.1 CVE-2025-52804 Patchstack
9.8 Critical The E-Commerce ERP Plugin profitori Privilege Escalation No login needed ≤ 2.1.1.3 CVE-2025-52836 Patchstack
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
5.3 Medium Residential Address Detection Plugin residential-address-detection Broken Access Control No login needed ≤ 2.5.9 Fixed in 2.5.10 CVE-2025-48155 Patchstack
7.1 High Import CDN-Remote Images Plugin import-cdn-remote-images Cross-Site Request Forgery No login needed ≤ 2.1.2 Fixed in 2.1.3 CVE-2025-48153 Patchstack
7.6 High YaySMTP Plugin smtp-sendinblue SQL Injection ≤ 1.3 Fixed in 1.3.1 CVE-2025-48161 Patchstack
6.5 Medium Image Wall Plugin image-wall Cross-Site Scripting ≤ 3.1 Fixed in 3.2 CVE-2025-48156 Patchstack
5.4 Medium Chatbox Manager Plugin wa-chatbox-manager Broken Access Control ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-48167 Patchstack
5.3 Medium Stop and Block bots plugin Anti bots Plugin antibots Broken Access Control No login needed ≤ 1.48 Fixed in 1.50 CVE-2025-48166 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-48295 Patchstack
4.4 Medium FG Drupal to Plugin fg-drupal-to-wp Server-Side Request Forgery ≤ 3.90.0 Fixed in 3.90.1 CVE-2025-48294 Patchstack
7.6 High SMTP for SendGrid – YaySMTP Plugin smtp-sendgrid SQL Injection YaySMTP plugin <= 1.5 - SQL Injection ≤ 1.5 Fixed in 1.5.1 CVE-2025-48301 Patchstack
7.6 High YayExtra Plugin yayextra SQL Injection ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48299 Patchstack
6.5 Medium LightBox Block Plugin lightbox-block Cross-Site Scripting ≤ 1.1.30 Fixed in 1.1.31 CVE-2025-54051 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54050 Patchstack
4.3 Medium Cost Calculator Plugin ql-cost-calculator Broken Access Control ≤ 7.4 Fixed in 7.5 CVE-2025-54047 Patchstack
7.6 High SMTP for Amazon SES Plugin smtp-amazon-ses SQL Injection ≤ 1.9 Fixed in 1.9.1 CVE-2025-54043 Patchstack
4.3 Medium WP Post Hide Plugin wp-post-hide Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-54042 Patchstack
4.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-54041 Patchstack
4.3 Medium Animator Plugin scroll-triggered-animations Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2025-54039 Patchstack
5.4 Medium Restaurant Menu by MotoPress Plugin mp-restaurant-menu Cross-Site Request Forgery No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-54038 Patchstack
5.4 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-54037 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Cross-Site Request Forgery No login needed ≤ 5.1.20 Fixed in 5.1.21 CVE-2025-54036 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-54035 Patchstack
6.5 Medium Theme Builder For Elementor Plugin theme-builder-for-elementor Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-54033 Patchstack
4.3 Medium WooCommerce Google Sheet Connector Plugin wc-gsheetconnector Cross-Site Request Forgery No login needed ≤ 1.3.20 Fixed in 1.4.0 CVE-2025-54030 Patchstack
8.5 High GymBase Theme Classes Plugin gymbase_classes SQL Injection ≤ 1.4 Fixed in 1.5 CVE-2025-54026 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-54024 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54023 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Cross-Site Request Forgery No login needed ≤ 6.4.0 Fixed in 6.4.1 CVE-2025-54022 Patchstack
5.4 Medium AntiSpam for Contact Form 7 Plugin cf7-antispam Cross-Site Request Forgery No login needed ≤ 0.6.3 Fixed in 0.6.4 CVE-2025-54020 Patchstack
4.3 Medium CM Pop-Up banners Plugin cm-pop-up-banners Broken Access Control ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54018 Patchstack
6.5 Medium Videopack Plugin video-embed-thumbnail-generator Cross-Site Scripting ≤ 4.10.3 Fixed in 4.10.4 CVE-2025-54016 Patchstack
6.6 Medium HT Contact Form 7 Plugin ht-contactform Local File Inclusion ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-54015 Patchstack
5.9 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting ≤ 2.11.16 Fixed in 2.11.17 CVE-2025-54013 Patchstack
4.3 Medium SMTP2GO Plugin smtp2go Broken Access Control ≤ 1.12.1 Fixed in 1.12.2 CVE-2025-54011 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only