WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,501–7,550 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 151 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Epeken All Kurir Plugin epeken-all-kurir Cross-Site Scripting ≤ 2.0.1 Fixed in 2.0.2 CVE-2025-58212 Patchstack
6.5 Medium Chatbox Manager Plugin wa-chatbox-manager Cross-Site Scripting ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-58211 Patchstack
6.5 Medium Transcoder Plugin transcoder Cross-Site Scripting ≤ 1.4.0 Fixed in 1.4.1 CVE-2025-58209 Patchstack
6.5 Medium PDF for Elementor Forms + Drag And Drop Template Builder Plugin pdf-for-elementor-forms Cross-Site Scripting ≤ 6.2.0 Fixed in 6.3.0 CVE-2025-58208 Patchstack
6.5 Medium ElementInvader Addons for Elementor Plugin elementinvader-addons-for-elementor Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58205 Patchstack
4.7 Medium Podlove Podcast Publisher Plugin podlove-podcasting-plugin-for-wordpress Open Redirect No login needed ≤ 4.2.5 Fixed in 4.2.6 CVE-2025-58204 Patchstack
4.4 Medium Solace Extra Plugin solace-extra Server-Side Request Forgery ≤ 1.3.2 Fixed in 1.3.3 CVE-2025-58203 Patchstack
4.3 Medium Simple Page Access Restriction Plugin simple-page-access-restriction Cross-Site Request Forgery No login needed ≤ 1.0.32 Fixed in 1.0.33 CVE-2025-58202 Patchstack
5.3 Medium AfterShip Tracking Plugin aftership-woocommerce-tracking Broken Access Control No login needed ≤ 1.17.17 Fixed in 1.17.18 CVE-2025-58201 Patchstack
6.5 Medium Xpro Theme Builder Plugin xpro-theme-builder Broken Access Control ≤ 1.2.9 Fixed in 1.2.10 CVE-2025-58198 Patchstack
6.5 Medium Simple Download Monitor Plugin simple-download-monitor Cross-Site Scripting ≤ 3.9.34 Fixed in 3.9.35 CVE-2025-58197 Patchstack
6.5 Medium UiCore Elements Plugin uicore-elements Cross-Site Scripting ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-58196 Patchstack
6.5 Medium Xpro Elementor Addons Plugin xpro-elementor-addons Cross-Site Scripting ≤ 1.4.17 Fixed in 1.4.18 CVE-2025-58195 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.3 Fixed in 5.4.4 CVE-2025-58194 Patchstack
4.3 Medium Uncanny Automator Plugin uncanny-automator Broken Access Control ≤ 6.7.0.1 Fixed in 6.8.0 CVE-2025-58193 Patchstack
4.3 Medium WP Bulk Delete Plugin wp-bulk-delete Broken Access Control ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-58192 Patchstack
5.3 Medium Printeers Print & Ship Plugin invition-print-ship Path Traversal Directory Traversal No login needed ≤ 1.17.0 CVE-2025-48081 Patchstack
5.9 Medium Admin Menu Groups Plugin admin-menu-groups Cross-Site Scripting ≤ 0.1.2 CVE-2025-49035 Patchstack
5.9 Medium Link View Plugin link-view Cross-Site Scripting ≤ 0.8.0 CVE-2025-49039 Patchstack
4.3 Medium Backup Bolt Plugin backup-bolt Cross-Site Request Forgery No login needed ≤ 1.5.0 CVE-2025-49040 Patchstack
6.4 Medium Lazy Load for Videos Plugin lazy-load-for-videos Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via data-video-title and href Attributes ≤ 2.18.7 CVE-2025-7732 Wordfence
4.4 Medium All-in-One WP Migration and Backup Plugin all-in-one-wp-migration Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Import ≤ 7.97 CVE-2025-8490 Wordfence
6.4 Medium SiteSEO – SEO Simplified Plugin siteseo Cross-Site Scripting SEO Simplified <= 1.2.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Broken Regex Expression ≤ 1.2.7 CVE-2025-9277 Wordfence
6.5 Medium School Management Plugin school-management Broken Access Control ≤ 93.2.0 CVE-2025-48108 Patchstack
4.7 Medium Automatic Plugin - AI content generator and auto poster Plugin Cross-Site Request Forgery AI content generator and auto poster plugin <= 3.118.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 3.118.0 CVE-2025-6247 Wordfence
4.3 Medium Tourfic Plugin tourfic Broken Access Control Missing Authorization in Multiple Functions ≤ 2.14.5 CVE-2024-8860 Wordfence
4.3 Medium Post Type Converter Plugin post-type-converter Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-48303 Patchstack
6.5 Medium Custom Query Shortcode Plugin custom-query-shortcode Path Traversal Authenticated (Contributor+) Path Traversal via lens Parameter ≤ 0.4.0 CVE-2025-8562 Wordfence
6.4 Medium Spexo Addons for Elementor Plugin sastra-essential-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown Widget ≤ 1.0.23 CVE-2025-8208 Wordfence
6.4 Medium ShortcodeHub Plugin shortcodehub Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via author_link_target Parameter ≤ 1.7.1 CVE-2025-7957 Wordfence
4.3 Medium Sertifier Certificate & Badge Maker for WordPress – Tutor LMS Plugin sertifier-certificates-open-badges Cross-Site Request Forgery Tutor LMS <= 1.19 - Cross-Site Request Forgery to Settings Update No login needed ≤ 1.19 Fixed in 1.20 CVE-2025-7841 Wordfence
4.3 Medium WP Filter & Combine RSS Feeds Plugin wp-filter-combine-rss-feeds Broken Access Control Missing Authorization to Authenticated (Contributor+) Feed Deletion ≤ 0.4 CVE-2025-7828 Wordfence
5.3 Medium WC Plus Plugin wc-plus Broken Access Control Missing Authorization to Unauthenticated Settings Manipulation No login needed ≤ 1.2.0 CVE-2025-7821 Wordfence
6.4 Medium WS Theme Addons Plugin ws-theme-addons Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via ws_weather Shortcode ≤ 2.0.0 CVE-2025-8062 Wordfence
4.3 Medium Silencesoft RSS Reader Plugin external-rss-reader Cross-Site Request Forgery Cross-Site Request Forgery to RSS Feed Deletion No login needed ≤ 0.6 CVE-2025-7842 Wordfence
4.3 Medium Restore Permanently delete Post or Page Data Plugin restore-permanently-delete-post-or-page-data Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-7839 Wordfence
4.3 Medium Ni WooCommerce Customer Product Report Plugin ni-woocommerce-customer-product-report Broken Access Control Missing Authorization to Authenticated (Subscriber+) Settings Update ≤ 1.2.4 CVE-2025-7827 Wordfence
6.4 Medium Ogulo – 360° Tour Plugin ogulo-360-tour Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slug Parameter ≤ 1.0.11 CVE-2025-9131 Wordfence
5.3 Medium Church Admin Plugin church-admin Broken Access Control No login needed ≤ 5.0.26 Fixed in 5.0.27 CVE-2025-57896 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-57895 Patchstack
4.3 Medium WPPizza Plugin wppizza Broken Access Control ≤ 3.19.8 Fixed in 3.19.8.1 CVE-2025-57894 Patchstack
4.3 Medium WP Fast Total Search Plugin fulltext-search Cross-Site Request Forgery No login needed ≤ 1.79.270 Fixed in 1.79.274 CVE-2025-57893 Patchstack
4.3 Medium Simple Statistics for Feeds Plugin simple-feed-stats Cross-Site Request Forgery No login needed ≤ 20250322 Fixed in 20250820 CVE-2025-57892 Patchstack
5.9 Medium Recurring PayPal Donations Plugin recurring-donation Cross-Site Scripting ≤ 1.8 Fixed in 1.9 CVE-2025-57891 Patchstack
5.9 Medium Sessions Plugin sessions Cross-Site Scripting ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-57890 Patchstack
5.3 Medium Jobmonster Theme noo-jobmonster Information Disclosure Sensitive Data Exposure No login needed ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57888 Patchstack
6.5 Medium Jobmonster Theme noo-jobmonster Cross-Site Scripting ≤ 4.8.0 Fixed in 4.8.1 CVE-2025-57887 Patchstack
5.4 Medium Accessibility Checker by Equalize Digital Plugin accessibility-checker Broken Access Control Insecure Direct Object References (IDOR) ≤ 1.30.0 Fixed in 1.30.1 CVE-2025-57886 Patchstack
4.3 Medium Fluent Support Plugin fluent-support Cross-Site Request Forgery No login needed ≤ 1.9.1 Fixed in 1.9.2 CVE-2025-57885 Patchstack
4.3 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Broken Access Control ≤ 12.1.1 Fixed in 12.1.2 CVE-2025-57884 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only