WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,551–7,600 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 152 of 358
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Spacious Theme spacious Broken Access Control Missing Authorization to Autheticated (Subscriber+) Demo Data Import ≤ 1.9.11 CVE-2025-9331 Wordfence
5.9 Medium WP Crontrol Plugin wp-crontrol Server-Side Request Forgery Authenticated (Administrator+) Blind Server-Side Request Forgery 1.17.0 – 1.19.1 CVE-2025-8678 Wordfence
6.4 Medium Bible SuperSearch Plugin biblesupersearch Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via selector_height Parameter ≤ 6.0.1 CVE-2025-8064 Wordfence
6.4 Medium SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) Plugin slingblocks Cross-Site Scripting Gutenberg Blocks by FunnelKit (Formerly WooFunnels) <= 1.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.6.0 CVE-2025-8607 Wordfence
4.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Broken Access Control Donation Plugin and Fundraising Platform <= 4.5.0 - Missing Authorization to Donation Update ≤ 4.5.0 Fixed in 4.6.1 CVE-2025-7221 Wordfence
5.3 Medium ProveSource Social Proof Plugin provesource Information Disclosure Sensitive Data Exposure No login needed ≤ 3.1.2 Fixed in 4.0.0 CVE-2025-48355 Patchstack
5.4 Medium Easy Digital Downloads Plugin easy-digital-downloads Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Deactivation via edd_sendwp_disconnect and edd_sendwp_remote_install Functions No login needed ≤ 3.5.0 Fixed in 3.5.1 CVE-2025-8102 Wordfence
6.5 Medium Notice Bar Plugin notice-bar Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-49389 Patchstack
4.3 Medium Sign-up Sheets Plugin sign-up-sheets Cross-Site Request Forgery No login needed ≤ 2.3.3 Fixed in 2.3.3.1 CVE-2025-49391 Patchstack
6.5 Medium Themify Icons Plugin themify-icons Cross-Site Scripting ≤ 2.0.3 Fixed in 2.0.4 CVE-2025-49395 Patchstack
5.9 Medium Themify Audio Dock Plugin themify-audio-dock Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-49392 Patchstack
6.5 Medium Colorbox Lightbox Plugin wp-colorbox Cross-Site Scripting ≤ 1.1.5 Fixed in 1.1.6 CVE-2025-49397 Patchstack
4.3 Medium Themify Builder Plugin themify-builder Broken Access Control ≤ 7.6.7 Fixed in 7.6.8 CVE-2025-49396 Patchstack
6.5 Medium Infility Global Plugin infility-global Path Traversal Arbitrary File Download ≤ 2.15.06 CVE-2025-47650 Patchstack
5.9 Medium Page Transition Plugin page-transition Cross-Site Scripting ≤ 1.3 CVE-2025-49412 Patchstack
5.3 Medium WP Discord Post Plus – Supports Unlimited Channels Plugin wp-discord-post-plus Cross-Site Request Forgery Supports Unlimited Channels plugin <= 1.0.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.0.2 CVE-2025-49896 Patchstack
6.5 Medium JetEngine Plugin jet-engine Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1.1 CVE-2025-53195 Patchstack
6.5 Medium JetEngine Plugin jet-engine Information Disclosure Sensitive Data Exposure ≤ 3.7.0 Fixed in 3.7.1.1 CVE-2025-53196 Patchstack
6.5 Medium Prevent files / folders access Plugin prevent-file-access Path Traversal ≤ 2.6.0 Fixed in 2.6.1 CVE-2025-53561 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Information Disclosure Sensitive Data Exposure ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53983 Patchstack
6.5 Medium JetMenu Plugin jet-menu Information Disclosure Sensitive Data Exposure ≤ 2.4.11.1 Fixed in 2.4.11.2 CVE-2025-53987 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Information Disclosure Sensitive Data Exposure ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53985 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Information Disclosure Sensitive Data Exposure ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53992 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Information Disclosure Sensitive Data Exposure ≤ 1.3.18 Fixed in 1.3.19 CVE-2025-53988 Patchstack
6.5 Medium JetPopup Plugin jet-popup Information Disclosure Sensitive Data Exposure ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53993 Patchstack
6.5 Medium JetWooBuilder Plugin jet-woo-builder Information Disclosure Sensitive Data Exposure ≤ 2.1.20 Fixed in 2.1.20.1 CVE-2025-53998 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Information Disclosure Sensitive Data Exposure ≤ 3.6.7 Fixed in 3.6.7.1 CVE-2025-54008 Patchstack
6.5 Medium Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.5 Fixed in 7.8.5 CVE-2025-54019 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Broken Access Control Settings Change No login needed ≤ 6.4.0 Fixed in 6.4.2 CVE-2025-54025 Patchstack
6.5 Medium Webba Booking Plugin webba-booking-lite Broken Access Control No login needed ≤ 5.1.20 Fixed in 5.1.22 CVE-2025-54040 Patchstack
6.5 Medium Cost Calculator Plugin ql-cost-calculator Cross-Site Scripting ≤ 7.4 Fixed in 7 .5 CVE-2025-54046 Patchstack
6.6 Medium Groundhogg Plugin groundhogg PHP Object Injection ≤ 4.2.2 Fixed in 4.2.2.1 CVE-2025-54053 Patchstack
4.3 Medium ColorMag Theme colormag Broken Access Control Missing Authorization to Authenticated (Subscriber+) ThemeGrill Demo Importer Plugin Installation ≤ 4.0.19 Fixed in 4.0.20 CVE-2025-9202 Wordfence
6.4 Medium WPC Smart Quick View for WooCommerce Plugin woo-smart-quick-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via woosq_btn Shortcode ≤ 4.2.1 CVE-2025-8618 Wordfence
4.4 Medium Contact Manager Plugin contact-manager Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via 'title' ≤ 8.6.5 CVE-2025-8783 Wordfence
6.4 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets ≤ 4.5.4 CVE-2025-8567 Wordfence
6.4 Medium Flexible Maps Plugin wp-flexible-map Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Flexible Maps Shortcode ≤ 1.18.0 CVE-2025-8622 Wordfence
4.3 Medium Media Library Assistant Plugin media-library-assistant Arbitrary File Deletion Authenticated (Author+) Limited File Deletion ≤ 3.27 Fixed in 3.28 CVE-2025-8357 Wordfence
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 6.4.7 CVE-2025-7496 Wordfence
6.5 Medium Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress Plugin wp-user-avatar Arbitrary Shortcode Execution ProfilePress <= 4.16.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 4.16.4 CVE-2025-8878 Wordfence
6.4 Medium Soledad Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h' ≤ 8.6.7 CVE-2025-8143 Wordfence
6.4 Medium Translate This - Google Translate Web Element Shortcode Plugin translate-this-google-translate-web-element-shortcode Cross-Site Scripting Google Translate Web Element Shortcode <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via base_lang Parameter ≤ 1.0 CVE-2025-8719 Wordfence
5.3 Medium BetterDocs Plugin betterdocs Broken Access Control Missing Authorization to Private And Password-Protected Posts Information Disclosure No login needed ≤ 4.1.1 CVE-2025-7499 Wordfence
5.3 Medium Drag and Drop Multiple File Upload for Contact Form 7 Plugin drag-and-drop-multiple-file-upload-contact-form-7 Path Traversal Directory Traversal via `wpcf7_guest_user_id` Cookie No login needed ≤ 1.3.9.0 Fixed in 1.3.9.1 CVE-2025-8464 Wordfence
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.14.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 3.14.3 CVE-2025-8896 Wordfence
5.4 Medium Advanced iFrame Plugin advanced-iframe Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2025.6 Fixed in 2025.10 CVE-2025-8089 Wordfence
6.1 Medium Ebook Store Plugin ebook-store Cross-Site Scripting Reflected XSS via $_SERVER['REQUEST_URI'] No login needed < 5.8015 Fixed in 5.8015 CVE-2025-8113 WPScan
6.4 Medium Intl DateTime Calendar Plugin intl-datetime-calendar Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via date Parameter ≤ 1.0.1 CVE-2025-8293 Wordfence
6.1 Medium weichuncai(WP伪春菜) Plugin weichuncai Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.5 CVE-2025-7686 Wordfence
6.4 Medium Anber Elementor Addon Plugin anber-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Banner button link ≤ 1.0.1 CVE-2025-7439 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only