WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,601–7,650 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 153 of 345
Severity Component Vulnerability Affected versions Published CVE Source
7.1 High Beautiful Cookie Consent Banner Plugin beautiful-and-responsive-cookie-consent Cross-Site Scripting No login needed ≤ 4.6.1 Fixed in 4.6.2 CVE-2025-49866 Patchstack
7.5 High Paid Member Subscriptions Plugin paid-member-subscriptions SQL Injection No login needed ≤ 2.15.1 Fixed in 2.15.2 CVE-2025-49870 Patchstack
6.5 Medium VG WORT METIS Plugin vgw-metis Broken Access Control ≤ 2.0.1 CVE-2025-50039 Patchstack
6.5 Medium Paytiko for WooCommerce Plugin paytiko Broken Access Control ≤ 1.3.21 CVE-2025-50032 Patchstack
7.1 High Video List Manager Plugin video-list-manager Cross-Site Scripting No login needed ≤ 1.7 CVE-2025-52776 Patchstack
7.2 High Alone Plugin alone Remote Code Execution Arbitrary Code Execution No login needed ≤ 7.8.2 Fixed in 7.8.5 CVE-2025-52718 Patchstack
7.1 High JobSearch Plugin wp-jobsearch Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 3.0.6 Fixed in 3.0.6 CVE-2025-52798 Patchstack
7.1 High WP-Recall Plugin wp-recall Cross-Site Scripting No login needed ≤ 16.26.14 CVE-2025-52796 Patchstack
8.1 High Kossy - Minimalist eCommerce Plugin kossy Local File Inclusion Minimalist eCommerce WordPress Theme <= 1.45 - Local File Inclusion No login needed ≤ 1.45 CVE-2025-52807 Patchstack
7.5 High Leyka Plugin leyka Local File Inclusion No login needed ≤ 3.32.1 CVE-2025-52805 Patchstack
8.8 High Red Art Plugin redart PHP Object Injection ≤ 3.8 Fixed in 3.9 CVE-2025-52828 Patchstack
8.1 High MobiLoud Plugin mobiloud-mobile-app-plugin Broken Access Control ≤ 4.6.5 CVE-2025-52813 Patchstack
9.3 Critical Video List Manager Plugin video-list-manager SQL Injection No login needed ≤ 1.7 CVE-2025-52831 Patchstack
9.3 Critical bSecure – Your Universal Checkout Plugin bsecure SQL Injection Your Universal Checkout plugin <= 1.7.9 - SQL Injection No login needed ≤ 1.7.9 CVE-2025-52830 Patchstack
9.3 Critical LMS Plugin lms SQL Injection No login needed ≤ 9.2 Fixed in 9.3 CVE-2025-52833 Patchstack
9.3 Critical NGG Smart Image Search Plugin ngg-smart-image-search SQL Injection No login needed ≤ 3.4.1 Fixed in 3.4.3 CVE-2025-52832 Patchstack
7.5 High Elessi Plugin elessi-theme Local File Inclusion ≤ 6.4.1 Fixed in 6.4.1 CVE-2025-49070 Patchstack
8.1 High CMSMasters Content Composer Plugin cmsmasters-content-composer Local File Inclusion No login needed ≤ 2.5.7 Fixed in 2.5.7 CVE-2025-4414 Patchstack
9.8 Critical WooCommerce Product Multi-Action Plugin woo-product-multiaction PHP Object Injection Deserialization of untrusted data No login needed ≤ 1.3 CVE-2025-49417 Patchstack
10.0 Critical FW Gallery Plugin fw-gallery Arbitrary File Upload No login needed ≤ 8.0.0 CVE-2025-49414 Patchstack
6.5 Medium MF Plus WPML Plugin mf-plus-wpml Broken Access Control Settings Change No login needed ≤ 1.1 CVE-2025-49431 Patchstack
7.2 High Allmart Plugin allmart-core Server-Side Request Forgery No login needed ≤ 1.0.0 CVE-2025-49418 Patchstack
6.5 Medium Card flip image slideshow Plugin card-flip-image-slideshow Cross-Site Scripting ≤ 1.5 CVE-2025-30983 Patchstack
8.5 High Pixelating image slideshow gallery Plugin pixelating-image-slideshow-gallery SQL Injection ≤ 8.0 CVE-2025-30979 Patchstack
8.5 High iFrame Images Gallery Plugin wp-iframe-images-gallery SQL Injection ≤ 9.0 CVE-2025-30969 Patchstack
8.5 High Cool fade popup Plugin cool-fade-popup SQL Injection ≤ 10.1 CVE-2025-30947 Patchstack
6.5 Medium Posts Slider Shortcode Plugin posts-slider-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-30943 Patchstack
5.3 Medium fluXtore Plugin fluxtore Broken Access Control No login needed ≤ 1.6.0 Fixed in 1.6.3 CVE-2025-30929 Patchstack
5.3 Medium CF7 7 Mailchimp Add-on Plugin cf7-mailchimp-addon Broken Access Control No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-29012 Patchstack
4.3 Medium LMSACE Connect Plugin lmsace-connect Broken Access Control ≤ 3.4 CVE-2025-29007 Patchstack
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack
5.9 Medium Easy Elements Hider Plugin easy-elements-hider Cross-Site Scripting ≤ 2.0 CVE-2025-28971 Patchstack
8.5 High Gallery Widget Plugin gallery-widget SQL Injection ≤ 1.2.1 CVE-2025-28969 Patchstack
8.5 High Contact Us page - Contact people LITE Plugin contact-us-page-contact-people SQL Injection Contact people LITE plugin <= 3.7.4 - SQL Injection ≤ 3.7.4 CVE-2025-28967 Patchstack
5.4 Medium URL Shortener Plugin exact-links Server-Side Request Forgery No login needed ≤ 3.0.7 CVE-2025-28963 Patchstack
6.5 Medium OwnerRez API Plugin ownerrez Cross-Site Scripting ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-28957 Patchstack
9.1 Critical Bulk Featured Image Plugin bulk-featured-image Arbitrary File Upload ≤ 1.2.4 CVE-2025-28951 Patchstack
4.6 Medium Frontend File Manager Plugin nmedia-user-file-uploader Content Injection ≤ 23.6 CVE-2025-27358 Patchstack
6.5 Medium Video Gallery Block Plugin video-gallery-block Cross-Site Scripting ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-27326 Patchstack
6.5 Medium WP fancybox Plugin wp-fancybox Cross-Site Scripting ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-26591 Patchstack
6.5 Medium (Simply) Guest Author Name Plugin guest-author-name Cross-Site Scripting ≤ 4.36 Fixed in 4.40 CVE-2025-24764 Patchstack
5.3 Medium uDesign Plugin udesign Broken Access Control No login needed ≤ 4.11.2 Fixed in 4.11.3 CVE-2025-24757 Patchstack
5.3 Medium Avada Theme avada Broken Access Control No login needed ≤ 7.11.10 Fixed in 7.11.11 CVE-2025-24748 Patchstack
7.7 High Chatra Live Chat + ChatBot + Cart Saver Plugin chatra-live-chat Cross-Site Scripting ≤ 1.0.11 CVE-2025-24735 Patchstack
4.3 Medium Contact Form 7 reCAPTCHA Plugin contact-form-7-recaptcha Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-23972 Patchstack
4.3 Medium Trust Payments Gateway for WooCommerce (JavaScript Library) Plugin trust-payments-gateway-3ds2 Cross-Site Request Forgery No login needed ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-53569 Patchstack
4.3 Medium Radio Station Plugin radio-station Cross-Site Request Forgery No login needed ≤ 2.5.12 Fixed in 2.5.13 CVE-2025-53568 Patchstack
6.5 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Cross-Site Scripting ≤ 7.8 Fixed in 7.9 CVE-2025-53566 Patchstack
6.4 Medium ProcessingJS Plugin processingjs-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.2.2 CVE-2025-6039 Wordfence
9.1 Critical AiBud WP Plugin aibuddy-openai-chatgpt Arbitrary File Upload ≤ 1.9 CVE-2025-23968 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only