WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,601–7,650 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 153 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.6 Medium Woocommerce Blocks – Woolook Plugin woolook Local File Inclusion Woolook <= 1.7.0 - Authenticated (Admin+) Local File Inclusion ≤ 1.7.0 CVE-2024-8393 Wordfence
6.1 Medium LatestCheckins Plugin latestcheckins Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1 CVE-2025-7683 Wordfence
6.1 Medium Linux Promotional Plugin linux-promotional-plugin Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.4 CVE-2025-7668 Wordfence
6.4 Medium Surbma | Recent Comments Shortcode Plugin surbma-recent-comments-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-7649 Wordfence
6.4 Medium Anber Elementor Addon Plugin anber-elementor-addon Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Carousel button link ≤ 1.0.1 CVE-2025-7440 Wordfence
6.1 Medium Last.fm Recent Album Artwork Plugin lastfm-recent-album-artwork Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.2 CVE-2025-7684 Wordfence
6.4 Medium Earnware Connect Plugin earnware-connect Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.74 Fixed in 1.0.75 CVE-2025-7651 Wordfence
6.4 Medium Embed Bokun Plugin embed-bokun Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via align Parameter ≤ 0.23 CVE-2025-6221 Wordfence
6.5 Medium ServerBuddy by PluginBuddy.com Plugin serverbuddy-by-pluginbuddy Cross-Site Request Forgery CSRF to PHP Object Injection ≤ 1.0.5 CVE-2025-49895 Patchstack
5.3 Medium Poll Maker – Versus Polls, Anonymous Polls, Image Polls Plugin poll-maker Information Disclosure Versus Polls, Anonymous Polls, Image Polls <= 5.8.9 - Unauthenticated Basic Information Exposure No login needed ≤ 5.8.9 Fixed in 5.9.0 CVE-2024-12575 Wordfence
5.3 Medium Ultimate Video Player Plugin fwduvp Broken Access Control No login needed ≤ 10.1 CVE-2025-49432 Patchstack
6.4 Medium Radius Blocks Plugin radius-blocks Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via subHeadingTagName Parameter ≤ 2.2.1 CVE-2025-5844 Wordfence
6.3 Medium Inpersttion For Plugin err-our-team Remote Code Execution Authenticated (Contributor+) Arbitrary Function Call ≤ 1.0 CVE-2025-8905 Wordfence
6.5 Medium Gestion de tarifs Plugin gestion-tarifs SQL Injection Authenticated (Contributor+) SQL Injection ≤ 1.4 CVE-2025-7662 Wordfence
6.4 Medium Plugin README Parser Plugin wp-readme-parser Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via target Parameter ≤ 1.3.15 CVE-2025-8720 Wordfence
6.4 Medium elink – Embed Content Plugin elink-embed-content Other Embed Content <= 1.1.0 - Authenticated (Contributor+) Insufficient Input Validation ≤ 1.1.0 CVE-2025-7507 Wordfence
4.3 Medium EventON Lite Plugin eventon-lite Information Disclosure Authenticated (Contributor+) Information Disclosure ≤ 2.4.7 CVE-2025-8091 Wordfence
4.4 Medium Alobaidi Captcha Plugin alobaidi-captcha Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Settings ≤ 1.0.3 CVE-2025-8080 Wordfence
6.1 Medium Add User Meta Plugin add-user-meta Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0.1 CVE-2025-7688 Wordfence
6.4 Medium WP Table Builder – WordPress Table Plugin wp-table-builder Cross-Site Scripting WordPress Table Plugin <= 2.0.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.0.12 Fixed in 2.0.13 CVE-2025-8604 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin essential-addons-for-elementor-lite Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.2.2 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via 'data-gallery-items' ≤ 6.2.2 CVE-2025-8451 Wordfence
6.4 Medium Graphina - Elementor Charts and Graphs Plugin graphina-elementor-charts-and-graphs Cross-Site Scripting Elementor Charts and Graphs <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 3.1.3 Fixed in 3.1.4 CVE-2025-8867 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Server-Side Request Forgery Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Server-Side Request Forgery ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-8680 Wordfence
4.3 Medium B Slider - Gutenberg Slider Block for WP Plugin b-slider Information Disclosure Gutenberg Slider Block for WP <= 2.0.0 - Authenticated (Subscriber+) Sensitive Information Exposure ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-8676 Wordfence
4.3 Medium flexo-social-gallery Plugin flexo-social-gallery Cross-Site Request Forgery No login needed ≤ 1.0006 CVE-2025-52769 Patchstack
4.3 Medium NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-52767 Patchstack
6.5 Medium Video Expander Plugin video-expander Cross-Site Scripting ≤ 1.0 CVE-2025-52771 Patchstack
5.4 Medium WP-Database-Optimizer-Tools Plugin wp-database-optimizer-tools Cross-Site Request Forgery No login needed ≤ 0.2 CVE-2025-53219 Patchstack
4.3 Medium CodeablePress Plugin codeablepress-simple-frontend-profile-picture-upload Broken Access Control ≤ 1.0.2 CVE-2025-53221 Patchstack
6.5 Medium Build App Online Plugin build-app-online Cross-Site Request Forgery No login needed ≤ 1.0.23 CVE-2025-53249 Patchstack
5.5 Medium Simplified Plugin simplified Server-Side Request Forgery ≤ 1.0.11 Fixed in 1.0.12 CVE-2025-53241 Patchstack
6.5 Medium WP Rentals Plugin wprentals Cross-Site Scripting ≤ 3.16.1 Fixed in 3.16.2 CVE-2025-53330 Patchstack
4.3 Medium App, SaaS & Software Startup Tech Theme - Stratus Theme stratusx Broken Access Control < 4.2.11 Fixed in 4.2.11 CVE-2025-53341 Patchstack
6.5 Medium Modernize Plugin modernize Cross-Site Scripting ≤ 3.4.0 CVE-2025-53342 Patchstack
4.3 Medium Modernize Plugin modernize Broken Access Control ≤ 3.4.0 CVE-2025-53343 Patchstack
4.3 Medium Kalium Theme kalium Cross-Site Request Forgery No login needed ≤ 3.18.3 Fixed in 3.19 CVE-2025-53347 Patchstack
5.9 Medium RSS Feed Pro Plugin rss-feed-pro Cross-Site Scripting ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-53581 Patchstack
6.5 Medium WordLift Plugin wordlift Cross-Site Scripting ≤ 3.54.5 Fixed in 3.54.6 CVE-2025-53582 Patchstack
6.5 Medium 12 Step Meeting List Plugin 12-step-meeting-list Cross-Site Scripting ≤ 3.18.3 Fixed in 3.18.4 CVE-2025-54054 Patchstack
6.5 Medium B Blocks Plugin b-blocks Cross-Site Scripting ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-54708 Patchstack
4.9 Medium Barcode Scanner with Inventory & Order Manager Plugin barcode-scanner-lite-pos-to-manage-products-inventory-and-orders Path Traversal Arbitrary File Download ≤ 1.9.0 Fixed in 1.9.1 CVE-2025-54715 Patchstack
4.3 Medium Easy Elementor Addons Plugin easy-elementor-addons Broken Access Control ≤ 2.2.7 Fixed in 2.2.8 CVE-2025-54712 Patchstack
5.9 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Cross-Site Scripting ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54727 Patchstack
5.4 Medium WP Membership Plugin wp-membership Broken Access Control Settings Change ≤ 1.6.3 Fixed in 1.6.4 CVE-2025-54717 Patchstack
4.3 Medium CM On Demand Search And Replace Plugin cm-on-demand-search-and-replace Cross-Site Request Forgery No login needed ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-54728 Patchstack
5.9 Medium Webba Booking Plugin webba-booking-lite Cross-Site Scripting ≤ 6.0.5 Fixed in 6.0.6 CVE-2025-54729 Patchstack
5.3 Medium Embedder for Google Reviews Plugin embedder-for-google-reviews Broken Access Control No login needed ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54730 Patchstack
4.3 Medium WPDM – Premium Packages Plugin wpdm-premium-packages Cross-Site Request Forgery Premium Packages Plugin <= 6.0.2 - Cross Site Request Forgery (CSRF) No login needed ≤ 6.0.2 Fixed in 6.0.3 CVE-2025-54732 Patchstack
5.3 Medium Nexter Blocks Plugin the-plus-addons-for-block-editor Broken Access Control No login needed ≤ 4.5.4 Fixed in 4.5.5 CVE-2025-54739 Patchstack
5.3 Medium Savoy Theme savoy Information Disclosure Sensitive Data Exposure No login needed ≤ 3.0.8 Fixed in 3.0.9 CVE-2025-54736 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only