WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,701–7,750 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 155 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WP LOL Rotation Plugin league-of-legends-rotation Cross-Site Scripting ≤ 1.0 CVE-2025-49437 Patchstack
6.5 Medium Supermalink Plugin supermalink Cross-Site Scripting ≤ 1.1 CVE-2025-49433 Patchstack
6.5 Medium AI Tools Plugin artificial-intelligence-auto-content-generator Broken Access Control Arbitrary Content Deletion ≤ 4.0.7 CVE-2025-50029 Patchstack
6.5 Medium CF7 Spreadsheets Plugin cf7-spreadsheets Cross-Site Scripting ≤ 2.3.2 CVE-2025-50040 Patchstack
6.5 Medium DB Backup Plugin db-backup Broken Access Control ≤ 6.0 CVE-2025-50031 Patchstack
4.2 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Path Traversal Visual Drag and Drop Editor <= 1.27.8 - Path Traversal ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52712 Patchstack
6.5 Medium Global Gallery Plugin global-gallery Broken Access Control No login needed ≤ 9.2.3 Fixed in 9.2.4 CVE-2025-52721 Patchstack
6.5 Medium Event Manager, Event Calendar and Booking Plugin eventin-pro Cross-Site Scripting ≤ 4.0.24 Fixed in 4.0.25 CVE-2025-52730 Patchstack
6.5 Medium PPWP Plugin password-protect-page Other Subscriber+ Access Bypass via REST API < 1.9.11 Fixed in 1.9.11 CVE-2025-5998 WPScan
6.1 Medium Injection Guard Plugin injection-guard Cross-Site Scripting Reflected XSS via $_SERVER['REQUEST_URI'] No login needed < 1.2.8 Fixed in 1.2.8 CVE-2025-8046 WPScan
6.1 Medium WP Shopify Plugin Cross-Site Scripting Reflected XSS No login needed < 1.5.4 Fixed in 1.5.4 CVE-2025-7808 WPScan
4.3 Medium QSM Plugin Cross-Site Request Forgery Template Creation via CSRF No login needed < 10.2.3 Fixed in 10.2.3 CVE-2025-6790 WPScan
5.4 Medium Structured Content Plugin Cross-Site Scripting Contributor Stored XSS < 1.7.0 Fixed in 1.7.0 CVE-2025-3414 WPScan
4.3 Medium Easy restaurant menu manager Plugin easy-pdf-restaurant-menu-upload Cross-Site Request Forgery Cross-Site Request Forgery to Menu Upload No login needed ≤ 2.0.2 Fixed in 2.0.3 CVE-2025-8491 Wordfence
6.5 Medium Multiple elFinder Plugins <= (Various Versions) Plugin file-manager-advanced Path Traversal Directory Traversal to Arbitrary File Deletion No login needed ≤ 1.8.9, ≤ 5.3.6, ≤ 8.4.2 CVE-2025-0818 Wordfence
4.3 Medium OceanWP Theme oceanwp Cross-Site Request Forgery Cross-Site Request Forgery to Ocean Extra Plugin Installation No login needed 4.0.9 – 4.1.1 Fixed in 4.1.2 CVE-2025-8891 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via fancyBox ≤ 2.0.9.0 Fixed in 2.0.9.1 CVE-2025-8874 Wordfence
4.3 Medium Simple Local Avatars Plugin simple-local-avatars Broken Access Control Missing Authorization to Authenticated (Subscriber+) Avatar Migration ≤ 2.8.4 Fixed in 2.8.5 CVE-2025-8482 Wordfence
4.8 Medium AnWP Football Leagues Plugin football-leagues-by-anwppro Content Injection Authenticated (Administrator+) CSV Injection ≤ 0.16.17 Fixed in 0.16.18 CVE-2025-8767 Wordfence
5.3 Medium FiboSearch Plugin ajax-search-for-woocommerce Broken Access Control No login needed ≤ 1.32.1 Fixed in 1.32.2 CVE-2025-47444 Patchstack
4.9 Medium Elementor Plugin elementor Path Traversal Authenticated (Administrator+) Arbitrary File Read via Image Import ≤ 3.30.2 Fixed in 3.30.3 CVE-2025-8081 Wordfence
6.4 Medium Software Issue Manager Plugin software-issue-manager Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter ≤ 5.0.0 CVE-2025-8314 Wordfence
6.4 Medium GMap - Venturit Plugin gmap-venturit Cross-Site Scripting Venturit <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'h' Parameter ≤ 1.1 CVE-2025-8568 Wordfence
6.4 Medium Simple Responsive Slider Plugin addi-simple-slider Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0 CVE-2025-8690 Wordfence
6.4 Medium Inline Stock Quotes Plugin inline-stock-quotes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via stock Shortcode ≤ 0.2 CVE-2025-8688 Wordfence
6.4 Medium Mosaic Generator Plugin mosaic-generator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via 'c' Parameter ≤ 1.0.5 CVE-2025-8621 Wordfence
6.4 Medium Wp chart generator Plugin wp-chart-generator Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via wpchart Shortcode ≤ 1.0.4 CVE-2025-8685 Wordfence
5.3 Medium WP Private Content Plus Plugin wp-private-content-plus Information Disclosure Unauthenticated Sensitive Information Exposure No login needed ≤ 3.6.2 CVE-2025-4390 Wordfence
6.4 Medium RT Easy Builder Plugin rt-easy-builder-advanced-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.3 CVE-2025-8462 Wordfence
4.3 Medium CBX Restaurant Booking Plugin Cross-Site Request Forgery Plugin Reset via CSRF No login needed ≤ 1.2.1 CVE-2025-7965 WPScan
6.4 Medium The7 Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title and data-dt-img-description Attributes ≤ 12.6.0 CVE-2025-7726 Wordfence
5.9 Medium OpenStreetMap for Gutenberg and WPBakery Page Builder Plugin Cross-Site Scripting Contributor+ Stored XSS ≤ 1.2.0 CVE-2025-6572 WPScan
5.3 Medium GiveWP – Donation Plugin and Fundraising Platform Plugin give Information Disclosure Donation Plugin and Fundraising Platform <= 4.6.0 - Unauthenticated Donor Data Exposure No login needed ≤ 4.6.0 CVE-2025-8620 Wordfence
6.4 Medium Gutenverse Plugin gutenverse Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Animated Text and Fun Fact Blocks ≤ 3.1.0 CVE-2025-7727 Wordfence
6.4 Medium Exclusive Addons for Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Countdown ≤ 2.7.9.4 Fixed in 2.7.9.5 CVE-2025-7498 Wordfence
6.4 Medium Betheme Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 28.1.3 CVE-2025-7399 Wordfence
5.4 Medium Element Pack Elementor Addons and Templates Plugin bdthemes-element-pack-lite Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Open Street Map Widget Marker Content ≤ 8.1.5 Fixed in 8.1.6 CVE-2025-8100 Wordfence
4.3 Medium Zakra Theme zakra Broken Access Control Missing Authorization to Subscriber+ Demo Import ≤ 4.1.5 CVE-2025-8595 Wordfence
6.4 Medium WPBakery Page Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.5 CVE-2025-7502 Wordfence
6.5 Medium FileBird – WordPress Media Library Folders & File Manager Plugin filebird SQL Injection WordPress Media Library Folders & File Manager <= 6.4.8 - Authenticated (Author+) SQL Injection ≤ 6.4.8 Fixed in 6.4.9 CVE-2025-6986 Wordfence
6.4 Medium WP Tournament Registration Plugin wp-tournament-registration Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via field Parameter ≤ 1.3.0 CVE-2025-6690 Wordfence
6.4 Medium Flex Guten Plugin flex-guten Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via thumbnailHoverEffect Parameter ≤ 1.2.5 CVE-2025-6256 Wordfence
6.4 Medium esri-map-view Plugin esri-map-view Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via esri-map-view Shortcode ≤ 1.2.3 CVE-2025-6259 Wordfence
6.4 Medium Download Counter Plugin download-counter Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via name Parameter ≤ 1.3 CVE-2025-8294 Wordfence
6.4 Medium Employee Directory Plugin employee-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter ≤ 4.5.1 CVE-2025-8295 Wordfence
6.4 Medium Campus Directory Plugin campus-directory Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter ≤ 1.9.1 CVE-2025-8313 Wordfence
6.4 Medium WP Easy Contact Plugin wp-easy-contact Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via noaccess_msg Parameter ≤ 4.0.1 CVE-2025-8315 Wordfence
6.4 Medium Ocean Social Sharing Plugin ocean-social-sharing Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-7500 Wordfence
4.3 Medium Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) Plugin header-footer-elementor Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Settings Update ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-8488 Wordfence
5.3 Medium BitFire Plugin Information Disclosure Unauthenticated Information Exposure No login needed ≤ 4.5 CVE-2025-6722 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only