WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,801–7,850 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 157 of 345
Severity Component Vulnerability Affected versions Published CVE Source
9.3 Critical GG Bought Together for WooCommerce Plugin gg-bought-together SQL Injection No login needed ≤ 1.0.2 CVE-2025-23967 Patchstack
8.1 High FW Gallery Plugin fw-gallery Local File Inclusion No login needed ≤ 8.0.0 CVE-2025-49416 Patchstack
8.1 High Sofass Plugin sofass Local File Inclusion No login needed ≤ 1.3.4 CVE-2025-24760 Patchstack
7.1 High Bulk YouTube Post Creator Plugin bulk-youtube-post-creator Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0 CVE-2025-49423 Patchstack
8.6 High FW Food Menu Plugin fw-food-menu Arbitrary File Deletion No login needed ≤ 6.0.0 CVE-2025-49448 Patchstack
9.8 Critical DWT - Directory & Listing Theme Privilege Escalation Directory & Listing WordPress Theme <= 3.3.6 - Unauthenticated Arbitrary User Password Reset No login needed ≤ 3.3.6 CVE-2024-12827 Wordfence
6.4 Medium A/B Testing Plugin ab-testing-for-wp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.18.2 CVE-2025-4587 Wordfence
6.4 Medium TableOn – WordPress Posts Table Filterable Plugin posts-table-filterable Cross-Site Scripting WordPress Posts Table Filterable <= 1.0.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via tableon_popup_iframe_button Shortcode ≤ 1.0.4.1 CVE-2025-5143 Wordfence
7.1 High Elessi Plugin elessi-theme Cross-Site Scripting No login needed ≤ 6.3.9 Fixed in 6.4.1 CVE-2025-49873 Patchstack
4.3 Medium ClipLink Plugin cliplink Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49964 Patchstack
4.3 Medium Oganro Travel Portal Search Widget for HotelBeds APITUDE API Plugin oganro-travel-portal-search-widget-for-hotelbeds-apitude-api Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49966 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium XML Travel Portal Widget Plugin oganro-reservation-widget Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-49968 Patchstack
4.3 Medium Live Sports Streamthunder Plugin live-sports-streamthunder Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-49967 Patchstack
4.3 Medium Zara 4 Image Compression Plugin zara-4 Broken Access Control ≤ 1.2.17.2 CVE-2025-49969 Patchstack
4.3 Medium Hello FSE Blog Plugin hello-fse-blog Broken Access Control ≤ 1.0.6 CVE-2025-49970 Patchstack
4.3 Medium eDS Responsive Menu Plugin eds-responsive-menu Broken Access Control ≤ 1.2 CVE-2025-49971 Patchstack
4.3 Medium Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes Plugin image-sizes-controller Broken Access Control ≤ 1.0.10 CVE-2025-49973 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
4.3 Medium UpStream: a Project Management Plugin upstream Broken Access Control ≤ 2.1.1 CVE-2025-49974 Patchstack
4.3 Medium Notifier Plugin notifier Broken Access Control ≤ 2.7.12 Fixed in 2.7.13 CVE-2025-49976 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-49975 Patchstack
4.3 Medium JobSearch Plugin wp-jobsearch Broken Access Control Insecure Direct Object References (IDOR) ≤ 3.0.6 Fixed in 3.0.6 CVE-2025-49978 Patchstack
4.3 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Request Forgery No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-49977 Patchstack
4.3 Medium WP User Profile Avatar Plugin wp-user-profile-avatar Broken Access Control ≤ 1.0.6 CVE-2025-49980 Patchstack
4.3 Medium Media Hygiene Plugin media-hygiene Broken Access Control ≤ 4.0.1 Fixed in 4.0.2 CVE-2025-49979 Patchstack
4.3 Medium WP Customer Area Plugin customer-area Broken Access Control ≤ 8.3.4 CVE-2025-49982 Patchstack
4.3 Medium User Roles and Capabilities Plugin user-roles-and-capabilities Broken Access Control ≤ 1.2.6 CVE-2025-49981 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.13.11 Fixed in 11.13.12 CVE-2025-49984 Patchstack
4.9 Medium WPThumb Plugin wp-thumb Server-Side Request Forgery ≤ 0.10 CVE-2025-49983 Patchstack
5.3 Medium Video List Manager Plugin video-list-manager Broken Access Control No login needed ≤ 1.7 CVE-2025-49986 Patchstack
4.9 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery ≤ 3.3.2 CVE-2025-49985 Patchstack
5.3 Medium Contact Form 7 AWeber Extension Plugin integrate-contact-form-7-and-aweber Broken Access Control No login needed ≤ 0.1.40 Fixed in 0.1.43 CVE-2025-49988 Patchstack
5.3 Medium CRM ERP Business Solution Plugin crm-erp-business-solution Broken Access Control No login needed ≤ 1.13 CVE-2025-49987 Patchstack
5.3 Medium Contentstudio Plugin contentstudio Broken Access Control No login needed ≤ 1.3.7 Fixed in 1.4.0 CVE-2025-49990 Patchstack
5.3 Medium App Builder Plugin app-builder Broken Access Control No login needed ≤ 5.5.6 Fixed in 5.5.8 CVE-2025-49989 Patchstack
5.3 Medium Cookie-Script.com Plugin cookie-script-com Broken Access Control No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-49993 Patchstack
5.3 Medium WP-Recall Plugin wp-recall Broken Access Control No login needed ≤ 16.26.14 CVE-2025-49991 Patchstack
5.3 Medium WP Visitor Statistics (Real Time Traffic) Plugin wp-stats-manager Broken Access Control No login needed ≤ 8.4 CVE-2025-49996 Patchstack
5.3 Medium Download Attachments Plugin download-attachments Broken Access Control Insecure Direct Object References (IDOR) No login needed ≤ 1.3.1 Fixed in 1.3.2 CVE-2025-49995 Patchstack
5.4 Medium WooCommerce Fortnox Integration Plugin woocommerce-fortnox-integration Broken Access Control ≤ 4.5.5 Fixed in 4.5.6 CVE-2025-49998 Patchstack
5.3 Medium Giveaways and Contests by RafflePress Plugin rafflepress Broken Access Control Broken Access Control + CSRF No login needed ≤ 1.12.18 Fixed in 1.12.19 CVE-2025-49997 Patchstack
5.4 Medium Kata Plus Plugin kata-plus Broken Access Control ≤ 1.5.3 Fixed in 1.5.4 CVE-2025-50009 Patchstack
5.4 Medium WooCommerce Manager – Customize and Control Cart page, Add to Cart button, Checkout fields easily Plugin innovs-woo-manager Broken Access Control Customize and Control Cart page, Add to Cart button, Checkout fields easily plugin <= 1.2.4.5 - Broken Access Control ≤ 1.2.4.5 CVE-2025-50008 Patchstack
5.9 Medium Recipes manager - WPH Plugin wph-recipes-manager Cross-Site Scripting ≤ 1.0.4 CVE-2025-50011 Patchstack
5.4 Medium Zapier Plugin zapier Broken Access Control ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-50010 Patchstack
5.9 Medium CSV Importer Improved Plugin csv-importer-improved Cross-Site Scripting ≤ 0.6.1 CVE-2025-50013 Patchstack
5.9 Medium Inventory Presser Plugin inventory-presser Cross-Site Scripting ≤ 15.2.6 Fixed in 15.2.7 CVE-2025-50012 Patchstack
5.9 Medium Hand Talk Plugin handtalk Cross-Site Scripting ≤ 6.1 Fixed in 6.2 CVE-2025-50015 Patchstack
5.9 Medium PDPA Consent for Thailand Plugin pdpa-consent Cross-Site Scripting ≤ 1.1.1 CVE-2025-50014 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only