WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 7,801–7,850 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Structured Content | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode |
≤ 1.6.4 |
CVE-2025-4608 |
Wordfence | |
| 6.4 Medium | WP Get The Table | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter |
≤ 1.5 Fixed in 1.6 |
CVE-2025-6387 |
Wordfence | |
| 6.4 Medium | muse.ai video embedding | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via muse-ai Shortcode |
≤ 0.4 Fixed in 0.4.1 |
CVE-2025-6262 |
Wordfence | |
| 6.4 Medium | Supreme Addons for Beaver Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_qrcodesabb Shortcode |
≤ 1.0.9 |
CVE-2025-3669 |
Wordfence | |
| 4.3 Medium | WP Wallcreeper | Broken Access Control Missing Authorization to Authenticated (Susbcriber+) Cache Enable/Disable |
≤ 1.6.1 |
CVE-2025-7822 |
Wordfence | |
| 6.4 Medium | WP Applink | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter |
≤ 0.4.1 |
CVE-2025-6385 |
Wordfence | |
| 6.4 Medium | Mine CloudVod | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via audio Parameter |
≤ 2.1.10 Fixed in 2.2.0 |
CVE-2025-8071 |
Wordfence | |
| 6.4 Medium | Get Youtube Subs | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via subscribe_link_att Function |
≤ 3.5 |
CVE-2025-7966 |
Wordfence | |
| 6.5 Medium | AI Engine | Path Traversal Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions |
≤ 2.9.4 |
CVE-2025-7780 |
Wordfence | |
| 6.1 Medium | Post Grid Master | Cross-Site Scripting Reflected Cross-Site Scripting via argsArray['read_more_text'] No login needed |
≤ 3.4.13 Fixed in 3.4.14 |
CVE-2025-5084 |
Wordfence | |
| 4.9 Medium | Security Ninja – Secure Firewall & Secure Malware Scanner | Path Traversal Secure Firewall & Secure Malware Scanner - 5.201 - 5.242 - Authenticated (Administrator+) Arbitrary File Read |
5.201 – 5.242 |
CVE-2025-8009 |
Wordfence | |
| 6.4 Medium | WPBakery Page Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Page Builder Elements |
≤ 8.4.1 |
CVE-2025-4968 |
Wordfence | |
| 6.1 Medium | WordPress Qwizcards | Cross-Site Scripting Reflected XSS No login needed |
≤ 3.9.4 |
CVE-2025-6174 |
WPScan | |
| 6.5 Medium | Omnishop | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary User Deletion via /users/delete REST Endpoint No login needed |
≤ 1.0.9 |
CVE-2025-6214 |
Wordfence | |
| 6.4 Medium | Valuation Calculator | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via link Parameter |
≤ 1.3.2 |
CVE-2025-5753 |
Wordfence | |
| 6.4 Medium | Fleetwire Fleet Management | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via fleetwire_list Shortcode |
≤ 1.0.19 Fixed in 1.0.20 |
CVE-2025-6261 |
Wordfence | |
| 5.5 Medium | Featured Image Plus – Quick & Bulk Edit with Unsplash | Server-Side Request Forgery Quick & Bulk Edit with Unsplash <= 1.6.6 - Authenticated (Admin+) Server-Side Request Forgery |
≤ 1.6.6 |
CVE-2025-5818 |
Wordfence | |
| 5.3 Medium | Omnishop | Broken Access Control Missing Registration Restriction to Unauthenticated Account Creation via /users/register REST Endpoint No login needed |
≤ 1.0.9 |
CVE-2025-6215 |
Wordfence | |
| 6.1 Medium | YANewsflash | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.0.3 |
CVE-2025-6054 |
Wordfence | |
| 6.4 Medium | Shortcodes Ultimate | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Image Title and Slide Link |
≤ 7.4.2 Fixed in 7.4.3 |
CVE-2025-8015 |
Wordfence | |
| 6.1 Medium | Like & Share My Site | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 0.2 |
CVE-2025-7685 |
Wordfence | |
| 5.3 Medium | Birth Chart Compatibility | Information Disclosure Unauthenticated Full Path Exposure No login needed |
≤ 2.0 |
CVE-2025-6082 |
Wordfence | |
| 6.1 Medium | Latest Post Accordian Slider | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 1.3 |
CVE-2025-7687 |
Wordfence | |
| 6.4 Medium | Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery | Cross-Site Scripting Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.6.7 |
CVE-2025-7644 |
Wordfence | |
| 6.4 Medium | WP-Members | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 3.5.4.1 Fixed in 3.5.4.2 |
CVE-2025-7495 |
Wordfence | |
| 6.4 Medium | User Registration | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode |
≤ 4.2.4 |
CVE-2025-6831 |
Wordfence | |
| 6.4 Medium | CRM and Lead Management by vcita | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via type Parameter |
≤ 2.7.5 |
CVE-2025-5240 |
Wordfence | |
| 4.4 Medium | Ebook Store | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Order Details |
≤ 5.8012 |
CVE-2025-7486 |
Wordfence | |
| 6.1 Medium | Shortcodes Ultimate | Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Shortcode Execution No login needed |
≤ 7.4.2 |
CVE-2025-7369 |
Wordfence | |
| 6.4 Medium | WP Shortcodes Plugin — Shortcodes Ultimate | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes |
≤ 7.4.2 |
CVE-2025-7354 |
Wordfence | |
| 6.4 Medium | Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor | Cross-Site Scripting Gutenberg Blocks – Page Builder for Gutenberg Editor <= 3.4.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Multiple Widgets |
≤ 3.4.8 |
CVE-2025-4685 |
Wordfence | |
| 6.4 Medium | ThemeREX Addons | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via trx_addons_get_svg_from_file Function |
≤ 2.35.1.1 |
CVE-2025-6997 |
Wordfence | |
| 5.3 Medium | Vchasno Kasa | Broken Access Control Unauthenticated Log File Clearing No login needed |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2025-6720 |
Wordfence | |
| 5.3 Medium | Vchasno Kasa | Broken Access Control Missing Authorization to Unauthenticated Invoice Generation No login needed |
≤ 1.0.3 Fixed in 1.0.4 |
CVE-2025-6721 |
Wordfence | |
| 6.1 Medium | Avishi WP PayPal Payment Button | Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed |
≤ 2.0 |
CVE-2025-7669 |
Wordfence | |
| 6.4 Medium | EPay.bg Payments | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 0.1 |
CVE-2025-7653 |
Wordfence | |
| 6.4 Medium | Partnerský systém Martinus | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.7.1 |
CVE-2025-7661 |
Wordfence | |
| 6.4 Medium | Temporarily Hidden Content | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.0.6 |
CVE-2025-7658 |
Wordfence | |
| 6.4 Medium | Live Stream Badger | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.4.3 |
CVE-2025-7655 |
Wordfence | |
| 6.5 Medium | Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read |
≤ 16.8 |
CVE-2025-7772 |
Wordfence | |
| 5.3 Medium | Listly: Listicles | Broken Access Control Unauthenticated Arbitrary Transient Deletion No login needed |
≤ 2.7 |
CVE-2025-5811 |
Wordfence | |
| 6.4 Medium | Testimonial Post type | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via auto_play Parameter |
≤ 1.2.1 |
CVE-2025-5800 |
Wordfence | |
| 6.4 Medium | Vertical scroll image slideshow gallery | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 11.1 |
CVE-2025-5752 |
Wordfence | |
| 4.4 Medium | Terms descriptions | Cross-Site Scripting Authenticated (Admin+) Stored Cross-Site Scripting |
≤ 3.4.8 |
CVE-2025-6719 |
Wordfence | |
| 6.5 Medium | B1.lt for WooCommerce | SQL Injection Authenticated (Subscriber+) SQL Injection |
≤ 2.2.56 Fixed in 2.2.57 |
CVE-2025-6717 |
Wordfence | |
| 6.4 Medium | Crowdfunding for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter |
≤ 3.1.14 |
CVE-2025-5767 |
Wordfence | |
| 4.3 Medium | Block Editor Gallery Slider | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Limited Post Meta Update |
≤ 1.1.1 |
CVE-2025-6726 |
Wordfence | |
| 6.4 Medium | Useful Tab Block – Responsive & AMP-Compatible | Cross-Site Scripting Responsive & AMP-Compatible <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via className Parameter |
≤ 1.3.2 |
CVE-2025-5754 |
Wordfence | |
| 4.3 Medium | Copymatic – AI Content Writer & Generator | Cross-Site Request Forgery AI Content Writer & Generator <= 2.1 - Cross-Site Request Forgery to Settings Update No login needed |
≤ 2.1 |
CVE-2025-6781 |
Wordfence | |
| 6.4 Medium | Map My Locations | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 1.1 |
CVE-2025-7660 |
Wordfence |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.