WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,851–7,900 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 158 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.1 Medium Zuppler Online Ordering Plugin zuppler-online-ordering Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.1.0 CVE-2025-6053 Wordfence
4.9 Medium Forminator Forms – Contact Form, Payment Form & Custom Form Builder Plugin forminator SQL Injection Contact Form, Payment Form & Custom Form Builder <= 1.45.0 - Authenticated (Administrator+) SQL Injection via `order_by` Parameter ≤ 1.45.0 CVE-2025-7638 Wordfence
4.3 Medium Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship Plugin biteship Broken Access Control Biteship <= 3.2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) View Order Tracking Details ≤ 3.2.0 CVE-2025-5816 Wordfence
6.4 Medium Ruven Themes: Shortcodes Plugin ruven-themes-shortcodes Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0 CVE-2025-7648 Wordfence
4.4 Medium Knowledge Base Plugin knowledgebase Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin Slug ≤ 2.3.1 CVE-2025-7431 Wordfence
5.3 Medium Stop User Enumeration Plugin stop-user-enumeration Other Protection Bypass No login needed < 1.7.3 Fixed in 1.7.3 CVE-2025-4302 WPScan
6.5 Medium Product XML Feed Manager for WooCommerce Plugin product-xml-feeds-for-woocommerce Broken Access Control No login needed ≤ 2.9.2 Fixed in 2.9.3 CVE-2025-30959 Patchstack
6.5 Medium Profiler - What Slowing Down Your WP Plugin profiler-what-slowing-down Broken Access Control What Slowing Down Your WP <= 1.0.0 - Broken Access Control No login needed ≤ 1.0.0 CVE-2025-48339 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Broken Access Control No login needed ≤ 3.2.3 Fixed in 3.2.4 CVE-2025-49319 Patchstack
6.5 Medium Internal Linking of Related Contents Plugin internal-linking-of-related-contents Broken Access Control No login needed ≤ 1.1.8 Fixed in 1.1.9 CVE-2025-49884 Patchstack
6.5 Medium Ultimate Push Notifications Plugin ultimate-push-notifications Broken Access Control No login needed ≤ 1.2.0 CVE-2025-50028 Patchstack
4.3 Medium Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now Broken Access Control ≤ 4.48 Fixed in 4.49 CVE-2025-48150 Patchstack
5.3 Medium Residential Address Detection Plugin residential-address-detection Broken Access Control No login needed ≤ 2.5.9 Fixed in 2.5.10 CVE-2025-48155 Patchstack
6.5 Medium Image Wall Plugin image-wall Cross-Site Scripting ≤ 3.1 Fixed in 3.2 CVE-2025-48156 Patchstack
5.4 Medium Chatbox Manager Plugin wa-chatbox-manager Broken Access Control ≤ 1.2.5 Fixed in 1.2.6 CVE-2025-48167 Patchstack
5.3 Medium Stop and Block bots plugin Anti bots Plugin antibots Broken Access Control No login needed ≤ 1.48 Fixed in 1.50 CVE-2025-48166 Patchstack
6.5 Medium Easy Elementor Addons Plugin easy-elementor-addons Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-48295 Patchstack
4.4 Medium FG Drupal to Plugin fg-drupal-to-wp Server-Side Request Forgery ≤ 3.90.0 Fixed in 3.90.1 CVE-2025-48294 Patchstack
6.5 Medium LightBox Block Plugin lightbox-block Cross-Site Scripting ≤ 1.1.30 Fixed in 1.1.31 CVE-2025-54051 Patchstack
6.5 Medium Responsive Addons for Elementor Plugin responsive-addons-for-elementor Cross-Site Scripting ≤ 1.7.3 Fixed in 1.7.4 CVE-2025-54050 Patchstack
4.3 Medium Cost Calculator Plugin ql-cost-calculator Broken Access Control ≤ 7.4 Fixed in 7.5 CVE-2025-54047 Patchstack
4.3 Medium WP Post Hide Plugin wp-post-hide Cross-Site Request Forgery No login needed ≤ 1.0.9 Fixed in 1.1.0 CVE-2025-54042 Patchstack
4.3 Medium Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-54041 Patchstack
4.3 Medium Animator Plugin scroll-triggered-animations Cross-Site Request Forgery No login needed ≤ 3.0.16 Fixed in 3.0.17 CVE-2025-54039 Patchstack
5.4 Medium Restaurant Menu by MotoPress Plugin mp-restaurant-menu Cross-Site Request Forgery No login needed ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-54038 Patchstack
5.4 Medium News Kit Elementor Addons Plugin news-kit-elementor-addons Broken Access Control ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-54037 Patchstack
4.3 Medium Webba Booking Plugin webba-booking-lite Cross-Site Request Forgery No login needed ≤ 5.1.20 Fixed in 5.1.21 CVE-2025-54036 Patchstack
4.3 Medium Newsletters Plugin newsletters-lite Cross-Site Request Forgery No login needed ≤ 4.10 Fixed in 4.11 CVE-2025-54035 Patchstack
6.5 Medium Theme Builder For Elementor Plugin theme-builder-for-elementor Cross-Site Request Forgery No login needed ≤ 1.2.3 Fixed in 1.2.4 CVE-2025-54033 Patchstack
4.3 Medium WooCommerce Google Sheet Connector Plugin wc-gsheetconnector Cross-Site Request Forgery No login needed ≤ 1.3.20 Fixed in 1.4.0 CVE-2025-54030 Patchstack
6.5 Medium WPAdverts Plugin wpadverts Cross-Site Scripting ≤ 2.2.5 Fixed in 2.2.6 CVE-2025-54024 Patchstack
6.5 Medium WP Delicious Plugin delicious-recipes Cross-Site Scripting ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54023 Patchstack
6.5 Medium Coupon Affiliates Plugin woo-coupon-usage Cross-Site Request Forgery No login needed ≤ 6.4.0 Fixed in 6.4.1 CVE-2025-54022 Patchstack
5.4 Medium AntiSpam for Contact Form 7 Plugin cf7-antispam Cross-Site Request Forgery No login needed ≤ 0.6.3 Fixed in 0.6.4 CVE-2025-54020 Patchstack
4.3 Medium CM Pop-Up banners Plugin cm-pop-up-banners Broken Access Control ≤ 1.8.4 Fixed in 1.8.5 CVE-2025-54018 Patchstack
6.5 Medium Videopack Plugin video-embed-thumbnail-generator Cross-Site Scripting ≤ 4.10.3 Fixed in 4.10.4 CVE-2025-54016 Patchstack
6.6 Medium HT Contact Form 7 Plugin ht-contactform Local File Inclusion ≤ 2.0.0 Fixed in 2.1.0 CVE-2025-54015 Patchstack
5.9 Medium Welcart e-Commerce Plugin usc-e-shop Cross-Site Scripting ≤ 2.11.16 Fixed in 2.11.17 CVE-2025-54013 Patchstack
4.3 Medium SMTP2GO Plugin smtp2go Broken Access Control ≤ 1.12.1 Fixed in 1.12.2 CVE-2025-54011 Patchstack
6.5 Medium JetSmartFilters Plugin jet-smart-filters Cross-Site Scripting ≤ 3.6.8 Fixed in 3.6.8.1 CVE-2025-54009 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.4.1 Fixed in 5.4.2 CVE-2025-54006 Patchstack
4.3 Medium Houzez Plugin houzez Broken Access Control ≤ 4.0.4 Fixed in 4.1.1 CVE-2025-53997 Patchstack
6.5 Medium JetSearch Plugin jet-search Cross-Site Scripting ≤ 3.5.10.1 Fixed in 3.5.11 CVE-2025-53996 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15.1 Fixed in 2.0.16 CVE-2025-53995 Patchstack
6.5 Medium JetPopup Plugin jet-popup Cross-Site Scripting ≤ 2.0.15 Fixed in 2.0.15.1 CVE-2025-53994 Patchstack
6.5 Medium JetTricks Plugin jet-tricks Cross-Site Scripting ≤ 1.5.4.1 Fixed in 1.5.4.2 CVE-2025-53991 Patchstack
6.5 Medium JetBlocks For Elementor Plugin jet-blocks Cross-Site Scripting ≤ 1.3.19 Fixed in 1.3.19.1 CVE-2025-53989 Patchstack
5.3 Medium Hestia Plugin hestia Broken Access Control No login needed ≤ 3.2.10 Fixed in 3.2.11 CVE-2025-53986 Patchstack
6.5 Medium JetTabs Plugin jet-tabs Cross-Site Scripting ≤ 2.2.9 Fixed in 2.2.9.1 CVE-2025-53984 Patchstack
6.5 Medium JetElements For Elementor Plugin jet-elements Cross-Site Scripting ≤ 2.7.7 Fixed in 2.7.7.1 CVE-2025-53982 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only