WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 7,901–7,950 of 17,889 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 6.4 Medium | Media Library Assistant | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes |
≤ 3.26 |
CVE-2025-7035 |
Wordfence | |
| 6.4 Medium | Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations | Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 2.0.8.2 |
CVE-2025-5284 |
Wordfence | |
| 6.4 Medium | Avada (Fusion) Builder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode |
≤ 3.12.1 |
CVE-2025-6747 |
Wordfence | |
| 6.4 Medium | Affiliate Reviews | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via numColumns Parameter |
≤ 1.0.6 |
CVE-2025-5845 |
Wordfence | |
| 6.4 Medium | Brandfolder | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter |
≤ 5.0.19 Fixed in 5.0.20 |
CVE-2025-5843 |
Wordfence | |
| 4.4 Medium | WP Event Manager | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 3.1.49 |
CVE-2025-2799 |
Wordfence | |
| 6.1 Medium | ProfileGrid – User Profiles, Groups and Communities | Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function No login needed |
≤ 5.9.5.4 |
CVE-2025-6977 |
Wordfence | |
| 5.5 Medium | Companion Auto Update | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via update_delay_days parameter |
≤ 3.9.2 |
CVE-2025-4369 |
Wordfence | |
| 6.4 Medium | Strong Testimonials | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields |
≤ 3.2.11 |
CVE-2025-7367 |
Wordfence | |
| 5.9 Medium | Modern Events Calendar Lite | SQL Injection Unauthenticated SQL Injection No login needed |
≤ 6.3.0 |
CVE-2021-4458 |
Wordfence | |
| 4.9 Medium | RSFirewall! | Path Traversal Authenticated (Admin+) Arbitrary File Read |
≤ 1.1.42 |
CVE-2025-7518 |
Wordfence | |
| 4.1 Medium | Broken Link Notifier | Content Injection Authenticated (Contributor+) CSV Injection |
≤ 1.3.0 |
CVE-2025-6838 |
Wordfence | |
| 6.4 Medium | FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel | Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting |
≤ 2.4.31 Fixed in 2.4.32 |
CVE-2025-6068 |
Wordfence | |
| 6.4 Medium | WPC Smart Compare for WooCommerce | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 6.4.6 Fixed in 6.4.7 |
CVE-2025-5530 |
Wordfence | |
| 5.3 Medium | WoodMart | Information Disclosure Unauthenticated Post Disclosure No login needed |
≤ 8.2.5 |
CVE-2025-6745 |
Wordfence | |
| 6.5 Medium | WP Register Profile With Shortcode | Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure |
≤ 3.6.2 |
CVE-2025-4593 |
Wordfence | |
| 6.4 Medium | Contest Gallery | Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting |
≤ 26.0.8 |
CVE-2025-6716 |
Wordfence | |
| 5.9 Medium | GeoDirectory | Cross-Site Scripting Contributor+ Stored XSS |
< 2.8.120 Fixed in 2.8.120 |
CVE-2025-6200 |
WPScan | |
| 4.3 Medium | Order Delivery Date Pro for WooCommerce | Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed |
2.0 – < 12.6.0 Fixed in 12.6.0 |
CVE-2025-2942 |
WPScan | |
| 4.8 Medium | Hostel | Cross-Site Scripting Admin+ Stored XSS |
< 1.1.5.9 Fixed in 1.1.5.9 |
CVE-2025-6236 |
WPScan | |
| 6.1 Medium | Hostel | Cross-Site Scripting Reflected XSS No login needed |
< 1.1.5.8 Fixed in 1.1.5.8 |
CVE-2025-6234 |
WPScan | |
| 5.5 Medium | Lana Downloads Manager | Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting |
≤ 1.10.0 Fixed in 1.11.0 |
CVE-2025-7387 |
Wordfence | |
| 6.1 Medium | Gwolle Guestbook | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter No login needed |
≤ 4.9.2 |
CVE-2025-5807 |
Wordfence | |
| 5.4 Medium | wpForo Forum | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar |
≤ 2.4.5 |
CVE-2025-4406 |
Wordfence | |
| 6.4 Medium | Events Manager | Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes |
≤ 6.6.4.4, 7.0.1 – 7.0.3 |
CVE-2025-6976 |
Wordfence | |
| 6.1 Medium | Event Manager | Cross-Site Scripting Reflected Cross-Site Scripting via `calendar_header` Parameter No login needed |
≤ 6.6.4.4, 7.0.1 – 7.0.3 |
CVE-2025-6975 |
Wordfence | |
| 6.4 Medium | Simple Featured Image | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter |
≤ 1.3.1 |
CVE-2025-7059 |
Wordfence | |
| 6.4 Medium | Kadence Blocks – Gutenberg Blocks for Page Builder Features | Cross-Site Scripting Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter |
≤ 3.5.10 |
CVE-2025-5678 |
Wordfence | |
| 6.5 Medium | WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible | Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed |
≤ 6.7.16 |
CVE-2025-3780 |
Wordfence | |
| 6.4 Medium | WoodMart | Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting |
≤ 8.2.3 |
CVE-2025-6743 |
Wordfence | |
| 5.3 Medium | Guest Support – Complete customer support ticket system | Broken Access Control Complete customer support ticket system for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Ticket Deletion No login needed |
≤ 1.2.2 |
CVE-2025-5957 |
Wordfence | |
| 6.4 Medium | Lightbox & Modal Popup WordPress Plugin – FooBox | Cross-Site Scripting FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting |
≤ 2.7.34 |
CVE-2025-5537 |
Wordfence | |
| 5.4 Medium | AI Engine | Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter |
≤ 2.8.4 |
CVE-2025-5570 |
Wordfence | |
| 6.4 Medium | Essential Addons for Elementor – Popular Elementor Templates and Widgets | Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets |
≤ 6.1.19 |
CVE-2025-6244 |
Wordfence | |
| 6.1 Medium | Contact Form 7 Database Addon | Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via tmpD Parameter No login needed |
≤ 1.3.1 |
CVE-2025-6740 |
Wordfence | |
| 6.5 Medium | Email Address Security by WebEmailProtector | Cross-Site Scripting |
≤ 3.3.6 |
CVE-2025-28976 |
Patchstack | |
| 5.3 Medium | WP Compress | Authentication Bypass Broken Authentication No login needed |
≤ 6.30.30 Fixed in 6.30.31 |
CVE-2025-47479 |
Patchstack | |
| 6.3 Medium | EventON | Broken Access Control |
≤ 4.9.9 |
CVE-2025-47565 |
Patchstack | |
| 6.5 Medium | WC Pickup Store | Broken Access Control Settings Change No login needed |
≤ 1.8.9 Fixed in 1.8.10 |
CVE-2025-47634 |
Patchstack | |
| 6.5 Medium | Booking Calendar Contact Form | Cross-Site Scripting |
≤ 1.2.58 Fixed in 1.2.59 |
CVE-2025-48231 |
Patchstack | |
| 6.8 Medium | Frontend Admin by DynamiApps | Path Traversal Arbitrary File Download |
≤ 3.28.7 Fixed in 3.28.8 |
CVE-2025-49303 |
Patchstack | |
| 6.5 Medium | VG WORT METIS | Broken Access Control |
≤ 2.0.1 |
CVE-2025-50039 |
Patchstack | |
| 6.5 Medium | Paytiko for WooCommerce | Broken Access Control |
≤ 1.3.21 |
CVE-2025-50032 |
Patchstack | |
| 6.5 Medium | MF Plus WPML | Broken Access Control Settings Change No login needed |
≤ 1.1 |
CVE-2025-49431 |
Patchstack | |
| 6.5 Medium | Card flip image slideshow | Cross-Site Scripting |
≤ 1.5 |
CVE-2025-30983 |
Patchstack | |
| 6.5 Medium | Posts Slider Shortcode | Cross-Site Scripting |
≤ 1.0 |
CVE-2025-30943 |
Patchstack | |
| 5.3 Medium | fluXtore | Broken Access Control No login needed |
≤ 1.6.0 Fixed in 1.6.3 |
CVE-2025-30929 |
Patchstack | |
| 5.3 Medium | CF7 7 Mailchimp Add-on | Broken Access Control No login needed |
≤ 2.4 Fixed in 2.4 |
CVE-2025-29012 |
Patchstack | |
| 4.3 Medium | LMSACE Connect | Broken Access Control |
≤ 3.4 |
CVE-2025-29007 |
Patchstack | |
| 4.3 Medium | WooCommerce Shop Page Builder | Broken Access Control |
≤ 2.27.7 |
CVE-2025-29001 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.