WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,802 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 7,901–7,950 of 17,889 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 159 of 358
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Media Library Assistant Plugin media-library-assistant Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via mla_tag_cloud and mla_term_list Shortcodes ≤ 3.26 CVE-2025-7035 Wordfence
6.4 Medium Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations Plugin master-addons Cross-Site Scripting Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations <= 2.0.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 2.0.8.2 CVE-2025-5284 Wordfence
6.4 Medium Avada (Fusion) Builder Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.12.1 CVE-2025-6747 Wordfence
6.4 Medium Affiliate Reviews Plugin affiliate-reviews Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via numColumns Parameter ≤ 1.0.6 CVE-2025-5845 Wordfence
6.4 Medium Brandfolder Plugin brandfolder Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 5.0.19 Fixed in 5.0.20 CVE-2025-5843 Wordfence
4.4 Medium WP Event Manager Plugin wp-event-manager Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 3.1.49 CVE-2025-2799 Wordfence
6.1 Medium ProfileGrid – User Profiles, Groups and Communities Plugin profilegrid-user-profiles-groups-and-communities Cross-Site Scripting User Profiles, Groups and Communities <= 5.9.5.4 - Reflected Cross-Site Scripting via 'pm_get_messenger_notification' function No login needed ≤ 5.9.5.4 CVE-2025-6977 Wordfence
5.5 Medium Companion Auto Update Plugin companion-auto-update Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting via update_delay_days parameter ≤ 3.9.2 CVE-2025-4369 Wordfence
6.4 Medium Strong Testimonials Plugin strong-testimonials Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting via Custom Fields ≤ 3.2.11 CVE-2025-7367 Wordfence
5.9 Medium Modern Events Calendar Lite Plugin modern-events-calendar-lite SQL Injection Unauthenticated SQL Injection No login needed ≤ 6.3.0 CVE-2021-4458 Wordfence
4.9 Medium RSFirewall! Plugin rsfirewall Path Traversal Authenticated (Admin+) Arbitrary File Read ≤ 1.1.42 CVE-2025-7518 Wordfence
4.1 Medium Broken Link Notifier Plugin broken-link-notifier Content Injection Authenticated (Contributor+) CSV Injection ≤ 1.3.0 CVE-2025-6838 Wordfence
6.4 Medium FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel Plugin foogallery Cross-Site Scripting Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel <= 2.4.31 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting ≤ 2.4.31 Fixed in 2.4.32 CVE-2025-6068 Wordfence
6.4 Medium WPC Smart Compare for WooCommerce Plugin woo-smart-compare Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 6.4.6 Fixed in 6.4.7 CVE-2025-5530 Wordfence
5.3 Medium WoodMart Plugin Information Disclosure Unauthenticated Post Disclosure No login needed ≤ 8.2.5 CVE-2025-6745 Wordfence
6.5 Medium WP Register Profile With Shortcode Plugin wp-register-profile-with-shortcode Information Disclosure Authenticated (Contributor+) Sensitive Information Exposure ≤ 3.6.2 CVE-2025-4593 Wordfence
6.4 Medium Contest Gallery Plugin contest-gallery Cross-Site Scripting Authenticated (Author+) Stored Cross-Site Scripting ≤ 26.0.8 CVE-2025-6716 Wordfence
5.9 Medium GeoDirectory Plugin geodirectory Cross-Site Scripting Contributor+ Stored XSS < 2.8.120 Fixed in 2.8.120 CVE-2025-6200 WPScan
4.3 Medium Order Delivery Date Pro for WooCommerce Plugin Information Disclosure Unauthenticated Arbitrary Post Title Disclosure No login needed 2.0 – < 12.6.0 Fixed in 12.6.0 CVE-2025-2942 WPScan
4.8 Medium Hostel Plugin hostel Cross-Site Scripting Admin+ Stored XSS < 1.1.5.9 Fixed in 1.1.5.9 CVE-2025-6236 WPScan
6.1 Medium Hostel Plugin hostel Cross-Site Scripting Reflected XSS No login needed < 1.1.5.8 Fixed in 1.1.5.8 CVE-2025-6234 WPScan
5.5 Medium Lana Downloads Manager Plugin lana-downloads-manager Cross-Site Scripting Authenticated (Administrator+) Stored Cross-Site Scripting ≤ 1.10.0 Fixed in 1.11.0 CVE-2025-7387 Wordfence
6.1 Medium Gwolle Guestbook Plugin gwolle-gb Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via `gwolle_gb_content` Parameter No login needed ≤ 4.9.2 CVE-2025-5807 Wordfence
5.4 Medium wpForo Forum Plugin wpforo Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via Profile Avatar ≤ 2.4.5 CVE-2025-4406 Wordfence
6.4 Medium Events Manager Plugin events-manager Cross-Site Scripting Authenticated(Contributor+) Stored Cross-Site Scripting via Plugin Shortcodes ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6976 Wordfence
6.1 Medium Event Manager Plugin events-manager Cross-Site Scripting Reflected Cross-Site Scripting via `calendar_header` Parameter No login needed ≤ 6.6.4.4, 7.0.1 – 7.0.3 CVE-2025-6975 Wordfence
6.4 Medium Simple Featured Image Plugin simple-featured-image Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via slideshow Parameter ≤ 1.3.1 CVE-2025-7059 Wordfence
6.4 Medium Kadence Blocks – Gutenberg Blocks for Page Builder Features Plugin kadence-blocks Cross-Site Scripting Gutenberg Blocks for Page Builder Features <= 3.5.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via `redirectURL` Parameter ≤ 3.5.10 CVE-2025-5678 Wordfence
6.5 Medium WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible Plugin wc-frontend-manager Broken Access Control Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible <= 6.7.16 - Missing Authorization to Unauthenticated Plugin Settings Modification No login needed ≤ 6.7.16 CVE-2025-3780 Wordfence
6.4 Medium WoodMart Theme Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 8.2.3 CVE-2025-6743 Wordfence
5.3 Medium Guest Support – Complete customer support ticket system Plugin guest-support Broken Access Control Complete customer support ticket system for WordPress <= 1.2.2 - Missing Authorization to Unauthenticated Ticket Deletion No login needed ≤ 1.2.2 CVE-2025-5957 Wordfence
6.4 Medium Lightbox & Modal Popup WordPress Plugin – FooBox Plugin foobox-image-lightbox Cross-Site Scripting FooBox <= 2.7.34 - Authenticated (Author+) Stored Cross-Site Scripting ≤ 2.7.34 CVE-2025-5537 Wordfence
5.4 Medium AI Engine Plugin ai-engine Cross-Site Scripting Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter ≤ 2.8.4 CVE-2025-5570 Wordfence
6.4 Medium Essential Addons for Elementor – Popular Elementor Templates and Widgets Plugin Cross-Site Scripting Popular Elementor Templates and Widgets <= 6.1.19 - Authenticated (Contributor+) Stored Cross-Site Scripting via `Calendar` And `Business Reviews` Widgets ≤ 6.1.19 CVE-2025-6244 Wordfence
6.1 Medium Contact Form 7 Database Addon Plugin contact-form-cfdb7 Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via tmpD Parameter No login needed ≤ 1.3.1 CVE-2025-6740 Wordfence
6.5 Medium Email Address Security by WebEmailProtector Plugin webemailprotector Cross-Site Scripting ≤ 3.3.6 CVE-2025-28976 Patchstack
5.3 Medium WP Compress Plugin wp-compress-image-optimizer Authentication Bypass Broken Authentication No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47479 Patchstack
6.3 Medium EventON Plugin eventon Broken Access Control ≤ 4.9.9 CVE-2025-47565 Patchstack
6.5 Medium WC Pickup Store Plugin wc-pickup-store Broken Access Control Settings Change No login needed ≤ 1.8.9 Fixed in 1.8.10 CVE-2025-47634 Patchstack
6.5 Medium Booking Calendar Contact Form Plugin booking-calendar-contact-form Cross-Site Scripting ≤ 1.2.58 Fixed in 1.2.59 CVE-2025-48231 Patchstack
6.8 Medium Frontend Admin by DynamiApps Plugin acf-frontend-form-element Path Traversal Arbitrary File Download ≤ 3.28.7 Fixed in 3.28.8 CVE-2025-49303 Patchstack
6.5 Medium VG WORT METIS Plugin vgw-metis Broken Access Control ≤ 2.0.1 CVE-2025-50039 Patchstack
6.5 Medium Paytiko for WooCommerce Plugin paytiko Broken Access Control ≤ 1.3.21 CVE-2025-50032 Patchstack
6.5 Medium MF Plus WPML Plugin mf-plus-wpml Broken Access Control Settings Change No login needed ≤ 1.1 CVE-2025-49431 Patchstack
6.5 Medium Card flip image slideshow Plugin card-flip-image-slideshow Cross-Site Scripting ≤ 1.5 CVE-2025-30983 Patchstack
6.5 Medium Posts Slider Shortcode Plugin posts-slider-shortcode Cross-Site Scripting ≤ 1.0 CVE-2025-30943 Patchstack
5.3 Medium fluXtore Plugin fluxtore Broken Access Control No login needed ≤ 1.6.0 Fixed in 1.6.3 CVE-2025-30929 Patchstack
5.3 Medium CF7 7 Mailchimp Add-on Plugin cf7-mailchimp-addon Broken Access Control No login needed ≤ 2.4 Fixed in 2.4 CVE-2025-29012 Patchstack
4.3 Medium LMSACE Connect Plugin lmsace-connect Broken Access Control ≤ 3.4 CVE-2025-29007 Patchstack
4.3 Medium WooCommerce Shop Page Builder Plugin dzs-wootable Broken Access Control ≤ 2.27.7 CVE-2025-29001 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the attacker needs no account, as the publisher's text states it, or as the score assumes when the text does not say.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. Some publishers only give the last affected version; when their references show the fix, the fixed release is the first one on wordpress.org after that version. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only