WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 751–800 of 2,392 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
6.4 Medium Essential Blocks Plugin essential-blocks Server-Side Request Forgery Authenticated (Author+) Server-Side Request Forgery ≤ 5.7.1 CVE-2025-11361 Wordfence
4.3 Medium Ally - Web Accessibility & Usability Plugin Cross-Site Request Forgery Web Accessibility & Usability <= 3.8.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.8.0 CVE-2025-10700 Wordfence
4.4 Medium Task Scheduler Plugin task-scheduler Server-Side Request Forgery Authenticated (Admin+) Blind Server-Side Request Forgery ≤ 1.6.3 CVE-2025-10056 Wordfence
4.3 Medium Theme Importer Plugin theme-importer Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-10312 Wordfence
4.3 Medium TopBar Plugin topbar Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-10300 Wordfence
4.3 Medium FunKItools Plugin funkitools Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.2 CVE-2025-10301 Wordfence
4.3 Medium Course Redirects for Learndash Plugin course-redirects-for-learndash Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-10376 Wordfence
4.3 Medium Web Accessibility By accessiBe Plugin accessibe Cross-Site Request Forgery No login needed ≤ 2.10 CVE-2025-10375 Wordfence
2.4 Low GSheetConnector For Gravity Forms Plugin gsheetconnector-gravity-forms Cross-Site Request Forgery Cross-Site Request Forgery to Arbitrary Plugin Activation/Deactivation ≤ 1.3.23 CVE-2025-8606 Wordfence
4.3 Medium Page Blocks Plugin page-blocks Cross-Site Request Forgery No login needed ≤ 1.1.0 CVE-2025-9626 Wordfence
6.8 Medium WP Scraper Plugin wp-scraper Server-Side Request Forgery Authenticated (Administrator+) Server-Side Request Forgery ≤ 5.8.1 CVE-2025-9975 Wordfence
4.3 Medium WidgetPack Comment System Plugin widgetpack-comment-system Cross-Site Request Forgery No login needed ≤ 1.6.1 CVE-2025-9621 Wordfence
5.4 Medium WP Go Maps (formerly WP Google Maps) Plugin wp-google-maps Cross-Site Request Forgery Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 9.0.46 CVE-2025-11166 Wordfence
4.3 Medium Trinity Audio Plugin trinity-audio Cross-Site Request Forgery No login needed ≤ 5.20.2 CVE-2025-9886 Wordfence
4.3 Medium Ultimate Viral Quiz Plugin ultimate-viral-quiz Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0 CVE-2025-10302 Wordfence
4.3 Medium AP Background Plugin ap-background Cross-Site Request Forgery No login needed ≤ 3.8.2 CVE-2025-9897 Wordfence
4.3 Medium Notification Bar Plugin simple-bar Cross-Site Request Forgery No login needed ≤ 2.2 CVE-2025-9895 Wordfence
4.3 Medium ContentMX Content Publisher Plugin contentmx-content-publisher Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-9889 Wordfence
4.3 Medium WP SinoType Plugin wp-sinotype Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9630 Wordfence
4.3 Medium Customify Theme customify Cross-Site Request Forgery No login needed ≤ 0.4.11 CVE-2025-8669 Wordfence
5.3 Medium Restrict User Registration Plugin restrict-user-registration Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.1 CVE-2025-9892 Wordfence
4.3 Medium PayPal Forms Plugin paypal-forms Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-10309 Wordfence
4.3 Medium Optimize More! – CSS Plugin optimize-more-css Cross-Site Request Forgery CSS <= 1.0.3 - Cross-Site Request Forgery to Plugin Settings Reset No login needed ≤ 1.0.3 CVE-2025-9945 Wordfence
6.1 Medium Mobile Site Redirect Plugin mobile-site-redirect Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2.1 CVE-2025-9884 Wordfence
4.3 Medium MPWizard – Create Mercado Pago Payment Links Plugin mpwizard Cross-Site Request Forgery Create Mercado Pago Payment Links <= 1.2.1 - Cross-Site Request Forgery to Arbitrary Post Deletion No login needed ≤ 1.2.1 CVE-2025-9885 Wordfence
9.8 Critical RestroPress – Online Food Ordering System Plugin restropress Information Disclosure Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT No login needed 3.0.0 – 3.1.9.2 CVE-2025-9209 Wordfence
4.3 Medium Comment Info Detector Plugin comment-info-detector Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.5 CVE-2025-10311 Wordfence
8.8 High TextBuilder Plugin textbuilder Cross-Site Request Forgery Cross-Site Request Forgery to Privilege Escalation via Account Takeover No login needed 1.0.0 – 1.1.1 CVE-2025-9213 Wordfence
4.0 Medium Block For Mailchimp – Easy Mailchimp Form Integration Plugin block-for-mailchimp Server-Side Request Forgery Easy Mailchimp Form Integration <= 1.1.12 - Unauthenticated Blind Server-Side Request Forgery No login needed ≤ 1.1.12 CVE-2025-10735 Wordfence
8.8 High LatePoint Plugin latepoint Cross-Site Request Forgery Cross-Site Request Forgery to Account Takeover via change_password() Function No login needed ≤ 5.1.94 CVE-2025-7052 Wordfence
6.1 Medium LockerPress – WordPress Security Plugin lockerpress-wordpress-security Cross-Site Request Forgery WordPress Security Plugin <= 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.0 CVE-2025-9946 Wordfence
4.3 Medium Chat by Chatwee Plugin chatwee Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.1.3 CVE-2025-9948 Wordfence
4.3 Medium VM Menu Reorder Plugin vm-menu-reorder Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.0 CVE-2025-9893 Wordfence
4.3 Medium Professional Contact Form Plugin professional-contact-form Cross-Site Request Forgery Cross-Site Request Forgery to Test Email Sending No login needed ≤ 1.0.0 CVE-2025-9944 Wordfence
4.3 Medium cForms – Light speed fast Form Builder Plugin cforms-plugin Cross-Site Request Forgery Light speed fast Form Builder <= 3.0.0 - Cross-Site Request Forgery No login needed ≤ 3.0.0 CVE-2025-9898 Wordfence
6.1 Medium Trust Reviews plugin for Google, Tripadvisor, Yelp, Airbnb and other platforms Plugin trust-reviews Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-9899 Wordfence
4.3 Medium Sync Feedly Plugin sync-feedly Cross-Site Request Forgery Cross-Site Request Forgery to Sync Trigger No login needed ≤ 1.0.1 CVE-2025-9894 Wordfence
4.3 Medium HidePost Plugin hidepost Cross-Site Request Forgery No login needed ≤ 2.3.8 CVE-2025-9896 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Limited File Deletion No login needed ≤ 3.12.0 CVE-2025-10498 Wordfence
4.3 Medium Ninja Forms – The Contact Form Builder That Grows With You Plugin ninja-forms Cross-Site Request Forgery The Contact Form Builder That Grows With You <= 3.12.0 - Cross-Site Request Forgery to Plugin Settings Update No login needed ≤ 3.12.0 CVE-2025-10499 Wordfence
5.4 Medium Silencesoft RSS Reader Plugin external-rss-reader Server-Side Request Forgery No login needed ≤ 0.6 CVE-2025-60181 Patchstack
7.1 High GST for WooCommerce Plugin gst-for-woocommerce Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-60173 Patchstack
7.1 High Flytedesk Digital Plugin flytedesk-digital Cross-Site Request Forgery No login needed ≤ 20181101 CVE-2025-60172 Patchstack
7.1 High Conditional Cart Messages for WooCommerce – YourPlugins.com Plugin yourplugins-wc-conditional-cart-notices Cross-Site Request Forgery YourPlugins.com Plugin <= 1.2.10 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.2.10 CVE-2025-60171 Patchstack
7.1 High HTACCESS IP Blocker Plugin htaccess-ip-blocker Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-60170 Patchstack
7.1 High W3SCloud Contact Form 7 to Zoho CRM Plugin w3s-cf7-zoho Cross-Site Request Forgery No login needed ≤ 3.2 CVE-2025-60169 Patchstack
7.1 High NewsmanApp Plugin newsmanapp Cross-Site Request Forgery No login needed ≤ 2.7.7 Fixed in 3.0.0 CVE-2025-60164 Patchstack
5.4 Medium ZoloBlocks Plugin zoloblocks Server-Side Request Forgery No login needed ≤ 2.3.11 Fixed in 2.3.12 CVE-2025-60161 Patchstack
9.6 Critical AR Plugin ar-for-wordpress Cross-Site Request Forgery No login needed ≤ 8.34 CVE-2025-60156 Patchstack
4.3 Medium Lenix scss compiler Plugin lenix-scss-compiler Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-60145 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only