WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 751–800 of 1,492 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 16 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Rewrite Plugin rewrite Cross-Site Request Forgery No login needed ≤ 0.2.1 CVE-2025-30617 Patchstack
4.3 Medium Flipdish Ordering System Plugin flipdish-ordering-system Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.5.2 CVE-2025-30601 Patchstack
4.3 Medium OSS Upload Plugin oss-upload Cross-Site Request Forgery WordPress OSS Upload plugin <= 4.8.9 Cross Site Request Forgery (CSRF) No login needed ≤ 4.8.9 CVE-2025-30598 Patchstack
4.3 Medium Generate Post Thumbnails Plugin generate-post-thumbnails Cross-Site Request Forgery No login needed ≤ 0.8 CVE-2025-30585 Patchstack
4.3 Medium Hacklog Remote Image Autosave Plugin hacklog-remote-image-autosave Cross-Site Request Forgery No login needed ≤ 2.1.0 CVE-2025-30576 Patchstack
4.3 Medium Super Static Cache Plugin super-static-cache Cross-Site Request Forgery No login needed ≤ 3.3.5 CVE-2025-30568 Patchstack
4.3 Medium Easy 301 Redirects Plugin odihost-easy-redirect-301 Cross-Site Request Forgery No login needed ≤ 1.33 CVE-2025-30557 Patchstack
4.3 Medium Fix Rss Feeds Plugin fix-rss-feed Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-30556 Patchstack
4.3 Medium Yummly Rich Recipes Plugin yummly-rich-recipes Cross-Site Request Forgery No login needed ≤ 4.2 CVE-2025-30549 Patchstack
4.3 Medium Cackle Plugin cackle Cross-Site Request Forgery No login needed ≤ 4.33 CVE-2025-30546 Patchstack
4.3 Medium SoundCloud Ultimate Plugin soundcloud-ultimate Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30542 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack
4.3 Medium Simple Optimizer Plugin simple-optimizer Cross-Site Request Forgery No login needed ≤ 1.2.7 CVE-2025-30538 Patchstack
4.3 Medium External image replace Plugin external-image-replace Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.8 CVE-2025-30535 Patchstack
4.3 Medium Image Captcha Plugin image-captcha Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.2 CVE-2025-30534 Patchstack
4.3 Medium WP Ride Booking Plugin wp-ride-booking Cross-Site Request Forgery No login needed ≤ 2.4 CVE-2025-30531 Patchstack
4.3 Medium Auto Load Next Post Plugin auto-load-next-post Cross-Site Request Forgery No login needed ≤ 1.5.14 CVE-2025-30529 Patchstack
4.3 Medium Typekit Plugin typekit Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-30526 Patchstack
4.3 Medium GP Back To Top Plugin gp-back-to-top Cross-Site Request Forgery No login needed ≤ 3.0 CVE-2025-30521 Patchstack
6.5 Medium Recapture for WooCommerce Plugin recapture-for-woocommerce Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-26899 Patchstack
4.3 Medium ZipList Recipe Plugin ziplist-recipe-plugin Cross-Site Request Forgery No login needed ≤ 3.1 CVE-2025-28868 Patchstack
4.3 Medium Spam Byebye Plugin spam-byebye Cross-Site Request Forgery No login needed ≤ 2.2.4 CVE-2025-28941 Patchstack
4.3 Medium Back To Top Plugin backtotop Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28940 Patchstack
4.3 Medium WP Performance Pack Plugin wp-performance-pack Broken Access Control ≤ 2.5.3 Fixed in 2.5.4 CVE-2025-28938 Patchstack
4.3 Medium Display Template Name Plugin display-template-name Cross-Site Request Forgery No login needed ≤ 1.7.1 CVE-2025-28927 Patchstack
4.3 Medium WP Add Active Class To Menu Item Plugin wp-add-active-class-to-menu-item Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28913 Patchstack
4.3 Medium Custom Dashboard Page Plugin custom-dashboard-page Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28912 Patchstack
4.3 Medium WP Hide Admin Bar Plugin wp-hide-admin-bar Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-28910 Patchstack
4.3 Medium WP No-Bot Question Plugin wp-no-bot-question Cross-Site Request Forgery No login needed ≤ 0.1.7 CVE-2025-28909 Patchstack
4.3 Medium Contact Form 7 Select Box Editor Button Plugin contact-form-7-select-box-editor-button Cross-Site Request Forgery No login needed ≤ 0.6 CVE-2025-28902 Patchstack
4.3 Medium Plugins Last Updated Column Plugin plugins-last-updated-column Cross-Site Request Forgery No login needed ≤ 0.1.3 Fixed in 0.1.4 CVE-2025-28887 Patchstack
4.3 Medium REST API TO MiniProgram Plugin rest-api-to-miniprogram Cross-Site Request Forgery No login needed ≤ 5.1.2 CVE-2025-28886 Patchstack
4.3 Medium WP Bulk Post Duplicator Plugin wp-bulk-post-duplicator Cross-Site Request Forgery No login needed ≤ 1.2 CVE-2025-28884 Patchstack
4.3 Medium Mobile Themes Plugin wp-mobile-themes Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28881 Patchstack
4.3 Medium Skrill Official Plugin official-skrill-woocommerce Cross-Site Request Forgery No login needed ≤ 1.0.66 Fixed in 1.0.67 CVE-2025-28876 Patchstack
4.3 Medium Frontpage category filter Plugin frontpage-category-filter Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-28867 Patchstack
4.3 Medium Login Logger Plugin login-logger Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-28866 Patchstack
4.3 Medium Builder for Contact Form 7 by Webconstruct Plugin cf7-builder Cross-Site Request Forgery No login needed ≤ 1.2.2 CVE-2025-28864 Patchstack
4.3 Medium Delete Original Image Plugin delete-original-image Cross-Site Request Forgery No login needed ≤ 0.4 CVE-2025-28863 Patchstack
4.3 Medium Comment Date and Gravatar remover Plugin remove-date-and-gravatar-under-comment Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-28862 Patchstack
4.3 Medium Maintenance Notice Plugin maintenance-notice Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-28859 Patchstack
4.3 Medium W3Counter Free Real-Time Web Stats Plugin blog-stats-by-w3counter Cross-Site Request Forgery No login needed ≤ 4.1 CVE-2025-28856 Patchstack
4.3 Medium XV Random Quotes Plugin xv-random-quotes Cross-Site Request Forgery Settings Reset via CSRF No login needed ≤ 1.40 CVE-2024-13580 WPScan
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Cross-Site Request Forgery Drag and Drop website builder <= 1.9.8 - Cross-Site Request Forgery (CSRF) To Post Contents Modification No login needed ≤ 1.9.8 CVE-2025-1926 Wordfence
6.1 Medium Contact Us By Lord Linus Plugin Cross-Site Scripting Admin+ Stored XSS via CSRF No login needed ≤ 2.6 CVE-2025-1382 WPScan
4.3 Medium easy-broken-link-checker Plugin Cross-Site Request Forgery Bulk Actions via CSRF ≤ 9.0.2 CVE-2025-1362 WPScan
5.4 Medium Email Keep Plugin Cross-Site Request Forgery Email Deletion via CSRF ≤ 1.1 CVE-2024-13826 WPScan
5.4 Medium Theme Options Z Plugin theme-options-z Cross-Site Request Forgery No login needed ≤ 1.4 CVE-2025-25121 Patchstack
4.3 Medium Admin Menu Manager Plugin admin-menu-manager Cross-Site Request Forgery No login needed ≤ 1.0.3 CVE-2025-26925 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only