WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,051–8,100 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 162 of 345
Severity Component Vulnerability Affected versions Published CVE Source
8.6 High WP Pipes Plugin wp-pipes Arbitrary File Deletion No login needed ≤ 1.4.2 Fixed in 1.4.3 CVE-2025-48267 Patchstack
7.1 High WC MyParcel Belgium Plugin wc-myparcel-belgium Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed 4.5.5 – beta Fixed in 4.5.6 CVE-2025-48279 Patchstack
7.5 High Membership For WooCommerce Plugin membership-for-woocommerce Broken Access Control No login needed ≤ 2.8.1 Fixed in 2.8.2 CVE-2025-49265 Patchstack
9.3 Critical MyStyle Custom Product Designer Plugin mystyle-custom-product-designer SQL Injection No login needed ≤ 3.21.1 Fixed in 3.21.2 CVE-2025-48281 Patchstack
8.1 High Blogbyte Plugin blogbyte Local File Inclusion No login needed ≤ 1.1.1 Fixed in 1.1.2 CVE-2025-49275 Patchstack
8.1 High Blogmine Plugin blogmine Local File Inclusion No login needed ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-49276 Patchstack
8.1 High Blogty Plugin blogty Local File Inclusion No login needed ≤ 1.0.11 Fixed in 1.0.12 CVE-2025-49278 Patchstack
8.1 High Blogprise Plugin blogprise Local File Inclusion No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-49277 Patchstack
8.1 High Blogvy Plugin blogvy Local File Inclusion No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49279 Patchstack
8.1 High Magty Plugin magty Local File Inclusion No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-49280 Patchstack
8.1 High Magze Plugin magze Local File Inclusion No login needed ≤ 1.0.9 Fixed in 1.0.10 CVE-2025-49282 Patchstack
8.1 High Magways Plugin magways Local File Inclusion No login needed ≤ 1.2.1 Fixed in 1.2.2 CVE-2025-49281 Patchstack
8.1 High MediClinic Plugin mediclinic Local File Inclusion No login needed ≤ 2.1 Fixed in 2.2 CVE-2025-49295 Patchstack
8.1 High GrandPrix Plugin grandprix Local File Inclusion No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2025-49296 Patchstack
8.1 High Grill and Chow Plugin grillandchow Local File Inclusion No login needed ≤ 1.6 Fixed in 1.6.1 CVE-2025-49297 Patchstack
8.8 High MaxiBlocks Plugin maxi-blocks Privilege Escalation Arbitrary Option Update to Privilege Escalation ≤ 2.1.0 Fixed in 2.1.1 CVE-2025-47601 Patchstack
5.5 Medium Foxit eSign Plugin esign-genie-for-wp Information Disclosure Other Vulnerability Type ≤ 2.0.3 CVE-2025-49419 Patchstack
7.1 High Konami Easter Egg Plugin konami-easter-egg Cross-Site Request Forgery No login needed ≤ v0.4 CVE-2025-49425 Patchstack
7.6 High WP Text Expander Plugin wp-text-expander SQL Injection ≤ 1.0.1 CVE-2025-49421 Patchstack
6.5 Medium Video Embeds Plugin video-embeds Cross-Site Scripting ≤ 0.1.1 CVE-2025-49429 Patchstack
6.5 Medium Abbie Expander Plugin abbie-expander Cross-Site Scripting ≤ 1.0.1 CVE-2025-49427 Patchstack
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium Wp Easy Allopass Plugin wordpress-easy-allopass Cross-Site Request Forgery No login needed ≤ 4.1.1 CVE-2025-49435 Patchstack
5.3 Medium Interactive Regional Map of Florida Plugin interactive-map-of-florida Broken Access Control No login needed ≤ 1.0 CVE-2025-49441 Patchstack
4.3 Medium WP Security Master Plugin wp-security-master Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-49440 Patchstack
6.5 Medium Bacon Ipsum Plugin bacon-ipsum Cross-Site Scripting ≤ 2.4 CVE-2025-49443 Patchstack
6.5 Medium Simple Nested Menu Plugin simple-nested-menu Cross-Site Scripting ≤ 1.0 CVE-2025-49442 Patchstack
4.3 Medium Admin Notes Plugin admin-note Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49446 Patchstack
4.3 Medium Interactive UK Regional Map Plugin interactive-uk-regional-map Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0 CVE-2025-49445 Patchstack
6.5 Medium SEPA Girocode Plugin sepa-girocode Cross-Site Scripting ≤ 0.5.1 CVE-2025-49450 Patchstack
4.3 Medium Interactive Regional Map of Africa Plugin interactive-map-of-africa Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49449 Patchstack
7.1 High BP Profile as Homepage Plugin bp-profile-as-homepage Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.1 CVE-2025-49453 Patchstack
7.5 High AI Mortgage Calculator Plugin ai-mortgage-calculator Local File Inclusion ≤ 1.0.1 CVE-2023-25995 Patchstack
5.9 Medium Bang tinh vay Plugin bang-tinh-lai-suat Cross-Site Scripting ≤ 1.0.1 CVE-2023-26000 Patchstack
6.5 Medium Sola Support Ticket Plugin sola-support-tickets Broken Access Control Arbitrary Content Deletion ≤ 3.17 CVE-2023-25997 Patchstack
4.3 Medium 6Storage Rentals Plugin 6storage-rentals Broken Access Control ≤ 2.19.5 CVE-2023-26002 Patchstack
5.9 Medium Next Event Calendar Plugin next-event-calendar Cross-Site Scripting ≤ 1.2 CVE-2023-26001 Patchstack
5.3 Medium KI Live Video Conferences Plugin ki-live-video-conferences Information Disclosure Sensitive Data Exposure No login needed ≤ 5.5.15 CVE-2025-23969 Patchstack
7.6 High WP Post Corrector Plugin wp-post-corrector SQL Injection ≤ 1.0.2 CVE-2023-26003 Patchstack
5.4 Medium TicketBAI Facturas para WooCommerce Plugin wp-ticketbai Broken Access Control ≤ 3.45 CVE-2025-24762 Patchstack
5.3 Medium KI Live Video Conferences Plugin ki-live-video-conferences Broken Access Control No login needed ≤ 5.5.15 CVE-2025-23971 Patchstack
5.4 Medium Pay with Contact Form 7 Plugin pay-with-contact-form-7 Cross-Site Request Forgery No login needed ≤ 1.0.4 CVE-2025-24772 Patchstack
5.3 Medium bbPress API Plugin bbp-api Broken Access Control No login needed ≤ 1.0.14 CVE-2025-24763 Patchstack
5.4 Medium No Spam At All Plugin no-spam-at-all Broken Access Control ≤ 1.3 CVE-2025-24778 Patchstack
5.4 Medium Responsive Flipbooks Plugin responsive-flipbooks Broken Access Control ≤ 1.0 CVE-2025-24776 Patchstack
4.3 Medium FastBook Plugin fastbook-responsive-appointment-booking-and-scheduling-system Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-26593 Patchstack
7.6 High Complete Google Seo Scan Plugin complete-google-seo-scan SQL Injection ≤ 3.5.1 CVE-2025-26590 Patchstack
4.3 Medium WP Media File Type Manager Plugin wp-media-file-type-manager Cross-Site Request Forgery No login needed ≤ 2.3.1 CVE-2025-27359 Patchstack
6.5 Medium Simple Google Static Map Plugin simple-google-static-map Cross-Site Scripting ≤ 1.0.1 CVE-2025-27334 Patchstack
7.1 High Post Author Plugin post-author Cross-Site Request Forgery No login needed ≤ 1.1.1 CVE-2025-28950 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only