WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,151–8,200 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 164 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium Nexa Blocks Plugin nexa-blocks Cross-Site Scripting ≤ 1.1.0 CVE-2025-30952 Patchstack
6.5 Medium BlockStrap Page Builder - Bootstrap Blocks Plugin blockstrap-page-builder-blocks Cross-Site Scripting Bootstrap Blocks plugin <= 0.1.36 - Cross Site Scripting (XSS) ≤ 0.1.36 Fixed in 0.1.37 CVE-2025-30951 Patchstack
6.5 Medium All Currencies for WooCommerce Plugin woocommerce-all-currencies Cross-Site Scripting ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-30950 Patchstack
4.7 Medium WP Gravity Forms Constant Contact Plugin gf-constant-contact Open Redirect No login needed ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-30954 Patchstack
4.7 Medium WP Gravity Forms Salesforce Plugin gf-salesforce-crmperks Open Redirect No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-30953 Patchstack
5.4 Medium Activity Plus Reloaded for BuddyPress Plugin bp-activity-plus-reloaded Broken Access Control ≤ 1.1.2 CVE-2025-30957 Patchstack
4.3 Medium Booqable Rental Plugin booqable-rental-reservations Cross-Site Request Forgery No login needed ≤ 2.4.25 CVE-2025-30956 Patchstack
5.4 Medium Advanced Post List Plugin advanced-post-list Cross-Site Request Forgery No login needed ≤ 0.5.6.2 CVE-2025-30968 Patchstack
5.4 Medium onOffice for WP-Websites Plugin onoffice-for-wp-websites Broken Access Control ≤ 6.5.1 Fixed in 6.10 CVE-2025-30958 Patchstack
4.9 Medium Nexa Blocks Plugin nexa-blocks Server-Side Request Forgery ≤ 1.1.1 CVE-2025-30976 Patchstack
4.3 Medium Post Grid Master Plugin ajax-filter-posts Broken Access Control ≤ 3.4.17 CVE-2025-30974 Patchstack
4.3 Medium Slack Notifications by dorzki Plugin dorzki-notifications-to-slack Broken Access Control ≤ 2.0.7 CVE-2025-30978 Patchstack
5.9 Medium Chaport Plugin chaport Cross-Site Scripting ≤ 1.1.6 Fixed in 1.1.7 CVE-2025-30977 Patchstack
6.3 Medium WP-Recall Plugin wp-recall Cross-Site Request Forgery CSRF to Privilege Escalation No login needed ≤ 16.26.14 CVE-2025-30981 Patchstack
4.3 Medium Simple Keyword to Link Plugin simple-keyword-to-link Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-30980 Patchstack
7.6 High Libro de Reclamaciones y Quejas Plugin libro-de-reclamaciones-y-quejas SQL Injection ≤ 0.9 Fixed in 1.0 CVE-2025-30989 Patchstack
5.4 Medium Elite Video Player Plugin elite-video-player Cross-Site Request Forgery No login needed ≤ 10.0.5 CVE-2025-30986 Patchstack
6.5 Medium WPDM – Premium Packages Plugin wpdm-premium-packages Cross-Site Scripting ≤ 6.0.6 Fixed in 6.0.7 CVE-2025-30991 Patchstack
4.3 Medium ThemeHunk Plugin themehunk-megamenu-plus Broken Access Control ≤ 1.2.0 CVE-2025-30990 Patchstack
4.3 Medium CubeWP Plugin cubewp-framework Cross-Site Request Forgery No login needed ≤ 1.1.29 CVE-2025-30994 Patchstack
7.1 High Widgetize Pages Light Plugin widgetize-pages-light Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 3.0 CVE-2025-30995 Patchstack
5.4 Medium Car Repair Services Plugin car-repair-services Server-Side Request Forgery No login needed ≤ 5.0 CVE-2025-30997 Patchstack
5.3 Medium Payment QR WooCommerce Plugin payment-qr-woo Broken Access Control No login needed ≤ 1.1.6 CVE-2025-31000 Patchstack
7.5 High External Store for Shopify Plugin wp-shopify Local File Inclusion ≤ 1.5.9 Fixed in 1.6.0 CVE-2025-30999 Patchstack
5.9 Medium Simple Membership Plugin simple-membership Cross-Site Scripting ≤ 4.6.3 Fixed in 4.6.4 CVE-2025-49333 Patchstack
6.5 Medium Image Hover Effects Block Plugin image-hover-effects-block Cross-Site Scripting ≤ 1.4.5 CVE-2025-31025 Patchstack
4.3 Medium WP Time Slots Booking Form Plugin wp-time-slots-booking-form Cross-Site Request Forgery No login needed ≤ 1.2.30 Fixed in 1.2.31 CVE-2025-49332 Patchstack
6.6 Medium Store Locator Plugin agile-store-locator Arbitrary File Upload ≤ 1.5.2 Fixed in 1.5.3 CVE-2025-49329 Patchstack
7.6 High Store Locator Plugin agile-store-locator SQL Injection ≤ 1.5.1 Fixed in 1.5.2 CVE-2025-49328 Patchstack
7.6 High ShortLinks Pro Plugin shortlinkspro SQL Injection ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-49327 Patchstack
7.6 High GamiPress Plugin gamipress SQL Injection ≤ 7.4.5 Fixed in 7.4.6 CVE-2025-49326 Patchstack
4.7 Medium Newspack Newsletters Plugin newspack-newsletters Open Redirect No login needed ≤ 3.13.0 Fixed in 3.14.0 CVE-2025-49325 Patchstack
5.3 Medium Job Board Manager Plugin job-board-manager Broken Access Control No login needed ≤ 2.1.60 Fixed in 2.1.61 CVE-2025-49324 Patchstack
8.5 High Hydra Booking Plugin hydra-booking SQL Injection ≤ 1.1.10 Fixed in 1.1.11 CVE-2025-49323 Patchstack
5.9 Medium 404 Page by SeedProd Plugin 404-page Cross-Site Scripting < 1.0.2 Fixed in 1.0.2 CVE-2025-49322 Patchstack
5.3 Medium FraudLabs Pro for WooCommerce Plugin fraudlabs-pro-for-woocommerce Broken Access Control No login needed ≤ 2.22.11 Fixed in 2.22.12 CVE-2025-49320 Patchstack
5.9 Medium WPtouch Plugin wptouch Cross-Site Scripting ≤ 4.3.60 Fixed in 4.3.61 CVE-2025-49318 Patchstack
4.3 Medium WP Page Loading Plugin wp-page-loading Cross-Site Request Forgery No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-49317 Patchstack
7.6 High Persian Woocommerce SMS Plugin persian-woocommerce-sms SQL Injection ≤ 7.0.10 Fixed in 7.1.0 CVE-2025-49315 Patchstack
6.5 Medium BRW Plugin ova-brw Cross-Site Scripting ≤ 1.8.6 Fixed in 1.8.7 CVE-2025-49314 Patchstack
7.5 High BRW Plugin ova-brw Local File Inclusion ≤ 1.8.6 Fixed in 1.8.7 CVE-2025-49313 Patchstack
6.5 Medium The Events Calendar Countdown Addon Plugin countdown-for-the-events-calendar Cross-Site Scripting ≤ 1.4.9 Fixed in 1.4.10 CVE-2025-49311 Patchstack
6.5 Medium Frontend Dashboard Plugin frontend-dashboard Cross-Site Scripting ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-49310 Patchstack
6.5 Medium HT Team Member Plugin ht-team-member Cross-Site Scripting ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-49309 Patchstack
7.5 High WP Travel Engine Plugin wp-travel-engine Local File Inclusion ≤ 6.5.1 Fixed in 6.5.2 CVE-2025-49308 Patchstack
7.5 High WP Multilang Plugin wp-multilang Local File Inclusion ≤ 2.4.19 Fixed in 2.4.19.1 CVE-2025-49307 Patchstack
6.5 Medium WP Social Widget Plugin wp-social-widget Cross-Site Scripting ≤ 2.3 Fixed in 2.3.1 CVE-2025-49306 Patchstack
6.5 Medium Product Catalog Simple Plugin post-type-x Cross-Site Scripting ≤ 1.8.1 Fixed in 1.8.2 CVE-2025-49305 Patchstack
6.5 Medium Search with Typesense Plugin search-with-typesense Cross-Site Scripting ≤ 2.0.10 Fixed in 2.0.11 CVE-2025-49304 Patchstack
6.5 Medium Greenshift Plugin greenshift-animation-and-page-builder-blocks Cross-Site Scripting ≤ 11.5.5 Fixed in 11.5.7 CVE-2025-49301 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only