WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,201–8,250 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 165 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WebHotelier Plugin webhotelier Cross-Site Scripting ≤ 1.9.2 Fixed in 1.10.0 CVE-2025-49299 Patchstack
6.5 Medium Event post Plugin event-post Cross-Site Scripting ≤ 5.10.1 Fixed in 5.10.2 CVE-2025-49298 Patchstack
5.3 Medium Crawlomatic Multisite Scraper Post Generator Plugin crawlomatic-multipage-scraper-post-generator Information Disclosure Sensitive Data Exposure via Log Exposure No login needed ≤ 2.6.8.2 Fixed in 2.6.9 CVE-2025-49294 Patchstack
4.3 Medium Crawlomatic Multisite Scraper Post Generator Plugin crawlomatic-multipage-scraper-post-generator Broken Access Control ≤ 2.6.8.2 Fixed in 2.6.9 CVE-2025-49293 Patchstack
4.3 Medium Profile Builder Plugin profile-builder Content Injection Content Spoofing No login needed ≤ 3.13.8 Fixed in 3.13.9 CVE-2025-49292 Patchstack
4.3 Medium Calculated Fields Form Plugin calculated-fields-form Cross-Site Request Forgery No login needed ≤ 5.3.58 Fixed in 5.3.59 CVE-2025-49291 Patchstack
5.0 Medium PDF for WPForms Plugin pdf-for-wpforms Broken Access Control ≤ 5.5.0 Fixed in 5.6.1 CVE-2025-49289 Patchstack
8.8 High Ultimate WP Mail Plugin ultimate-wp-mail Privilege Escalation Account Takeover via Email Log Leak ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-49288 Patchstack
4.3 Medium Product Feed for WooCommerce Plugin webtoffee-product-feed Broken Access Control ≤ 2.2.8 Fixed in 2.2.9 CVE-2025-49287 Patchstack
4.3 Medium WP Table Builder Plugin wp-table-builder Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.7 CVE-2025-49286 Patchstack
4.3 Medium WP Cookie Notice for GDPR, CCPA & ePrivacy Consent Plugin gdpr-cookie-consent Cross-Site Request Forgery No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-49285 Patchstack
4.3 Medium WP Maintenance Mode & Site Under Construction Plugin wp-maintenance-mode-site-under-construction Cross-Site Request Forgery No login needed ≤ 4.3 Fixed in 4.4 CVE-2025-49284 Patchstack
4.3 Medium Anti-spam, Spam protection, ReCaptcha for all forms and GDPR-compliant Plugin gdpr-compliant-recaptcha-for-all-forms Cross-Site Request Forgery No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-49283 Patchstack
4.3 Medium WP Tools Plugin wptools Cross-Site Request Forgery No login needed ≤ 5.24 Fixed in 5.25 CVE-2025-49273 Patchstack
4.3 Medium Trinity Audio Plugin trinity-audio Broken Access Control ≤ 5.20.0 Fixed in 5.20.1 CVE-2025-49272 Patchstack
5.3 Medium WP-CRM System Plugin wp-crm-system Broken Access Control No login needed ≤ 3.4.2 Fixed in 3.4.3 CVE-2025-49270 Patchstack
4.3 Medium Market Exporter Plugin market-exporter Cross-Site Request Forgery No login needed ≤ 2.0.22 Fixed in 2.0.23 CVE-2025-49269 Patchstack
5.3 Medium Verge3D Plugin verge3d Broken Access Control No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2025-49268 Patchstack
7.6 High WC Vendors Marketplace Plugin wc-vendors SQL Injection ≤ 2.5.6 Fixed in 2.5.7 CVE-2025-49263 Patchstack
7.6 High Sina Extension for Elementor Plugin sina-extension-for-elementor Cross-Site Scripting ≤ 3.6.1 Fixed in 3.7.0 CVE-2025-49262 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Arbitrary Shortcode Execution ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49250 Patchstack
4.3 Medium Team Showcase Plugin team-showcase-cm Broken Access Control ≤ 25.05.13 Fixed in 25.05.13 CVE-2025-49248 Patchstack
4.3 Medium Testimonials Showcase Plugin testimonials-showcase Broken Access Control ≤ 1.9.16 Fixed in 1.9.18 CVE-2025-49246 Patchstack
6.5 Medium Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting ≤ 7.3.5 Fixed in 7.4.0 CVE-2025-49244 Patchstack
6.5 Medium ShiftNav – Responsive Mobile Menu Plugin shiftnav-responsive-mobile-menu Cross-Site Scripting Responsive Mobile Menu plugin <= 1.8 - Cross Site Scripting (XSS) ≤ 1.8 Fixed in 1.8.1 CVE-2025-49243 Patchstack
6.5 Medium Bellows Accordion Menu Plugin bellows-accordion-menu Cross-Site Scripting ≤ 1.4.3 Fixed in 1.4.4 CVE-2025-49242 Patchstack
5.3 Medium oik Plugin oik Broken Access Control No login needed ≤ 4.15.1 Fixed in 4.15.2 CVE-2025-49241 Patchstack
4.3 Medium DocsPress Plugin docspress Broken Access Control ≤ 2.5.2 Fixed in 2.5.3 CVE-2025-49240 Patchstack
5.4 Medium Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Cross-Site Request Forgery No login needed ≤ 5.5.0 Fixed in 5.6.0 CVE-2025-49239 Patchstack
4.3 Medium Everest Backup Plugin everest-backup Cross-Site Request Forgery No login needed ≤ 2.3.3 Fixed in 2.3.4 CVE-2025-49238 Patchstack
7.4 High POEditor Plugin poeditor Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 0.9.10 Fixed in 0.9.11 CVE-2025-49237 Patchstack
5.3 Medium Raychat Plugin raychat Broken Access Control No login needed ≤ 2.1.0 Fixed in 2.2.0 CVE-2025-49236 Patchstack
6.5 Medium RTMKit Plugin rometheme-for-elementor Cross-Site Scripting ≤ 1.6.0 Fixed in 1.6.1 CVE-2025-49235 Patchstack
9.8 Critical Mr. Murphy Theme mr-murphy PHP Object Injection No login needed ≤ 1.2.12.1 Fixed in 1.2.12.1 CVE-2025-49072 Patchstack
9.8 Critical Sweet Dessert Theme sweet-dessert PHP Object Injection No login needed ≤ 1.1.13 Fixed in 1.1.13 CVE-2025-49073 Patchstack
7.1 High Real Time Validation for Gravity Forms Plugin real-time-validation-for-gravity-forms Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.7.0 CVE-2025-48329 Patchstack
8.8 High WP Posts Carousel Plugin wp-posts-carousel PHP Object Injection ≤ 1.3.12 Fixed in 1.3.13 CVE-2025-39358 Patchstack
8.5 High Photography Theme photography PHP Object Injection ≤ 7.5.2 CVE-2025-47584 Patchstack
9.0 Critical Motors - Events Plugin stm-motors-events Local File Inclusion Events plugin <= 1.4.7 - Unauthenticated Local File Inclusion No login needed ≤ 1.4.7 CVE-2025-47586 Patchstack
5.4 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control ≤ 3.2.0 Fixed in 3.2.1 CVE-2025-48335 Patchstack
4.3 Medium Real Time Validation for Gravity Forms Plugin real-time-validation-for-gravity-forms Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.7.0 CVE-2025-48328 Patchstack
6.5 Medium The Plus Addons for Elementor Page Builder Lite Plugin the-plus-addons-for-elementor-page-builder Cross-Site Scripting ≤ 6.2.7 Fixed in 6.2.8 CVE-2025-49076 Patchstack
6.5 Medium Wishlist Plugin wishlist Cross-Site Scripting ≤ 1.0.43 Fixed in 1.0.44 CVE-2025-49075 Patchstack
6.5 Medium WidgetKit Plugin widgetkit-for-elementor Cross-Site Scripting ≤ 2.5.4 Fixed in 2.5.5 CVE-2025-49074 Patchstack
6.5 Medium Ocean Extra Plugin ocean-extra Cross-Site Scripting ≤ 2.4.8 Fixed in 2.4.9 CVE-2025-49068 Patchstack
6.5 Medium Nasa Core Plugin nasa-core Cross-Site Scripting ≤ 6.4.1 Fixed in 6.4.1 CVE-2025-49067 Patchstack
4.3 Medium Dynamic Pricing and Discount Rules Plugin discount-and-dynamic-pricing Cross-Site Request Forgery No login needed ≤ 2.2.9 Fixed in 2.3.0 CVE-2025-49077 Patchstack
5.3 Medium QuickCab Plugin quickcab Broken Access Control No login needed ≤ 1.3.3 CVE-2025-48337 Patchstack
6.4 Medium WordPress Ajax Load More and Infinite Scroll Plugin cpt-ajax-load-more Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter ≤ 1.6.0 CVE-2025-5586 Wordfence
6.4 Medium ESV Bible Shortcode Plugin esv-bible-shortcode-for-wordpress Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.0.2 CVE-2025-5534 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only