WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 801–850 of 1,928 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium My Wp Brand Plugin my-wp-brand Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-53269 Patchstack
4.3 Medium Import external attachments Plugin import-external-attachments Cross-Site Request Forgery No login needed ≤ 1.5.12 CVE-2025-53268 Patchstack
4.3 Medium Hide Admin Bar From Front End Plugin hide-admin-bar-from-front-end Cross-Site Request Forgery No login needed ≤ 1.0.0 CVE-2025-53267 Patchstack
5.4 Medium Virusdie Plugin virusdie Cross-Site Request Forgery No login needed ≤ 1.1.3 Fixed in 1.1.4 CVE-2025-53265 Patchstack
4.3 Medium ONet Regenerate Thumbnails Plugin onet-regenerate-thumbnails Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-53264 Patchstack
5.4 Medium Address Autocomplete via Google for Gravity Forms Plugin gf-google-address-autocomplete Cross-Site Request Forgery No login needed ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-53263 Patchstack
5.4 Medium Writesonic Plugin writesonic Cross-Site Request Forgery No login needed ≤ 1.0.5 Fixed in 1.0.6 CVE-2025-53262 Patchstack
4.3 Medium WP YouTube Live Plugin wp-youtube-live Cross-Site Request Forgery No login needed ≤ 1.10.0 Fixed in 1.10.1 CVE-2025-53261 Patchstack
4.3 Medium Cyrlitera Plugin cyrlitera Cross-Site Request Forgery No login needed ≤ 1.3.0 Fixed in 1.3.1 CVE-2025-53254 Patchstack
4.3 Medium WooCommerce PDF Invoice Builder Plugin woo-pdf-invoice-builder Cross-Site Request Forgery No login needed ≤ 1.2.148 Fixed in 1.2.149 CVE-2025-53203 Patchstack
4.3 Medium Cookiebot Plugin cookiebot Cross-Site Request Forgery No login needed ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-53197 Patchstack
4.3 Medium Burst Statistics Plugin burst-statistics Cross-Site Request Forgery No login needed ≤ 2.0.6 Fixed in 2.0.8 CVE-2025-53193 Patchstack
4.3 Medium DarkMySite Plugin darkmysite Cross-Site Request Forgery No login needed ≤ 1.2.8 Fixed in 1.2.9 CVE-2025-32281 Patchstack
4.3 Medium VR Calendar Plugin vr-calendar-sync Cross-Site Request Forgery Cross-Site Request Forgery to Calendar Sync No login needed ≤ 2.4.7 CVE-2025-5936 Wordfence
4.3 Medium Homerunner Plugin homerunner-smartcheckout Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.30 CVE-2025-5932 Wordfence
4.3 Medium ClipLink Plugin cliplink Cross-Site Request Forgery No login needed ≤ 1.1 CVE-2025-49964 Patchstack
4.3 Medium Oganro Travel Portal Search Widget for HotelBeds APITUDE API Plugin oganro-travel-portal-search-widget-for-hotelbeds-apitude-api Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49966 Patchstack
4.3 Medium PixelBeds Channel Manager and Hotel Booking Engine Plugin pixelbeds-channel-manager-booking-engine Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-49965 Patchstack
4.3 Medium XML Travel Portal Widget Plugin oganro-reservation-widget Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-49968 Patchstack
4.3 Medium Live Sports Streamthunder Plugin live-sports-streamthunder Cross-Site Request Forgery No login needed ≤ 2.1 CVE-2025-49967 Patchstack
4.3 Medium TM Replace Howdy Plugin tm-replace-howdy Cross-Site Request Forgery No login needed ≤ 1.4.2 CVE-2025-49972 Patchstack
4.3 Medium JobWP Plugin jobwp Cross-Site Request Forgery No login needed ≤ 2.4.0 Fixed in 2.4.1 CVE-2025-49975 Patchstack
4.3 Medium WP Inventory Manager Plugin wp-inventory-manager Cross-Site Request Forgery No login needed ≤ 2.3.4 Fixed in 2.3.5 CVE-2025-49977 Patchstack
4.9 Medium PowerPress Podcasting Plugin powerpress Server-Side Request Forgery ≤ 11.13.11 Fixed in 11.13.12 CVE-2025-49984 Patchstack
4.9 Medium WPThumb Plugin wp-thumb Server-Side Request Forgery ≤ 0.10 CVE-2025-49983 Patchstack
4.9 Medium Auto Upload Images Plugin auto-upload-images Server-Side Request Forgery ≤ 3.3.2 CVE-2025-49985 Patchstack
6.5 Medium Mailing Group Listserv Plugin wp-mailing-group Cross-Site Request Forgery No login needed ≤ 3.0.5 CVE-2025-50036 Patchstack
6.5 Medium Real Estate Manager Plugin real-estate-manager Cross-Site Request Forgery No login needed ≤ 7.3 CVE-2025-50044 Patchstack
6.4 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Server-Side Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Server Side Request Forgery (SSRF) ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52713 Patchstack
4.3 Medium Post and Page Builder by BoldGrid Plugin post-and-page-builder Cross-Site Request Forgery Visual Drag and Drop Editor plugin <= 1.27.8 - Cross Site Request Forgery (CSRF) No login needed ≤ 1.27.8 Fixed in 1.27.9 CVE-2025-52711 Patchstack
4.3 Medium YITH PayPal Express Checkout for WooCommerce Plugin yith-paypal-express-checkout-for-woocommerce Cross-Site Request Forgery No login needed ≤ 1.49.0 Fixed in 1.49.1 CVE-2025-48111 Patchstack
4.3 Medium Responsive Plus Plugin responsive-add-ons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-49856 Patchstack
4.3 Medium Advanced Settings Plugin advanced-settings Cross-Site Request Forgery No login needed ≤ 3.0.1 Fixed in 3.0.2 CVE-2025-49865 Patchstack
4.9 Medium ProfileGrid Plugin profilegrid-user-profiles-groups-and-communities Server-Side Request Forgery ≤ 5.9.5.2 Fixed in 5.9.5.3 CVE-2025-49877 Patchstack
6.1 Medium XiSearch bar Plugin xisearch-bar Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 2.6 CVE-2025-6063 Wordfence
4.3 Medium Yougler Blogger Profile Page Plugin yougler-blogger-profile-page Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ v1.01 CVE-2025-6062 Wordfence
4.3 Medium AI Image Lab – Free AI Image Generator Plugin ai-image-generator-lab Cross-Site Request Forgery Free AI Image Generator <= 1.0.6 - Cross-Site Request Forgery to API Key Update No login needed ≤ 1.0.6 CVE-2025-4592 Wordfence
6.1 Medium Zen Sticky Social Plugin zen-social-sticky Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.3 CVE-2025-6055 Wordfence
6.1 Medium Easy Flashcards Plugin easy-flashcards Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.1 CVE-2025-6040 Wordfence
6.1 Medium WP URL Shortener Plugin wp-url-shortener Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 1.2 CVE-2025-6064 Wordfence
4.3 Medium Seraphinite Accelerator Plugin seraphinite-accelerator Cross-Site Request Forgery Cross-Site Request Forgery to Multiple Administrative Actions No login needed ≤ 2.27.21 CVE-2025-6059 Wordfence
4.3 Medium WP Sliding Login/Dashboard Panel Plugin wp-sliding-logindashboard-panel Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 2.1.1 CVE-2025-5928 Wordfence
5.3 Medium Digital Marketing and Agency Templates Addons for Elementor Plugin digital-marketing-agency-templates-for-elementor Cross-Site Request Forgery Cross-Site Request Forgery to Import No login needed ≤ 1.1.1 CVE-2025-5938 Wordfence
4.3 Medium WP2HTML Plugin wp2html Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 1.0.2 CVE-2025-5930 Wordfence
6.1 Medium Link Shield Plugin link-shield Cross-Site Request Forgery Cross-Site Request Forgery to Stored Cross-Site Scripting No login needed ≤ 0.5.4 CVE-2025-5926 Wordfence
4.3 Medium Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Request Forgery No login needed ≤ 5.1.0 Fixed in 5.1.1 CVE-2025-49510 Patchstack
4.3 Medium Bunny’s Print CSS Plugin bunnys-print-css Cross-Site Request Forgery Cross-Site Request Forgery to Settings Update No login needed ≤ 0.95 CVE-2025-5925 Wordfence
4.3 Medium Atelier Create CV Plugin atelier-create-cv Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.1.5 CVE-2025-49439 Patchstack
4.3 Medium Wp Easy Allopass Plugin wordpress-easy-allopass Cross-Site Request Forgery No login needed ≤ 4.1.1 CVE-2025-49435 Patchstack
4.3 Medium WP Security Master Plugin wp-security-master Cross-Site Request Forgery No login needed ≤ 1.0.2 CVE-2025-49440 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only