WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,314 vulnerabilities, 1,598 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 9, 2026.

Showing 801–850 of 1,493 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium ClickWhale Plugin clickwhale Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.4.3 Fixed in 2.4.4 CVE-2025-26963 Patchstack
4.3 Medium Booknetic Plugin booknetic Cross-Site Request Forgery No login needed ≤ 4.0.9 CVE-2025-26926 Patchstack
4.3 Medium Önceki Yazı Link Plugin onceki-yazi-linki Cross-Site Request Forgery No login needed ≤ 1.3 CVE-2025-27357 Patchstack
4.3 Medium Namaste! LMS Plugin namaste-lms Cross-Site Request Forgery No login needed ≤ 2.6.5 CVE-2025-27353 Patchstack
4.3 Medium Phee's LinkPreview Plugin linkpreview Cross-Site Request Forgery No login needed ≤ 1.6.7 CVE-2025-27344 Patchstack
4.3 Medium WooCommerce Recargo de Equivalencia Plugin woo-recargo-de-equivalencia Cross-Site Request Forgery No login needed ≤ 1.6.24 CVE-2025-27342 Patchstack
5.4 Medium F12-Profiler Plugin f12-profiler Cross-Site Request Forgery No login needed ≤ 1.3.9 Fixed in 1.4.0 CVE-2025-27340 Patchstack
4.3 Medium Minimum Password Strength Plugin minimum-password-strength Cross-Site Request Forgery No login needed ≤ 1.2.0 CVE-2025-27339 Patchstack
4.3 Medium Just Variables Plugin just-wp-variables Cross-Site Request Forgery No login needed ≤ 1.2.3 CVE-2025-27336 Patchstack
4.3 Medium Auto Tag Links Plugin auto-tag-links Cross-Site Request Forgery No login needed ≤ 1.0.13 CVE-2025-27335 Patchstack
4.3 Medium WP-PostRatings Cheater Plugin wp-postratings-cheater Cross-Site Request Forgery No login needed ≤ 1.5 CVE-2025-27328 Patchstack
4.3 Medium Simple Google Sitemap Plugin simple-google-sitemap Cross-Site Request Forgery No login needed ≤ 1.6 CVE-2025-27318 Patchstack
4.3 Medium RAYS Grid Plugin rays-grid Cross-Site Request Forgery No login needed ≤ 1.3.1 CVE-2025-27317 Patchstack
4.3 Medium JPG, PNG Compression and Optimization Plugin wp-image-compression Cross-Site Request Forgery No login needed ≤ 1.7.35 CVE-2025-27316 Patchstack
4.3 Medium All-In-One Cufon Plugin all-in-one-cufon Cross-Site Request Forgery No login needed ≤ 1.3.0 CVE-2025-27315 Patchstack
4.3 Medium Bulk Content Creator Plugin bulk-content-creator Cross-Site Request Forgery No login needed ≤ 1.2.1 CVE-2025-27311 Patchstack
4.3 Medium Erima Zarinpal Donate Plugin erima-zarinpal-donate Cross-Site Request Forgery No login needed ≤ 1.0 CVE-2025-27290 Patchstack
6.5 Medium Social Warfare Plugin social-warfare Cross-Site Scripting ≤ 4.5.5 Fixed in 4.5.6 CVE-2025-26973 Patchstack
4.3 Medium GlobalQuran Plugin globalquran Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 1.0 CVE-2025-25143 Patchstack
5.4 Medium Infusionsoft Analytics Plugin infusionsoft-web-tracker Cross-Site Request Forgery No login needed ≤ 2.0 CVE-2025-25145 Patchstack
4.3 Medium Songkick Concerts and Festivals Plugin songkick-concerts-and-festivals Cross-Site Request Forgery No login needed ≤ 0.9.7 Fixed in 0.10.0 CVE-2025-25146 Patchstack
4.3 Medium Indeed API Plugin indeed-api Cross-Site Request Forgery CSRF to Settings Change No login needed ≤ 0.5 CVE-2025-25103 Patchstack
5.4 Medium WP Spell Check Plugin wp-spell-check Cross-Site Request Forgery No login needed ≤ 9.21 Fixed in 9.22 CVE-2025-25111 Patchstack
6.1 Medium Child Themes Helper Plugin child-themes-helper Cross-Site Request Forgery CSRF to Arbitrary File Deletion No login needed ≤ 2.2.7 CVE-2025-25093 Patchstack
4.7 Medium LikeBot – Decentralized like-system Plugin Cross-Site Scripting Decentralized like-system <= 0.85 - Admin+ Stored XSS via CSRF No login needed ≤ 0.85 CVE-2025-0522 WPScan
6.1 Medium WP Projects Portfolio with Client Testimonials Plugin Cross-Site Scripting Stored XSS via CSRF No login needed ≤ 3.0 CVE-2024-13115 WPScan
5.4 Medium Traveler Layout Essential For Elementor Plugin traveler-layout-essential-for-elementor Server-Side Request Forgery No login needed ≤ 1.4 Fixed in 1.4 CVE-2025-22701 Patchstack
6.5 Medium Powerful Auto Chat Plugin powers-triggers-of-woo-to-chat Cross-Site Scripting ≤ 1.9.8 CVE-2025-22292 Patchstack
4.6 Medium WP Finance Plugin Cross-Site Scripting Stored XSS via CSRF ≤ 1.3.6 CVE-2024-13096 WPScan
5.4 Medium Dynamic URL SEO Plugin dynamic-url-seo Cross-Site Request Forgery No login needed ≤ 1.0 Fixed in 1.2 CVE-2025-23985 Patchstack
5.4 Medium Oshine Modules Plugin oshine-modules Server-Side Request Forgery Unauthenticated Server Side Request Forgery (SSRF) No login needed ≤ 3.3.8 Fixed in 3.3.8 CVE-2024-44055 Patchstack
4.3 Medium Bulk Me Now Plugin Cross-Site Request Forgery Message Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12709 WPScan
4.3 Medium WP Go Maps Plugin wp-google-maps Cross-Site Request Forgery No login needed ≤ 9.0.40 Fixed in 9.0.41 CVE-2025-24742 Patchstack
4.3 Medium Coming Soon Page, Under Construction & Maintenance Mode by SeedProd Plugin coming-soon Cross-Site Request Forgery No login needed ≤ 6.18.9 Fixed in 6.18.10 CVE-2025-24540 Patchstack
5.4 Medium BuddyPress Groups Extras Plugin buddypress-groups-extras Cross-Site Request Forgery No login needed ≤ 3.6.10 Fixed in 3.7.0 CVE-2025-24538 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Cross-Site Request Forgery No login needed ≤ 6.7.0 Fixed in 6.7.1 CVE-2025-24537 Patchstack
5.4 Medium Responsive Slider by MetaSlider Plugin ml-slider Cross-Site Request Forgery No login needed ≤ 3.92.0 Fixed in 3.92.1 CVE-2025-24533 Patchstack
6.5 Medium Altra Side Menu Plugin Cross-Site Request Forgery Abitrary Menu Deletion via CSRF No login needed ≤ 2.0 CVE-2024-12774 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Bulk Delete via CSRF No login needed ≤ 8.2.4 CVE-2024-12436 WPScan
4.3 Medium WP Customer Area Plugin customer-area Cross-Site Request Forgery Event Log Deletion via CSRF No login needed ≤ 8.2.4 CVE-2024-12280 WPScan
4.3 Medium Call Now Button Plugin call-now-button Cross-Site Request Forgery No login needed ≤ 1.4.13 Fixed in 1.4.14 CVE-2025-24738 Patchstack
4.3 Medium FluentSMTP Plugin fluent-smtp Cross-Site Request Forgery No login needed ≤ 2.2.80 Fixed in 2.2.81 CVE-2025-24739 Patchstack
5.4 Medium Side Menu Lite Plugin side-menu-lite Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 5.3.1 Fixed in 5.3.2 CVE-2025-24724 Patchstack
5.4 Medium Herd Effects Plugin mwp-herd-effect Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.2.1 Fixed in 6.2.2 CVE-2025-24716 Patchstack
5.4 Medium Modal Window Plugin modal-window Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 6.1.4 Fixed in 6.1.5 CVE-2025-24717 Patchstack
4.4 Medium Comment Edit Core – Simple Comment Editing Plugin simple-comment-editing Server-Side Request Forgery Simple Comment Editing Plugin <= 3.0.33 - Server Side Request Forgery (SSRF) ≤ 3.0.33 Fixed in 3.1.0 CVE-2025-24703 Patchstack
5.4 Medium Counter Box Plugin counter-box Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 2.0.5 Fixed in 2.0.6 CVE-2025-24715 Patchstack
5.4 Medium Button Generator – easily Button Builder Plugin button-generation Cross-Site Request Forgery easily Button Builder Plugin <= 3.1.1 - Cross Site Request Forgery (CSRF) No login needed ≤ 3.1.1 Fixed in 3.1.2 CVE-2025-24713 Patchstack
5.4 Medium Sticky Buttons Plugin sticky-buttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 4.1.1 Fixed in 4.1.2 CVE-2025-24720 Patchstack
4.3 Medium Attire Blocks Plugin attire-blocks Cross-Site Request Forgery No login needed ≤ 1.9.6 Fixed in 1.9.7 CVE-2025-24696 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only