WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,262 vulnerabilities, 1,570 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 8, 2026.

Showing 801–850 of 1,456 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 17 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Flickr Shortcode Importer Plugin flickr-shortcode-importer PHP Object Injection ≤ 2.2.3 CVE-2025-46481 Patchstack
6.4 Medium BeerXML Shortcode Plugin beerxml-shortcode Server-Side Request Forgery ≤ 0.7.1 Fixed in 0.8 CVE-2025-46511 Patchstack
6.5 Medium GNA Search Shortcode Plugin gna-search-shortcode Cross-Site Scripting ≤ 0.9.5 CVE-2025-46540 Patchstack
6.5 Medium Ocean Extra Plugin ocean-extra Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.4.6 CVE-2025-3472 Wordfence
6.4 Medium Ocean Extra Plugin oceanwp Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 2.4.6 CVE-2025-3457 Wordfence
7.1 High Arconix Shortcodes Plugin arconix-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.1.15 Fixed in 2.1.16 CVE-2025-24621 Patchstack
7.1 High Event Espresso – Custom Email Template Shortcode Plugin email-shortcode Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.0.0 CVE-2025-32507 Patchstack
7.1 High Cool Flipbox – Shortcode & Gutenberg Block Plugin flip-boxes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-32521 Patchstack
7.1 High bbPress2 shortcode whitelist Plugin bbpress2-shortcode-whitelist Cross-Site Request Forgery CSRF to XSS No login needed ≤ 2.2.1 CVE-2025-39432 Patchstack
6.5 Medium Rescue Shortcodes Plugin rescue-shortcodes Cross-Site Scripting ≤ 3.1 Fixed in 3.3 CVE-2025-39528 Patchstack
6.5 Medium Uix Shortcodes Plugin uix-shortcodes Cross-Site Scripting ≤ 2.0.4 Fixed in 2.0.5 CVE-2025-39574 Patchstack
6.5 Medium Themify Shortcodes Plugin themify-shortcodes Cross-Site Scripting ≤ 2.1.3 Fixed in 2.1.4 CVE-2025-39581 Patchstack
6.4 Medium User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor Plugin profile-builder Cross-Site Scripting Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.13.6 CVE-2025-2314 Wordfence
6.5 Medium Sign-up Sheets Plugin sign-up-sheets Content Injection Shortcode Injection No login needed ≤ 2.3.0.1 Fixed in 2.3.1 CVE-2025-26996 Patchstack
5.4 Medium Everest Forms Plugin everest-forms Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 3.1.1 CVE-2025-3422 Wordfence
7.3 High ORDER POST Plugin order-post Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.2 CVE-2025-2805 Wordfence
7.3 High azurecurve Shortcodes in Comments Plugin azurecurve-shortcodes-in-comments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 2.0.2 CVE-2025-2809 Wordfence
6.4 Medium ZoomSounds Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 6.91 CVE-2025-0839 Wordfence
6.5 Medium DobsonDev Shortcodes Plugin dobsondev-shortcodes Cross-Site Scripting Stored Cross Site Scripting (XSS) ≤ 2.1.12 CVE-2025-31754 Patchstack
6.5 Medium Author Bio Shortcode Plugin author-bio-shortcode Cross-Site Scripting ≤ 2.5.3 CVE-2025-31731 Patchstack
6.4 Medium Contempo Real Estate Core Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 3.6.3 CVE-2025-2906 Wordfence
4.8 Medium SP Blog Designer Plugin sp-blog-designer Arbitrary Shortcode Execution No login needed ≤ 1.0.0 CVE-2025-31606 Patchstack
6.5 Medium WP Date and Time Shortcode Plugin wp-date-and-time-shortcode Cross-Site Scripting ≤ 2.6.7 Fixed in 2.6.8 CVE-2025-31590 Patchstack
6.5 Medium Shortcodes by United Themes Plugin Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 5.1.6 CVE-2024-13557 Wordfence
7.3 High So-Called Air Quotes Plugin so-called-air-quotes Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 0.1 CVE-2025-2803 Wordfence
8.2 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to SQL Injection No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30788 Patchstack
7.1 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 5.25.08 Fixed in 5.25.10 CVE-2025-30787 Patchstack
5.4 Medium PDF for WPForms Plugin pdf-for-wpforms Arbitrary Shortcode Execution ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-30767 Patchstack
7.1 High Narnoo Operator Plugin narnoo-shortcodes Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 2.0.0 CVE-2025-23680 Patchstack
6.4 Medium Advanced Woo Search Plugin advanced-woo-search Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via aws_search_terms Shortcode ≤ 3.28 CVE-2025-2302 Wordfence
8.8 High EZ SQL Reports Shortcode Widget and DB Backup Plugin elisqlreports Cross-Site Request Forgery Cross-Site Request Forgery to Remote Code Execution No login needed 4.11.13 – 5.25.08 CVE-2025-2319 Wordfence
6.4 Medium DesignThemes Core Features Plugin Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 4.8 CVE-2025-0845 Wordfence
6.5 Medium IG Shortcodes Plugin ig-shortcodes Cross-Site Scripting WordPress IG Shortcodes plugin <= 3.1 Cross Site Scripting (XSS) ≤ 3.1 CVE-2025-30597 Patchstack
4.3 Medium Info Boxes Shortcode and Widget Plugin info-boxes-shortcode-and-widget Cross-Site Request Forgery No login needed ≤ 1.15 CVE-2025-30541 Patchstack
8.8 High s2Member Pro Plugin Local File Inclusion Authenticated (Contributor+) Local File Inclusion to Remote Code Execution via Shortcode ≤ 250214 CVE-2024-12563 Wordfence
7.3 High Logo Slider Plugin gs-logo-slider Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.7.3 CVE-2025-2262 Wordfence
6.5 Medium Ohio Extra Plugin ohio-extra Content Injection Shortcode Injection No login needed ≤ 3.4.7 CVE-2025-26924 Patchstack
7.3 High Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin simply-schedule-appointments Arbitrary Shortcode Execution Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.6.8.5 CVE-2025-1119 Wordfence
6.4 Medium CC-IMG-Shortcode Plugin cc-img-shortcode Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting ≤ 1.1.0 CVE-2025-1559 Wordfence
4.3 Medium Page Builder: Pagelayer – Drag and Drop website builder Plugin pagelayer Information Disclosure Drag and Drop website builder <= 1.9.8 - Authenticated (Contributor+) Private Post Disclosure in pagelayer_builder_posts_shortcode ≤ 1.9.8 CVE-2024-13430 Wordfence
7.3 High WPCS – WordPress Currency Switcher Professional Plugin currency-switcher Arbitrary Shortcode Execution WordPress Currency Switcher Professional <= 1.2.0.4 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 1.2.0.4 CVE-2025-2169 Wordfence
6.3 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Broken Access Control Registration, Profile, Commerce & More <= 16.26.10 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shortcode Exeuction ≤ 16.26.10 CVE-2025-1325 Wordfence
6.4 Medium WP-Recall – Registration, Profile, Commerce & More Plugin wp-recall Cross-Site Scripting Registration, Profile, Commerce & More <= 16.26.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ≤ 16.26.10 CVE-2025-1324 Wordfence
4.3 Medium Code Snippets CPT Plugin code-snippets-cpt Arbitrary Shortcode Execution Authenticated (Subscriber+) Arbitrary Shortcode Execution ≤ 2.1.0 CVE-2024-13895 Wordfence
6.5 Medium Shortcode Cleaner Lite Plugin shortcode-cleaner-lite Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Export ≤ 1.0.9 CVE-2025-1481 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_slider Shortcode ≤ 3.10.7 CVE-2024-11731 Wordfence
6.5 Medium Listingo - Business Listing and Directory Theme Arbitrary Shortcode Execution Business Listing and Directory WordPress Theme <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution No login needed ≤ 3.2.7 CVE-2024-13815 Wordfence
6.4 Medium Master Slider – Responsive Touch Slider Plugin master-slider Cross-Site Scripting Responsive Touch Slider <= 3.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via ms_layer Shortcode ≤ 3.10.6 CVE-2024-13757 Wordfence
6.4 Medium WP Shortcodes Plugin — Shortcodes Ultimate Plugin shortcodes-ultimate Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via src Parameter ≤ 7.3.3 CVE-2025-0370 Wordfence
6.4 Medium Structured Content (JSON-LD) #wpsc Plugin structured-content Cross-Site Scripting Authenticated (Contributor+) Stored Cross-Site Scripting via sc_fs_local_business Shortcode ≤ 1.6.3 CVE-2025-0512 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only