WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,501–8,550 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 171 of 345
Severity Component Vulnerability Affected versions Published CVE Source
4.3 Medium Bot for Telegram on WooCommerce Plugin bot-for-telegram-on-woocommerce Broken Access Control ≤ 1.2.6 Fixed in 1.2.7 CVE-2025-48268 Patchstack
6.5 Medium Active Products Tables for WooCommerce Plugin profit-products-tables-for-woocommerce Cross-Site Scripting ≤ 1.0.6.8 Fixed in 1.0.6.9 CVE-2025-48266 Patchstack
4.3 Medium Year Make Model Search for WooCommerce Plugin ymm-search Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.0.11 Fixed in 1.0.12 CVE-2025-48265 Patchstack
4.3 Medium Product Code for WooCommerce Plugin product-code-for-woocommerce Cross-Site Request Forgery CSRF to Database Update No login needed ≤ 1.5.0 Fixed in 1.5.1 CVE-2025-48264 Patchstack
6.5 Medium MultiVendorX Plugin dc-woocommerce-multi-vendor Cross-Site Scripting ≤ 4.2.22 Fixed in 4.2.23 CVE-2025-48263 Patchstack
4.3 Medium Url Rewrite Analyzer Plugin url-rewrite-analyzer Broken Access Control ≤ 1.3.3 Fixed in 1.3.4 CVE-2025-48262 Patchstack
4.3 Medium GDPR CCPA Compliance Support Plugin ninja-gdpr-compliance Broken Access Control ≤ 2.7.3 Fixed in 2.7.4 CVE-2025-48260 Patchstack
4.3 Medium WP Mapa Politico España Plugin wp-mapa-politico-spain Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 3.8.0 Fixed in 3.8.1 CVE-2025-48259 Patchstack
6.5 Medium Mega Menu Block Plugin getwid-megamenu Cross-Site Scripting ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-48258 Patchstack
6.5 Medium Projectopia Plugin projectopia-core Broken Access Control ≤ 5.1.17 Fixed in 5.1.18 CVE-2025-48257 Patchstack
6.5 Medium Import Social Events Plugin import-facebook-events Cross-Site Scripting ≤ 1.8.5 Fixed in 1.8.6 CVE-2025-48256 Patchstack
4.3 Medium Broadcast Live Video Plugin videowhisper-live-streaming-integration Cross-Site Request Forgery Live Streaming : WebRTC, HLS, RTSP, RTMP plugin <= 6.2.4 - Cross Site Request Forgery (CSRF) No login needed ≤ 6.2.4 Fixed in 6.2.5 CVE-2025-48255 Patchstack
6.5 Medium Change Add to Cart Button Text for WooCommerce Plugin add-to-cart-button-labels-for-woocommerce Cross-Site Scripting ≤ 2.2.2 Fixed in 2.2.3 CVE-2025-48254 Patchstack
6.5 Medium Free Shipping Bar: Amount Left for Free Shipping for WooCommerce Plugin amount-left-free-shipping-woocommerce Cross-Site Scripting ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-48253 Patchstack
6.5 Medium Back Button Widget Plugin back-button-widget Cross-Site Scripting ≤ 1.6.8 Fixed in 1.7.0 CVE-2025-48252 Patchstack
6.5 Medium Additional Custom Emails & Recipients for WooCommerce Plugin custom-emails-for-woocommerce Cross-Site Scripting ≤ 3.5.1 Fixed in 3.5.2 CVE-2025-48251 Patchstack
6.5 Medium Coupons & Add to Cart by URL Links for WooCommerce Plugin url-coupons-for-woocommerce-by-algoritmika Cross-Site Scripting ≤ 1.7.7 Fixed in 1.7.8 CVE-2025-48250 Patchstack
6.5 Medium EAN for WooCommerce Plugin ean-for-woocommerce Cross-Site Scripting ≤ 5.4.6 Fixed in 5.4.7 CVE-2025-48249 Patchstack
6.5 Medium Sitewide Discount for WooCommerce: Apply Discount to All Products Plugin global-shop-discount-for-woocommerce Cross-Site Scripting ≤ 2.2.1 Fixed in 2.2.2 CVE-2025-48248 Patchstack
4.3 Medium Shortlinks by Pretty Links Plugin pretty-link Broken Access Control ≤ 3.6.15 Fixed in 3.6.16 CVE-2025-48247 Patchstack
5.4 Medium The Events Calendar Plugin the-events-calendar Broken Access Control ≤ 6.11.2.1 Fixed in 6.12.0 CVE-2025-48246 Patchstack
5.9 Medium Exclusive Addons Elementor Plugin exclusive-addons-for-elementor Cross-Site Scripting ≤ 2.7.9 Fixed in 2.7.9.1 CVE-2025-48244 Patchstack
4.3 Medium reCAPTCHA for all Plugin recaptcha-for-all Cross-Site Request Forgery No login needed ≤ 2.26 Fixed in 2.27 CVE-2025-48243 Patchstack
6.5 Medium Legal Pages Plugin legal-pages Broken Access Control ≤ 1.4.5 Fixed in 1.4.6 CVE-2025-48242 Patchstack
6.5 Medium Cost of Goods for WooCommerce Plugin cost-of-goods-for-woocommerce Cross-Site Scripting ≤ 3.7.0 Fixed in 3.7.1 CVE-2025-48240 Patchstack
6.5 Medium Product Notes Tab & Private Admin Notes for WooCommerce Plugin product-notes-for-woocommerce Cross-Site Scripting ≤ 3.1.0 Fixed in 3.1.1 CVE-2025-48239 Patchstack
7.1 High AWcode Toolkit Plugin awcode-toolkit Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.18 Fixed in 1.0.19 CVE-2025-48238 Patchstack
6.5 Medium Wishlist for WooCommerce Plugin wish-list-for-woocommerce Cross-Site Scripting ≤ 3.2.2 Fixed in 3.2.3 CVE-2025-48237 Patchstack
8.5 High bunny.net Plugin bunnycdn Cross-Site Scripting ≤ 2.3.0 Fixed in 2.3.1 CVE-2025-48236 Patchstack
6.5 Medium WP Image Mask Plugin wp-image-mask Cross-Site Scripting ≤ 3.1.2 Fixed in 3.1.3 CVE-2025-48235 Patchstack
6.5 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting ≤ 3.3.0 Fixed in 3.3.1 CVE-2025-48234 Patchstack
7.1 High Affiliates Manager Google reCAPTCHA Integration Plugin affiliates-manager-google-recaptcha-integration Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.0.6 Fixed in 1.0.7 CVE-2025-48233 Patchstack
6.5 Medium Xpro Addons For Beaver Builder – Lite Plugin xpro-addons-beaver-builder-elementor Cross-Site Scripting Lite plugin <= 1.5.5 - Cross Site Scripting (XSS) ≤ 1.5.5 Fixed in 1.5.6 CVE-2025-48232 Patchstack
6.4 Medium EventON - WordPress Virtual Event Calendar Plugin Broken Access Control WordPress Virtual Event Calendar Plugin <= 4.9.6 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting ≤ 4.9.6 CVE-2025-3527 Wordfence
8.1 High WPBot Pro Wordpress Chatbot Plugin Arbitrary File Deletion Authenticated (Subscriber+) Arbitrary File Deletion ≤ 13.6.2 CVE-2025-3812 Wordfence
4.3 Medium Wishlist Plugin wishlist Information Disclosure Sensitive Data Exposure ≤ 2.1.0 CVE-2025-31062 Patchstack
5.3 Medium Rozario Theme rozario Broken Access Control No login needed ≤ 1.4 CVE-2025-31065 Patchstack
4.3 Medium Wishlist Plugin wishlist Broken Access Control ≤ 2.1.0 CVE-2025-31063 Patchstack
4.3 Medium Seven Stars Theme sevenstars Cross-Site Request Forgery No login needed ≤ 1.4.4 CVE-2025-31068 Patchstack
5.3 Medium Acerola Plugin acerola Broken Access Control No login needed ≤ 1.6.5 CVE-2025-31066 Patchstack
5.3 Medium The Business Theme nrgbusiness Broken Access Control No login needed ≤ 1.6.1 CVE-2025-31630 Patchstack
5.3 Medium HotStar – Multi-Purpose Business Theme hotstar Broken Access Control Multi-Purpose Business Theme <= 1.4 - Broken Access Control No login needed ≤ 1.4 CVE-2025-31071 Patchstack
4.3 Medium Spare Theme spare Cross-Site Request Forgery No login needed ≤ 1.7 CVE-2025-31639 Patchstack
8.5 High SHOUT Plugin lbg-audio8-html5-radio_ads SQL Injection ≤ 3.5.3 CVE-2025-31637 Patchstack
8.5 High UberSlider Plugin uber-classic SQL Injection ≤ 2.6 Fixed in 2.6 CVE-2025-31641 Patchstack
8.5 High Magic Responsive Slider and Carousel Plugin magic-carousel SQL Injection ≤ 1.6 Fixed in 1.6 CVE-2025-31640 Patchstack
4.3 Medium WP Ultimate Tours Builder Plugin wp_ultimatetoursbuilder Cross-Site Request Forgery No login needed ≤ 1.055 CVE-2025-31921 Patchstack
5.4 Medium Pixel WordPress Form BuilderPlugin & Autoresponder Plugin pixel-formbuilder Cross-Site Request Forgery No login needed ≤ 1.0.3 Fixed in 1.0.4 CVE-2025-31915 Patchstack
5.4 Medium CSS3 Accordions Plugin css3_accordions Broken Access Control ≤ 3.0 Fixed in 3.1 CVE-2025-31923 Patchstack
7.1 High CSS3 Accordions Plugin css3_accordions Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 3.0 Fixed in 3.1 CVE-2025-31922 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only