WordPress vulnerability database
Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.
Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.
Showing 8,601–8,650 of 17,220 vulnerabilities matching your filters
| Severity | Component | Vulnerability | Affected versions | Published | CVE | Source |
|---|---|---|---|---|---|---|
| 7.1 High | ShayanWeb Admin FontChanger | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 1.9.1 Fixed in 1.10 |
CVE-2025-48114 |
Patchstack | |
| 6.5 Medium | Broadstreet Ads | Cross-Site Scripting |
≤ 1.51.2 Fixed in 1.51.3 |
CVE-2025-48113 |
Patchstack | |
| 7.1 High | Dot html,php,xml etc pages | Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed |
≤ 1.0 |
CVE-2025-48112 |
Patchstack | |
| 6.5 Medium | Uncanny Toolkit for LearnDash | Cross-Site Scripting |
≤ 3.7.0.2 Fixed in 3.7.0.3 |
CVE-2025-48080 |
Patchstack | |
| 4.3 Medium | ProfileGrid | Broken Access Control |
≤ 5.9.5.1 Fixed in 5.9.5.2 |
CVE-2025-48079 |
Patchstack | |
| 4.8 Medium | WolfNet IDX | Cross-Site Scripting Admin+ Stored XSS |
≤ 1.19.1 |
CVE-2023-6783 |
WPScan | |
| 4.8 Medium | AI ChatBot for WordPress – WPBot | Cross-Site Scripting WPBot < 6.2.4 - Admin+ Stored XSS |
< 6.2.4 Fixed in 6.2.4 |
CVE-2025-0329 |
WPScan | |
| 4.8 Medium | MapPress Maps | Cross-Site Scripting Admin+ Stored XSS via Map Settings |
< 2.93 Fixed in 2.93 |
CVE-2024-8620 |
WPScan | |
| 4.8 Medium | Hustle | Cross-Site Scripting Admin+ Stored XSS |
≤ 7.8.5 |
CVE-2024-8492 |
WPScan | |
| 4.3 Medium | Joy Of Text Lite – SMS messaging | Cross-Site Request Forgery SMS messaging for WordPress <= 2.3.1 - Settings Update via CSRF No login needed |
≤ 2.3.1 |
CVE-2024-7984 |
WPScan | |
| 4.8 Medium | Clicksold IDX | Cross-Site Scripting Admin+ XSS |
≤ 1.90 |
CVE-2024-7769 |
WPScan | |
| 4.8 Medium | Simple Share | Cross-Site Scripting Admin+ XSS |
≤ 0.5.3 |
CVE-2024-7556 |
WPScan | |
| 4.8 Medium | Podlove Podcast Publisher | Cross-Site Scripting Admin+ Stored XSS |
< 4.2.1 Fixed in 4.2.1 |
CVE-2024-13730 |
WPScan | |
| 4.8 Medium | Podlove Podcast Publisher | Cross-Site Scripting Admin+ Stored XSS |
< 4.1.24 Fixed in 4.1.24 |
CVE-2024-13729 |
WPScan | |
| 4.8 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS |
< 4.2.7.5.1 Fixed in 4.2.7.5.1 |
CVE-2024-13128 |
WPScan | |
| 4.8 Medium | LearnPress – WordPress LMS | Cross-Site Scripting WordPress LMS Plugin < 4.2.7.5.1 - Admin+ Stored XSS |
< 4.2.7.5.1 Fixed in 4.2.7.5.1 |
CVE-2024-13127 |
WPScan | |
| 6.1 Medium | WordPress连接微博 | Cross-Site Scripting Stored XSS via CSRF No login needed |
≤ 2.5.6 |
CVE-2024-12282 |
WPScan | |
| 4.8 Medium | Panorama – WordPress Project Management | Cross-Site Scripting WordPress Project Management Plugin <= 1.5.1 - Admin+ Stored XSS |
≤ 1.5.1 |
CVE-2024-11843 |
WPScan | |
| 6.1 Medium | tarteaucitron.js | Cross-Site Scripting Stored XSS via CSRF No login needed |
< 0.3.0 Fixed in 0.3.0 |
CVE-2024-11719 |
WPScan | |
| 5.4 Medium | tarteaucitron.js | Cross-Site Scripting Author+ Stored XSS |
< 0.3.0 Fixed in 0.3.0 |
CVE-2024-11718 |
WPScan | |
| 4.3 Medium | Tours | Broken Access Control |
≤ 1.0.0 Fixed in 1.0.1 |
CVE-2024-51666 |
Patchstack | |
| 5.3 Medium | Jetpack Debug Tools | Broken Access Control No login needed |
< 2.0.1 Fixed in 2.0.1 |
CVE-2024-56006 |
Patchstack | |
| 7.1 High | WP2LEADS | Cross-Site Request Forgery No login needed |
≤ 3.5.0 Fixed in 3.5.1 |
CVE-2025-32922 |
Patchstack | |
| 5.4 Medium | Front End Users | Broken Access Control |
≤ 3.2.35 |
CVE-2025-47580 |
Patchstack | |
| 7.5 High | Eventin | Path Traversal Arbitrary File Download No login needed |
≤ 4.0.26 Fixed in 4.0.27 |
CVE-2025-47445 |
Patchstack | |
| 9.3 Critical | SMS Alert Order Notifications | SQL Injection WooCommerce plugin <= 3.8.1 - SQL Injection No login needed |
≤ 3.8.1 Fixed in 3.8.2 |
CVE-2025-47682 |
Patchstack | |
| 6.5 Medium | BNS Twitter Follow Button | Cross-Site Scripting |
≤ 0.3.8 |
CVE-2025-47578 |
Patchstack | |
| 8.8 High | WordPress Review Plugin: The Ultimate Solution for Building a Review Website | Local File Inclusion Authenticated (Contributor+) Local File Inclusion via Post Custom Fields |
≤ 5.3.5 |
CVE-2025-2158 |
Wordfence | |
| 7.2 High | WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg | Arbitrary File Deletion Authenticated (Administrator+) Arbitrary File Deletion |
≤ 4.1.1.2 |
CVE-2025-4206 |
Wordfence | |
| 8.8 High | 1 Click WordPress Migration Plugin – 100% FREE for a limited time | Broken Access Control Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload |
≤ 2.2 |
CVE-2025-3455 |
Wordfence | |
| 4.3 Medium | Contentstudio | Broken Access Control |
≤ 1.3.5 Fixed in 1.3.7 |
CVE-2025-47692 |
Patchstack | |
| 5.5 Medium | Ultimate Member | Remote Code Execution Arbitrary Function Call |
≤ 2.10.3 Fixed in 2.10.4 |
CVE-2025-47691 |
Patchstack | |
| 5.3 Medium | Advanced File Manager | Broken Access Control Broken Access Control to Notice Dismissal No login needed |
≤ 5.3.1 Fixed in 5.3.2 |
CVE-2025-47688 |
Patchstack | |
| 6.5 Medium | DELUCKS SEO | Cross-Site Scripting |
≤ 2.5.9 Fixed in 2.6.0 |
CVE-2025-47686 |
Patchstack | |
| 7.1 High | Contribuinte Checkout | Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed |
≤ 2.0.03 Fixed in 2.0.04 |
CVE-2025-47685 |
Patchstack | |
| 5.4 Medium | Smaily for WP | Cross-Site Request Forgery No login needed |
≤ 3.1.7 |
CVE-2025-47684 |
Patchstack | |
| 7.2 High | WP Maintenance | PHP Object Injection |
≤ 6.1.9.7 Fixed in 6.1.9.8 |
CVE-2025-47683 |
Patchstack | |
| 4.3 Medium | Web Accessibility with Max Access | Cross-Site Request Forgery No login needed |
≤ 2.0.9 Fixed in 2.1.0 |
CVE-2025-47681 |
Patchstack | |
| 6.5 Medium | RS WP Book Showcase | Cross-Site Scripting |
≤ 6.7.59 |
CVE-2025-47679 |
Patchstack | |
| 6.5 Medium | Photo Gallery | Cross-Site Scripting GT3 Image Gallery & Gutenberg Block Gallery plugin <= 2.7.7.25 - Cross Site Scripting (XSS) |
≤ 2.7.7.25 Fixed in 2.7.7.26 |
CVE-2025-47677 |
Patchstack | |
| 6.5 Medium | User Login History | Cross-Site Scripting |
≤ 2.1.6 Fixed in 2.1.7 |
CVE-2025-47676 |
Patchstack | |
| 6.5 Medium | Woobox | Cross-Site Scripting |
≤ 1.6 Fixed in 1.7 |
CVE-2025-47675 |
Patchstack | |
| 4.3 Medium | Credova_Financial | Cross-Site Request Forgery No login needed |
≤ 2.5.0 Fixed in 2.5.1 |
CVE-2025-47674 |
Patchstack | |
| 6.5 Medium | CBX Map for Google Map & OpenStreetMap | Cross-Site Scripting |
≤ 1.1.12 Fixed in 2.0.0 |
CVE-2025-47669 |
Patchstack | |
| 5.9 Medium | CookieCode | Cross-Site Scripting |
≤ 2.4.4 |
CVE-2025-47668 |
Patchstack | |
| 5.4 Medium | LiveAgent | Cross-Site Request Forgery No login needed |
≤ 4.4.7 Fixed in 4.4.8 |
CVE-2025-47667 |
Patchstack | |
| 5.9 Medium | N360 | Splash Screen | Cross-Site Scripting |
≤ 1.0.6 Fixed in 1.0.7 |
CVE-2025-47665 |
Patchstack | |
| 4.4 Medium | WP Pipes | Server-Side Request Forgery |
≤ 1.4.2 |
CVE-2025-47664 |
Patchstack | |
| 6.5 Medium | Woobox | Cross-Site Scripting |
≤ 1.6 Fixed in 1.7 |
CVE-2025-47662 |
Patchstack | |
| 5.4 Medium | 워드프레스 결제 심플페이 | Cross-Site Request Forgery No login needed |
≤ 5.2.11 Fixed in 5.3.3 |
CVE-2025-47661 |
Patchstack |
About this data
- Where it comes from
- Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
- What is included
- CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
- Severity
- The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
- Affected versions
- The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
- Updates
- Every day, after the CVE List publishes its end-of-day changes.
CVE® records are © The MITRE Corporation and used under the CVE Terms of Use. CVE is a registered trademark of The MITRE Corporation.