WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,651–8,700 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 174 of 345
Severity Component Vulnerability Affected versions Published CVE Source
6.5 Medium WPBakery Visual Composer WHMCS Elements Plugin void-visual-whmcs-element Cross-Site Scripting ≤ 1.0.4.3 CVE-2025-47659 Patchstack
9.3 Critical Productive Commerce Plugin productive-commerce SQL Injection No login needed ≤ 1.1.40 CVE-2025-47657 Patchstack
6.5 Medium Spiraclethemes Site Library Plugin spiraclethemes-site-library Cross-Site Scripting ≤ 1.5.4 Fixed in 1.5.5 CVE-2025-47656 Patchstack
7.1 High theMarketer Plugin themarketer Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47655 Patchstack
7.5 High WP-Recall Plugin wp-recall Local File Inclusion ≤ 16.26.14 CVE-2025-47653 Patchstack
8.8 High Open Close WooCommerce Store Plugin woc-open-close Local File Inclusion ≤ 4.9.9 CVE-2025-47649 Patchstack
7.1 High Pays – WooCommerce Payment Gateway Plugin axima-payment-gateway Cross-Site Request Forgery WooCommerce Payment Gateway plugin <= 2.6 - Cross Site Request Forgery (CSRF) No login needed ≤ 2.6 Fixed in 2.7 CVE-2025-47648 Patchstack
4.3 Medium Sidebar Manager Light Plugin sidebar-manager-light Cross-Site Request Forgery No login needed ≤ 1.18 CVE-2025-47647 Patchstack
4.7 Medium Integrations of Zoho CRM with Elementor form Plugin integrations-of-zoho-crm-with-elementor-form Open Redirect No login needed ≤ 1.0.8 CVE-2025-47644 Patchstack
7.6 High ELEX Product Feed for WooCommerce Plugin elex-product-feed SQL Injection ≤ 3.1.2 CVE-2025-47643 Patchstack
7.1 High Supertext Translation and Proofreading Plugin polylang-supertext Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 4.26 CVE-2025-47639 Patchstack
5.9 Medium WP Discord Invite Plugin wp-discord-invite Cross-Site Scripting ≤ 2.5.3 Fixed in 2.6.0 CVE-2025-47638 Patchstack
7.5 High List category posts Plugin list-category-posts Local File Inclusion ≤ 0.91.0 Fixed in 0.92.0 CVE-2025-47636 Patchstack
5.5 Medium WebinarPress Plugin wp-webinarsystem Server-Side Request Forgery ≤ 1.33.28 CVE-2025-47635 Patchstack
4.3 Medium Awin – Advertiser Tracking for WooCommerce Plugin awin-advertiser-tracking Cross-Site Request Forgery Advertiser Tracking for WooCommerce plugin <= 2.0.0 - CSRF to Product Feed Regeneration No login needed ≤ 2.0.0 Fixed in 2.0.1 CVE-2025-47633 Patchstack
6.5 Medium Awesome Gallery Plugin awesome-gallery Cross-Site Scripting ≤ 1.0 CVE-2025-47632 Patchstack
6.5 Medium Ajax Load More Plugin ajax-load-more Cross-Site Scripting ≤ 7.3.1.2 Fixed in 7.3.1.3 CVE-2025-47630 Patchstack
7.2 High WP-CRM System Plugin wp-crm-system PHP Object Injection ≤ 3.4.5 Fixed in 3.4.6 CVE-2025-47629 Patchstack
5.4 Medium QS Dark Mode Plugin qs-dark-mode Broken Access Control ≤ 3.0 CVE-2025-47628 Patchstack
5.9 Medium Submission DOM tracking for Contact Form 7 Plugin cf7-submission-dom-tracking Cross-Site Scripting ≤ 2.1 Fixed in 2.2 CVE-2025-47626 Patchstack
5.9 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Scripting ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-47625 Patchstack
4.3 Medium DoFollow Case by Case Plugin dofollow-case-by-case Cross-Site Request Forgery No login needed ≤ 3.5.1 Fixed in 3.6.0 CVE-2025-47624 Patchstack
5.9 Medium Easy PayPal Buy Now Button Plugin wp-ecommerce-paypal Cross-Site Scripting ≤ 2.0 Fixed in 2.0.1 CVE-2025-47623 Patchstack
5.9 Medium Email Notification on Login Plugin email-notification-on-login Cross-Site Scripting ≤ 1.7.0 CVE-2025-47622 Patchstack
6.5 Medium Meks Flexible Shortcodes Plugin meks-flexible-shortcodes Cross-Site Scripting ≤ 1.3.6 Fixed in 1.3.7 CVE-2025-47621 Patchstack
7.1 High Martins Free Monetized Ad Exchange Network Plugin martins-free-and-easy-ad-network-get-more-visitors Cross-Site Request Forgery No login needed ≤ 1.0.6 CVE-2025-47620 Patchstack
5.9 Medium WP Front User Submit / Front Editor Plugin front-editor Cross-Site Scripting ≤ 5.0.6 CVE-2025-47617 Patchstack
6.5 Medium aBlocks Plugin ablocks Cross-Site Scripting ≤ 1.9.2 Fixed in 1.9.3 CVE-2025-47616 Patchstack
5.9 Medium Amazon Product in a Post Plugin amazon-product-in-a-post-plugin Cross-Site Scripting ≤ 5.2.2 CVE-2025-47615 Patchstack
4.3 Medium LessButtons Social Sharing and Statistics Plugin lessbuttons Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.6.1 CVE-2025-47614 Patchstack
5.4 Medium ClickWhale Plugin clickwhale Broken Access Control ≤ 2.4.6 Fixed in 2.4.7 CVE-2025-47612 Patchstack
4.3 Medium EasyMe Connect Plugin easyme-connect Cross-Site Request Forgery No login needed ≤ 3.0.3 Fixed in 3.0.4 CVE-2025-47609 Patchstack
5.9 Medium Show All Comments Plugin show-all-comments-in-one-page Cross-Site Scripting ≤ 7.0.1 CVE-2025-47607 Patchstack
4.3 Medium Simple Giveaways Plugin giveasap Cross-Site Request Forgery No login needed ≤ 2.49.0 CVE-2025-47606 Patchstack
5.9 Medium WP jQuery DataTable Plugin wp-jquery-datatable Cross-Site Scripting ≤ 4.1.0 CVE-2025-47605 Patchstack
6.5 Medium Inline Related Posts Plugin intelly-related-posts Cross-Site Scripting ≤ 3.8.0 Fixed in 3.9.0 CVE-2025-47604 Patchstack
5.4 Medium Calculate Prices based on Distance For WooCommerce Plugin calculate-prices-based-on-distance-for-woocommerce Broken Access Control ≤ 1.3.5 Fixed in 1.3.6 CVE-2025-47602 Patchstack
4.3 Medium WP Podcasts Manager Plugin wp-podcasts-manager Cross-Site Request Forgery No login needed ≤ 1.3 Fixed in 1.4 CVE-2025-47597 Patchstack
4.3 Medium Beacon Lead Magnets and Lead Capture Plugin beacon-by Cross-Site Request Forgery No login needed ≤ 1.5.8 Fixed in 1.5.9 CVE-2025-47596 Patchstack
5.9 Medium Color Your Bar Plugin color-your-bar Cross-Site Scripting ≤ 2.0 CVE-2025-47595 Patchstack
4.3 Medium Soccer Live Scores Plugin soccer-live-scores Cross-Site Request Forgery No login needed ≤ 1.0.5 CVE-2025-47594 Patchstack
5.9 Medium Really Simple Under Construction Page Plugin really-simple-under-construction Cross-Site Scripting ≤ 1.4.6 CVE-2025-47593 Patchstack
5.9 Medium Terms Popup On User Login Plugin terms-popup-on-user-login Cross-Site Scripting TPUL plugin <= 2.0.8 - Cross Site Scripting (XSS) ≤ 2.0.8 Fixed in 2.0.9 CVE-2025-47592 Patchstack
4.3 Medium Bulk Featured Image Plugin bulk-featured-image Broken Access Control ≤ 1.2.4 CVE-2025-47591 Patchstack
4.3 Medium WPSpeed Plugin wpspeed Cross-Site Request Forgery No login needed ≤ 2.6.5 Fixed in 2.6.6 CVE-2025-47590 Patchstack
6.5 Medium Ebook Store Plugin ebook-store Cross-Site Scripting ≤ 5.8009 Fixed in 5.8010 CVE-2025-47589 Patchstack
7.6 High YaySMTP Plugin yaysmtp SQL Injection ≤ 2.6.4 Fixed in 2.6.5 CVE-2025-47587 Patchstack
4.3 Medium Wiki Embed Plugin wiki-embed Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Settings Change No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47551 Patchstack
6.6 Medium Instantio Plugin instantio Arbitrary File Upload ≤ 3.3.16 Fixed in 3.3.17 CVE-2025-47550 Patchstack
9.1 Critical BEAF Plugin beaf-before-and-after-gallery Arbitrary File Upload ≤ 4.6.10 Fixed in 4.6.11 CVE-2025-47549 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only