WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,694 vulnerabilities, 1,872 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 11, 2026.

Showing 8,701–8,750 of 17,220 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 175 of 345
Severity Component Vulnerability Affected versions Published CVE Source
5.4 Medium Wbcom Designs - Activity Link Preview For BuddyPress Plugin activity-link-preview-for-buddypress Server-Side Request Forgery Activity Link Preview For BuddyPress plugin <= 1.4.4 - Server Side Request Forgery (SSRF) No login needed ≤ 1.4.4 Fixed in 1.6.0 CVE-2025-47548 Patchstack
6.5 Medium SendPulse Email Marketing Newsletter Plugin sendpulse-email-marketing-newsletter Cross-Site Scripting ≤ 2.1.6 Fixed in 2.1.7 CVE-2025-47547 Patchstack
7.1 High WP Compress Plugin wp-compress-image-optimizer Cross-Site Request Forgery No login needed ≤ 6.30.30 Fixed in 6.30.31 CVE-2025-47546 Patchstack
5.3 Medium Poll Maker Plugin poll-maker Other Race Condition No login needed ≤ 5.7.7 Fixed in 5.7.8 CVE-2025-47545 Patchstack
7.6 High Dynamic Pricing With Discount Rules for WooCommerce Plugin aco-woo-dynamic-pricing SQL Injection ≤ 4.5.8 Fixed in 4.5.9 CVE-2025-47544 Patchstack
4.3 Medium TrueBooker Plugin truebooker-appointment-booking Cross-Site Request Forgery No login needed ≤ 1.0.7 Fixed in 1.0.8 CVE-2025-47543 Patchstack
4.3 Medium Simple calendar for Elementor Plugin simple-calendar-for-elementor Cross-Site Request Forgery No login needed ≤ 1.6.5 Fixed in 1.6.6 CVE-2025-47542 Patchstack
5.3 Medium weMail Plugin wemail Information Disclosure Sensitive Data Exposure No login needed ≤ 1.14.13 Fixed in 1.14.14 CVE-2025-47540 Patchstack
7.6 High Cart tracking for WooCommerce Plugin cart-tracking-for-woocommerce SQL Injection ≤ 1.0.17 Fixed in 1.0.18 CVE-2025-47538 Patchstack
7.6 High PDF Invoice Builder for WooCommerce Plugin pdf-for-woocommerce SQL Injection ≤ 5.3.8 Fixed in 5.4.0 CVE-2025-47537 Patchstack
8.1 High Graphina Plugin graphina-elementor-charts-and-graphs Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Local File Inclusion No login needed ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47533 Patchstack
7.5 High XT Event Widget for Social Events Plugin xt-facebook-events Local File Inclusion ≤ 1.1.7 Fixed in 1.1.8 CVE-2025-47531 Patchstack
4.3 Medium Ovation Elements Plugin ovation-elements Broken Access Control ≤ 1.1.2 Fixed in 1.1.3 CVE-2025-47528 Patchstack
5.4 Medium GS Variation Swatches for WooCommerce Plugin gs-woo-variation-swatches Broken Access Control ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47526 Patchstack
5.9 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.0 Fixed in 5.3.1 CVE-2025-47525 Patchstack
5.9 Medium Quran multilanguage Text & Audio Plugin quran-text-multilanguage Cross-Site Scripting ≤ 2.3.23 Fixed in 2.3.24 CVE-2025-47524 Patchstack
4.3 Medium Seznam Webmaster Plugin seznam-webmaster Cross-Site Request Forgery No login needed ≤ 1.4.7 Fixed in 1.4.8 CVE-2025-47523 Patchstack
5.9 Medium AWEOS WP Lock Plugin aweos-wp-lock Cross-Site Scripting ≤ 1.4.8 Fixed in 1.4.9 CVE-2025-47522 Patchstack
5.9 Medium Robo Gallery Plugin robo-gallery Cross-Site Scripting ≤ 5.0.2 Fixed in 5.0.3 CVE-2025-47521 Patchstack
5.9 Medium Charitable Plugin charitable Cross-Site Scripting ≤ 1.8.5.1 Fixed in 1.8.5.2 CVE-2025-47520 Patchstack
4.3 Medium Easy PayPal Events Plugin easy-paypal-events-tickets Cross-Site Request Forgery No login needed ≤ 1.2.2 Fixed in 1.3 CVE-2025-47519 Patchstack
5.9 Medium Contact Form 7 – PayPal & Stripe Add-on Plugin contact-form-7-paypal-add-on Cross-Site Scripting PayPal & Stripe Add-on plugin <= 2.3.4 - Cross Site Scripting (XSS) ≤ 2.3.4 Fixed in 2.4.1 CVE-2025-47518 Patchstack
7.1 High Accept Donations with PayPal & Stripe Plugin easy-paypal-donation Cross-Site Request Forgery CSRF to Stored XSS No login needed ≤ 1.4.5 Fixed in 1.5 CVE-2025-47517 Patchstack
5.9 Medium Time Clock Plugin time-clock Cross-Site Scripting ≤ 1.2.3 Fixed in 1.3 CVE-2025-47516 Patchstack
6.5 Medium WP DPE-GES Plugin wp-dpe-ges Cross-Site Scripting ≤ 1.6 Fixed in 1.7 CVE-2025-47515 Patchstack
7.1 High ELI's Related Posts Footer Links and Widget Plugin spostarbust Cross-Site Request Forgery Cross Site Request Forgery (CSRF) to Stored XSS No login needed ≤ 1.2.04.20 Fixed in 1.2.04.25 CVE-2025-47514 Patchstack
7.5 High Display Eventbrite Events Plugin widget-for-eventbrite-api Local File Inclusion ≤ 6.3 Fixed in 6.3 CVE-2025-47510 Patchstack
6.5 Medium Top 10 Plugin top-10 Cross-Site Scripting ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-47509 Patchstack
7.5 High GamiPress Plugin gamipress Local File Inclusion ≤ 7.3.7 Fixed in 7.3.8 CVE-2025-47508 Patchstack
6.5 Medium Better Search Plugin better-search Cross-Site Scripting ≤ 4.1.0 Fixed in 4.1.1 CVE-2025-47507 Patchstack
6.5 Medium Contextual Related Posts Plugin contextual-related-posts Cross-Site Scripting ≤ 4.0.2 Fixed in 4.0.3 CVE-2025-47506 Patchstack
6.5 Medium Product Time Countdown for WooCommerce Plugin product-countdown-for-woocommerce Cross-Site Scripting ≤ 1.6.2 Fixed in 1.6.3 CVE-2025-47505 Patchstack
6.5 Medium Custom Checkout Fields for WooCommerce Plugin custom-checkout-fields-for-woocommerce Cross-Site Scripting ≤ 1.8.3 Fixed in 1.9.0 CVE-2025-47504 Patchstack
6.5 Medium NGG Smart Image Search Plugin ngg-smart-image-search Cross-Site Scripting ≤ 3.3.3 Fixed in 3.4.1 CVE-2025-47503 Patchstack
6.5 Medium Mollie Forms Plugin mollie-forms Cross-Site Scripting ≤ 2.7.12 Fixed in 2.7.13 CVE-2025-47502 Patchstack
6.5 Medium Content Control Plugin content-control Cross-Site Scripting ≤ 2.6.1 Fixed in 2.6.2 CVE-2025-47501 Patchstack
6.5 Medium Simple Blog Stats Plugin simple-blog-stats Cross-Site Scripting ≤ 20250416 Fixed in 20250423 CVE-2025-47499 Patchstack
7.5 High Hotel Booking Plugin nd-booking Local File Inclusion ≤ 3.6 Fixed in 3.7 CVE-2025-47498 Patchstack
6.5 Medium Logo Showcase Plugin logo-showcase Cross-Site Scripting ≤ 3.0.4 Fixed in 3.0.5 CVE-2025-47497 Patchstack
7.5 High PublishPress Authors Plugin publishpress-authors Local File Inclusion ≤ 4.7.5 Fixed in 4.7.6 CVE-2025-47496 Patchstack
6.5 Medium Blockspare Plugin blockspare Cross-Site Scripting ≤ 3.2.9 Fixed in 3.2.10 CVE-2025-47495 Patchstack
7.5 High EventON Plugin eventon-lite Local File Inclusion ≤ 2.4.1 Fixed in 2.4.2 CVE-2025-47494 Patchstack
6.5 Medium Ultimate Blocks Plugin ultimate-blocks Cross-Site Scripting ≤ 3.2.9 Fixed in 3.3.0 CVE-2025-47493 Patchstack
7.4 High Contact Form Widget Plugin new-contact-form-widget Cross-Site Request Forgery No login needed ≤ 1.4.6 Fixed in 1.4.7 CVE-2025-47491 Patchstack
8.5 High Ultimate WP Mail Plugin ultimate-wp-mail SQL Injection ≤ 1.3.4 Fixed in 1.3.5 CVE-2025-47490 Patchstack
6.5 Medium Beds24 Online Booking Plugin beds24-online-booking Cross-Site Scripting ≤ 2.0.29 Fixed in 2.0.30 CVE-2025-47489 Patchstack
6.5 Medium Bold Page Builder Plugin bold-page-builder Cross-Site Scripting ≤ 5.3.2 Fixed in 5.3.3 CVE-2025-47488 Patchstack
5.3 Medium Responsive Plus Plugin responsive-add-ons Broken Access Control No login needed ≤ 3.1.9 Fixed in 3.2.0 CVE-2025-47486 Patchstack
5.3 Medium Cozy Blocks Plugin cozy-addons Broken Access Control No login needed ≤ 2.1.22 Fixed in 2.1.23 CVE-2025-47485 Patchstack
6.4 Medium Display Remote Posts Block Plugin display-remote-posts-block Server-Side Request Forgery ≤ 1.1.0 Fixed in 1.1.1 CVE-2025-47484 Patchstack

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only